Massive breach spills credentials for thousands of sensitive networks

https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security.jpg

Hudson Rock said the attackers went on to “actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis.” From there, they used the GPU cluster to crack the hashes, meaning to try massive combinations of plain-text passwords until they found the right one. These passwords allowed the threat actors to move laterally to compromise Active Directory environments and other centralized authentication systems.

“This aggressive methodology has led to severe, real-world consequences,” Hudson Rock said. “Diachenko’s research confirmed full network compromises at multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Most alarmingly, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated by the group.”

In the interview, Diachenko put it more succinctly. “The scale is the sophistication,” he said.

The scale didn’t stop there. The attackers used the massive cluster to run a” feedback-driven, 12-level recursive...

Copyright of this story solely belongs to arstechnica.com. To see the full text click HERE

Read more