United States
美國版塊
Cyber-security
網絡安全
Bear hunt
獵熊
Hackers have vaulted into the heart of America’s government
黑客已經潛入美國政府的核心
On september 25th Russia’s president, Vladimir Putin, warned that a “largescale confrontation in the digital sphere” was looming. He offered a solution. Russia and America would “exchange guarantees of non-interference in each other’s internal affairs, including electoral processes, including using ICT”—in short, a cybertruce. Even as he spoke, his hackers were apparently deep inside some of America’s most sensitive networks.
9月25日,俄羅斯總統弗拉基米爾·普京警告稱,“數字領域的大規模對抗”一觸即發。他提出了一個解決辦法。即俄羅斯和美國將“彼此保證不通過信息和通信技術等方式干涉對方的內政,包括選舉進程”——簡而言之,就是網絡休戰協議。就在普京講話的時候,他手下的黑客顯然已經深入到美國最敏感的一些網絡中。
American officials claim that a group of hackers known as APT29, or more evocatively as Cozy Bear, thought to be part of the SVR, Russia’s foreign intelligence service, penetrated several American government bodies—the list so far includes the Treasury, Commerce, State and Homeland Security Departments, along with the National Institutes of Health—where they could read emails at will. It appears to be one of the largest-ever acts of digital espionage against America.
美國官員聲稱,美國政府認為名為APT29的黑客組織(或者更能讓人想起的舒適熊組織)隸屬于俄羅斯對外情報局(SVR),該組織侵入了幾個美國政府機構。迄今為止,入侵名單包括美國財政部、商務部、國土安全部,以及國立衛生研究院,黑客組織可以隨意瀏覽這些政府機構的電子郵件。這似乎是有史以來針對美國的最大規模的數字間諜活動之一。
The intrusion took a circuitous route. Between March and June, SolarWinds, a Texan company, pushed out updates to its Orion software, which is widely used to help organisations monitor their networks. The malware hitched a ride on those updates. Once downloaded, it allowed hackers to impersonate an organisation’s system administrators, who typically have the run of the entire network. It cleverly funnelled out data by disguising it as legitimate traffic while parrying anti-virus tools. Once inside, intruders can remain present even if Orion is disconnected.
黑客入侵采取了迂回的方式。今年3月至6月,德州公司SolarWinds推出了旗下Orion軟件的更新,該軟件被廣泛用于幫助組織監控其網絡。惡意軟件搭上了更新的便車。一旦下載,黑客就可以冒充一個組織的系統管理員,而系統管理員通常負責整個網絡的運行。惡意軟件巧妙地將數據偽裝成合法流量,同時避開反病毒工具。一旦進入,即使Orion被斷開連接,入侵者也可以繼續存在。
譯文由可可原創,僅供學習交流使用,未經許可請勿轉載。