Some of the most powerful espionage tools created by the National Security Agency's elite group of hackers have been revealed in recent days, a development that could pose severe consequences for the spy agency's operations and the security of government and corporate computers.
A cache of hacking tools with code names such as Epicbanana, Buzzdirection and Egregiousblunder appeared mysteriously online over the weekend, setting the security world abuzz with speculation over whether the material was legitimate.
The file appeared to be real, according to former NSA personnel who worked in the agency's hacking division, known as Tailored Access Operations (TAO).
"Without a doubt, they're the keys to the kingdom," said one former TAO employee, who spoke on the condition of anonymity to discuss sensitive internal operations. "The stuff you're talking about would undermine the security of a lot of major government and corporate networks both here and abroad."
Said a second former TAO hacker who saw the file: "From what I saw, there was no doubt in my mind that it was legitimate."
The file contained 300 megabytes of information, including several "exploits," or tools for taking control of firewalls in order to control a network, and a number of implants that might, for instance, exfiltrate or modify information.
The exploits are not run-of-the-mill tools to target everyday individuals. They are expensive software used to take over firewalls, such as Cisco and Fortinet, that are used "in the largest and most critical commercial, educational and government agencies around the world," said Blake Darche, another former TAO operator and now head of security research at Area 1 Security.
The software apparently dates back to 2013 and appears to have been taken then, experts said, citing file creation dates, among other things.
"What's clear is that these are highly sophisticated and authentic hacking tools," said Oren Falkowitz, chief executive of Area 1 Security and another former TAO employee.
Several of the exploits were pieces of computer code that took advantage of "zero-day" or previously unknown flaws or vulnerabilities in firewalls, which appear to be unfixed to this day, said one of the former hackers.
The disclosure of the file means that at least one other party - possibly another country's spy agency - has had access to the same hacking tools used by the NSA and could deploy them against organizations that are using vulnerable routers and firewalls. It might also see what the NSA is targeting and spying on. And now that the tools are public, as long as the flaws remain unpatched, other hackers can take advantage of them, too.
The NSA did not respond to requests for comment.
"Faking this information would be monumentally difficult, there is just such a sheer volume of meaningful stuff," Nicholas Weaver, a computer security researcher at the University of California at Berkeley, said in an interview. "Much of this code should never leave the NSA."
The tools were posted by a group calling itself the Shadow Brokers using file-sharing sites such as BitTorrent and DropBox.
As is typical in such cases, the true identity of whoever put the tools online remains hidden. Attached to the cache was an "auction" note that purported to be selling a second set of tools to the highest bidder: "!!! Attention government sponsors of cyber warfare and those who profit from it !!!! How much you pay for enemies cyber weapons?"
The group also said that if the auction raised 1 million bitcoins - equivalent to roughly $500 million - it would release the second file to the world.
The auction "is a joke," Weaver said. "It's designed to distract. It's total nonsense." He said that "bitcoin is so traceable that a Doctor Evil scheme of laundering $1 million, let alone $500 million, is frankly lunacy."
One of the former TAO operators said he suspected that whoever found the tools doesn't have everything. "The stuff they have there is super-duper interesting, but it is by far not the most interesting stuff in the tool set," he said. "If you had the rest of it, you'd be leading off with that, because you'd be commanding a much higher rate."
TAO, a secretive unit that helped craft the digital weapon known as Stuxnet, has grown in the past decade or so from several hundred to more than 2,000 personnel at the NSA's Fort Meade, Md., headquarters. The group dates to the early 1990s. Its moniker, Tailored Access Organization, suggests a precision of technique that some officials have likened to brain surgery. Its name also reflects how coding whizzes create exquisite tools from scratch, in the same way a fine tailor takes a bolt of wool and fashions a bespoke suit - only the computer geeks more often work in jeans and T-shirts. "We break out the Nerf guns and have epic Nerf gun fights," one of the former hackers said.
Some former agency employees suspect that the leak was the result of a mistake by an NSA operator, rather than a successful hack by a foreign government of the agency's infrastructure.
When NSA personnel hack foreign computers, they don't move directly from their own covert systems to the targets', fearing that the attack would be too easy to trace. They use a form of proxy server called a "redirector" that masks the hackers' origin. They use one or more such servers to make it difficult to trace a hack.
"NSA is often lurking undetected for years on the . . . [proxy hops] of state hackers," former agency contractor Edward Snowden tweeted Tuesday. "This is how we follow their operations."
At the same time, other spy services, like Russia's, are doing the same thing to the United States.
It is not unprecedented for a TAO operator to accidentally upload a large file of tools to a redirector, one of the former employees said. "What's unprecedented is to not realize you made a mistake," he said. "You would recognize, 'Oops, I uploaded that set' and delete it."
Critics of the NSA have suspected that the agency, when it discovers a software vulnerability, frequently does not disclose it, thereby putting at risk the cybersecurity of anyone using that product. The file disclosure shows why it's important to tell software-makers when flaws are detected, rather than keeping them secret, one of the former agency employees said, because now the information is public, available for anyone to employ to hack widely used Internet infrastructure.
Snowden, Weaver and some of the former NSA hackers say they suspect Russian involvement in the release of the cache, though no one has offered hard evidence. They say the timing - in the wake of high-profile disclosures of Russian government hacking of the Democratic National Committee and other party organizations - is notable.
Tweeted Snowden: "Circumstantial evidence and conventional wisdom indicates Russian responsibility." He said that the disclosure "is likely a warning that someone can prove U.S. responsibility for any attacks that originated from this" redirector or malware server by linking it to the NSA.
"This could have significant foreign policy consequences," he said in another tweet. "Particularly if any of those operations targeted U.S. allies" or their elections.
"Accordingly," he tweeted, "this may be an effort to influence the calculus of decision-makers wondering how sharply to respond to the DNC hacks."
In other words, he tweeted, it looks like "somebody sending a message" that retaliating against Russia for its hacks of the political organizations "could get messy fast."
The Washington Post
Wed Aug 17 2016

