In Baltimore and Beyond, a Stolen N.S.A. Tool Wreaks

New Post Public Reply Private Reply Replies (1) Message Board
PoemStone cashclan #36584
174
In Baltimore and Beyond, a Stolen N.S.A. Tool Wreaks Havoc
< >


The National Security Agency headquarters in Maryland. A leaked N.S.A. cyberweapon, EternalBlue, has caused billions of dollars in damage worldwide. A recent attack took place in Baltimore, the agency’s own backyard.

By Nicole Perlroth and Scott Shane

May 25, 2019


Microsoft employees reviewing malware data at the company’s offices in Redmond, Wash. EternalBlue exploits a flaw in unpatched Microsoft software

For nearly three weeks, Baltimore has struggled with a cyberattack by digital extortionists that has frozen thousands of computers, shut down email and disrupted real estate sales, water bills, health alerts and many other services.

But here is what frustrated city employees and residents do not know: A key component of the malware that cybercriminals used in the attack was developed at taxpayer expense a short drive down the Baltimore-Washington Parkway at the National Security Agency, according to security experts briefed on the case.

Since 2017, when the N.S.A. lost control of the tool, EternalBlue, it has been picked up by state hackers in North Korea, Russia and, more recently, China, to cut a path of destruction around the world, leaving billions of dollars in damage. But over the past year, the cyberweapon has boomeranged back and is now showing up in the N.S.A.’s own backyard.

It is not just in Baltimore. Security experts say EternalBlue attacks have reached a high, and cybercriminals are zeroing in on vulnerable American towns and cities, from Pennsylvania to Texas, paralyzing local governments and driving up costs.

The N.S.A. connection to the attacks on American cities has not been previously reported, in part because the agency has refused to discuss or even acknowledge the loss of its cyberweapon, dumped online in April 2017 by a still-unidentified group calling itself the Shadow Brokers. Years later, the agency and the Federal Bureau of Investigation still do not know whether the Shadow Brokers are foreign spies or disgruntled insiders.

Thomas Rid, a cybersecurity expert at Johns Hopkins University, called the Shadow Brokers episode “the most destructive and costly N.S.A. breach in history,” more damaging than the better-known leak in 2013 from Edward Snowden, the former N.S.A. contractor.

“The government has refused to take responsibility, or even to answer the most basic questions,” Mr. Rid said. “Congressional oversight appears to be failing. The American people deserve an answer.”

The N.S.A. and F.B.I. declined to comment.

Since that leak, foreign intelligence agencies and rogue actors have used EternalBlue to spread malware that has paralyzed hospitals, airports, rail and shipping operators, A.T.M.s and factories that produce critical vaccines. Now the tool is hitting the United States where it is most vulnerable, in local governments with aging digital infrastructure and fewer resources to defend themselves.
Editors’ Picks
Living With Lyme Disease, Stronger With Love
Emma Thompson Gets a Shock at 60
Why Workers Without College Degrees Are Fleeing Big Cities
On May 7, city workers in Baltimore had their computers frozen by hackers. Officials have refused to pay the $100,000 ransom.Credit.
Image
On May 7, city workers in Baltimore had their computers frozen by hackers. Officials have refused to pay the $100,000 ransom.Credit.

Before it leaked, EternalBlue was one of the most useful exploits in the N.S.A.’s cyberarsenal. According to three former N.S.A. operators who spoke on the condition of anonymity, analysts spent almost a year finding a flaw in Microsoft’s software and writing the code to target it. Initially, they referred to it as EternalBluescreen because it often crashed computers — a risk that could tip off their targets. But it went on to become a reliable tool used in countless intelligence-gathering and counterterrorism missions.

EternalBlue was so valuable, former N.S.A. employees said, that the agency never seriously considered alerting Microsoft about the vulnerabilities, and held on to it for more than five years before the breach forced its hand.

The Baltimore attack, on May 7, was a classic ransomware assault. City workers’ screens suddenly locked, and a message in flawed English demanded about $100,000 in Bitcoin to free their files: “We’ve watching you for days,” said the message, obtained by The Baltimore Sun. “We won’t talk more, all we know is MONEY! Hurry up!”

