episode.ascii — live render
● episode

Force on Force

TL;DRIn 2020, Microsoft and a security consortium used a court order and a fake IP redirect (127.0.0.1) to disrupt TrickBot, a massive ransomware-enabling botnet, partly to protect US election infrastructure ahead of the vote.

Jordan Bloemen & Scott Francis Winder discuss the attack on Trickbot.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: H t t p s colon forward slash forward slash one two seven zero zero zero one. Imagine an army, or like a squadron of an army. Now these guys, this squadron, they're running riot on enemy terrain. Every day they're getting a new radio command telling them to take this city or raid this armament or storm this fort, and these guys are ruthless. They wake up, they get their radio command, they do the job, and they repeat. They don't know where they'll be tomorrow, only what they've got to do today. And let's say one morning, they get that radio command, And it says, before I give you your instructions, you're to change radio frequencies. The new channel, 127001. They switch over their radios, and a minute later, the voice comes back and gives them their new command. Standby. So for one whole day, the feared band of men sits and waits. They let their heart rate drop a little. They enjoy the balmy weather and a nice warm night. The next day they wake up, they tune into the radio, and the commands don't come. They wait and they wait until one of the men finally asks if they should check the old frequency. And when they do, when they turn their radios back to their original bandwidth, the one that had been sending them on a reign of terror across the land, they find the normal voice giving the same old command asking where the heck they have been, why they changed frequencies, what was going on. Turns out the squadron had been duped. Someone had found their way onto their frequency and tricked them into changing channels to the wrong bandwidth. And sure, it didn't really last that long. It was a lot of work for one day of calm, but still two important lessons to be learned here. First, a day of calm means that maybe some people who would have bumped into that ruthless squadron didn't. But second, and and this is really the big one, that squadron learned that someone knows how to get onto their radios, which means that they can't really trust a damn thing that comes out of them. Bringing us nicely all the way back around to 01/2001. On September 22, millions of Windows computers that are infected with and a part of the TrickBot botnet received a simple instruction. Your control server has a new address. That address? 127001. For some interesting but complicated reasons, it's impossible for those servers to reach that address. So, they stood by. Someone had hopped on and intentionally told everyone to report to this new address, to tune into this different radio frequency, to just stand by and enjoy the balmy weather. This isn't a story where we explain botnets. We've done that a lot and enough. This isn't even a story about TrickBot, though we are going to start there. This is about who tuned in and gave that fake address 127001. Because who they are, and the fight that they're fighting, that's something kinda new. This is Force on Force, here on Hacked. We're gonna come dangerously close to breaking a promise in this episode.

Speaker 2: I I don't make any promises that I don't keep, Jordan.

Speaker 1: Well, you're gonna come real close to explaining what a botnet is.

Speaker 2: I think I've done that, like, nine times. So maybe we could just pull a sample out of a previous episode.

Speaker 1: I think we can rely on people knowing what a botnet is in this episode.

Speaker 2: Y'all know what a botnet is.

Speaker 1: Y'all know what a botnet is. Let's move forward assuming you know what a botnet is.

Speaker 2: Just pause this episode and go back in time. Look at some of the previous episodes that have botnet in the title.

Speaker 1: So this is a story about TrickBot. And an important thing to know about TrickBot is that TrickBot is a botnet for hire. Scott, what is a botnet for hire?

Speaker 2: Well, it's a botnet, which I'm not gonna explain what it is, that you pay money to access and leverage.

Speaker 1: Right. So someone someone controls all of these different computers, and then someone comes to them and says, I've got some money. I want you to deploy something to the voice.

Speaker 2: Came dangerously close to defining what a botnet is.

Speaker 1: Right up to the edge. I stared into the abyss and it stared back.

Speaker 2: Yes. You approach somebody and say, hey. You control all these computers via your botnet, and I would like to leverage that botnet. How much would you charge me per thousand PCs or whatever the the going rate that they're bartering on is?

Speaker 1: Since 2016, the operators of Tripod have provided customers access to an army of infected machines, giving them a one stop shop delivery mechanism for really whatever kind of malware they wanted to deliver in the first place, including, and importantly for this story, ransomware. This army of machines includes both end user computers and Internet of Things devices, you know, routers, which has extended TrickBot's reach into households and larger brick and mortar organizations. In this, TrickBot is a pretty normal, if not really large botnet. But if we look at its behavior over the four years that it's been operating, two really interesting things about Trickbot pop up. There's what people have hired to do with it, and there's how the operators keep expanding it, how they keep capturing more machines. In terms of the latter, in terms of expanding TrickBot, well, obviously, it starts with phishing.

