Showing posts with label Cyber War. Show all posts
Showing posts with label Cyber War. Show all posts

Friday, June 27, 2014

Stuxnet-Like ‘Havex’ Malware Strikes European industrial SCADA Systems.



Stuxnet-Like ‘Havex’ Malware Strikes European industrial SCADA Systems.
Swati Khandelwal has an article on the website The Hacker News, today, June 26, 2014, with the title above. 
He writes that [cyber] security researchers have uncovered a new, Stuxnet-like malware, named as ‘Havex,’ which was used in a number of previous cyber attacks against organizations in Europe — the energy sector.”
Just like the Famous Stuxnet Worm, which was specifically designed to sabotage the Iranian nuclear project, the new trojan Havex — is also programmed to infect industrial control system softwares of SCADA and ICS systems, — with the capability to possibly disable hydroelectric dams, overload nuclear power plants, and even shut down a country’s power grid –with a single keystroke.”
According to the [cyber] security firm F-Secure, who first discovered it as a Backdoor:W32/Havex.A, it is a generic remote access Trojan (RAT); and, has recently been used to carry out industrial espionage against a number of companies in Europe — that use or develop industrial applications and machines,” wrote Mr. Khandelwal.

Smarty Pants, Trojanized Installers

Mr. Khandelwal notes that “in order to accomplish this, besides the traditional infection methods such as explicit kits and spam emails, cyber criminals also used another effective method to spread Havex RAT, i.e., hacking the websites of software companies; and, waiting for targets to install trojanizd versions of legitimate apps.”

During installation, the trojanized software setup drops a file called “mbcheck.dll, which is actually Havex malware, that attackers are using as a backdoor. “The C and C server will [then] instruct infected computers to download and execute further components,”

— “We gathered and analyzed 88 variants of the Havex RAT used to gain access to, and harvest data from, networks and machines of interest. This analysis included investigation of 146 command and control servers contacted by the variants, which in turn, — involved tracing around 1500 IP addresses in an attempt to identify victims,” F-Secure said.

F-Secure didn’t mention the names of the affected vendors, but an industrial machine producer and two educational organizations in France, with companies in Germany — were targeted.

Information Gathering.

“Havex RAT is equipped with a new component, whose purpose is to gather network and connected devices information — by leveraging the OPC (Open Platform Communications) standard,” wrote Mr. Khandelwal. “The malware scans the local network for the devices that respond to OPC requests to gather information about industrial control devices; and, then sends that information back to its command-and-control server.”
“Other than this, it also include information-harvesting tools that gather data from the infected systems,” adds Mr. Khandelwal, such as:
— Operating system related information;
— A credential-harvesting tool that stole passwords stored on open
web browsers;
— A component that communicates to different Command-And-Control
servers using custom protocols; and, execute tertiary payloads in
memory.
“So far, we have not seen any payloads that attempts to control the connected hardware.” F-Secure confirmed.

Motivation.

“While their motivation is unclear at this point, “We also identified an additional component used by the attackers that includes code to harvest data from infected machines used in ICS/SCADA systems in those organizations,” said F-Secure.

Havex Trojan From Russia?

“In January of this year, the cyber security firm CrowdStrike revealed about a cyber espionage campaign, dubbed “Energetic Bear,” where hackers possibly tied to Russian Federation penetrating the computer networks of energy companies in Europe, the United States, and Asia.

According to CrowdStrike, the malwares used in those cyber attacks were Havex RAT and SYSMain RAT, and both tools have been operated by the attackers since at least 2011. That means, it is possible that Havex RAT could somehow be linked to Russian hackers; or, state-sponsored Russian Government [entities].”

Unfortunately, what originates in Russia, or anywhere else for that matter — with respect to cyber malware/viruses, etc., doesn’t stay in Russia. I would expect other cyber malcontents to deconstruct and reverse-engineer this bug in order to see if it can be made even more “lethal,” and damaging that it may already be. V/R, RCP

Friday, April 5, 2013

'New Axes Of Evil' - North Korea and Iran are both caught moving weapons; Israel shores up its cyber defenses.


