Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The name that keeps coming up is Jia Tan (https://github.com/JiaT75/) but we have no way of knowing if this is a real name, pseudonym, or even a collective of people.


Given the sophistication of this attack it would indeed be downright negligent to presume that it's the attackers' legal name and that they have zero OPSEC.


He used ProtonMail. I wonder if ProtonMail can pull IP logs for this guy and share them.


It might be worth looking into, but:

1) Probably by design protonmail doesn't keep these kinds of logs around for very long

2) Hacking groups pretty much always proxy their connection through multiple layers of machines they've rooted, making it very difficult or impossible to actually trace back to the original IP


For [1], unfortunately it does.

True regarding the second point.

[1]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...


It's also worth pointing out, given the almost two years of seemingly valuable contribution, that this could be a real person who was compromised or coerced into pushing the exploit.


It’s also worth pointing out that parts of the RCE were prepared almost two years ago which makes this entirely implausible.


Were they? The attacker has had commit rights for 1.5 years or so, but my understanding is that all the exploit components were recent commits. Is that wrong?


Interesting to look through the "starred" repos of that account ... seems like a hit list: https://github.com/JiaT75?tab=stars




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: