Was an insider behind the NSA hack?

Linguistic analysis casts doubt on "Russian hacker" claims

The perpetrator of the Shadow Brokers breach at the NSA may in fact by an English-speaking insider at the American agency, rather than a Russian hacker collective, as first presumed.

Earlier this month, attackers revealed they had managed to gain access to cyber weapons from the Equation Group, widely thought to be the NSA's own state hacking collective. They circulated 300 files online detailing zero-day exploits - several of which have been confirmed as genuine - and auctioned off a second, encrypted cache to the highest bidder.

It was initially theorised that the hackers were foreign operatives with the most popular theory being that they were Russian. This was spurred on by the fact that the Pastebin post from the perpetrators was in broken English.

However, linguistic analysis by Shlomo Aragon, professor of Computer Science and director of the Linguistic Cognition Laboratory at the Illinois Institute of Technology (IIT) suggested that the author of the post is actually a native English-speaker trying to disguise the fact they are anglophone.

"The texts contain a variety of different grammatical errors that are not usual in the English of US native speakers," writes Aragon in a post on Taia Global. These include the omission of definite and indefinite articles ("a" and "the"), the omission of infinitive "to" (e.g., "I want get" instead of "I want to get") and confusion of tenses.

However, he points out that, while there are grammatical errors, there are no spelling errors, irrespective of how complex the word is. Additionally, the grammatical errors are inconsistent and the author uses plenty of idioms, even though they do contain mistakes in grammar. This has let Aragon to the conclusion that "the author is most likely a native speaker of US English who is attempting to sound like a non-native speaker by inserting a variety of random grammatical errors".

Separately, others have come to the conclusion that the perpetrator is an NSA insider.

Cyber security professional and white hat hacker Matt Suiche said in a post on Medium that a former NSA analyst had come to him with this theory, speaking on the condition of anonymity.

After discussions with this source, several points were put forward suggesting the "hackers" were in fact a single person working from within the NSA. These include the fact that the name ShadowBrokers originally comes from the computer game Mass Effect, and that the NSA Tailored Access Operations (TAO) group, where the cyber weapons stolen are thought to come from, apparently has a "big gaming culture"

Also, the depository containing the NSA TAO toolkit is reportedly stored on a separate network that is not connected to the internet at all (which would impede someone trying to hack from the outside).

The "TAO Team had severe concerns about how easy it was to just walk out with the data on a USB drive" and a native English-speaker could easily fake broken English to make themselves sound Russian (although Suiche does not go into as much detail as Aragon in terms of analysis).

However, Suiche does concede "this is only a possible scenario" and "the discussion is open".

Featured Resources

How virtual desktop infrastructure enables digital transformation

Challenges and benefits of VDI

Free download

The Okta digital trust index

Exploring the human edge of trust

Free download

Optimising workload placement in your hybrid cloud

Deliver increased IT agility with the cloud

Free Download

Modernise endpoint protection and leave your legacy challenges behind

The risk of keeping your legacy endpoint security tools

Download now

Recommended

US gov issues fresh warning over Russian threat to critical infrastructure
cyber warfare

US gov issues fresh warning over Russian threat to critical infrastructure

12 Jan 2022
Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021
Hackers use open source Microsoft dev platform to deliver trojans
Security

Hackers use open source Microsoft dev platform to deliver trojans

14 May 2021

Most Popular

How to move Microsoft's Windows 11 from a hard drive to an SSD
Microsoft Windows

How to move Microsoft's Windows 11 from a hard drive to an SSD

4 Jan 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

6 Jan 2022
Microsoft Exchange servers break thanks to 'Y2K22' bug
email delivery

Microsoft Exchange servers break thanks to 'Y2K22' bug

4 Jan 2022