Solar winds HQ in Austin raided by FBI, US Marshals and Texas Rangers

51,247 Views | 57 Replies | Last: 12 hrs ago by C@LAg
HarryJ33tamu
How long do you want to ignore this user?
https://www.thegatewaypundit.com/2020/12/breaking-fbi-texas-rangers-us-marshals-raid-solarwinds-hq-austin/

I know, I know - Gateway Pundit. But they're just reporting what the guy said on Hannity's show today. I'll look for more sources
peacedude
How long do you want to ignore this user?
AG
Quick! It's the Feds! They're onto us!
Not a Bot
How long do you want to ignore this user?
AG
SolarWinds was the apparent victim of a hacking campaign orchestrated by a nation-state.

https://arstechnica.com/information-technology/2020/12/18000-organizations-downloaded-backdoor-planted-by-cozy-bear-hackers/

This company provides a lot of networking tools for businesses. Up to 18,000 of their clients, including DHS, DoT, and Commerce, were affected.
jagvocate
How long do you want to ignore this user?
AG
Big, if true.
Clob94
How long do you want to ignore this user?
Soooooo somebody working inside the company is a mole?
Stat Monitor Repairman
How long do you want to ignore this user?
They got offices in Eastern Europe. CR and somewhere else if I recall.
tlepoC
How long do you want to ignore this user?
AG
It's not the beginning of the end. It's the end of the beginning.
MrProfit
How long do you want to ignore this user?
AG
Yes, right off SW parkway. CEO may have known for a while... see unusual preplanned stock sales.
Burrus86
How long do you want to ignore this user?
AG
Theoretically: could the nation backed hackers be American....as in the DOD?
black_ice
How long do you want to ignore this user?
tlepoC said:

It's not the beginning of the end. It's the end of the beginning.




Tibbers
How long do you want to ignore this user?
Cactus Jack said:

SolarWinds was the apparent victim of a hacking campaign orchestrated by a nation-state.

https://arstechnica.com/information-technology/2020/12/18000-organizations-downloaded-backdoor-planted-by-cozy-bear-hackers/

This company provides a lot of networking tools for businesses. Up to 18,000 of their clients, including DHS, DoT, and Commerce, were affected.
The hack sounds more like covering tracks considering they are the ones getting raided, don't you think? Didn't we see a similar hack in 2016? DoD is not fooled and neither is the DIA.
eric76
How long do you want to ignore this user?
AG
So they provide tools for managed service providers (MSPs).

MSPs are good targets for attackers since once you get through them, you can likely get into any network they manage. I think that for a number of organizations whose files were encrypted by ransomware attackers in the last year. the attacks came through the MSP used by the organization.
Not a Bot
How long do you want to ignore this user?
AG
https://texags.com/forums/30/topics/3165842

The nerdery thread on this for more information.
peacedude
How long do you want to ignore this user?
AG
Yes...especially if their specialties include: CEH, CSSP, SEC+ (and the two other +s), MS in Cyber but preferably PHD. 15+ years of experience & military intel preferred.

12 spots, ironically.

P.S. TS/SCI w/FSPoly
HECUBUS
How long do you want to ignore this user?
AG
Mr Robot lives. I work in the same campus for a different company and have seen the scrawny dude in a hoodie appearing to need vitamins and sleep.

Whoop! Slammm Dunk! Apologies to normal folks who have not seen Mr. Robot.
74Ag1
How long do you want to ignore this user?
AG
So does SW have a connection to the election or they just dumping stock to make a profit?
OldArmyBrent
How long do you want to ignore this user?
AG
MrProfit said:

Yes, right off SW parkway. CEO may have known for a while... see unusual preplanned stock sales.

I'm not sure I would call it unusual to sell stock after a 6 month run up in price after you announced your departure as CEO.
FJB
How long do you want to ignore this user?
AG
74Ag1 said:

So does SW have a connection to the election or they just dumping stock to make a profit?


https://m.theepochtimes.com/dominion-voting-systems-uses-firm-that-was-hacked_3617507.html
Sex Panther
How long do you want to ignore this user?
AG
HECUBUS said:

Mr Robot lives. I work in the same campus for a different company and have seen the scrawny dude in a hoodie appearing to need vitamins and sleep.

