Former Yandex CISO weighs in on alleged Five Eyes hack

It's not known which of the alliance's five countries is behind the espionage operation

Russian hack concept

A former Yandex CISO has addressed the allegations made against the Five Eyes intelligence alliance which allegedly used a rare strain of malware to spy on user accounts relating to Russia's leading search engine.

The malware called Regin is known to have been used by Five Eyes in previous operations, according to information that was previously unearthed in the 2014 Edward Snowden leak of NSA documents.

Advertisement - Article continues below

According to sources familiar with the matter, who spoke to Reuters which first broke the story, it couldn't be determined which country launched the attack on Russia's leading search engine which was discovered between October and November 2018.

The Five Eyes intelligence alliance is formed of the UK, US, Canada, Australia and New Zealand and operates under the agreement that all information can be shared without fear of it being leaked outside of the alliance.

The former CISO of Yandex, which is often referred to as Russia's Google, took to Twitter upon reading the news to offer some interesting insights into the attack.

Taking a more offensive stance, Vladimir Ivanov exclusively and repeatedly addressed the attackers as "NSA" instead of speculating the true origin of the attack like the sources of the information did.

Advertisement
Advertisement - Article continues below

"NSA is not an easy fish to catch, so kudos to you-know-how-you-are at Yandex security team," he said.

Advertisement - Article continues below

"As a former Yandex CISO I am extremely proud of the team that was able to detect and respond to NSA hacking attack," he added.

Ivanov quoted a section of the article which claimed the purpose of the attack wasn't strictly to spy on Yandex users, but to understand how Yandex authenticates user accounts before saying how the information has been in plain sight.

He alluded to Yandex being transparent in its methods of account authentication which included two-factor authentication and a proprietary Yandex Key application, according to self-written posts to Russian website Habr.

Addressing the NSA directly over Twitter, Ivanov said if they wanted to know how Yandex authenticates user accounts "you could've just asked".

"Yandex does not enrich Uranium, is not a critical infrastructure company, not a military agency," he said. "It's a NASDAQ trading commercial company. I wonder what's the justification to hack into it. Cannot avoid seeing similarities with Chinese attack on Google."

Advertisement - Article continues below

"This particular attack was detected at a very early stage by the Yandex security team. It was fully neutralized before any damage was done," Yandex spokesperson Ilya Grabovsky said to Reuters. "The Yandex security team's response ensured that no user data was compromised by the attack."

The sources said the hack was for espionage purposes and not to steal intellectual property or disrupt system operations. The hackers were able to remain concealed on the Yandex network for "several weeks" before being discovered.

Yandex recruited Kaspersky to help clean up the situation and it was the antivirus software company which was able to establish that the attackers were targeting a group of developers inside Yandex, according to the sources.

The Regin malware used in the attack was reportedly modified from previous versions with never before seen code compared to the previous iterations. Reports tied older version of Regin to GCHQ and NSA joint hacking operations on a Belgian telco in 2013.

GCHQ and the NSA declined to comment while the Home Office did not reply to requests for comment at the time of publication.

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement
Advertisement

Recommended

Visit/security/28170/what-is-cyber-warfare
Security

What is cyber warfare?

16 Mar 2020
Visit/mobile/google-android/356373/over-2-dozen-additional-android-apps-found-stealing-user-data
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020
Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020

Most Popular

Visit/business-strategy/careers-training/356422/ibm-job-ad-calls-for-12-year-experience-with-6-year-old
Careers & training

IBM job ad calls for 12-years of experience with six-year-old Kubernetes

13 Jul 2020
Visit/business/business-operations/356395/nvidia-overtakes-intel-as-most-valuable-us-chipmaker
Business operations

Nvidia overtakes Intel as most valuable US chipmaker

9 Jul 2020
Visit/software/development/356420/linux-kernel-to-strip-out-racially-insensitive-terms
Development

Linux kernel to strip out racially insensitive terms

13 Jul 2020