Here's a high-res image of SVR headquarters (former First Chief Directorate, KGB) that I purchased for my book, by Marina Lystseva
Also, a subtle point on terminology: exfiltrating data from regular foreign intelligence targets — however stealthy, targeted, or labor-intensive — should not be called an "attack." An intrusion becomes an attack when adversaries modify, delete, or leak targeted files.
Yes, that’s better https://twitter.com/ildannymoore/status/1338553048768110594
The exploitation of the SolarWinds updates/installs has been going on since at least March, so about 9 months. It's not over. Shutting the backdoor is one thing. Getting an advanced, persistent, stealthy adversary out of your network is another thing.
SolarWinds appears to be an excellent entry point into a large number of high-value intelligence targets ("fewer than 18,000," according to SolarWinds). The adversary likely faced a permanent tension throughout the entire campaign: scale up or keep tight OPSEC?
That tension came to a head with the targeting of FireEye — which appears to have been the undoing of the entire campaign. A very imprudent, probably arrogant move. Somebody in Yasenevo likely got into deep trouble for going after Mandiant.
You can follow @RidT.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.