X

The Specter of Cyber Piracy: How a Hacker Touched the Reins of the Internet

The Specter of Cyber Piracy: How a Hacker Touched the Reins of the Internet
Monday 15 April 2024 - 13:40
Zoom

A real-life espionage thriller.

It's a chilling affair that raises serious concerns in the cybersecurity world. It all began in 2021 when a mysterious user operating under the pseudonym Jia Cheong Tan started to get involved in the open-source project XZ Utils, a highly popular compression tool on Linux. Over the next three years, this programmer made no less than 6,000 code modifications, skillfully concealing a backdoor that could have allowed malicious actors to access hundreds of millions of websites worldwide.

The discovery of this intrusion was almost accidental. Andres Freund, an engineer at Microsoft, noticed that the remote connection protocol of a variant of Linux Debian was unusually slow. His meticulous investigation eventually uncovered this unprecedented security flaw.

Since this revelation, the cybersecurity world has been in turmoil, determined to uncover the identity of this mysterious Jia Tan. According to Costin Raiu, head of the global research and analysis team at the Russian cybersecurity company Kaspersky, it could be a state-sponsored group with substantial resources to infiltrate essential open-source projects over the long term.

"This is a more cunning attack than any previous attacks on software supply chains. This attack was more sophisticated than anything I have seen before," he said, citing China, Russia, or North Korea as potential sponsors.

Regardless, this hacker (or group of hackers) demonstrated remarkable discretion, using a VPN and a Singaporean IP address for each communication. A looming shadow that briefly grazed the control of the global web before narrowly being uncovered.


Read more