Speaker 2: The toolbox for hacking really just includes phishing these days. So if you're good at phishing, you can pretty much do Steal Bitcoin, take over computers, shut down the Israeli government, whatever. Just if you know how to fish, it's all you teach a man to fish, he eats her or sorry. Give a man a fish, he eats for a day. Teach a man to fish, he steals Bitcoin for life.

Speaker 1: If you were doing it in the last six months, so you were try you're going you're going fishing?

Speaker 2: Yep. Going fishing.

Speaker 1: What kind of social engineering tactics would you use? What kind of lures would you be putting out there in the world?

Speaker 2: Oh, I think anything contemporary, you know, playing on people's emotions. Same as marketing. You know, Jordan I work in marketing, which we've discussed before. And, you know, hope and fear are the two main emotions that drive people's, decisions. So I would play off of hope and fear. You know, you see that in phishing attacks all the time. You know, you won something, you know, the classic phone scam of, hey, you want a free cruise? You know, click one to receive your prize, and next thing you know, you're giving your Visa number to somebody. Then number two would be, you know, you're dying, somebody's dead, something's hurt, whatever. Play off of the fear. And so those, I think, would be the two ways that I would go.

Speaker 1: And that's exactly the way TrickBot has gone. Imagine you're the operators of TrickBot and you're trying to capture more machines using spam and spear phishing attacks. Seven or so months ago, you were given the single best lure a spear fisherman could ever help for. Of course,

Speaker 3: one of the key issues tomorrow night is expected to be the coronavirus.

Speaker 4: As our nation climbs higher into

Speaker 5: a third surge of COVID cases

Speaker 6: How will the COVID nineteen vaccine be ready in The UK?

Speaker 1: For the last six months, the most popular lure used in phishing attacks to spread TrickBot, COVID nineteen.

Speaker 2: Sure. Hope and fear. Yeah. Leverage leverage brand. Like, this is just marketing. These people are just good at marketing. Look at whatever Outbrain, which is one of those, like, you know, crappy link companies that you go to a news site. Next thing you know, there's, like, five Outbrain articles linked off of it being, like, you know, how to be a better ally in the BLM struggles. And it's like, you know, whatever's contemporary things they're selling, you could probably just clone those and sell those.

Speaker 1: This actor from this sitcom from the nineties, you won't believe what they look like now.

Speaker 2: Just click on the next 100 pages of this website. We will eventually maybe show you a photo.

Speaker 1: It's always the, like, thirty fifth thing in a listicle.

Speaker 2: But you can't jump into the list. You have to go page by page and see 600 ads per page.

Speaker 7: You used

Speaker 1: to be able to go up to the top in the domain thing and find the number of the page and just type in a late number and hope that that wasn't crushing past the end of the listicle. Do you ever do that?

Speaker 2: Man, you are you are a hacker, Jordan.

Speaker 1: Oh, I do have a show about it. And then there's what people have been using TrickBot for. When we look at a broad breakdown of documented instances of TrickBot being deployed since it first bubbled up in 2016. Well, we see a lot of banks. Essentially, a typical case for TrickBot sees the malware spying on the infected machine to gain access to banking, tax, and email user credentials. The reasons for that are obvious. Email is useful for two factor authentication, and spreading the malware further via an addition called Trick Booster, which hijacks the victim's email to spam their contacts, spreading TrickBot onto more machines. But a few years ago, everyone realized all at once that between SMS, biometric, and really any form of two factor authentication, stealing banking information become a really colossally difficult way to make money. And a lot of people just switched over to ransomware because it's less time consuming.

Speaker 2: Totally. If you control someone's computer and you can routinely ransomware attack them and they routinely and consistently pay, then why not?

Speaker 1: As the general hacking community switched to ransomware, so too did Trickbot's users, which is all to say that the answer to the question, what is TrickBot used for and how does it spread, is really whatever its user base wants to use it for, which is sort of unsatisfying until you start to think of TrickBot more like a platform. It's like asking what do people use an OS for? The answer is whatever they want. TrickBot is a tool, and tools have many, many uses. This is the part in the story when it's useful to stop picturing a TrickBot victim as an individual user, and start imagining something a little bit bigger. Kinda like an institution. Let's start with a hospital. Why would it be useful to infect a hospital with TrickBot?

