# Hello all!  We are ShadowEye, a handful of industry professionals who have a strong interest in the operations of and evolution of nation-state attackers. Generally, the publishing of these kinds of analyses tends to be restricted to a known set of vendors, usually following a predictable methodology, with a heavy focus on malware and campaigns targetting Microsoft products. While exceptionally useful as PR pieces, essays authored with IDA Pro and full of footnotes of hashes aren't particularly useful for understanding the broader picture of how these groups operate, the processes they use, their development standards, and ultimately the way they use their resources, which is what we aim to provide. ## Why are we doing this anonymously, you ask? Being industry professionals, we've no particular interest in drawing the ire or attention of any organisation down on our friends and colleagues. It's also a good way for us to demonstrate that we don't have any vested financial interest in publishing these analyses. ## Are we the CIA/FSB/PLA/DPRK? No. While we're probably going to initially focus on the NSA and CIA leaks due to the vast body of material released, we don't have any biases towards or against any set of operators. We also want to draw attention to the fact that for all the information published by Crowdstrike, Kaspersky, Symantec et al, no threat actor groups have stopped operating. These are professional teams and consequently the loss of a toolset will not affect their general operations. Discussing their processes is equally unlikely to disrupt any of their work, but will help us reach our goal of drinks with thegrugq in Thailand. ## Why are we so dismissive of vendors? It's not our intent to be dismissive of some of the excellent work produced by a number of vendors, more a general critique of the way that information is presented. Lists of IoCs that consist of filenames and hashes are not particularly useful; implants can be and are regularly tailored and customized for specific targets. Similarly, many of these reports take a very narrow viewpoint indeed, focusing on a single "campaign", which often is more beneficial to the attackers than anyone looking to protect themselves. We are, however, completely dismissive of using months of hard work analysing malware as evidence that a particular silver-bullet product, be it antivirus, next generation endpoint protection, an appliance, or anything else, has any other purpose besides filtering out the bottom-feeders of the malware world. ## Can you help? Yes, absolutely. We need peer-reviews, corrections, and feedback. Samples from campaigns are welcome, too. We will supply contact details at a later date, but for now, comments on here are fine. *Image Credit: BoingBoing*
author | shadoweye |
---|---|
permlink | introductions |
category | security |
json_metadata | {"tags":["security","introduceyourself","steemit","hacking","technology"],"app":"steemit/0.1","format":"markdown","image":["https://media.boingboing.net/wp-content/uploads/2013/06/eagle_new_layers_verizon1.jpg"]} |
created | 2017-10-12 11:02:42 |
last_update | 2017-10-12 11:12:42 |
depth | 0 |
children | 9 |
last_payout | 2017-10-19 11:02:42 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.458 HBD |
curator_payout_value | 0.026 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 2,879 |
author_reputation | 57,669,623,601 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,480,940 |
net_rshares | 199,591,143,430 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
steevc | 0 | 33,265,735,256 | 10% | ||
finnian | 0 | 10,222,229,462 | 10% | ||
synapse | 0 | 146,569,016,179 | 100% | ||
tomekkk | 0 | 8,378,322,256 | 100% | ||
kromosoom | 0 | 161,631,026 | 1% | ||
fattyvillalba | 0 | 602,220,751 | 100% | ||
mabhedal | 0 | 145,078,193 | 100% | ||
shadoweye | 0 | 246,910,307 | 100% |
Welcome to Steemit! From that intro post, I'm not sure if you are a friend or foe of liberty. The assumption is that you're a friend. Would you expand on your group's long term objectives and ideals please? I look forward to seeing your future content. I suspect you are, as a collective, not new to Steemit.com, but I'll share my new user information just in case it helps. --- ### Webpages There are a ton of other webpages to help you with Steemit. Here are some of the best for beginners: https://steemd.com/ (This site is used to keep track of your voting power and other stats. You do not want to run out of voting power, and you only get so much per day. I keep my voting power around 80% for example.) https://steem.makerwannabe.com/ (This site will tell you who follows you, who unfollows you, and who mutes you. It is great for meeting new people too. I regularly check it to see who has followed me to see if I should follow them back.) https://steemit.chat/ (This site is the official chat webpage for Steemit. There are Discord channels too, but I usually stick to the official site. Come in to network and meet new friends. You can directly message people there too, so it makes it easier to communicate with your closest friends.) ### Bots Oh yeah, there are a lot of bots on here. If you see a cookie cutter reply, especially to your intro post, it is almost certainly a bot. Check the account's reputation. If it is low, I would recommend just ignoring