National Security Agency exposes tool used by Russian hackers

World 11:35 29.05.2020

The National Security Agency on Thursday publicly accused an infamous Russian hacking group of exploiting a flaw in software commonly found in Linux computers, EDNews.net reports citing Stars and Stripes.

The NSA said it observed hackers from a unit within the GRU, a Russian intelligence agency, using the flaw in order to gain access to computers.

The flaw exists in software called “Exim,” known as a Message Transfer Agent, which helps facilitate the sending of email, according to the agency. The hacking group, known as Sandworm, has been exploiting the flaw since August 2019, the NSA said.

By exposing how the flaw works, the NSA effectively sought to remove a tool from the Russian hacking arsenal.

The announcement marks a subtle escalation between the two intelligence agencies and comes after an executive order issued by President Donald Trump in 2018 that gave the Department of Defense, which includes the NSA, new powers to call out foreign hacking operations and to conduct more of their own.

“An unauthenticated remote attacker can send a specially crafted email to execute commands with root privileges allowing the attacker to install programs, modify data and create new accounts,” the NSA press release said. The agency is urging users and administrators to apply an already released fix for the Exim flaw. The agency didn’t provide any details on which computer systems the Russian hackers had compromised using the flaw.

Sandworm has been linked to devastating hacks in Ukraine, twice shutting down the country’s power grid and other essential services. The group has also been accused by the U.S. as being behind the infamous NotPetya virus, which decimated computer networks at major companies including Merck & Co. Inc., and attacks on the 2018 Winter Olympics.

In February, the U.S. State Department linked Sandworm to the attacks on Georgian government websites and television stations.

Until recently, it was exceedingly rare for the U.S. government to link hacking operations to the intelligence agencies of foreign governments. When it did occur, it was often through formal documents accompanied by extensive evidence, like the Justice Department indictments of five Chinese military hackers in 2014.But as the aggressiveness of those hacking operations has increased, so has the pressure to name the intelligence agencies and even the specific units involved.

In the case of Russia, the GRU’s operations, including the hacking of participants in the 2016 U.S. presidential election, have made it a particular focus of NSA’s efforts over the last four years.

Former UK Ambassador: ‘Negotiations between Azerbaijan, Armenia without mediators are big step’

News line

Russian deputy defense minister arrested for two months
Russian deputy defense minister arrested for two months
12:45 24.04.2024
China urges US to stop arming Taiwan
China urges US to stop arming Taiwan
12:30 24.04.2024
The Gulf Observer Highlights Return of Four Gazakh Villages
12:25 24.04.2024
Zelensky thanks the US Senate for aid package
Zelensky thanks the US Senate for aid package
12:15 24.04.2024
Magnitude 5.4 quake hits coast of Tonga
Magnitude 5.4 quake hits coast of Tonga
11:55 24.04.2024
Russian attack injures six people in Ukraine's Kharkiv, governor says
11:44 24.04.2024
Kyrgyz President leaves for Azerbaijan - UPDATED
Kyrgyz President leaves for Azerbaijan - UPDATED
11:34 24.04.2024
CSTO Secretary-General: ‘Armenia should assess security threats’
11:10 24.04.2024
Ammunition found in Azerbaijan’s Khankandi
Ammunition found in Azerbaijan’s Khankandi
10:54 24.04.2024
Umud Mirzayev Condemns Flag Burning Incident in Yerevan, Highlights Role of Armenian Separatists
10:33 24.04.2024
President Ilham Aliyev: Armenia blocks possibility of building land connection with Nakhchivan Autonomous Republic
President Ilham Aliyev: Armenia blocks possibility of building land connection with Nakhchivan Autonomous Republic
10:14 24.04.2024
"Significance of Russian 'Peacekeeper' Withdrawal in South Caucasus - Insights from Political Expert Neil Watson
10:00 24.04.2024
Ilham Aliyev: Education of the young generation is one of our main priorities
09:46 24.04.2024
President: France, India, and Greece weaponizing Armenia against us—we can't just sit and wait
09:30 24.04.2024
Joe Biden to sign Ukraine aid bill on April 24
09:17 24.04.2024
President: Attainable to reach Azerbaijan-Armenia agreement before COP29, even on basic principles
09:02 24.04.2024
President Ilham Aliyev: We never forgot about issue of four villages
08:53 24.04.2024
President of Azerbaijan: 'World to need fossil fuels for many more years'
President of Azerbaijan: 'World to need fossil fuels for many more years'
23:00 23.04.2024
AI giants adopt safety measures to prevent child exploitation
AI giants adopt safety measures to prevent child exploitation
22:00 23.04.2024
Former UK Ambassador: ‘Negotiations between Azerbaijan, Armenia without mediators are big step’
21:00 23.04.2024
Raisi: There could be nothing left of Israel's govt if it attacks again
20:25 23.04.2024
President Aliyev: We aim for COP29's success in addressing climate change issue
20:00 23.04.2024
Lithuania welcomes agreement between Azerbaijan and Armenia
Lithuania welcomes agreement between Azerbaijan and Armenia
19:19 23.04.2024
Ukraine receives armored personnel carriers from Lithuania
Ukraine receives armored personnel carriers from Lithuania
19:00 23.04.2024
Sergey Stankevich: 'Soon, the new era in the history of the South Caucasus will be talked' - INTERVIEW
18:45 23.04.2024
Armenian Parliament rejected draft of opposition regarding border delimitation with Azerbaijan
18:18 23.04.2024
Pundit: Iran sees Azerbaijan as a potential threat to itself
18:00 23.04.2024
Czechia to hold extraordinary meeting of NATO foreign ministers in May
17:48 23.04.2024
Australian PM calls Elon Musk an 'arrogant billionaire' in row over attack footage
Australian PM calls Elon Musk an 'arrogant billionaire' in row over attack footage
17:29 23.04.2024
Umud Mirzayev: 'Revanchist politics led Armenia to disaster'
17:15 23.04.2024
Ilham Aliyev: Azerbaijan closely partners with all Eurasian Union members, except Armenia.
17:00 23.04.2024
Peacekeepers leaving Karabakh, peace in the South Caucasus, World War III? - Expert talk on Ednews
16:45 23.04.2024
Chinese Entities Procure Nvidia Chips Despite US Export Restrictions
Chinese Entities Procure Nvidia Chips Despite US Export Restrictions
16:33 23.04.2024
First border marker installed along Azerbaijan-Armenia border
16:25 23.04.2024
Poland: We’re ready to host nuclear weapons
16:12 23.04.2024
President: Azerbaijan's economy is self-sufficient and shows sustainable growth even during crises
15:58 23.04.2024
Iran's attack on Israel, withdrawal of Russian peacekeepers, peace talks... - Insights from Andrew Korybko
15:35 23.04.2024
Azerbaijani, Czech FMs make speech at joint press conference
14:46 23.04.2024
Ilham Aliyev participating in international forum themed ‘COP29 and Green Vision for Azerbaijan’ at ADA University - VİDEO
14:22 23.04.2024
Erdogan warns Armenia: Opportunities doors are never left open forever
14:12 23.04.2024
Hamısı