Was an insider behind the NSA hack?

Linguistic analysis casts doubt on "Russian hacker" claims

The perpetrator of the Shadow Brokers breach at the NSA may in fact by an English-speaking insider at the American agency, rather than a Russian hacker collective, as first presumed.

Earlier this month, attackers revealed they had managed to gain access to cyber weapons from the Equation Group, widely thought to be the NSA's own state hacking collective. They circulated 300 files online detailing zero-day exploits - several of which have been confirmed as genuine - and auctioned off a second, encrypted cache to the highest bidder.

It was initially theorised that the hackers were foreign operatives with the most popular theory being that they were Russian. This was spurred on by the fact that the Pastebin post from the perpetrators was in broken English.

However, linguistic analysis by Shlomo Aragon, professor of Computer Science and director of the Linguistic Cognition Laboratory at the Illinois Institute of Technology (IIT) suggested that the author of the post is actually a native English-speaker trying to disguise the fact they are anglophone.

"The texts contain a variety of different grammatical errors that are not usual in the English of US native speakers," writes Aragon in a post on Taia Global. These include the omission of definite and indefinite articles ("a" and "the"), the omission of infinitive "to" (e.g., "I want get" instead of "I want to get") and confusion of tenses.

However, he points out that, while there are grammatical errors, there are no spelling errors, irrespective of how complex the word is. Additionally, the grammatical errors are inconsistent and the author uses plenty of idioms, even though they do contain mistakes in grammar. This has let Aragon to the conclusion that "the author is most likely a native speaker of US English who is attempting to sound like a non-native speaker by inserting a variety of random grammatical errors".

Separately, others have come to the conclusion that the perpetrator is an NSA insider.

Cyber security professional and white hat hacker Matt Suiche said in a post on Medium that a former NSA analyst had come to him with this theory, speaking on the condition of anonymity.

After discussions with this source, several points were put forward suggesting the "hackers" were in fact a single person working from within the NSA. These include the fact that the name ShadowBrokers originally comes from the computer game Mass Effect, and that the NSA Tailored Access Operations (TAO) group, where the cyber weapons stolen are thought to come from, apparently has a "big gaming culture"

Also, the depository containing the NSA TAO toolkit is reportedly stored on a separate network that is not connected to the internet at all (which would impede someone trying to hack from the outside).

The "TAO Team had severe concerns about how easy it was to just walk out with the data on a USB drive" and a native English-speaker could easily fake broken English to make themselves sound Russian (although Suiche does not go into as much detail as Aragon in terms of analysis).

However, Suiche does concede "this is only a possible scenario" and "the discussion is open".

Featured Resources

The definitive guide to warehouse efficiency

Get your free guide to creating efficiencies in the warehouse

Free download

The total economic impact™ of Datto

Cost savings and business benefits of using Datto Integrated Solutions

Download now

Three-step guide to modern customer experience

Support the critical role CX plays in your business

Free download

Ransomware report

The global state of the channel

Download now

Recommended

Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021
Hackers use open source Microsoft dev platform to deliver trojans
Security

Hackers use open source Microsoft dev platform to deliver trojans

14 May 2021
NSA issues guidance on encrypted DNS usage
Domain Name System (DNS)

NSA issues guidance on encrypted DNS usage

15 Jan 2021

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

17 Sep 2021
What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

17 Sep 2021