The leaked file contained 300 megabytes of information, including tools for taking control of firewalls in order to control a network

Ramsay reveals hundreds of lucky cat statues stolen from new restaurant
Gordon Ramsay says about 477 Japanese cat models called maneki-neko were stolen from his Lucky Cat 22 Bishopsgate restaurant.

Zayn Rayyan case: Two child witnesses complete testimony today
So far, 20 prosecution witnesses, including the two children, have been called for this trial, according to the Deputy Public Prosecutor.

Macron says he will tell Trump not to be weak with Putin in Washington visit
Emmanuel Macron says showing any weakness to Russia's Vladimir Putin would make it harder to deal with China and Iran.

Israeli PM Netanyahu says Hamas will pay for not returning Shiri Bibas
Netanyahu accuse Hamas of acting "in an unspeakably cynical manner" by placing body of a Gaza woman in the coffin instead of Shiri Bibas.

Trump pulls US out of key global climate assessment, sources say
The US is a co-chair along with Malaysia of a working group on climate mitigation, or ways to reduce greenhouse gas emissions.

Japan to court Tesla on Nissan investment, FT reports
The group hopes Tesla will invest strategically, believing it's interested in acquiring Nissan's US plants, the report says.

185 children linked to GISB handed over to families - Exco
The children have been handed over to their families on bond with conditions by the court.

IRS fires 6,000 employees as Trump slashes US government
The move will eliminate roughly 6% of the agency's workforce in the midst of the busy tax-filing season.

Elon Musk wields chainsaw at conservative gathering, a gift from Argentina's Milei
This is the chainsaw for bureaucracy, says Elon Musk.
![[OPINION] For never again the world must know more about the Khojaly genocide [OPINION] For never again the world must know more about the Khojaly genocide](https://resizer-awani.eco.astro.com.my/tr:w-177,h-100,q-100,f-auto/https://img.astroawani.com/2025-02/41740112820_KhazarUniversity.jpg)
[OPINION] For never again the world must know more about the Khojaly genocide
For Azerbaijanis, the Khojaly genocide is more than a historical event - it is a collective trauma that shapes their identity and worldview.

Israeli military says body released by Hamas is not of a hostage
Two bodies were identified as infants, but a third, believed to be their mother, Shiri, didn't match any hostage and remains unidentified.

Key takeaways from Trump-Putin talks: Ukraine, energy, NATO, sanctions
Here's what is known so far about what was discussed.
![[COLUMNIST] Whose rights? Islam, eurocentrism and the limits of human rights [COLUMNIST] Whose rights? Islam, eurocentrism and the limits of human rights](https://resizer-awani.eco.astro.com.my/tr:w-177,h-100,q-100,f-auto/https://img.astroawani.com/2024-09/41726025526_UnitedNations.jpg)
[COLUMNIST] Whose rights? Islam, eurocentrism and the limits of human rights
For as long as rights are understood on Occidental terms, problems would inevitably remain. What is needed is an appreciation of diversity.

Argentina court clears 3 accused in singer Liam Payne's death
The court upheld the pre-trial detention of a hotel employee and a restaurant waiter held since last month.

Spanish ex-soccer boss Rubiales sentenced to pay fine over kiss without consent
Court also acquits Luis Rubiales' three co-defendants accused of attempting to coerce Jenni Hermoso into saying the kiss was consensual.

King’s health significantly improved after treatment - PM
Datuk Seri Anwar Ibrahim says he had the opportunity to seek an audience with the King twice during his official visit to Bahrain.

Why Trump wants the US Department of Education shut down
The vast majority of US children attend the country's free public schools, which are a big employer and economic engine.

How did a jet flip upside down on a Toronto runway and everyone survive?
Here is what we know about this accident and similar crashes.

TIMELINE - Trump's remarks on plan to take over Gaza, displace Palestinians
The plan has been condemned globally, with Palestinians, Arab nations and rights experts saying it was tantamount to "ethnic cleansing."

'No to drugs' signboards mooted as condition for concert permit
Datuk Hussein Omar Khan says it was part of their recommendations as efforts to curb drug taking at entertainment events.