'New Axes Of Evil' - North Korea and Iran are both caught moving weapons; Israel shores up its cyber defenses.(TOI).The Friday front page of Haaretz focuses on North Korea and how the rogue nation stole the spotlight this week from Iran’s nuclear talks with the US. The paper also includes a profile of Kim Jong Un, the North Korean leader, which includes recent highlights from his regime, including a marriage, a nuclear test, and a visit from former NBA star Dennis Rodman.
Haaretz also includes a short article about American sources stating that North Korea has moved missiles and could be preparing a launch.

That movement of missiles may not have raised alarm bells at Haaretz, but it is the top story over at Israel Hayom – “At the push of a button,” reads the article headline. The paper includes an opinion piece by Boaz Bismuth, who tries to explain the recent rise in tensions on the Korean peninsula. “What North Korea really wants is recognition, not war,” Bismuth writes. He goes on to state that the balance of power between North Korea and the United States is laughable, but the Americans aren’t laughing, partly because they don’t have a clear intelligence picture on the country. He writes that North Korea is using the nuclear option to ensure the survival of the regime, just like Iran.

Carl in Jerusalem brings us the following story: Israel preparing for cyber attack!

The attack is set for Sunday, April 7 — coincidentally, or perhaps not, the eve of Holocaust Memorial Day in Israel. Computer system administrators and security experts have been shoring up network defenses, changing passwords, and ensuring that they have the Internet bandwidth to withstand an attack.

In their latest screed, the hackers behind the newest incarnation of #OpIsrael, the ongoing attempt to “wipe Israel off the map of the Internet,” appealed for unity in the hacker community, which needed to come together to attack Israel. “We can’t be consumed by our petty differences any more,” said the message, posted on hacker-friendly websites. “We will be united in our common interest. We will once again be fighting for freedom.” In a theatrical flourish (using a quote from the 1996 film “Independence Day,” which portrayed mankind fighting off a Martian invasion), the hackers state: “’We will not go quietly into the night! We will not vanish without a fight! We’re going to live on, we’re going to survive.”

While the attacks are aimed at government, bank, academic, and business websites (the hackers have published extensive lists of their targets), ordinary Israelis should take precautions as well — just in case, said the Israel Internet Association (ISOC), which is taking the threat so seriously that it will be operating a hotline (03-9700911) for people to report attacks, and will update its website throughout the day with status reports about what is going on in cyberspace.Hmmm.......Unknown to them, they are heading for eternal judgment, they think they are coming to make war against God, but they are being gathered for judgment. ~ Isaiah 13:6-8. Read the full story here and here.

Wednesday, March 13, 2013

We the People’website cracked the 100,000-signature threshold now White House must respond to 'Stop CISPA' petition.


We the People’website cracked the 100,000-signature threshold now White House must respond to 'Stop CISPA' petition.(RT).A petition on the White House’s ‘We the People’website cracked the 100,000-signature threshold needed to provokean official response this week, and now a member of US PresidentBarack Obama’s staff will have to speak out about the CISPA bill,which was recently reintroduced before American lawmakers.
Up until earlier this year, the White House required petitionsto collect only 25,000 signatures to garner an official response.In a matter of just three weeks, however, an anti-CISPA petitionhas become one of the most popular ones on the site.
Rep. Mike Rogers (R-Mich.) and Sen. Dutch Ruppersberger(D-Calif.) unveiled CISPA to their Capitol Hill colleagues last year and touted it as a surefire solution to the impending cyber war that lawmakers in Washington — including the Pres. Obama — have repeatedly warned of during his tenure as commander-in-chief. In the wake of protests aimed at other computer bills, such as the Stop Online Piracy Act (SOPA) and its sister bill, the Protect IPAct (PIPA), the public response to CISPA was overly negative and it never advanced in the House of Representatives far enough to be voted on before the last congressional season expired. Rogers and Ruppersberger recently reintroduced their failed bill, however, and hope to have it added to the books soon as warnings of a cyberwar with the likes of Iran and China continue to come from Washington’s elite.
The authors of CISPA describe it as a bill to provide for the sharing of certain cyber threat intelligence and cyber threat information between the intelligence community and cyber security entities, but critics say it does much more than that. Because it creates an inter-connected system for private businesses and government agencies to share information, privacy advocates say it puts too much personal information into the hands of Uncle Sam.
CISPA is about information sharing. It creates broad legal exemptions that allow the government to share ‘cyber threat intelligence’ with private companies, and companies to share ‘cyber threat information’ with the government, for the purposes of enhancing cyber security. The problems arise from the definitions of these terms, especially when it comes to companies sharing data with the feds, reads the Stop CISPA petition that must soon bemet with a response from the White House.
Last month, Pres. Obama signed an executive order that will set up the frameworkfor a cyber-protection system that will serve as a starting-pointfor any eventually CISPA or CISPA-like laws. In doing so, though,he urged Congress to consider Rogers’ and Ruppersberger’ bill.
I signed a new executive order that will strengthen our cyber defenses by increasing information sharing, and developing standards to protect our national security, our jobs and our privacy. Now, Congress must act as well, by passing legislation to give our government a greater capacity to secure our networks and deter attacks, the president said.
CISPA has been condemned by the Electronic Frontier Foundation,software developers Mozilla and former Rep. Ron Paul, who called the actessentially an Internet monitoring bill that permits both the federal government and private companies to view your private online communications with no judicial oversight, provided, of course, that they do so in the name of cyber security.”Hmmm.....He might say well now you need 500,000 signatures.Read the full story here.