Today, Baltimore remains handicapped as city officials refuse to pay, though workarounds have restored some services. Without EternalBlue, the damage would not have been so vast, experts said. The tool exploits a vulnerability in unpatched software that allows hackers to spread their malware faster and farther than they otherwise could.

North Korea was the first nation to co-opt the tool, for an attack in 2017 — called WannaCry — that paralyzed the British health care system, German railroads and some 200,000 organizations around the world. Next was Russia, which used the weapon in an attack — called NotPetya — that was aimed at Ukraine but spread across major companies doing business in the country. The assault cost FedEx more than $400 million and Merck, the pharmaceutical giant, $670 million.

The damage didn’t stop there. In the past year, the same Russian hackers who targeted the 2016 American presidential election used EternalBlue to compromise hotel Wi-Fi networks. Iranian hackers have used it to spread ransomware and hack airlines in the Middle East, according to researchers at the security firms Symantec and FireEye.

“It’s incredible that a tool which was used by intelligence services is now publicly available and so widely used,” said Vikram Thakur, Symantec’s director of security response.

One month before the Shadow Brokers began dumping the agency’s tools online in 2017, the N.S.A. — aware of the breach — reached out to Microsoft and other tech companies to inform them of their software flaws. Microsoft released a patch, but hundreds of thousands of computers worldwide remain unprotected.

Hackers seem to have found a sweet spot in Baltimore, Allentown, Pa., San Antonio and other local, American governments, where public employees oversee tangled networks that often use out-of-date software. Last July, the Department of Homeland Security issued a dire warning that state and local governments were getting hit by particularly destructive malware that now, security researchers say, has started relying on EternalBlue to spread.

Microsoft, which tracks the use of EternalBlue, would not name the cities and towns affected, citing customer privacy. But other experts briefed on the attacks in Baltimore, Allentown and San Antonio confirmed the hackers used EternalBlue. Security responders said they were seeing EternalBlue pop up in attacks almost every day.

Amit Serper, head of security research at Cybereason, said his firm had responded to EternalBlue attacks at three different American universities, and found vulnerable servers in major cities like Dallas, Los Angeles and New York.

The costs can be hard for local governments to bear. The Allentown attack, in February last year, disrupted city services for weeks and cost about $1 million to remedy — plus another $420,000 a year for new defenses, said Matthew Leibert, the city’s chief information officer.

He described the package of dangerous computer code that hit Allentown as “commodity malware,” sold on the dark web and used by criminals who don’t have specific targets in mind. “There are warehouses of kids overseas firing off phishing emails,” Mr. Leibert said, like thugs shooting military-grade weapons at random targets.

The malware that hit San Antonio last September infected a computer inside Bexar County sheriff’s office and tried to spread across the network using EternalBlue, according to two people briefed on the attack.

This past week, researchers at the security firm Palo Alto Networks discovered that a Chinese state group, Emissary Panda, had hacked into Middle Eastern governments using EternalBlue.

“You can’t hope that once the initial wave of attacks is over, it will go away,” said Jen Miller-Osborn, a deputy director of threat intelligence at Palo Alto Networks. “We expect EternalBlue will be used almost forever, because if attackers find a system that isn’t patched, it is so useful.”
Adm. Michael S. Rogers, who led the N.S.A. during the leak, has said the agency should not be blamed for the trail of damage.CreditErin Schaff for The New York Times

Until a decade or so ago, the most powerful cyberweapons belonged almost exclusively to intelligence agencies — N.S.A. officials used the term “NOBUS,” for “nobody but us,” for vulnerabilities only the agency had the sophistication to exploit. But that advantage has hugely eroded, not only because of the leaks, but because anyone can grab a cyberweapon’s code once it’s used in the wild.

Some F.B.I. and Homeland Security officials, speaking privately, said more accountability at the N.S.A. was needed. A former F.B.I. official likened the situation to a government failing to lock up a warehouse of automatic weapons.

In an interview in March, Adm. Michael S. Rogers, who was director of the N.S.A. during the Shadow Brokers leak, suggested in unusually candid remarks that the agency should not be blamed for the long trail of damage.

