Source: Upper Echelon
The Most Terrifying Hack I Have Ever Seen - Moveit
Jun 15, 2023 · 11m 48s
https://www.youtube.com/watch?v=R7wz6RxcjDE
foreign I don't normally do multiple uploads in a single day it's super rare in fact it's just not really a pattern I can sustain at all but this one this one felt like it needed to be rushed and it needed to be talked about and I know it's two doomer-ish topics in one day bear with me on that but it just sort of is what it
is for context lately I've been starting to become much more aware of the cyber security and digital threat landscape I've worked with multiple sources expert sources I might add and while I'm still very much green in this particular area myself I'm I'm a quick learner I like to think so I'm not normally a breaking news type channel it's definitely exhilarating being on The Cutting Edge of
topics when that's possible but it's not really my goal as a Creator here on YouTube my goal is to produce things that have value beyond the platform if I can warn about a scam and save people a bunch of money that's a positive impact if I can bring attention to an incredible indie game that deserves more popularity same deal I have one of those hopefully releasing
tomorrow actually but when talking about impact there's a lot of choices available today right now when we're saying the words impact it feels fitting to lead in with that the scariest hack I have ever seen is is unfolding in real time and maybe I can't really do anything about that at all maybe it's just me shouting into the proverbial void if you will but it still
felt like the kind of breaking news where I don't really have a choice it just has to be covered here's the overview June 15th at roughly 12 p.m Eastern Time articles began circulating and mass dominating the news cycle for basically all major technology-focused Publications these articles pertain to a ransomware attack by an apt an advanced persistent threat group known as klopp ta-505 this group had allegedly
gained access to a managed file transfer program mft developed by progress software corporation known as moveit which was then used to compromise a bevy of companies such as Shell First National Bank A-Plus Federal Credit Union United Healthcare Services Incorporated power Financial Credit Union Minnesota Department of Education Illinois Department of innovation and Technology University of Georgia green shield Canada HCI College multiple federal agents sees by the
way and more I could actually spend a rather long time listing out the companies affected by this attack and there's many more but the point is to say that it is very very far-reaching and affects a large number of Industries however despite the main cycle of news breaking on the 15th this is not the earliest point in time when the vulnerability was first discussed reported by
help Net security the Minnesota Department of Education claims to have discovered the vulnerability or been told about it as early as May 31st moving over to bleeping computer reported on June 8 2023 klopp ransomware had been testing the vulnerability since April of 2022 according to them and had been searching for it since as far back as 2021. the vulnerability being used appears to have been given
the ID cve 2023 34362 although it may actually be an entirely new bug as of yet undiscovered the precise details are unclear at this time a proof of concept for 34362 can be found on GitHub but here's the part that matters for people that don't really want to follow along with all of that all of this is possible because a threat actor gained unauthorized access to
a file transfer system in effect called move it and then use that access to exfiltrate sensitive data from various users of that software makes sense that's really the basic gist of it well to explain why this is the scariest hack I've ever seen in my life let's look at what move it does what is the software and who uses it simply put moveit is one of
many different file transfer or sharing systems out there and funnily enough it's rather small comparatively speaking by market share it's actually 23rd with just 0.13 percent estimated by data knives that may sound small and the scope of this hack may seem benign to some until you look slightly deeper under solutions on their website there is an entire dedicated section for the US government quote moveit helps
it teams at almost every Federal civilian agency and military branch to securely transfer Mission critical information and assure the performance of their Network to infrastructures and applications end quote and that is where the danger lies almost every Federal civilian agency and military branch uses the software for Mission critical information that has been compromised by the way that software has been compromised by a threat actor who
is now verifiably posting secret confidential and sensitive corporate information publicly now for the sake of being thorough I'm not going to do the thing where I say trust me bro and just tell you I've seen it with my own eyes here is the klopp prunion website right now where the confirmed info dumps from successful targets are being posted actively I can't scroll through much of this
and I certainly cannot download a single thing I'm not posting the onion or anything like that but this data is comprehensive there are individual passport scans contained from what I understand and the basic gist of it is that they basically have what they say they have the breach is real and the scope of data that is being released is unprecedented maybe this will put things in
perspective directly from sisa the cyber security and infrastructure Security Agency which is the national coordinator for critical infrastructure security resilience that's a mouthful quote sisa remains in close contact with progress software and our partners at the FBI to understand prevalence within federal agencies and critical infrastructure end quote AKA there has been a breach of federal agencies and critical infrastructure hence the scariest hack I've ever seen
now for those that want to go down the rabbit hole a little bit here June 15th is a hell of a day to coincidentally witness widespread news break about an unprecedented hack especially involving Banks and Credit Unions because June 14th one day prior multiple known hacker groups those being Revel killnet and Anonymous Sudan announced a public Alliance to destroy the Western payment system Swift make of
