Feeds

Krebs nabs ‘RSA attack’ list

Hundreds of networks hit

Choosing a cloud hosting partner with confidence

When RSA’s network security was breached earlier this year, the result wasn’t only the replacement of its SecurID tokens all over the world.

At the time, specialists believed that similar techniques could have been deployed against other victims who mostly didn’t go public. Only a handful of stories confirmed the use of information gained in the “RSA hack” to other targets – such as Lockheed-Martin and L-3 Communications.

Now, Krebs On Security has published a list of networks that carried attack traffic of some kind, either because hosts on the networks were compromised, because malicious traffic traversed the networks from other sources, or because researchers were building infected machines to observe their phone-home behaviour.

Most of the command servers were in China, he writes, with a handful in South Korea, the USA, Brazil, India, Italy, Pakistan and the UK.

As Krebs notes publishing the list, it has to be interpreted carefully. It would, for example, be unfair to assume that Trend Micro or Cisco’s IronPort business were compromised when they were more likely to be researching the attacks. Even so, his report states that around 20 percent of America’s Fortune 500 companies are on the list (keeping in mind, however, that some of those are the likes of Cisco, or telcos whose networks weren’t compromised but whose customers were).

The analysis is based on sources of traffic being sent back to the control machines used in the attack against RSA, and identified traffic sources by their AS names (that is, the names by which the networks advertise their routes).

Krebs notes the presence of names like Facebook, Amazon and Wells fargo on the list, as well as government departments in several countries, and a bunch of academic networks.

The Register’s scan of the list for Australian companies only identifies carriers (AAPT, Amnet, Pacific Internet, Macquarie Telecom, Telstra, TPG Internet, Westnet, Verizon Australia and Optus subsidiary Uecomm among them) and data centres (Micron21). ®

Internet Security Threat Report 2014

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.