“If Toyota makes pickup trucks and someone takes a pickup truck, welds an explosive device onto the front, crashes it through a perimeter and into a crowd of people, is that Toyota’s responsibility?” he asked. “The N.S.A. wrote an exploit that was never designed to do what was done.”

At Microsoft’s headquarters in Redmond, Wash., where thousands of security engineers have found themselves on the front lines of these attacks, executives reject that analogy.

“I disagree completely,” said Tom Burt, the corporate vice president of consumer trust, insisting that cyberweapons could not be compared to pickup trucks. “These exploits are developed and kept secret by governments for the express purpose of using them as weapons or espionage tools. They’re inherently dangerous. When someone takes that, they’re not strapping a bomb to it. It’s already a bomb.”

Brad Smith, Microsoft’s president, has called for a “Digital Geneva Convention” to govern cyberspace, including a pledge by governments to report vulnerabilities to vendors, rather than keeping them secret to exploit for espionage or attacks.

Last year, Microsoft, along with Google and Facebook, joined 50 countries in signing on to a similar call by French President Emmanuel Macron — the Paris Call for Trust and Security in Cyberspace — to end “malicious cyber activities in peacetime.”

Notably absent from the signatories were the world’s most aggressive cyberactors: China, Iran, Israel, North Korea, Russia — and the United States.
Featured stocks: Coffee Shoppe
For conservative debate: "Keeping it Real"
Game Changing stock $SHMP

Scroll down for more posts ▼

Top 10 Most Recent News Articles

Luxury Air Celebrates 18 Years of Comfort Service

Updated Category News Views 2

Celebrating 18 Years: A Journey of Comfort It's not often you see a business weave itself so seamlessly into the fabric of its community. But that's exactly what Luxury Air A/C & Heating has done in Conroe, The Woodlands, and across Montgomery County. Hit 18 years in the HVAC game, and you've clearly nailed something other folks can't quite replicate. Guess there's no...

Continue Reading
TriStar Bank Community Room: A Space for Growth

Updated Category News Views 1

Building Bridges Through Community Investment Well, ain't this something? Columbia, Tennessee, just got a splash of fresh air. We're talking about the new Southern Regional Technology Center nested in Columbia State Community College. Now, the name on everyone's lips? The TriStar Bank Community Room. But it ain't just about a name plastered up on a wall inside a shiny...

Continue Reading
BMO Sheds U.S. Branches, Eyes Strategic Growth

Updated Category News Views 1

Why BMO is Slimming Down in the States You know, when a heavyweight like BMO Financial Group starts shedding branches left and right, you gotta ask yourself what the grand plan is. In a move that looks more like a strategic dance than an abrupt U-turn, BMO's gotten rid of 138 U.S. branches, handing them over to First-Citizens Bank. We're talking outlets scattered from...

Continue Reading
Primero Gains Global Edge with Win Systems Buy

Updated Category News Views 2

Here's the move: Primero Games, the U.S.-based gaming maestro, just grabbed a hefty piece of the puzzle with their acquisition of Win Systems' Gaming Division. Not two companies merging into obscurity, but a strategic maneuver aiming to scatter new seeds in Latin America and the Caribbean with over 3,000 gaming positions primed and ready. What's in the Pot? You've got...

Continue Reading
SIAL West Asia Ignites Global F&B Trade at Guangzhou

Updated Category News Views 0

A Convergence of Global Taste You could feel the buzz in the air as the 2026 SIAL West Asia International Food Exhibition kicked off at the Guangzhou Poly World Trade Center Expo. Throw over 1,500 exhibitors from the far corners of the globe into a sprawling 60,000-square-meter trade floor, and you've got yourself a melting pot of flavors and cultures revolving around a...

Continue Reading
EF English Live's Approach to Workplace Confidence

Updated Category News Views 3

Pioneering English Confidence for the Global Workplace Stepping into a meeting with international partners requires more than just textbook knowledge of English. It's about confidently expressing ideas, adapting on the fly, and engaging with global colleagues. Enter EF English Live, a leader in transforming workplace communication through targeted English learning. Expert...

