Deleted tweet detection is currently running at reduced
capacity due to changes to the Twitter API. Some tweets that have been
deleted by the tweet author may not be labeled as deleted in the PolitiTweet
interface.
Showing page 283 of 2161.
Eric Geller @ericgeller
@JennyENicholson that doesn't feel like luxury galactic vacationing to me — PolitiTweet.org
Eric Geller @ericgeller
Meyers called #HermeticWiper "pretty nasty" and noted that it disables a Windows security feature called Volume Shadow Copy, which creates backups of files. A lot of ransomware does this. "It takes some care to make sure that it's going to make a big mess for the target." — PolitiTweet.org
Eric Geller @ericgeller
#HermeticWiper accepts command-line arguments, suggesting that the hackers could have deployed it via a script, according to CrowdStrike's @Adam_Cyber. The two commands tell the malware: (1) how long to stay asleep on a target before activating (2) when to shut the PC down — PolitiTweet.org
Eric Geller @ericgeller
Partition Master, not Partition Manager, sorry. — PolitiTweet.org
Eric Geller @ericgeller
Guerrero-Saade likened #HermeticWiper to Shamoon (Saudi Aramco hack) and Destover (Sony hack) in that it deploys an… https://t.co/ihvcGfplN4
Eric Geller @ericgeller
#HermeticWiper also doesn't appear to work on Windows 10, Guerrero-Saade told me, which is fine for Ukraine, where most computers run older versions of Windows — in many cases, pirated versions. — PolitiTweet.org
Kevin Beaumont @GossiTheDog
Ukraine gov estimates only 40% of their state MS software is pirated (MS estimate 70%). https://t.co/WzDP2qaDNC
Eric Geller @ericgeller
Guerrero-Saade likened #HermeticWiper to Shamoon (Saudi Aramco hack) and Destover (Sony hack) in that it deploys and abuses a driver for a legitimate program (in this case, EaseUS Partition Manager) to bypass the normal obstacles to deep hard-drive control that malware faces. — PolitiTweet.org
Eric Geller @ericgeller
The wiper exploits a Microsoft feature that configures settings across multiple computers on a network, so it's designed for networks where the attacker has that kind of broad access. It's "fire-and-forget," Guerrero-Saade said, compared to WhisperGate, which needed more input. — PolitiTweet.org
Eric Geller @ericgeller
#HermeticWiper will look for as many as 100 physical drives to erase, trash the Master Boot Record, trash user folders, trash the Windows Registry, and then target the filesystem "and actually try to wipe things by sector," Guerrero-Saade said. — PolitiTweet.org
Eric Geller @ericgeller
Ukraine #HermeticWiper malware is "incredibly thorough," @juanandres_gs told me tonight. "It's got at least five or six different ways that it's trashing different aspects of the operating system." "It makes WhisperGate look like it was written by script kiddies," he said. — PolitiTweet.org
Eric Geller @ericgeller
@HowellONeill I'm in a dominant position in national-level tweeting — PolitiTweet.org
Eric Geller @ericgeller
https://t.co/Xa5ZM8utxp — PolitiTweet.org
Eric Geller @ericgeller
Reading this, I have to step back for a moment and just try to process the fact that this is actually happening. It's so pointless and cruel. — PolitiTweet.org
max seddon @maxseddon
@PentagonPresSec "They're telling you that this flame will liberate the people of Ukraine, but the Ukrainian people… https://t.co/DC8HhM7xsX
Eric Geller @ericgeller
Meanwhile, on the kinetic side of the Ukraine crisis... https://t.co/RBUigxP5Bg https://t.co/9uDlfMqiXH — PolitiTweet.org
Eric Geller @ericgeller
As of now, Symantec has seen the wiper Ukraine, Latvia, and Lithuania, per a statement a few minutes ago from their PR team. They reiterate that so far they've seen attacks on financial companies and government contractors. (Chien told me they're military contractors.) — PolitiTweet.org
Eric Geller @ericgeller
@RossSchulman the weakest boa constrictor ever discovered in nature — PolitiTweet.org
Eric Geller @ericgeller
#HermeticWiper https://t.co/OFy7i7ad15 — PolitiTweet.org
ESET research @ESETresearch
Based on the discussion on Twitter by fellow researchers and discussing this naming at #ESETresearch, we will conti… https://t.co/Yxm972U2YM
Eric Geller @ericgeller
@HowellONeill @Grace_Segers I actually only scheduled this one a few minutes ago and I stand by that choice because my followers need some variety from my feed — PolitiTweet.org
Eric Geller @ericgeller
I have never heard @Grace_Segers get so mad before (she was right and she should say it) — PolitiTweet.org
Hoth Takes @HothTakes
This excerpt from @Grace_Segers' notes for our new episode gives you a pretty good sense of how frustrated we were… https://t.co/frLEnRMQdm
Eric Geller @ericgeller
@snlyngaas @NateBeachW @jfslowik specifically military contractor https://t.co/60mtKDNQD9 — PolitiTweet.org
Eric Geller @ericgeller
Symantec's Chien says the government organizations they're seeing targeted by the wiper are contractors involved in… https://t.co/mXOnp2lZTt
Eric Geller @ericgeller
@byrdinator @Grace_Segers @igorbobic me but replace Force with FOIA https://t.co/STO9vZTD2Z — PolitiTweet.org
Eric Geller @ericgeller
Symantec's Chien says the government organizations they're seeing targeted by the wiper are contractors involved in "supporting the military sector." Number of targets likely to change rapidly as analysts review data. Symantec has seen 3 as of now, but don't read much into that. — PolitiTweet.org
Eric Geller @ericgeller
Yet another dimension of the proliferating cyber campaign against Ukraine. "The type of malware deployed on the cloned Ukrainian websites...show a link to previous cyber attacks on the Ukrainian government dating to April 2021, as well as on the government of Georgia." — PolitiTweet.org
Christo Grozev @christogrozev
We discovered a nest of digital wasp: a GRU-linked malware server that contained a Trojan-rigged clone of the site… https://t.co/O8awgeFSiz
Eric Geller @ericgeller
ESET has seen "several organizations targeted" but isn't ready to provide numerical estimates, a spokesperson says. They've seen more than the two organizations cited by Symantec. — PolitiTweet.org
Eric Geller @ericgeller
@Grace_Segers @kept_simple @nycsouthpaw @fordm I love being a Ford explorer* *a person who scrolls through Matt Ford's tweets — PolitiTweet.org
Eric Geller @ericgeller
Jean-Ian Boutin, head of ESET's threat research team, says the wiper targeted "large organizations." "The malware based on its time stamp was created two months ago, however it was deployed only today and we have seen it only in Ukraine." — PolitiTweet.org
Eric Geller @ericgeller
@kept_simple @nycsouthpaw @fordm I've always said you can't 'ford not to follow Ford — PolitiTweet.org
Eric Geller @ericgeller
@jwarminsky @HowellONeill @gregotto @Bing_Chris WOW — PolitiTweet.org
Eric Geller @ericgeller
@HowellONeill @jwarminsky @gregotto @Bing_Chris [email protected] — PolitiTweet.org
Eric Geller @ericgeller
@selenalarson Symantec says yes — PolitiTweet.org
Eric Geller @ericgeller
@HowellONeill Not inconsistent with what you tweeted about "an organization which has presence in both Ukraine and Latvia." Seems like that organization is based in Ukraine but has offices elsewhere. — PolitiTweet.org