Whoop! Slammm Dunk! Apologies to normal folks who have not seen Mr. Robot.


lb3
How long do you want to ignore this user?
AG
74Ag1 said:

So does SW have a connection to the election or they just dumping stock to make a profit?
It appears that Dominion uses SolarWind.
Stat Monitor Repairman
How long do you want to ignore this user?
Oppsie daisy.
Tibbers
How long do you want to ignore this user?
SexyAg said:

74Ag1 said:

So does SW have a connection to the election or they just dumping stock to make a profit?


https://m.theepochtimes.com/dominion-voting-systems-uses-firm-that-was-hacked_3617507.html


Here is an idea. Solarwinds, like cloudflare, is a middle man for data. Since we know that Dominion was using Solarwinds as a middleman for data and we also know from Michigan's dominion systems analysis that the logs were erased, we can most likely assume that we would find similar results in Barcelona, Serbia and Frankfurt.

The last hope would be that Solarwinds would have packet traffic logs of dominion servers saying hello to foreign entities or we could also show that Solarwinds logs would be erased at that time as well. Spurious evidence.

If you are approaching this problem from the position of the military setting a trap, one would be ready and waiting, watching these malign actions occur real-time and already have snagged the logs through covert method. Combine that with the exposure of deleted evidence and it shows without dispute felonious behavior.
kb2001
How long do you want to ignore this user?
AG
Lots of companies use Solarwinds, our network team included. They were pretty much the gold standard 10 years ago, and are still a major player in network monitoring and management.

This is really bad. Primarily because it was compromised a while ago, and managed to put the malicious code into Orion software updates, so customers who are keeping up with patching are all impacted. The group basically waited until all their intended targets were susceptible before attacking.
Sid Farkas
How long do you want to ignore this user?
AG
no matter what happens next with this story...in the very least, these things should happen:

1. FBI issues FISA warrants to spy on the incoming (Biden) admin under the assumption they were involved in something nefarious (actual evidence not nec, fake evidence will do...they can even let republicans concoct the fake evidence)
2, FBI entraps unsuspecting and likely innocent subjects in the new admin - ruining their lives
3. outgoing intelligence and fed law enforcement executives become regulars on cable news and oped pages swearing they have evidence of Biden's collusion with foreign actors who affected the outcome of the election - even as they swear under oath to the contrary in secret closed door meetings
4. media should swallow the lies - hook, line and sinker and repeat them over and over
5. Social media should ban content and users who dont play along with the lies
6. Impeach 46
7. if the above doesnt work, make next year's flu sound as dangerous as airborne ebola and shut the economy down
8. If further action is required - use party machinery to create civil unrest
...
9. Profit
OldArmyBrent
How long do you want to ignore this user?
AG
kb2001 said:

Lots of companies use Solarwinds, our network team included. They were pretty much the gold standard 10 years ago, and are still a major player in network monitoring and management.

This is really bad. Primarily because it was compromised a while ago, and managed to put the malicious code into Orion software updates, so customers who are keeping up with patching are all impacted. The group basically waited until all their intended targets were susceptible before attacking.

If someone was able to insert code with the digital signature of SW, why should we believe there nothing else being exploited right now? That's why everything Solarwinds was turned off. I realize I'm oversimplifying, but this is terrifying. Orion was not the only thing compromised.
kb2001
How long do you want to ignore this user?
AG
OldArmyBrent said:

kb2001 said:

Lots of companies use Solarwinds, our network team included. They were pretty much the gold standard 10 years ago, and are still a major player in network monitoring and management.

This is really bad. Primarily because it was compromised a while ago, and managed to put the malicious code into Orion software updates, so customers who are keeping up with patching are all impacted. The group basically waited until all their intended targets were susceptible before attacking.

If someone was able to insert code with the digital signature of SW, why should we believe there nothing else being exploited right now? That's why everything Solarwinds was turned off. I realize I'm oversimplifying, but this is terrifying. Orion was not the only thing compromised.
Agreed, this is really bad. The compromise was to a SAML assertion that allowed the attackers to generate high level users. Who knows what else they could have done to any products, they could still have sleeper accounts in SW's infrastructure. This is really bad
WestAustinAg
How long do you want to ignore this user?
AG
The office is in Southwest Parkway. Go see for yourself.
Dominion IT Rep
How long do you want to ignore this user?
Gateway pundit Headline: ZOMG RAID!
Quote:

BREAKING: FBI, Texas Rangers and US Marshals Raid SolarWinds HQ

Actual article:
Quote:

"Sean. I'm here in Texas. I have a good friend who's a ranger who passed to me that the FBI, the Texas Rangers and the US Marshals are all at the SolarWinds headquarters in Austin, Texas and they are currently looking"