Speaker 2: Sure. Yeah. Well, you know, you you locked down the family photos. It might be worth $500 or a thousand. You locked down, you know, the digital medical records for a country. You know, what's that worth? What's the the cost associated with redoing them? Hundreds of millions?

Speaker 1: On October 12, Microsoft put out a press release. The release announced that they, along with a consortium of other InfoSec companies, had launched an attack, an attack on TrickBot.

Speaker 2: Makes sense.

Speaker 1: Why does that make sense?

Speaker 2: It's attacking their computers. They're running Windows operating system. Windows is the vulnerable target for TrickBot. It makes sense that Windows and Microsoft and the programmers at Windows would have a better understanding of things they can do inside the operating system to bar it, block it, disable it, control it, etcetera.

Speaker 1: I wanna go back to that army metaphor. The army facing down our rogue squadron. The army facing down Trickbot would seem at first blush to be led by Microsoft. And if you stopped reading the news coverage up until that very specific point, you'd be left rightfully thinking that was the case. That October 12 document I cited earlier was an announcement that Microsoft had taken action after the United States District Court for the Eastern District of Virginia granted their request for a court order to halt Trickbot. And this is where that false radio signal, that made up IP address come in. Here's an important and I think interesting quote from Microsoft. It's a little long, but, quote, During the investigation that underpinned our case, we were able to identify operational details, including the infrastructure TrickBot used to communicate with and control victim computers, the way infected computers talk to each other, and TrickBot's mechanisms to evade detection and attempts to disrupt its operations. As we observed the infected computers connected to and receiving instructions from command and control servers, we were able to identify the precise IP addresses of those servers. With this evidence, the court granted approval for Microsoft and our partners to disable the IP addresses, render the content stored on the command and control servers inaccessible, suspend all services to the botnet operators, and block any effort by the TrickBot operators to purchase or lease additional servers. Sounds comprehensive. Sounds like they took TrickBot down. Before we get to whether or not that's actually the case, I wanted to know why. Beyond just altruism, beyond the fact that most of these infected machines are Windows machines and that's bad for Microsoft's bottom line, why did the government give them the authority to lead this attack on trick bot servers in The US? Right now, with everything going on in the world. The answer? Elections. Right after this break. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10 of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 7: When you finally find your thing, you want the whole world to know about that thing. So you use a thing called Canva to make it an even bigger and better thing. Whether you want to create flyers for that thing, make presentations for that thing, or design merch for that thing, you can do anything. So people can see your thing, feel your thing, love your thing. The next thing you know, it's a thing. Canva, the thing that makes anything a thing.

Speaker 1: Imagine you wanna mess with an election. Maybe not the results, but trust in the results. Say you wanted to sow doubt. The actual systems that count ballots are some of the most locked down and secure in the world. But what about the systems that are used to report those votes? What about voter registration sites? Imagine the doubt and chaos that you could sow if on election day, you could press a button and lock down or lock out people from accessing those machines.

Speaker 2: You know, if you've got essentially control of a massive amount of computers, you could roll out, you know, essentially malware that was projecting incorrect polling locations, incorrect election dates. You could there's literally nothing you really can't do with good malware. So if you were building one targeted specifically to, you know, election related information, you could probably, if you really wanted to get into it, like, inject all kinds of nasty misinformation into places where it's not supposed to be. You know, you could probably slot things into people's calendars that are incorrect. You could there be an unlimited amount of ways for you to kind of play with people's lives.

Speaker 1: Trickbot has already been deployed against large institutions. It's been used against major health care providers like Universal Health Services, whose systems it crippled by deploying the ransomware Ryuk. The attack forced staff to restart manual systems and paper records across a system that runs more than 400 facilities across The United States and Britain. Some patients reportedly were rerouted to other emergency rooms entirely and experienced pretty long delays in getting test results. Let's imagine that exact same tactic I just outlined applied to an election. Let's imagine that on election day, you had the ability to those really important computers, the ones used for registration reporting, to just press a button and have that computer go, Oh, ransomware. We've locked down your hard drive. You can't use this device anymore. That device locked down in that moment, I feel like that could create, like, incredible chaos.

Speaker 2: Well, I think not only yes. First and foremost, yes. That would create incredible chaos. But if you had a lot of the computer systems that were doing vote telling and tracking and stuff like that under full control, you could then also probably manipulate the results of the election, which would be, you know, a major major way to forecast out.

