Ukraine says hackers abuse SyncThing tool to steal data

2 years ago by Kid to c/cybersecurity

The Computer Emergency Response Team of Ukraine (CERT-UA) reports about a new campaign dubbed "SickSync," launched by the UAC-0020 (Vermin) hacking group in attacks on the Ukrainian defense forces.
dariusj18 41 points 2 years ago

Got worried about a synching vuln, but no, they are just using it as a file transfer agent for their own malware.

path: 0 10496885, hotness: undefined, score: 41, children: 10
slazer2au 26 points 2 years ago

Threat actor using software as intended.

path: 0 10496885 10496937, hotness: undefined, score: 26, children: 9
dariusj18 35 points 2 years ago

Next article, "hackers abuse bash to list directory contents and write the output to a file."

path: 0 10496885 10496937 10497193, hotness: undefined, score: 35, children: 7
kid 6 points 2 years ago

Honestly, I didn't think about vulnerability in SyncThing when I read the article. But I wondered why defense forces would have p2p open on their networks.

path: 0 10496885 10496937 10497193 10497370, hotness: undefined, score: 6, children: 6
slazer2au 4 points 2 years ago

When you say P2P you think torrents. But syncthing have rendezvou helpers to facilitate connections without seeing any data.

path: 0 10496885 10496937 10497193 10497370 10497580, hotness: undefined, score: 4, children: 5
MentalGymnastics 0 points 2 years ago
path: 0 10496885 10496937 10498230, hotness: undefined, score: 0, children: 0
jet 18 points 2 years ago

Use... Not abuse.

I just lost a bunch of respect for bleeping computer

path: 0 10497211, hotness: undefined, score: 18, children: 8
MentalGymnastics -19 points 2 years ago

Oh no you lost respect because someone use the wrong word. My day is ruined that you lose respect. How will the world continue because jet@hackertalks.com haves lost respect. Also they abused it because in the Eula you agree not to use their software in this manner. So they improperly used this software to exfiltrate data. I haven't seen you write your own articles either. Sorry let me not abuse you too much.

path: 0 10497211 10498160, hotness: undefined, score: -19, children: 7
kid 11 points 2 years ago

Instance Rules

Be respectful. Everyone should feel welcome here.

path: 0 10497211 10498160 10498374, hotness: undefined, score: 11, children: 3
MentalGymnastics 1 point 2 years ago
path: 0 10497211 10498160 10498374 10498793, hotness: undefined, score: 1, children: 0
MentalGymnastics 1 point 2 years ago
path: 0 10497211 10498160 10498374 10498765, hotness: undefined, score: 1, children: 0
MentalGymnastics -4 points 2 years ago
path: 0 10497211 10498160 10498374 10498698, hotness: undefined, score: -4, children: 0
jet 5 points 2 years ago

https://github.com/...

The license does not restrict use of a file transfer protocol for file transfer. In fact it's the Mozilla public license. It's very permissive

Got to admit, your comment matches your username, kudos

path: 0 10497211 10498160 10498253, hotness: undefined, score: 5, children: 2
MentalGymnastics -7 points 2 years ago

The license clearly does not apply. Nice try though. I mean it does take some mental work to think synchthing permits this type of abuse. Wait is that too disrespectful?

path: 0 10497211 10498160 10498253 10498918, hotness: undefined, score: -7, children: 1
jet 7 points 2 years ago

If the license the code is published with doesn't apply, what license would apply?

path: 0 10497211 10498160 10498253 10498918 10499298, hotness: undefined, score: 7, children: 0
cybersecurity
cybersecurity

@sh.itjust.works

login for more options
10144
5227
1224

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We're all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

go to feed...