Related: 34 Civil Liberties Groups Speak Out Against CISPA in Lead Up to Hearings

Monday, January 21, 2013

"Red October" virus reaches Iran, local experts neutralize the threat


"Red October" virus reaches Iran, local experts neutralize the threat.(TI).A computer virus by the name of "Red October" has been discovered in Iran, according to country's Communications and Technology Ministry, ILNA reported.
Iran's deputy communications and technology minister Ali Hakim-Javadi confirmed the information, adding that Iranian experts were able to fight the infection, and prevent local agencies and organizations from being compromised.
"The way we understand it, the virus tried to penetrate local computer networks, and diplomatic centers to acquire sensitive, classified information," Hakim-Javadi said.
About a week ago, Kaspersky Lab said that the primary focus of the campaign was targeting countries in eastern Europe, "former USSR Republics and countries in Central Asia.
Kaspersky Lab said "there is strong technical evidence to indicate the attackers have Russian-speaking origins."
Kaspersky said Red October also infected smartphones and collected login information to test on other systems.
Red October, which is named after the Russian submarine featured in the Tom Clancy novel The Hunt For Red October, has what Kaspersky Lab called a unique "resurrection" module that hid in Adobe Reader and Microsoft Office programmes that allowed the attackers to regain access if the virus was discovered and removed.Read the full story here.

Wednesday, January 16, 2013

"Stuxnet going Rogue?" - Malware infects US power facilities through USB drives.


"Stuxnet going Rogue?" - Malware infects US power facilities through USB drives.(TW).By Grant Gross.Two U.S. power companies reported infections of malware during the past three months, with the bad software apparently brought in through tainted USB drives, according to the U.S. Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).
In one case, the industrial control system at a power generation facility was infected with "common and sophisticated malware" apparently through an employee's USB drive, according to the ICS-CERT Monitor for October to December 2012.
The publication did not name the malware discovered.
The tainted USB drive came in contact with a "handful of machines" at the power generation facility and investigators found sophisticated malware on two engineering workstations critical to the operation of the control environment, ICS-CERT said.
Investigators didn't find malware on 11 other workstations examined, ICS-CERT said.
ICS-CERT recommended that the power facility adopt new USB use guidelines, including the cleaning of a USB device before each use.
In the second incident, a power company contacted ICS-CERT in early October to report a virus infection in a turbine control system. About 10 computers were affected, ICS-CERT said.
An outside technician used a USB drive to upload software updates during equipment upgrades, ICS-CERT said. The malware delayed the plant's reopening by three weeks, the organization said.Hmmm....Whodunit.....Stuxnet......China.....Iran?Read the full story here.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Tuesday, August 14, 2012

Kaspersky - Gauss: Abnormal Distribution.


