Top Banner
“Hacking Team” Hack Comprehensive Timeline By Kamalesh Lunkad CT+ student ASCL
33

Hacking team

Apr 09, 2017

Download

Education

Kamalesh Lunkad
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Hacking team

“Hacking Team” Hack

Comprehensive TimelineBy Kamalesh Lunkad

CT+ student ASCL

Page 2: Hacking team

Hacking Team is a Italian surveillance company.

Sells spyware to governments all around the world, was seriously Hacked on July 5th.

This Hack ripped the company's corporate secrets, emails, source code and files, and leaked over internet.

Hacking (Hacked) Team

Page 3: Hacking team

The attacker either had direct Physical access to security engineer Christian Pozzi's PC or used malware to achieve a similar level of access to download all data.

We can tell simply by looking at a folder name among the files that were leaked onto the internet.

(Covered Later in this presentation)

Saturday  July 5th 2015 or beforeAttack Began

Page 4: Hacking team

Hacking Team’s Twitter feed was taken over. The banner on the page changed to “Hacked Team.”

July 5th 2015

Page 5: Hacking team

Hackers Leaked all the stolen data online, including all emails, source code and files.

1st Tweet

Page 6: Hacking team

Transperency report of 400GB

Page 7: Hacking team

After taking over Hacking Team’s twitter account

Attacker started to publish emails that were leaked as part of the 400GB files.

Sunday July 6, 2015

Page 8: Hacking team
Page 9: Hacking team
Page 10: Hacking team
Page 11: Hacking team

Phineas Fisher,a hacker which previously took responsibility for an attack on Gamma came forward taking responsibility for this too.

Who is Responsible?

Page 12: Hacking team

Attacker did not answer further questions asked on twitter but he said he will revel how he hacked :Hacking Team”

Page 13: Hacking team

Christian Pozzi, Hacking Team system and security engineer, took to Twitter to refute claims made by the cyber attackers.

The Twitter account has been deleted, but a (https://archive.is/Ca8Kz) containing his comments can be accessed:

Damage Control (Incident Response)

Page 14: Hacking team

While at first calm, Pozzi's tweets became increasingly frantic.

Page 15: Hacking team

Later his account also got hacked

Page 16: Hacking team

11.30 GMT :  Hacking Team's Twitter account wrestled control back

Hacking Team removed messages, screenshots of stolen data and mockery levied against the company

Hacking Team’s Twitter account archive before deleting posts here https://archive.is/n0om8)

14.09 GMT: The Hacking Team website is offline.

May be because cyberattack or the company took it down avoid further problems or the heat of the media.

July 6th 2015

Page 17: Hacking team

15.07 GMT: The Company’s surveillance solution code leaked onto GitHub. (https://github.com/hackedteam/)

Page 18: Hacking team

Wikileaks created a database to comb through all released email of HT. https://wikileaks.org/hackingteam/emails/

July 9th

Page 19: Hacking team

https://ht.transparencytoolkit.org/ One can access all the data online and

download any file

Online mirror of 400 Gb data

Page 20: Hacking team

Contract with Ethiopia Leaked Docs

Page 21: Hacking team

Hacking Team assigned Anonymizers to customers from Lebanon and Egypt. The IPs are for VPN services in the U.S. and Germany

VPN servers

Page 22: Hacking team

A list of VPS credentialsVPS servers

Page 23: Hacking team

Customer lists

Page 24: Hacking team
Page 25: Hacking team

Mexico was discovered to be top client.

Page 26: Hacking team

Product listsAn example of the type of products offered by Hacking Team and their associated cost in Euro

Page 27: Hacking team

Collectors and anonymizers

Page 28: Hacking team
Page 29: Hacking team
Page 30: Hacking team

Hacking Team had recently told the UN that they had never done business with the country.

Contract with Sudan

Page 31: Hacking team

A contract with a company in Israel for €55,000 Euro.

Page 32: Hacking team

A contract with Lebanon for €100,000 Euro.

Page 33: Hacking team