Feeds

Don't let hackers know Mandiant founder checks his email on an iPad. Oh.

Mandia prefers face-to-face natter to avoid piles of spyware booby-traps

Internet Security Threat Report 2014

Infosec 2014 Mandiant boss Kevin Mandia says he has cut back on email and only uses an iPad to check his inbox as he fends off counterattacks from hackers.

In 2013, the company published a landmark report on the so-called APT1 espionage crew: the detailed dossier claimed Shanghai-based People's Liberation Army Unit 61398 had hacked and injected malware into 141 organisations globally over seven years, and swiped terabytes of corporate secrets as a result.

Months later it emerged hackers had lifted personal information from CorporateCarOnline, a limousine-booking firm used by Mandia as well as basketball star LeBron James, Donald Trump and many other famous figures.

Data grabbed from the limo biz included names and addresses and credit numbers in a plain-text archive, plus travel records and instructions to drivers. The records were found on the same servers used by hackers to store information stolen from PR Newswire as well as source code taken from Adobe, investigative journalist Brian Krebs reported in November 2013.

Around that time, Mandia received emails with spyware-loaded PDFs of limo invoices. The US Air Force officer-turned-businessman said he strongly suspected the Chinese were behind that phishing expedition.

"People try to hack us all the time," Mandia told The Reg at the Infosec trade show in London last week.

Mandiant was acquired by FireEye in a stock-and-cash deal worth more than $1bn, a move that installed Mandia as FireEye's COO. In his new role, and as before, Mandia insists security breaches of one sort or another are inevitable, so his strategy is to minimise the consequences of a system compromise.

"I try to do as much business as I can either face-to-face or on the phone," Mandia explained by way of example. "I don't do a lot of email and, when I do, I use an iPad."

The Kremlin raised ripples in the security world this year by ditching iPads for Android tablets from Samsung. Politicians, government officials and high-profile business folk have long been the target of espionage, online and offline, but as the world becomes more and more connected, spying is likely to increase.

"I'd advise firms not to keep what they don't need and to keep their internet presence small – contrary to what marketing may say," he advised.

Hall of mirrors

APT1 is very much back in business after a "brief hiatus", according to Mandia. The hacking gang is using a whole new infrastructure built after infiltrating systems at universities and small businesses in the US. These compromised assets – "thousands of new victims", we're told – are used as launch pads for lucrative espionage missions, Mandia said.

He also argued the actions of NSA whistleblower Edward Snowden have had no effect on cyber-espionage activity. "Nation states that are hacking are still hacking," Mandia noted.

The self-styled Syrian Electronic Army, miscreants in Iran, Russia, Ukraine and China, and Anonymous hacktivists are the main cast in Mandiant's cyber-threat theatre. Most of the firm's clients are either US organisations or multi-national corps.

Mandia, who served in Uncle Sam's air force and in the Pentagon before leaving for the private sector, said Mandiant "hadn't seen" any cyber-espionage activity that traced back to the United States, maintaining that US spooks hack foreigners for "security reasons and not economic" reasons. Judging by Snowden-sourced documents, NSA cyber-spies allegedly raided oil giant Petrobras in Brazil and the Mexican president's email inbox for those aforementioned security reasons, it seems. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Choosing a cloud hosting partner with confidence
Download Choosing a Cloud Hosting Provider with Confidence to learn more about cloud computing - the new opportunities and new security challenges.