{"id":195899,"date":"2017-06-01T22:20:37","date_gmt":"2017-06-02T02:20:37","guid":{"rendered":"http:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/vietnamese-hackers-appear-to-be-researching-an-nsa-backdoor-tool-cyberscoop\/"},"modified":"2017-06-01T22:20:37","modified_gmt":"2017-06-02T02:20:37","slug":"vietnamese-hackers-appear-to-be-researching-an-nsa-backdoor-tool-cyberscoop","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/nsa-2\/vietnamese-hackers-appear-to-be-researching-an-nsa-backdoor-tool-cyberscoop\/","title":{"rendered":"Vietnamese hackers appear to be researching an NSA backdoor tool &#8211; CyberScoop"},"content":{"rendered":"<p><p>    A hacker group with suspected ties to the Vietnamese government    appears to be researching a leaked National Security Agency    tool codenamed ODDJOB, based on documents uploaded to the    repository VirusTotal andtied    to a source already identified as OceanLotus group,    otherwise known     as APT32.  <\/p>\n<p>    A classified user manual for ODDJOB was originally published on    April 14 by a mysterious group, known for sharing NSA    documents, named the Shadow Brokers. A copy of this same    document was then uploaded April 17 to VirusTotal along with    other malicious email attachments by OceanLotus. Multiple U.S.    cybersecurity firms say OceanLotus is aligned with the    interests of the Vietnamese government.  <\/p>\n<p>    The specific version of the manual uploaded by OceanLotus was    not weaponized, meaning it didnt carry malware that could be    used to convert the harmless PDF to a phishing lure.  <\/p>\n<p>    ODDJOB is a high-quality, masterfully engineered digital weapon    believed to have been once used to help U.S. spies collect    intelligence stored on machines running older versions of    Microsoft Windows. Details on this backdoor implant are scarce    at the moment. The operational computer code behind ODDJOB    was not    released by the ShadowBrokers.  <\/p>\n<p>    OceanLotus apparent interest in the ODDJOB manual underscores    the efforts now being made by nation-backed hacking groups to    better understand, and potentially reuse, leaked NSA    capabilities  a fear perhaps already realized with the    WannaCry ransomware campaign.  <\/p>\n<p>    When ODDJOB is deployed against a target computer it attempts    to obscure network traffic by appearing to be the Microsoft    Background Intelligence Transfer Services, or BITS, which is    typically used by Windows Update to apply a patch to a    computer.  <\/p>\n<p>    As of Thursday afternoon, the related file uploaded to    VirusTotal remained in plain view.  <\/p>\n<p>    The manual was first made public by the Shadow Brokers in    April, but interest in this document by nation-states was    previously unreported.  <\/p>\n<p>    CyberScoop     first reported Wednesday that OceanLotus was likely    behinda cyber-espionage operation aimed at the    Philippines government; a campaign which similarly saw    sensitive documents be uploaded to VirusTotal. The reason for    why these documents are being uploaded to a public forum    remains unclear.  <\/p>\n<p>    In addition to the ODDJOB manual, the aforementioned file dump    includes, among other documents, an     apparently leaked transcript of a phone conversation    between U.S. President Donald Trump and Philippines President    Rodrigo Duterte,briefing notes for a call between    Philippine government officials and a U.S. senator, and    internal documents tied to the Philippine National Security    Council.  <\/p>\n<p>    OceanLotus has been known to conduct missions against valuable    corporations, foreign governments, dissidents and domestic    journalists since at least 2014,     according to research conducted by FireEye.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more:<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.cyberscoop.com\/vietnamese-hackers-appear-researching-nsa-backdoor-tool\/\" title=\"Vietnamese hackers appear to be researching an NSA backdoor tool - CyberScoop\">Vietnamese hackers appear to be researching an NSA backdoor tool - CyberScoop<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A hacker group with suspected ties to the Vietnamese government appears to be researching a leaked National Security Agency tool codenamed ODDJOB, based on documents uploaded to the repository VirusTotal andtied to a source already identified as OceanLotus group, otherwise known as APT32. A classified user manual for ODDJOB was originally published on April 14 by a mysterious group, known for sharing NSA documents, named the Shadow Brokers <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/nsa-2\/vietnamese-hackers-appear-to-be-researching-an-nsa-backdoor-tool-cyberscoop\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94881],"tags":[],"class_list":["post-195899","post","type-post","status-publish","format-standard","hentry","category-nsa-2"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/195899"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=195899"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/195899\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=195899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=195899"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=195899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}