that what you will these groups have their own extensive history and atmosphere but the frequency of large-scale damaging digital events I'll call them is accelerating this is the part where I get called a conspiracy theorist and I understand the inclination believe me I do but just hear me out I'm not going to speculate on why this is becoming a wider narrative I'm not going to speculate
on motivation in the slightest or some kind of deeper meaning or anything like that Beyond simply showing a piece of content that's all I'm going to do but everyone should be aware of the wind let's say especially when the wind starts blowing stronger this right here is the world economic Forum I know a lot of people have very intense opinions on what this group is why
it exists and what it does but let's take a look at the video they posted two years ago called a Cyber attack with covet-like characteristics it's a decent video it is mostly discussing the danger of a digital virus of sorts that spreads through connected devices in an exponential way and they also have an apt comparison and there's a bunch more to make if you wanted to
it's a very real threat by the way but let's look at this through a macro lens I'm not telling anyone what to think nor am I assigning motive in the slightest my simple goal is to State a series of facts in chronological order the world economic Forum in 2019 partnering with Johns Hopkins University hosted a round table called event 201 this event simulated a fictional coronavirus
outbreak and attempted to delve into the mechanics of government reaction and risk mitigation quote experts agree that it is only a matter of time before one of these epidemics becomes Global a pandemic with potentially catastrophic consequences a severe pandemic which becomes event 201 would require reliable cooperation among several Industries National governments and key International institutions end quote it is not my place to speculate on that
further some people view this event as an obvious effort to take aimed at getting ahead of obvious potential problems others view it as an early warning sign the powers that be mapping out their plan of sorts I am not weighing in on that discussion let's be clear other than to say that regardless of where you fall individually whether you believe in the world economic Forum as
an institution thereby trusting what they put out into the world as result or if you despise them believing them to be a Malignant Force with a powerful hidden agenda of some kind it really doesn't matter directly before the onset of covid-19 an experiment was run aimed at exploring the effects of a novel coronavirus and we all know what happened soon after that two years ago in
2021 a narrative push began occurring by the world economic Forum where they were warning of impending Danger from cyber attacks cyber attacks that possess covet-like characteristics if we're being more precise later in 2023 during The wef Summit in Davos managing director Jeremy Jurgens warns again that some sort of catastrophic cyber security event is likely within the next two years and now we are witnessing heightened frequency
and impact of cyber threat actors who have managed to infiltrate what can only be described as a specialized file sharing service used by government agencies and Military this is an evolving situation ransomware hacks to some may seem like a far-off Hollywood style concept but there or not they're real they happen every day and this is a big one a good example to draw from reported by
the BBC in 2020 is when ransomware actors gained access to the University of California San Francisco files the negotiation itself took time and the university ended up paying out over a million dollars to the hackers via Bitcoin some companies pay some companies don't but klopp is now in possession of an unknown amount of data from federal agencies and critical infrastructure with a clear intention to publish
it if whatever demands they are making fail to be met on time we'll learn more over time about what's going on and I should add that klopp have made an explicit claim on their PR site that they have deleted all government data in particular they are according to their claims only interested in businesses everything else related to government workers or files has supposedly been deleted but
the question needs to be asked even if this particular event is not what instigates a global catastrophe a la wef predictions how long will it be before something else does it is very clear abundantly clear to anyone who pays even the slightest bit of attention that the world of cyber warfare is high stakes and we're kind of playing it for Keeps which leaves us wondering if
or rather when will something occur that does the financial industry it's not outside the realm of possibility this is not something where you just brush it off and say oh man it's never going to happen it can happen what kind of situations are coming down the pike because if the frequency and severity of these infiltrations continue we very well may arrive at a Crossroads where the
economic and social impact will become just as large if not larger than covet 19. I know I publish a lot of Doomer topics lately and a lot of people are getting sick of them but that's the I've been researching agree disagree feedback Etc feel free to leave it all down below in the comments section for anyone interested upper echelon has a comprehensive link database of cyber
security techniques services and solutions linked down below that we've worked rather hard on for anyone who wants to protect themselves better on an individual level there's things that are free things that you pay money for it's all up to you as an individual it's flexible you can Implement what you want where you want it's just a lot of useful things that we hope will be valuable
to people but yeah that's it I'll cut it there and stop rambling as always thank you all for watching I do have an indie Spotlight coming tomorrow some upbeat stuff from some more fun things not just the Doomer stuff but I don't know that's that's the rabbit hole I've been going down lately and I'm not really sorry about it thank you all for watching and have
a nice night [Music] [Music]
Social actions (Like, Bookmark, Comment, Deeplink) land in Manage phase · Premiuum integration later