Speaker 1: Mhmm. So a fair question. Certainly a question I'd be asking if I was listening to this. Trickbot's been kicking around since 2016, operated by if not explicitly the Russian state then certainly a group of hackers who all speak Russian, running riot through banking, healthcare and acting as this service for hire for people all over the world looking to loot and steal data online. But this year, it becomes patently clear that TrickBot has become so prevalent, so pervasive that there's a very real chance it is infecting or targeting computers that The United States might be relying on for its elections. And if it hasn't, then there's a decent chance it's been used in a campaign to target those computers. So a mission is embarked upon to bring down Trickbot and secure American democracy, spearheaded by none other than Microsoft. I am being glib. Microsoft is a power player in infosec and they've worked on large scale campaigns like this before, but still, a private company tackling a threat to a nation's democracy, Not really what you'd expect. Bringing us all the way to Fort Meade, Maryland. Right into the center of an imposing $500,000,000 concrete and glass facility nestled in a sprawling complex of other $500,000,000 concrete and glass facilities right into the heart of the American military, right into the heart of Cyber Command.

Speaker 8: The newest US military command is responsible not for a piece of land or air, but cyberspace. Special correspondent Mike Saray has this exclusive inside view of the men and women protecting the military's digital networks at the United States Cyber Command.

Speaker 1: Cyber Command. Formed in 2009 and elevated to a full and independent command in 2017, Cyber Command is the cyberspace operation of the Department of Defense. And while not initially reported as such, the tip of the spear in the attack against Trickbot. And suddenly, this weird confusing story all kind of clicks together. In the months prior to a contested election with documented foreign interference, TrickBot is identified as a potential threat, a potential attack vector through which machines essential to the election's operations could be compromised, throwing the results of said election into doubt. So, either in parallel with or as part of a consortium of infosec companies with Microsoft as the public face, Cyber Command launches an attack to take both infected machines and control servers offline. And it works. Congratulations. Job well done. Democracy secured. Until, a few days after the seizure of TrickBot's US servers, some spam goes out, trying to lure in new machines to join none other than TrickBot. US intelligence group Intel four seventy one reported that within four days after the attack, TrickBot was back up and running.

Speaker 9: Admiral Mike Rogers commands both the NSA and US Cyber Command.

Speaker 1: Today, we face threats that have increased in sophistication, magnitude, intensity, volume, and velocity. So here's what happened. This operation, the one we've been talking about, did take down all of TrickBot's command and control servers in The United States. But as of the following Thursday afternoon, 11 servers outside of the country that had been running before this action were still online. From Jakarta to Indonesia to the Dutch province of Utrecht to Bogota, TrickBot was alive and well, operating all over the world. General Paul Nakasone, head of Cyber Command, called this tactic, called this plan, part of what he calls persistent engagement. Basic idea being that by constantly engaging your enemy with attacks like this, you're demanding some of their attention at all times, diminishing their capacity to do harm, which is a very glass half full way of looking at what happened here.

Speaker 9: These cyber teams are drawn from all the services and ranks. Some were trained by the military. Others were recruited for their cyber skills.

Speaker 3: You know, it's not like fighting a war in another domain where you deploy troops, you fight, you go home. Conflict in the constant.

Speaker 1: At the results of cybercom's first official cyber attack meant to disable the means for an enemy cyber attack, what's known as a force on force attack. In a way, Cybercom attacking Trickbot is historic. Actually, no. I wanna unpack that a little bit. Saying it's the first Force on Force attack that The US has ever launched, and we got that language from a pretty in-depth wired interview with Paul Nakasone. It's kind of making a distinction without a difference. Like, I'm sure there's a way to explain how this attack against TrickBot is different than the attack The US launched in 2012 against Iran but I can't think of what it is. So, knowing what we know, having seen what we've seen, having experienced the scope of difficulty of trying to take this kind of thing down, is there any way to keep these machines secure? Is there any way to keep this system safe?

