Source: Upper Echelon
The Website That Saved The World (Literally)
Mar 20, 2023 · 15m 46s
https://www.youtube.com/watch?v=YqNJtGpphks
foreign this video is brought to you by surf shark stick around here more about the discount they are providing to the entire upper echelon community no beating around the bush how on Earth is it possible that a single domain name effectively saved the internet and what in the world could even require such a thing that's the question we're answering today but it's a complicated question to
answer because it's not just about computer viruses or malware kill switches it's about global cyber weapons pseudo-anonymous hacker collectives and government agencies sounds like a conspiracy right obviously but it's not and the reality at least to me is fascinating what is eternal blue that question is quite obviously pivotal for today but that is a question with a lot of implications Eternal blue according to the Hyper
Security encyclopedia as well as pretty much every other reputable Source you will come across is what's called a zero day exploit that is widely believed to have been developed by the NSA otherwise known as the National Security Agency of the United States of America now a certain level of explanation is required here especially since my prior video about the global cyber war was not as thorough
as it likely should have been Eternal blue is in exploit targeting the Windows operating system likely developed by the NSA as an offensive tactic in their ongoing struggle against threat actors all around the world more precisely the NSA and other connected agencies participating in the deployment or development of cyber Weaponry are almost totally fixated on developing offensive capabilities rather than defensive ones in simplest terms possible
America wants to carry the biggest digital stick and that works well up to a point however in the case of Eternal blue things derailed rather quickly when an organization known as The Shadow Brokers heck of a name I know managed to begin leaking government-funded cyber Weaponry to the public setting aside precisely how the shadow Brokers whoever they are managed to obtain access to United States cyber
Weaponry developed by the NSA some suspect that they gained access from an apt named equation group widely believed to be directly associated with the NSA themselves and also one of the most sophisticated cyber warfare collectives in the world While others maintain that only through equation group did the shadow Brokers manage to get access to something called out which is suspected to be a direct arm of
the NSA itself known more precisely as the tailored access operations unit still others believe that this was an act of War funded by Russia I can't say for certain but suffice it to say theories abound regardless of how regardless of why the simple reality is this on August 13 2016 the shadow Brokers published an auction this auction unbeknownst to the public at the time contained government-level
cyber infiltration tools and came with a message quote attention government sponsors of cyber warfare and those who profit from it how much you pay for enemies cyber weapons not malware you find in networks both sides rat plus LP full State sponsor tool set we find cyber weapons made by creators of stuxnet Dooku flame kaspersy calls equation group we follow equation group Traffic we find equation group
Source range we hack equation group we find many many equation group cyber weapons you see pictures we give you some equation group Files free you see this is good proof no you enjoy you break many things you find many intrusions you write many words but not all we are auction the best files end quote this message despite the broken English or perhaps even enhanced by it
is chilling especially in hindsight as it references things like stuxnet which is a cyber weapon deployed against Iran which successfully undercut their entire nuclear program by infiltrating and reprogramming the centrifuge control systems in a deliberate and highly sophisticated Act of international sabotage thinking back any claim that similar exploits would be released should have been terrifying okay before continuing on it's time for me to promote a
product to get some money and offer all of you watching a hefty discount in the process on surf shark surfshark is a VPN virtual private Network and vpns protects you from a bunch of things there are certain types of phishing attacks malware DNS tunneling DDOS attacks you name it and also Shields you to a degree from the inevitable and constant data harvesting as well as tracking
from Big tech companies for those more focused on Raw entertainment value social can unlock additional content on streaming websites like Netflix for example it has to do with licensing agreements I won't bore every one of a technical explanation here simply change your region and enjoy increased options in your video content streaming Library social can get you around Regional censorship such as government restrictions on websites which
is a thing nowadays and also offers encryption IP protection or modification and so much more that's not even the end so shark has a multitude of uses for a multitude of problems but for the sake of time all I have to say is that if you click the link down below right now using promo code Echelon you can get 83 off and three full months free
again that's promo code Echelon for 83 off and three entire months for free if you click the link Down Below in the description today big thank you to surfshark for sponsoring the channel further messages released by The Shadow Brokers detailed precisely how to engage with their auction but from what it appears limited engagement as a result of mass skepticism perhaps kept the bidding relatively low it