Continue Reading
PerfectVape Unveils Online Deals Amid Vape Craze

Updated Category News Views 3

PerfectVape's Digital Bargain Bonanza Alright, so you think you've seen savings? Well, PerfectVape's throwing a real bone to those hunting for vape deals online. They're slapping 10% off on select disposable vapes—no strings, just a promo code, PV10, you punch in at checkout. We've got ourselves an internet-era sale without needing to elbow through crowds. Browsing Made...

Continue Reading
Raiders' Telenovela Hype Ignites Passion in Mexico

Updated Category News Views 1

Raider Nation's Heart Beats in Mexico Hell, you ever see a football game that feels like a soap opera? You bet your boots that's exactly what the Raiders are cooking down in Mexico City. We're not talking about just any ol' season opener; it's the curtain call of Corazón de Plata y Negro. This ain't your average fanfare—it's a spectacle teeming with raw, unfiltered...

Continue Reading
Tech Job Market Surges: 86,000 Hires in August Boost

Updated Category News Views 2

Tech Job Growth Defies Corporate Layoffs Job markets in the tech world are hotter than a two-dollar pistol. Despite seeing some layoffs in tech firms, the demand for skilled tech workers is still booming. You got tech companies tightening the bolts, laying off around 14,700 folks, but here's the kicker: overall tech employment shot up with 86,000 new jobs in August....

Continue Reading
BellRing Brands Faces Legal Probe; Fiduciary Duties Questioned

Updated Category News Views 1

What's Stirring at BellRing Brands? Hey, no time like the present to dive headfirst into this mess BellRing's found itself in. On the heels of a lackluster sales forecast, just announced about a year ago, Kahn Swick & Foti's got their magnifying glasses out, searching for any shady dealings by those running the show at BellRing Brands, LLC. Why Is BellRing in the Hot...

Continue Reading

Top 5 Most Recently Viewed Articles

Ohana Real Estate Investors: Honored as Top Hotel Group in 2026

Updated Category News Views 300

A Stellar Achievement in Hospitality Just when you think the hotel industry can't get any more competitive, Ohana Real Estate Investors goes and bags the "Hotel Ownership Group of the Year" from the Forbes Travel Guide at their Summit in Monaco. This isn’t just a trophy on a mantle; it's a serious nod from the big players at CBRE and FTG, recognizing years of solid...

Continue Reading
Ionis Pharmaceuticals Sells $500 Million in Stock Offering

Updated Category News Views 126

Ionis Pharmaceuticals Unveils Major Stock Offering Ionis Pharmaceuticals, Inc. (NASDAQ: IONS) has announced a significant financial move involving a public offering of common stock. This underwritten offering includes 11,500,000 shares, each priced at $43.50, with total gross proceeds projected to reach an impressive $500.3 million. The funds raised are intended to...

Continue Reading
BPCE SFH's Strategic Restructuring for Noteholders Ahead

Updated Category News Views 105

Notice to Noteholders from BPCE SFH Notice to Noteholders To: Noteholders From: BPCE SFH 7, promenade Germaine Sablon 75013 Paris Copy: Fiscal Agent, Principal Paying Agent, and Calculation Agent: BNP Paribas Securities Services Les Grands Moulins de Pantin 9 rue du Débarcadère 93500 PANTIN BPCE SFH (“Issuer”) Legal Entity Identifier (LEI): 969500T1UBNNTYVWOS04...

Continue Reading
IMUNON Highlights Progress in Ovarian Cancer Treatment Plans

Updated Category News Views 109

Company Overview IMUNON, Inc. (Nasdaq: IMNN) is a clinical-stage biotechnology company dedicated to advancing innovative cancer therapies that leverage the body's natural defenses. The company focuses on developing a range of pioneering treatments utilizing their non-viral DNA technology platform. Recent Financial Results In its second quarter of 2025, IMUNON reported a...

Continue Reading
Supernus Pharmaceuticals Announces Q3 Earnings Call Details

Updated Category News Views 34

Supernus Pharmaceuticals Plans Third Quarter Earnings Call Supernus Pharmaceuticals, Inc. (NASDAQ: SUPN), a leading biopharmaceutical company, is excited to share details about their upcoming conference call to discuss financial results for the third quarter of 2024. This event is set to take place shortly after the market closes, scheduled for November 4, 2024. Overview...

Continue Reading