Speaker 2: Yeah. Well, I think, you know, the classic you can always go to the classic, which is air gapping everything. Essentially, just take them off the Internet. So any kind of electoral systems run on private secured networks that don't touch the outside world, which to me makes loads of sense. I think the moving the Hydra, you know, moving the head of the Hydra from American servers back to native Russian servers or, you know, wherever they need to be, is fine. You know, I think there's a lot of control that the governments have over data traffic coming in and out. So they probably have the ability to filter out a lot of if they can pinpoint precision, choose, and know the addresses that it's communicating through, they can probably do a lot of work to disable it at the nation level, which doesn't do anything to the actual hydra itself besides, like, cut off an arm, the American arm of it's missing. But even then, they're probably so smart that there's other ways to backdoor into them and teach them and get them to train. You know? The get bypassing any kind of control these days seems pretty easy. You know? You know, we have technological snooping and monitoring on our communication devices. So, you know, I listened to a podcast the other day about a drug ring out of Colorado called the Syndicate, and they were using some iOS games messenger platform inside of it. And it's like, you know, nobody's looking for illegal communications there. Mhmm. So I'm sure these malware bots are not using just dedicated network traffic and dead like, connecting between each other, but they're using other types of platforms and stuff to communicate.

Speaker 1: Is the is the takeaway then that like this is it feels defeatist to say this, but is the idea that, okay, well, if chaos machines exist, we that we cannot turn off, we cannot disable, there are too many of them and they're too plentiful, is the result then that we just need to find better ways to insulate our institutions from chaos? Like, it's it's like you can't probably turn off the chaos machine at this point. People can create chaos in other countries' democracies. That seems to just be a thing that we have to now live with. Oh, I think it's

Speaker 7: That seems

Speaker 1: to just be a thing

Speaker 7: that we have to now live with.

Speaker 2: Oh, I think it's been a thing that we've lived with. It's just that I think we're a little bit more used to being friends of the people that we're doing it rather than having it done to.

Speaker 1: And we've seen how just tricky it can be to bounce back from this, for a country to bounce back from something like this. It's possible, but it's it's tough.

Speaker 2: All you have to do is, like, if you try and comprehensively understand Venezuela, you will see that, like, nobody is pure. And I think that's, you know, what what has happened and the meddling that went on in Venezuela, we're starting to see happening in America. You know, everything is in doubt because of foreign influence, which arms both sides of the fight because everybody is pointing fingers at everyone else, which then just causes more chaos.

Speaker 1: And we've just gotten better at exerting influence.

Speaker 2: Yeah. I think everybody's gotten better at exerting influence. I think we're as far as, you know, mass social manipulation goes, I think it's only, like, a couple 100 year old game that we've been playing, and we're getting new tools and new text and new mediums and new platforms and new information to do it with.

Speaker 1: We didn't wanna do a normal election episode. And this story is nice in that it kind of sneaks its way around to being about that. In the four years since our last election special, the tools that people use to sow distrust in an election have gotten, if not more powerful, then certainly more refined. And if this story, Story of TrickBot, teaches us anything, as much of a grab bag of a story as it is, it's that elections and, I guess, democracies as a whole are kinda like a currency. Faith plays a big role. Once people lose faith, it becomes worth less. Most of that isn't hacking and social engineering and misinformation, but I think there are still really important lessons in the story of the attack on TrickBot about how fragile that trust can be. Scott and I are Canadian. We're witnesses to this American election that's happening, after this episode drops, not participants in it. So I guess just all I really have to say is is good good luck. May this be the peak of the distrust and not the beginning. Thanks for listening.

Speaker 5: If you've got an insurance question, you could talk to the butcher at your local grocery store. He'd probably talk about trimming the fat, but it'd be about your brisket, not your insurance policies. Or you could talk to your local GEICO agent. They offer personalized assistance in finding the choicest cuts of coverage for all your insurance needs, which means more money for filet mignon. Or if you're a vegetarian, tofu lay mignon. To find a GEICO agent near you, visit geico.com/local.

Speaker 6: This episode is brought to you by Nespresso. Being the best version of yourself is an everyday journey, and it begins in the morning by taking a moment to ground yourself. With the new Nespresso Vertuo Up coffee machine, morning routines become rituals, just one gentle press. And coffee brews, unfolding into whatever you need today. Bold or delicate, iced or hot, familiar or new. Press to explore. Every coffee, a new world. New Vertuo up. Shop now at nespresso.com.

Speaker 4: The right window treatments change everything. Your sleep, your privacy, the way every room looks and feels. At blinds.com, we've spent thirty years making it surprisingly simple to get exactly what your home needs. We've covered over 25,000,000 windows and have 50,005 star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real design professionals, free samples, zero pressure. Right now, get up to 45% off-site wide plus get a free professional measure at blinds.com. Rules and restrictions apply.