them. Everything is public on Steemit, so you can go look at an account's comments and replies. Are they all the same? It's a bot. ### Sourcing and Adding Photos Adding photos to your account as a new Steemian may be confusing at first too. The easiest way it to click to "Submit a Story." Once in there, use the built in Steemit tool to upload an image from your computer. Below the posting window, you will see "Insert images by dragging & dropping, pasting from the clipboard, or by selecting them." Click on the blue text. Once the image is uploaded, you can copy and paste the link into your account settings. Here's a link to a Google Document I made to help with the coding: https://docs.google.com/document/d/1NlAoGnP8q7ZAxGsEnvza-qotUGkoaae4SwXdubAhi2g/edit?usp=sharing ### Account Verification Verifying your identity is very important because it will get you more support and people will trust you more. The best way to verify is to link back to your Steemit account by using another public social media account. For example, I posted my Steemit articles from here through my Twitter account. Another person posted their Steemit information on their Facebook account. Some people will even post a video of themselves writing out their account information since that cannot be Photoshopped. The more famous a person is or the more valuable their content is, the more important it is that they verify. If a new account falls within those two categories and fails to verify, it may get blacklisted. ### Security Do not use your owner key to log into Steemit.com to post. Use your private posting key instead. Keep your owner key offline as much as possible, and only use it when you must. Per the advice given by Arcanage, you should only use your owner key to: 1. Recover your account. 2. Change the other keys. 3. Give a present to your children a few minutes before dying. A lot of scams have been happening on Steemit recently. If you click a link to a site that prompts you to log into it, be extra careful. Double and triple check the address to make sure it is really steemit.com. A recent scam was using "lsteemit" as the domain name, and people were entering their owner keys to log into it. That allowed the scammers to take those user's accounts, empty the money from them, and then ruin their reputation by using the newly hacked accounts to further the scam. If you find or suspect a scam, please report it in the #steemitabuse channel on steemit.chat. --- Again, welcome, and I've followed you! If you have any questions about getting started, look me up on the chat site.
author | finnian |
---|---|
permlink | re-shadoweye-introductions-20171012t150225255z |
category | security |
json_metadata | {"tags":["security","steemitabuse"],"links":["https://steemd.com/","https://steem.makerwannabe.com/","https://steemit.chat/","https://docs.google.com/document/d/1NlAoGnP8q7ZAxGsEnvza-qotUGkoaae4SwXdubAhi2g/edit?usp=sharing"],"app":"steemit/0.1"} |
created | 2017-10-12 15:02:24 |
last_update | 2017-10-12 15:03:24 |
depth | 1 |
children | 2 |
last_payout | 2017-10-19 15:02:24 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 4,127 |
author_reputation | 4,742,383,200,746 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,499,299 |
net_rshares | 4,375,079,407 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 4,375,079,407 | 100% |
Many thanks for the welcome and introductory advice, it is proving of use to some of our group who are less familiar with the Steem platform. Our long term goals are quite simple: attempt to shed light on the workings (tools, tactics and procedures) of nation-state hacking groups, regardless of which nation they are from, in a factual and neutral manner. We wish to do this for a variety of reasons, including beliefs in freedom of information, privacy, transparency, and citizens right to know. Further to that, we want to provide information that is not biased towards a commercial or national agenda.
author | shadoweye |
---|---|
permlink | re-finnian-re-shadoweye-introductions-20171012t155537087z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-10-12 15:55:39 |
last_update | 2017-10-12 15:55:39 |
depth | 2 |
children | 1 |
last_payout | 2017-10-19 15:55:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.048 HBD |
curator_payout_value | 0.007 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 607 |
author_reputation | 57,669,623,601 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,504,034 |
net_rshares | 23,638,161,316 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
finnian | 0 | 19,308,655,652 | 20% | ||
shadoweye | 0 | 4,329,505,664 | 100% |
You're very welcome and I thank you for the further clarification.
author | finnian |
---|---|
permlink | re-shadoweye-re-finnian-re-shadoweye-introductions-20171012t170407349z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-10-12 17:04:06 |
last_update | 2017-10-12 17:04:06 |
depth | 3 |
children | 0 |
last_payout | 2017-10-19 17:04:06 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 66 |
author_reputation | 4,742,383,200,746 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,509,615 |
net_rshares | 4,375,079,407 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 4,375,079,407 | 100% |
Julian Assange is that you? :) In any case, keep us posted @shadoweye and welcome to our home.