wasn't until the end of October 2016 that things really started to heat up when the shadow Brokers published another message their sixth total correspondence with the outside world at the time that read as follows quote the shadow Brokers is trying auction people to know like the shadow Brokers is trying crowdfunding peoples is No Liking now the shadow Brokers is trying direct sales be checking out list
of Wares if you like you email the shadow Brokers with name of Wares you want to make purchase the shadow Brokers is emailing you back Bitcoin address you make payment the shadow broker is emailing you link plus decryption password if not liking this transaction method you finding the shadow Brokers on underground marketplaces and making transactions with escrow files as always being signed end quote this particular
message finally began to cause adequate concern despite the lack of executable files contained the most recent request by the show Shadow Brokers to find willing buyers came with around 60 unique folders complete with screenshots of the tools of file structure and pertinent names still possibly fake yes or some kind of hoax but the pressure was mounting that this unknown person or person's group Etc had actually
managed to obtain classified cyber weaponry and might actually be preparing to sell or disperse it April 8 2017 everything finally came to a head the shadow Brokers on this particular Day released a post on the platform called medium which served as a call out towards then president Donald Trump politics aside this medium post contained among many other things a conclusory paragraph that reads as follows quote
Mr President Trump the shadow Brokers sincerely is hoping you are being the real deal and that you received this as constructive criticism toward Maga some Americans consider or maybe considering the shadow Brokers Traders we disagreeing we view this as keeping our oath to protect and defend against enemies foreign and domestic the shadow broker's wishes we could be due doing more but revolutions slash Civil Wars taking
money time and people the shadow Brokers has is having little of each as our auction was an apparent failure be considering this our form of protest the password for the eqgrp auction files is crdj quote parenthetical semicolon VA period star ndl or I nzb9m question mark at K2 closed parenthetical pound sign greater than deb7 MN end quote that string of numbers letters and symbols Unleashed hell
this password opened access to what were unfortunately very real cyber weapons obtained by the shadow Brokers among them Eternal blue and roughly one month later the damage started May 12 2017 at precisely 744 UTC a novel worm built around Eternal blue hits the market and begins encrypting computers victim computers classified as crypto ransomware want to cry leveraged the nsa's now leaked cyber weapon to infiltrate Windows
computers encrypt them and demand payment in the form of Bitcoin funnily enough Windows themselves were already aware of the exploit having released an operating system update about a month prior which supposedly closed the hole in reality this operating system update did patch the exploit that made Eternal blue even possible and functionally stopped the malware in its tracks but a tremendous number of operating systems at a
corporate government and civilian level as well were as of yet unsecured how many times have we all of us watching this or myself deliberately postponed an update how many times have companies held on to outdated operating system licenses to cut down on individual cost and how many systems in the world to this very day still run unsecured Windows operating system versions answer a lot of them
this novel malware strain colloquially dubbed wannacry began to encrypt systems and spread itself relying on SMB Port vulnerabilities to infect additional networked devices the exact rate at which the malware managed to spread itself remains largely unknown other than a consensus that hundreds of thousands of individual devices were infected within mere hours an estimated 200 to 300 000 computers were encrypted across 150 countries entire Hospital Systems
corporate databases infrastructure critical infrastructure electricity boards Banks shipping companies anything running a slightly outdated Windows operating system was vulnerable and the damage was beginning to spiral out of control luckily as we can obviously surmise from the title itself there was a solution embedded deep down in the malware's code was a kill switch wannacry whether it be to mitigate reverse engineering or some sort of ultimate Fail-Safe
who knows would call out to a specific domain name before initiating its ransomware payload that domain well it's blocked locally Now by most isps and security service providers but when first set loose it pointed here a string of gibberish to be sure a complicated and a necessary domain one would think but if the ransomware was unable to access it or call to it the attack began
discovering this relatively quickly on the same day to be precise just a few hours after its immediate exponential and viral spread had begun a researcher named Marcus Hutchins made the discovery and proceeded to register the domain in preparation for this video I actually reached out to Marcus directly hoping to chat with him on the subject or rather I commented on a YouTube video and I would
