Recently, there have been claims that the people who hacked the Democratic National Committee (DNC) have been traced back to Russia. Tracing hackers after the fact is usually an inexact science.

Typically, people who are attacking a system, go through a number of intermediate machines. The logs and tracking information on these machines are then wiped, leaving an approximation as to which incoming connection accessed which outgoing connection.


Rocco Maglio, CISSP

The DNC stated that they discovered the hack in late April because of unusual network activity. They then contacted a DNC lawyer, Michael Sussmann, who in turn contacted the cybersecurity firm Crowdstrike.
Crowdstrike installed monitoring software on the DNC network the next day. Crowdstrike alleged that the hack originated with Russia. They were not able to determine how the hackers got into the network but they theorized that it was through “spearphishing.”

Spearphishing is where an email crafted to the individual contains a link or payload containing malware. It is different from normal “phishing” in that it contains information specifically targeting an individual.
It appears that crowdstrike attempted to trace the hack and concluded that the hack originated from Russia.

Tracing a hack is an art and hackers often leave false trails. For instance, the validity of the claim that the hack of Sony reported to have originated from North Korea, has been questioned by a number of analysts. They theorize that it might have been an insider hacking rather than a nation state hacker.

Crowdstrike apparently based their assessment that the hack originated in Russia on tracing the the connections, cyrillic (Russian and several other countries) metadata in documents and the software used.
The software that was used in this hack was similar to software used in other hacks attributed to Russia.

The evidence that this hack originated from the Russian government is circumstantial at best and it is surprising that many in the media are treating it as a fact.

Hackers often provide false clues to obscure their identity especially in high profile attacks that the hackers expect will be thoroughly investigated.

By

You missed