author | kaliju |
---|---|
permlink | re-shadoweye-introductions-20171012t122245646z |
category | security |
json_metadata | {"tags":["security"],"users":["shadoweye"],"app":"steemit/0.1"} |
created | 2017-10-12 12:22:51 |
last_update | 2017-10-12 12:22:51 |
depth | 1 |
children | 0 |
last_payout | 2017-10-19 12:22:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 95 |
author_reputation | 34,142,096,389,326 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,486,666 |
net_rshares | 8,020,978,914 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 8,020,978,914 | 100% |
Nice! I can see that you have signed up recently so welcome aboard. This deserves an upvote and I hope to read more from you in the future! As you are new to steemit, getting those big upvotes are gonna be hard so I suggest you to try out @MinnowPowerUp as you can earn up to 30% more steem power than just powering up with steem directly! It's a subscription based daily upvote bot that draws its power from a delegation pool. I have also made [__this post__](https://steemit.com/steemit/@kromosoom/how-to-invest-smartly-into-steem-power-and-how-to-buy-steem) where I explain my experience with the service in more depth and show how I earn over $1 a day in upvotes.
author | kromosoom |
---|---|
permlink | re-introductions-20171014t135120 |
category | security |
json_metadata | "{"app": "pysteem/0.5.4"}" |
created | 2017-10-14 13:51:18 |
last_update | 2017-10-14 13:51:18 |
depth | 1 |
children | 0 |
last_payout | 2017-10-21 13:51:18 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 667 |
author_reputation | 22,127,725,207,689 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,668,735 |
net_rshares | 6,380,324,136 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 6,380,324,136 | 100% |
Welcome shadoweye, hope you will have a great time here on steemit!
author | lopezdacruz |
---|---|
permlink | re-introductions-20171012t161902 |
category | security |
json_metadata | "" |
created | 2017-10-12 16:19:03 |
last_update | 2017-10-12 16:19:03 |
depth | 1 |
children | 0 |
last_payout | 2017-10-19 16:19:03 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.123 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 67 |
author_reputation | 1,850,776,799,275 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,505,954 |
net_rshares | 50,887,099,906 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
lopezdacruz | 0 | 46,603,167,986 | 100% | ||
shadoweye | 0 | 4,283,931,920 | 100% |
Hi @shadoweye... Nice to know about you... Welcome to Steemit..🌹.. This is a nice intro post... I hope you will do great over here..😊.. Follow Me @onority
author | onority |
---|---|
permlink | re-shadoweye-introductions-20171012t123646067z |
category | security |
json_metadata | {"tags":["security"],"users":["shadoweye","onority"],"app":"steemit/0.1"} |
created | 2017-10-12 12:36:57 |
last_update | 2017-10-12 12:36:57 |
depth | 1 |
children | 0 |
last_payout | 2017-10-19 12:36:57 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 154 |
author_reputation | 57,066,785,022 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,487,711 |
net_rshares | 7,747,536,451 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 7,747,536,451 | 100% |
Hello, Shadoweye, Let me welcome you to Steemit. Hope you gonna have fun with our community. Feel free to follow me @rightuppercorner Have a great time @rightuppercorner
author | rightuppercorner |
---|---|
permlink | 20171012t110526245z |
category | security |
json_metadata | {} |
created | 2017-10-12 11:05:27 |
last_update | 2017-10-12 11:05:27 |
depth | 1 |
children | 0 |
last_payout | 2017-10-19 11:05:27 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 170 |
author_reputation | -126,230,223,794 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,481,102 |
net_rshares | 7,884,257,682 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 7,884,257,682 | 100% |
A new Steemian ^^ hello @shadoweye I hope you enjoy your time here, its a great community ! Nice post, wish you much luck! I will follow your account. Don't hesitate to contact or follow me at any time :-) See you around @tradewonk
author | tradewonk |
---|---|
permlink | re-shadoweye-introductions-20171013t084333399z |
category | security |
json_metadata | {"tags":["security"],"users":["shadoweye","tradewonk"],"app":"steemit/0.1"} |
created | 2017-10-13 08:43:33 |
last_update | 2017-10-13 08:43:33 |
depth | 1 |
children | 0 |
last_payout | 2017-10-20 08:43:33 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 231 |
author_reputation | 133,615,265,755,348 |
root_title | Introductions... |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 17,566,182 |
net_rshares | 5,514,423,003 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
shadoweye | 0 | 5,514,423,003 | 100% |