still be very much interested to do so however I was unable to make contact and he has also migrated away from Twitter in particular completely which serves as one of the main Outreach channels that I myself use regardless Marcus Hutchins decided to register within just a few hours the kill switch domain effectively paralyzing the wannacry malware attack to be clear it was not destroyed merely forced
into a sort of docile holding pattern if you will where it never triggered its encryption payload meaning that within hours a worldwide Cyber attack that was successfully crippling entire portions of critical infrastructure in your countries had been shut down the kill switch prevented already infected computers from becoming encrypted but if for any reason the domain itself the kill switch domain went down the Carnage would inevitably
begin again so many systems at the time were unprotected and so many pieces of our internet Foundation were susceptible this malware had the potential to deliver World altering consequences if not for the Speedy actions of Marcus Hutchins and similar dedicated researchers who protect people like you and me from dangers beyond our comprehension for years after 2017 wannacry continued to spread inert in a way defanged one
could say but out in the Wilds nonetheless waiting for an opportunity to strike again many tries were made to bring down this kill switch domain DDOS attacks infiltration tactics by Foreign actors who knows you name it it happened but over time security systems were able to compensate operating systems were updated and wannacry faded into memory as something that almost destroyed the modern world but didn't losses
were impossible to precisely determine but ranged an estimate from a few hundred million to four and a half billion dollars of damage in just a few hours as just a single example and keep in mind there are many many more again 150 countries 300 000 individual systems right were encrypted by this but just one single example encrypting Hospital Systems in the UK caused 19 000 appointments
to be canceled or pushed back meaning that cancer screenings or infectious disease Diagnostics were postponed leading to an unknown amount of human collateral damage ten dollars and ninety six cents that's the price that Marcus Hutchins paid to prevent tens of billions of dollars in damage or more and Stave off world shaping digital consequences since then researchers have made great strides in combating these types of attacks
but to this very day the ability for malicious code to infiltrate and Destroy consistently outpaces preemptive efforts to stop it unlike more traditional cyber infiltrations that rely typically on social engineering I have a video coming out about that kind of stuff very soon or oftentimes human error that's a big one wannacry and eternal blue were a self-perpetuating internet disease once infected your system was then a
danger to every other online device in its Network regardless of what you did with an agency developed nation-level cyber weapon at its core rightfully appalled by this Microsoft president and chief legal officer Brad Smith said quote we need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits end quote lambasting the NSA for their deliberate usage of
a zero day exploit instead of responsibly working to prevent some kind of attack right they discovered something like this and then instead of taking preemptive measures to mitigate damage they turned it into a devastating weapon this government Mantra Mantra however you want to say it of carry the biggest digital stick does not translate well to the world of cyber warfare and while we may hold the
advantage right now and we may hold it for a long time into the future who knows the risk of collateral damage from these government-sponsored funded and developed digital nukes for lack of a better term is omnipresent how long is it before another comparable breach occurs will we get lucky next time will someone find a kill switch fast enough or will some new form of cyber weapon
be unleashed the cripples the functionality of the entire internet or the infrastructure of complete Nations and continents who knows because as convoluted and dramatic as these words might seem and I do understand they seem hyperbolic and over the top they're really not we live in a reality now where everything we know love understand and rely on can change or be destroyed in a matter of seconds
careers companies profiles computers everything the best defense be aware be hyper Vigilant of course but also come to terms with the now ever present danger of digital Weaponry directly aimed at you built by your own government that is completely safe so they say right up until the moment it's not that's the story of wannacry a website that saved the online World a hero who managed to
discover it thank you to him and the razor's Edge we actually truly do live on if you want to support please check out the links down below merch social media the video sponsor sir shark of course etc etc but I'll cut it there and stop rambling also please let me know if this type of video is something you want to see more of I'm currently running
an experiment where I'm manufacturing a false identity I'm engaging with the the bot networks right that that plague social media like I'm doing a lot of these topics right now and I'm working decently hard on them so I want to know if this is something that that subscribers want to see because I'm interested in continuing but yeah I'll cut it there as always thank you all
for watching and have a nice night foreign [Music] foreign
Social actions (Like, Bookmark, Comment, Deeplink) land in Manage phase · Premiuum integration later