recommended reading

Hackers execute sophisticated strike on government cybersecurity contractor Bit9


Unprotected computers at a cybersecurity contractor that services the Defense Information Systems Agency and many other federal agencies were compromised in a way that enabled the company's product to run viruses on customer networks.

The incident echoes a 2011 hack job at security vendor RSA where outsiders stole the contractor's proprietary login technology to gain access to RSA-protected defense companies’ networks. This time, the target was Bit9, a firm specializing in so-called application whitelisting, which is intended to allow only those software programs listed as safe to operate. Reporter Brian Krebs of the blog Krebs on Security broke the news of the breach Friday afternoon.

DISA, the departments of Justice and Commerce, Immigration and Customs Enforcement (an arm of the Homeland Security Department), the National Transportation Safety Board, Centers for Disease Control and Prevention,  and General Services Administration recently acquired Bit9 tools, according to contract records, agency reports, and government spending databases reviewed by Nextgov.

Five of the top 10 aerospace and defense companies, along with more than 20 federal, civilian, Pentagon and intelligence agencies are Bit9 customers, the company's website states.  

Application whitelisting works under the premise that letting in only trusted, “signed” applications is safer than trying to block infections through anti-virus software, which does not spot viruses until they are discovered by researchers.

To undermine Bit9's technology, intruders grabbed signed certificates from the company’s computers and used them on malicious software to trick customers' Bit9-protected systems into executing what the systems thought were trusted applications.

After Krebs contacted Bit9, the company posted an admission of the problem. Bit9 Chief Executive Officer Patrick Morley wrote, “Due to an operational oversight within Bit9, we failed to install our own product on a handful of computers within our network. As a result, a malicious third party was able to illegally gain temporary access to one of our digital code-signing certificates that they then used to illegitimately sign malware."

At least three customers “were affected” by the falsely-certified malware, Morley added, without describing the nature of the clients’ business.

During the RSA assault, bad actors also filched that company’s secret sauce – in that instance, login coding -- to penetrate an RSA customer. The hackers excised information about RSA’s SecurID identification verification technology, and then piggybacked off that information to access Lockheed Martin Corp.'s network. The defense contractor notified the public it had contained the breach.

The two-step attack laid bare the risk of adversaries compromising Pentagon suppliers’ computers as part of a larger plot to reach other, higher-value government information.

Eugene Spafford, a computer science professor at Purdue University, told Krebs, “Those defense contractors were the real targets, but they were using a very strong security tool – RSA’s tokens. So, if you’re an attacker and faced with a strong defense, you can try to break straight through, or find ways around that defense. This is more than likely [the product of] very targeted, careful thinking by someone who understands a higher level of security strategy.”

The article quoted Spafford as saying the Bit9 and RSA attacks can be thought of as “supply chain” hacks.

Officials for Bit9, based in Waltham, Mass., said indications are that the breach was not the result of a problem with their product, and the product was not compromised. To shield the three customers hit and other clients, Bit9 revoked the certificate and has “ensured Bit9 is installed on all of our physical and virtual machines," Morley said.

(Image via Lightspring /

Threatwatch Alert

Network intrusion / Stolen credentials

85M User Accounts Compromised from Video-sharing Site Dailymotion

See threatwatch report


Close [ x ] More from Nextgov

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Data-Centric Security vs. Database-Level Security

    Database-level encryption had its origins in the 1990s and early 2000s in response to very basic risks which largely revolved around the theft of servers, backup tapes and other physical-layer assets. As noted in Verizon’s 2014, Data Breach Investigations Report (DBIR)1, threats today are far more advanced and dangerous.

  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

  • PIV- I And Multifactor Authentication: The Best Defense for Federal Government Contractors

    This white paper explores NIST SP 800-171 and why compliance is critical to federal government contractors, especially those that work with the Department of Defense, as well as how leveraging PIV-I credentialing with multifactor authentication can be used as a defense against cyberattacks

  • Toward A More Innovative Government

    This research study aims to understand how state and local leaders regard their agency’s innovation efforts and what they are doing to overcome the challenges they face in successfully implementing these efforts.

  • From Volume to Value: UK’s NHS Digital Provides U.S. Healthcare Agencies A Roadmap For Value-Based Payment Models

    The U.S. healthcare industry is rapidly moving away from traditional fee-for-service models and towards value-based purchasing that reimburses physicians for quality of care in place of frequency of care.

  • GBC Flash Poll: Is Your Agency Safe?

    Federal leaders weigh in on the state of information security


When you download a report, your information may be shared with the underwriters of that document.