For the record We have been looking for more information on this so-called raid and contacted friends in Austin but have not yet confirmed this incident.
No mention of "raid". One would expect law enforcement would be working with an important IT company that was the victim of a foreign attack.
OldArmyBrent
How long do you want to ignore this user?
AG
Dominion IT Rep said:

Gateway pundit Headline: ZOMG RAID!
Quote:

BREAKING: FBI, Texas Rangers and US Marshals Raid SolarWinds HQ

Actual article:
Quote:

"Sean. I'm here in Texas. I have a good friend who's a ranger who passed to me that the FBI, the Texas Rangers and the US Marshals are all at the SolarWinds headquarters in Austin, Texas and they are currently looking"

For the record We have been looking for more information on this so-called raid and contacted friends in Austin but have not yet confirmed this incident.
No mention of "raid". One would expect law enforcement would be working with an important IT company that was the victim of a foreign attack.

Another sock is here!
titan
How long do you want to ignore this user?
S

The meaning seems to be that in a roundabout way, it would mean China had the theoretical power to have admin level access to any system using this. Which would mean Dominion even manipulated from there. IF this is what it is starting look like.
FrioAg 00:
Leftist Democrats "have completely overplayed the Racism accusation. Honestly my first reaction when I hear it today is to assume bad intentions by the accuser, not the accused."
Tibbers
How long do you want to ignore this user?
Ding ding ding!

Or rather

Ching Chang Chong!

All we would need is the logs to show packet transfer to solidify this theory.

The hack on the treasury happened the day after the CCP list was "leaked"

The Hunter Biden investigation led directly to China. Who would have gained the most from rigging the Presidential election? China.

Christine Fang Fang Fang news drops to show corruption on the House Intel committee, a candidate handpicked by Pelosi.

Pelosi tells America in Chinatown that there is nothing to fear in Feb. Feinstein had a Chinese spy as a driver for 20 years...it all goes back to China.
MouthBQ98
How long do you want to ignore this user?
AG
All sorts of back doors could be installed across large swathes of the internet infrastructure that might take years to ferret out.
Cassius
How long do you want to ignore this user?
OldArmyBrent said:

kb2001 said:

Lots of companies use Solarwinds, our network team included. They were pretty much the gold standard 10 years ago, and are still a major player in network monitoring and management.

This is really bad. Primarily because it was compromised a while ago, and managed to put the malicious code into Orion software updates, so customers who are keeping up with patching are all impacted. The group basically waited until all their intended targets were susceptible before attacking.

If someone was able to insert code with the digital signature of SW, why should we believe there nothing else being exploited right now? That's why everything Solarwinds was turned off. I realize I'm oversimplifying, but this is terrifying. Orion was not the only thing compromised.

What if they simply accessed the source using someone's credentials at SW. Most source is in the cloud now. That wouldn't mean anything and everything is compromised.
mickeyrig06sq3
How long do you want to ignore this user?
AG
Tibbers said:

Ding ding ding!

Or rather

Ching Chang Chong!

All we would need is the logs to show packet transfer to solidify this theory.

The hack on the treasury happened the day after the CCP list was "leaked"

The Hunter Biden investigation led directly to China. Who would have gained the most from rigging the Presidential election? China.

Christine Fang Fang Fang news drops to show corruption on the House Intel committee, a candidate handpicked by Pelosi.

Pelosi tells America in Chinatown that there is nothing to fear in Feb. Feinstein had a Chinese spy as a driver for 20 years...it all goes back to China.

I'm fully onboard for going after the CCP, Feinstein, and Swalwell,. But that opening salvo in your post is definitely uncalled for. Crap like that is what helps reinforce the false stereotype that outsiders try to paint on the Aggie family.

China, Russia, or both; only time will tell. CISA talked about the fact that when using the exploit, the hackers cover their tracks on the Solarwinds server and then start utilizing the various malware/worms that they've been able to propagate from the initial foothold. It's going to take a lot of forensic auditing by companies and outside security firms to get the full story; probably will take 6 months to a year to fully flesh out. This one will go down in CyberSec books along with Stuxnet and NotPetya.
ironmanag
How long do you want to ignore this user?
AG
Our country and our computers and our software is totally safe. Liberals, MSM and Biden said so so it has to be true.
According to the Biden White House, what Joe Biden says does not represent the official position of the Biden administration.
Page 1 of 2
 
×
subscribe Verify your student status
See Subscription Benefits
Trial only available to users who have never subscribed or participated in a previous trial.