Article GusQuixote / Audio / media article

The Phantom Hack

The Untold Story of 9/11

By Gus Quixote

November 5, 20251,106 words6 min read15 outbound sources
Back to articles

This is 1 of 3.

They’ll all be this short and sweet.

None of it is complicated, it just needed to be reassembled.

I already did the hard parts!


Read it on X, but good luck searching for it.
https://x.com/GusQuixote/status/1985528847651999821


The attack — “NIMDA”

💥“Nimda” was a computer worm that was either launched or recurrent on September 11th that was a pivotal moment in the world of hacking and cyberespionage at large.💥

According to the Finnish cybersecurity firm F-Secure, the Nimda Worm was the first worm to modify existing websites and the first worm to use normal end user machines to scan for vulnerable websites.1

Most key to note from F-Secure was that the Nimda Worm, through modifying websites, could also infect any of the most insignificant files in routine page downloads from websites.

This in itself opens another pathway for additional, potentially undetected intrusions…and even could affect hardware, firmware, software updates, or system updates within closed networks.


Canada, China implicated

An October 11, 2001 F-Secure update notified the public of an email attack launched using a false email address as the sender, with the update providing even more details that are now leading to even more shocking revelations.

F-Secure encounters first Nimda “variant”

“This worm is especially relevant to F-Secure as around 15:00 GMT on 11th of October, 2001, hundreds of emails infected with Nimda.A was sent to various addresses around the world. These emails looked like they were sent by “mikko.hypponen@datafellows.com” (do note that F-Secure used to be called datafellows.com; company name and domain was changed in early 2000). Mr. Mikko Hypponen is our Manager of Anti-Virus Research. He naturally had nothing to do with this incident. These emails were apparently sent from an infected machine located somewhere in Canada.-

https://www.f-secure.com/v-descs/nimda.shtml

Carnegie Mellon University’s CERT Division released a regular 2001 cyber report which included notes on 26 CA-2001-26: Nimda Worm.2

In the September 25, 2001 revision of the Nimda Worm report, CMU’s CERT laid out:

“Nimda stores the time the last batch of emails were sent in the Windows registry, and every 10 days will repeat the process of harvesting addresses and sending the worm via email.

Given that the Nimda Worm recycles its attack process every 10 days until patched actually provided another clue to pair with Nimda’s programming to seek out Code Red II and sadmind/IIS worm vulnerabilities3.

Doing the math

Beginning with October 11 as a firm, fixed date with a verified transmission of an email due to the Nimda Worm, we can count backward and forward 10 days from that exact day to look for the emergence, or reemergence of global computer worms.

July 3, 2001 is also an important date moving forward.

The Nimda Worm was reported on September 18, one week following the attack on the World Trade Center, Pentagon, and supposedly Capitol Hill.

But for the worm to have been detected meant that it was already deployed by September 18, and for a later batch of emails to be sent on October 11, 2001 on an already ongoing 10-day cycle of the same bug, this indicates that the Nimda Worm attack either originated on, or recurred on September 11.

Now that the infamous attacks of September 11, 2001 are directly within these crosshairs, F-Secure’s “Net-Worm:W32/Nimda” threat description also laid out:

“This technique enables Nimda to easily reach intranet web sites located behind firewalls - something worms such as Code Red couldn’t directly do.”

Nimda targeted Code Red “backdoors”

First worm - Code Red I

Code Red was an interesting worm in several ways4:

  1. The worm was programmed to scan and attack a fixed set of IP addresses5. This could be evidence of several things: a.) A drastic and wildly amateur flaw; b.) Foreknowledge of IP addresses that weren’t yet available, but soon would be. This possibility would an indicate an incremental, prolonged attack; or c.) It was only intended to target internal networks at this stage of a prolonged, developing attack already under way.

  2. The worm didn’t functionally damage or alter anything else besides displaying “graffiti” announcing a Chinese attack, displaying a web address, and then beginning a week-long DDoS (denial of service) attack on the server that hosted the White House website at “www1-whitehouse-gov”

  3. There were actually TWO variants of Code Red I released one week apart6, but the second July 19th variant which was purportedly engineered to infect more machines and quicker, but was supposedly released at a time that only gave newly infected systems around 24 hours to propagate.

This set of questions as a whole further draws into a focus a more serious question in the event that the first version of Code Red was targeted at closed, internal networks:

How did the attack get seeded in the first place, being as it was not an email-propagating worm?

Code Red II more malicious

The August 4, 2001 release of Code Red II7 was a noticeable upgrade and further scaling up of a clear series of strategic development. The new worm specifically sought out the backdoors left by the Code Red v2, and further installed full-blown “backdoors,” granting an attacker full access to the entire system8.

HINDSIGHT: Code Red/Nimda a continuous attack

Patterns emerged beginning with a hack by an organization in Guangzhou, China — The Honker Union — and an attack called the “1i0n Worm.”

It was the first in a longer line of progressively more pointed and intentional cyber attacks, of course, but the secondary patterns in hindsight, when juxtaposing a separate timeline, points the entire ordeal at two key figures time and time again:

The United States Central Intelligence Agency with support from the National Security Agency, and the Communist Party of China.

A 2001 SANS Institute report9 highlighted a real possibility with an viable technical explanation that in the coming days and weeks will prove to be the most probable case:

“If the attacker’s own IP address was one of the first “few” (i.e. first 100 or 1000) IP addresses to be scanned in the known list of IP addresses, the attacker could then set up a sniffer and by logging all the attempted connections to TCP port 80 to their own IP. By doing so, the attacker would be able to compile a fairly comprehensive list of systems infected by the worm.”


Catch up with The Biggest, Longest Hack here:

More to come, next.


Footnotes:

Search the receipts

Start typing. Articles, threads, authors, and collections are all in the same file.