Kaspersky - Gauss: Abnormal Distribution.(SCL).We began our investigation into Gauss in early June 2012. Based on data obtained through the Kaspersky Security Network, we noticed right away that the Trojan appeared to be widely distributed in three particular countries in the Middle East. Further observation later confirmed this three-country concentration. As of 31 July 2012, we've counted around 2500 unique PCs on which files from the Gauss collection have been found. The highest number of infections is recorded in Lebanon, with more than 1600 computers affected. The Gauss code (winshell.ocx) contains direct commands to intercept data required to work with Lebanese banks - including the Bank of Beirut, Byblos Bank and Fransabank. In Israel and the Palestinian Territory, 750 incidents have been recorded. Gauss is a project developed in 2011-2012 along the same lines as the Flame project. The malware has been actively distributed in the Middle East for at least the past 10 months. The largest number of Gauss infections has been recorded in Lebanon, in contrast to Flame, which spread primarily in Iran. Functionally, Gauss is designed to collect as much information about infected systems as possible, as well as to steal credentials for various banking systems and social network, email and IM accounts. The Gauss code includes commands to intercept data required to work with several Lebanese banks - for instance, Bank of Beirut, Byblos Bank, and Fransabank. Curiously, several Gauss modules are named after famous mathematicians. The platform includes modules that go by the names 'Gauss', 'Lagrange', 'Godel', 'Tailor', 'Kurt' (in an apparent reference to Godel). The Gauss module is responsible for collecting the most critical information, which is why we decided to name the entire toolkit after it. Gauss is a much more widespread threat than Flame. However, we have found no self-replication functionality in the modules that we have seen to date, which leaves open the question of its original attack vector. Executive Summary The first known Gauss infections date back to September-October 2011. During that period, the Gauss authors modified different modules multiple times. They also changed command server addresses. In the middle of July 2012, when we had already discovered Gauss and were studying it, the command servers went offline. Read the full story here.

Thursday, July 26, 2012

Iran: "If virus attacks on Iran continue, U.S. will get its teeth knocked out"


Iran: "If virus attacks on Iran continue, U.S. will get its teeth knocked out".(TA).If the U.S. continues to spread virus attacks on Iran, it will suffer a fatal blow and get its teeth knocked out, an official from Iran's General Defense Headquarters Cyber Security department said, IRNA reported. Commenting on the recent news about Iranian nuclear plants being attacked by the virus, the official noted that cyber-attacks against Iran are useless. Earlier today Bloomberg reported citing the F-Secure Security Labs website that Iran's nuclear facilities have suffered a cyber attack that shut down computers and played music from the rock band AC/DC. A new worm has targeted Iran's nuclear program, shutting down the "automation network" at the Natanz and Fordo facilities, the Internet security site reported, citing an e- mail it said was sent by a scientist inside Iran's Atomic Energy Organization. The virus also prompted several of the computers on site to play the song "Thunderstruck" by AC/DC at full volume in the middle of the night, according to the e-mail, part of which is published in English on the website. F-Secure Security Labs, which is linked to F-Secure Oyj (FSC1V), the Finnish maker of security and cloud software, said that while it was unable to verify the details of the attack described, it had confirmed that the scientist who reported them was sending and receiving the e-mails from within Iran's Atomic Energy Organization. Iranian official urged the U.S. to stop harassing Iran via cyber attacks, or it will get a proper response. Iran's nuclear program and oil facilities have been subject to a succession of cyber attacks that the Foreign Ministry said in May were launched by hostile governments as part of a broader "soft war." Iran accuses the U.S. and Israel of trying to sabotage its technological progress. Both countries say Iran's nuclear activities may have military intent, an allegation that Iran denies.Read the full story here.

