NSA Hacking Tools Were Leaked Online. Here's What You Need to Know

Advertisement
By Andrea Peterson, The Washington Post | Updated: 18 August 2016 13:21 IST
A cache of powerful hacking tools used by the National Security Agency have leaked online in what could be the biggest blow to the agency since 2013, when Edward Snowden came forward with documents that exposed the scope of its surveillance capabilities.

The leak raises new questions about how the NSA uses its offensive hacking ability and whether its approach ultimately leaves everyday users, not just the agency's targets, at risk.

Here's what you need to know about the leak:

What happened?
Over the weekend, a group calling itself the Shadow Brokers posted online what it claims is a trove of malware used by the Equation Group - a code name for hackers that cybersecurity researchers have linked to the NSA.

Advertisement

The 300-some megabytes of information appear to date to 2013 and is allegedly just a free taste of a larger trove that the Shadow Brokers will release once a digital "auction" for the information is held. The group is asking for 1 million Bitcoins - or about a half-billion dollars - before they will let it all loose. However, many experts are skeptical of the auction.

Advertisement

"It's designed to distract. It's total nonsense," Nicholas Weaver, a computer security researcher at the University of California at Berkeley, told The Washington Post's Ellen Nakashima.

Weaver said bitcoin "is so traceable that a Doctor Evil scheme of laundering $1 million, let alone $500 million, is frankly lunacy."

Advertisement

What do these tools actually do?
The files contain what appears to be part of a sophisticated cyber arsenal. Among the digital weapons are "exploits" - hard-to-develop tools used for penetrating and taking over firewalls made by companies, such as Cisco and Fortinet, that are commonly used to protect computer networks.

There are also "implant" tools that can help hackers do things like siphon out or modify information on a system once they've broken in.

Advertisement

Several of the tools relied on previously unknown - or "zero-day" - bugs in software that appear to remain vulnerable now.

How sure are we that these tools actually belonged to the NSA?
They seem pretty legit. Although the NSA is staying mum, former NSA hackers told The Post that they appeared legitimate - as have other outside experts. Some file names from the cache also match up with programs or tools previously referenced in Snowden's revelations.

"Faking this information would be monumentally difficult, there is just such a sheer volume of meaningful stuff," Weaver told The Post.

But it's not clear that the NSA at large was hacked. Instead, an NSA operator may have mistakenly uploaded a full tool set to a proxy server that the agency used to carry out infiltrations, experts told The Post.

So who are these Shadow Brokers? The group's name appears to be a reference to a character in the "Mass Effect" video games who sells off information to the highest bidder.

But many, including Weaver and Snowden, say Russia is behind the leak. While there's no hard evidence connecting Russia to the data as of now, on Twitter, Snowden argued that Russia may have released the cache to wave the U.S. government away from officially blaming hacks against the Democratic National Committee and other political organizations on the country.

Putting the tools out there "is likely a warning that someone can prove U.S. responsibility for any attacks that originated from" the server that hosted them, he said. That could have major diplomatic fallout if, for instance, the tools were linked to spying on U.S. allies, Snowden argued.

WikiLeaks also tweeted that it had a full copy of the NSA tools cache that it would soon put up online, which may bolster the Russia theory. WikiLeaks posted Democratic National Committee files online last month, which many suspect came from Russian cyberattacks on the party organization.

Are the tools still out there online? What does this mean for my security?
Yes. The Shadow Brokers put the files online in a few different ways, including using a peer-to-peer file sharing method called bittorrent - which makes it very hard, if not impossible, to delete them from the Web.

That's bad news for user security: For one, these tools are now available to criminal hackers.

But secondly, the leak raises questions about how the government handles zero-day vulnerabilities. There's an official process called an equities review that the government uses to weigh when it will tell software makers about security problems it discovers in their products.

But the exact process is murky - and critics of the NSA have long suspected that the agency hoards undisclosed vulnerabilities to use in its information-gathering efforts. The reliance on zero-day bugs that remain unpatched today by the leaked tools suggest that the agency sat on problems for years.

When those problems go unfixed, it leaves everyday people vulnerable because other hackers might find and exploit the same issues. This new leak seems to prove that other people can find the same vulnerabilities as the NSA - and in some cases, even gain access to the same tools the agency uses to exploit them.

© 2016 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  2. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  3. OpenAI Says ChatGPT Will Soon Become an Operating System
  4. Redmi K90 Ultra Could Bring a Massive Battery Upgrade
  5. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  6. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  7. Thamma Now Streaming on Amazon Prime Video
  8. Global Smartphone Shipments Will Reportedly Drop in 2026 Due to This Reason
  1. Astronomers Witness Longest-Lasting Gamma-Ray Burst in History, 8 Billion Light-Years Away
  2. Sub-Millimeter Robots Can Sense, Think, and Act Autonomously, New Study Finds
  3. Earth’s Atmosphere Has Been Leaking Onto the Moon for Billions of Years, Study Finds
  4. New Orbital Clues Reveal How Hot Jupiters Moved Close to Their Stars
  5. Heartiley Battery Out on OTT: Know Where to Watch This Tamil Sci-Fi Series Online
  6. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  7. Private Satellites Pinpoint Methane Emissions from Oil, Gas, and Coal Facilities Worldwide
  8. Ishq Vishk Rebound Out on OTT: Know Where to Watch This Rohit Saraf Starrer Romcom
  9. Theeyavar Kulai Nadunga Now Streaming Online: Where to Watch This Dark Psychology Thriller
  10. My Lottery Dream Now Available For Streaming Online On This Platform: What You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.