CISA announced yesterday that a hacker has accessed and decrypted data from a U.S. federal agency. The name of the federal agency where the breach occurred , as well as the date of the intrusion or any details about the hacker, are not currently known.
CISA officials revealed the breach after releasing a detailed incident response (IR) report detailing every step the hacker took. The report, which was reviewed by ZDNet, reveals how the hacker gained access to the federal agency's internal networks by leveraging compromised Microsoft Office 365 account credentials , domain administrator accounts , and credentials for the agency's Pulse Secure VPN server .

According to CISA, the hacker logged into Office 365 accounts to view and download help desk email attachments with “Intranet Access” and “ VPN passcodes ” in the subject line. The hacker searched for these files even though he had already gained privileged access to the service’s network, likely to find other parts of the network that he could attack.
The hacker also had access to the local Active Directory, where he modified settings and studied the structure of the service's internal network. In addition, the hacker installed an SSH tunnel and reverse SOCKS proxy, custom malware , and connected a hard drive, which he controlled, to the service's network.

As CISA analysts reported, the hacker was able to move freely during his “operation,” leaving less evidence for forensic analysis. In addition, the hacker created his own local account on the network. Analyzing the forensic evidence, CISA noted that the hacker used this account to browse the local network, execute PowerShell commands, and gather important files into ZIP archives. However, CISA noted that it could not confirm whether the hacker removed the ZIP archives, although this likely happened in the end. CISA also reported that the malware (inetinfo.exe) that the hacker installed on the federal agency’s network was able to bypass the agency’s anti-malware protection.
However, researchers said they detected the intrusion through EINSTEIN, CISA's intrusion detection system that monitors federal political networks, and were therefore able to counter the hacker who bypassed the US federal agency's anti-malware protection.