Tuesday, June 19, 2012

Researcher: CIA, NSA may have infiltrated Microsoft to write malware







Researcher: CIA, NSA may have infiltrated Microsoft to write malware.(ITWorld).By Kevin Fogarty.Did spies posing as Microsofties write malware in Redmond? 
A leading security researcher has suggested Microsoft's core Windows and application development programming teams have been infiltrated by covert programmer/operatives from U.S. intelligence agencies. If it were true it would be another exciting twist to the stories of international espionage, sabotage and murder that surround Stuxnet, Duqu and Flame, the most successful cyberwar weapons deployed so far, with the possible exception of Windows itself.
Nevertheless, according to Mikko Hypponen, chief research officer of antivirus and security software vendor F-Secure, the scenario that would make it simplest for programmers employed by U.S. intelligence agencies to create the Stuxnet, Duqu and Flame viruses and compromise Microsoft protocols to the extent they could disguise downloads to Flame as patches through Windows Update is that Microsoft has been infiltrated by members of the U.S. intelligence community. 
After studying the code for Duqu, security researchers at Kaspersky Labs said the malware was most similar to the kind of work done by old-school programmers able to write code for more than one platform at a time, do good quality control to make sure the modules were able to install themselves and update in real time, and that the command-and-control components ahd been re-used from previous editions.
Having programmers, spies and spy-supervisors from the NSA, CIA or other secret government agencies infiltrate Microsoft in order to turn its technology to their own evil uses (rather than Microsoft's) is the kind of premise that would get any writer thrown out of a movie producer's office for pitching an idea that would put the audience to sleep halfway through the first act.
Not only is it unlikely, the "action" most likely to take place on the Microsoft campus would be the kind with lots of tense, acronymically dense debates in beige conference rooms and bland corporate offices.
Earlier this month the NYT ran a story detailing two years worth of investigations during which a range of U.S. officials, including, eventually, President Obama, confirmed the U.S. had been involved in writing the Stuxnet and Flame malware and siccing them on Iran.
That's far from conclusive proof that the NSA has moved its nonexistent offices to Redmond, Wash. It doesn't rule it out either, however.
Very few malware writers are able to write such clean code that can install on a variety of hardware systems, assess their new environments and download the modules they need to successfully compromise a new network, Kaspersky researchers said.
Stuxnet and Flame are able to do all these things and to get their own updates through Windows Update using a faked Windows Update security certificate. No other malware writer, hacker or end user has been able to do that before.
Knowing it happened this time makes it more apparent that the malware writers know what they are doing and know Microsoft code inside and out.
Even in his own blog, Hypponen makes fun of those who make fun of Flame as ineffective and unremarkable, but doesn't actually suggest moles at Microsoft are to In the end it doesn't really matter. The faked certificates and ride-along on Windows Update demonstrate the malware writers have compromised the core software development operations at Microsoft.
They don't have to live there to do it; virtual compromise on the code itself would do the job more effectively than putting warm bodied programmers in the middle of highly competitive, highly intelligent, socially awkward Microsofties with a habit of asking the wrong question and insisting on an answer.The risk of having any such infiltration discovered is far too high to expose the cyberwar version of Seal Team Six to the perils of Redmond. Still, the assumption seems to be true metaphorically, if not physically, so it's safer to assume Microsoft and its software have both been compromised. Given the track record of Stuxnet, Duqu and Flame for compromising everything they're aimed at, that assumption isn't even much of a stretch.Read the full story here.

Sunday, June 17, 2012

'Stuxnet is so deeply embedded in Iran, their counterstrike plans are already known'





'Stuxnet is so deeply embedded in Iran, their counterstrike plans are already known'.HT: IsraelMatzav.Here's a blog that the 'anti-virus experts' at Symantec and Kaspersky (and others) ought to be reading. They claim - and back it up - to have known about Stuxnet and Flame (which they call Stuxnet 3.0) since 2009 (Hat Tip: Jawa Report).

If they are correct, Flame is not automatically uninstalling on every computer in Iran, but only on computers where the Iranians start to look for it. And just because it disappears doesn't meant it can't come back. Here's the key part:
Stuxnet/flame puts USA in same position
as when US was only one with atom bomb,
MAD NOT APPLICABLE, first strike
can take out everything, leaving enemy nothing
to retaliate WITH.

Stuxnet is so deeply embedded in Iran
their counterstrike plans are already known.

This powerful weapon is so comprehensive
it is a deterrent in and of its self,
You don't slap someone who has you
by the balls like stuxnet has Iran.

The flip side of the suicide function,
as the press calls it, isn't suicide at all.
Its artificial intelligence, if you start looking
for Flame it knows and disappears.
Flip side is its so easy to penetrate PCs
dumping all traces of its self isn't a problem
it will revisit later.
Read the full story here.It's fascinating.

Thursday, June 14, 2012

'Flame' can Steal Data Even When Computers Are Not Connected to the Internet.





'Flame' can Steal Data Even When Computers Are Not Connected to the Internet.(AP).By Susanne Posel.Experts specializing in malware from Bitdefender have uncovered a special capability in Flame’s code that allows the virus to steal data from computers that are not connected to the Internet or networked machines.

Flame can move stolen data to a USB memory stick plugged into an infected harddrive. Bitdefender asserts that this ability has never been witnessed before.

This cyber-espionage virus will move stolen information to an USB outlet, then seemingly wait for the chance to upload it to the malware controllers once the infected computer links to the Internet.

Bogdan Botezatu, malware analyst from Bitdefeder, said:
It turns users into data mules. Chances are, at some point, a user with an infected flash drive will plug it into a secure computer in a contained environment, and Flame will carry the target’s information from the protected environment to the outside world…It uses its ability to infect to ensure an escape route for the data. This is is somewhat revolutionary for a piece of malware.
Eugene Kaspersky, of the Russian Kaspersky Lab, uncovered Flame under orders from the UN.


At the Global Media and Technology Summit, Kaspersky’s team made the connection between Flame and Stuxnet and the cyberattack on Iran by the US and Israel.

The US and Israel came together to attack Iran; along with the European Union and a wide range of employed experts to guarantee that the worm would perform as planned.

This virus attacked and damaged Iranian centrifuges used to enrich uranium at the Natanz facility.The Obama administration claims to be “launching an investigation into Flame, which is a highly classified project.

Independent researchers have long attributed Stuxnet and Flame to the same cyberattacks and even claimed they are the same virus. Kaspersky’s lab has hard evidence of this fact.

The Pentagon, through a report in 2011, assessed that the US is involved in cyberespionage, but claims it is a defense to the thefts of industrial and defense secrets of other cyberspies.

Roel Schouwenberg, a senior researcher at Kaspersky Lab, commented:
We are now 100 percent sure that the Flame and Stuxnet groups worked together. The fact that the Flame group shared their source code with the Stuxnet group shows they cooperated at least once.
These two viruses share the same pieces of code at their based developmental stage, making them virtually identical; and most likely created by the same entity.

Alexander Gostev, Kaspersky Lab’s Chief Security Expert, says: What we have found is very strong evidence that the Stuxnet/Duqu and Flame cyberweapons are connected.Read the full story here.

Sunday, June 10, 2012

"Harakiri" - Flame Operators Command Software to Remove Itself from Infected Machines to Make Further Analysis More Difficult.





"Harakiri" - Flame Operators Command Software to Remove Itself from Infected Machines to Make Further Analysis More Difficult.(CIO).Via: Cryptogon.The creators of the Flame cyber-espionage threat ordered infected computers still under their control to download and execute a component designed to remove all traces of the malware and prevent forensic analysis, security researchers from Symantec said on Wednesday. Flame has a built-in feature called SUICIDE that can be used to uninstall the malware from infected computers. 
However, late last week, Flame’s creators decided to distribute a different self-removal module to infected computers that connected to servers still under their control, Symantec’s security response team said in a blog post. The module is called browse32.ocx and its most recent version was created on May 9, 2012. “It is unknown why the malware authors decided not to use the SUICIDE functionality, and instead make Flamer perform explicit actions based on a new module,” the Symantec researchers said. However, even though it is similar in functionality to the SUICIDE feature — both being able to delete a large number of files associated with the malware — the new module goes a step further. “It locates every [Flame] file on disk, removes it, and subsequently overwrites the disk with random characters to prevent anyone from obtaining information about the infection,” the Symantec researchers said. “This component contains a routine to generate random characters to use in the overwriting operation. It tries to leave no traces of the infection behind.”Hmmmmm....."The ultimate cyber ninja?"Read the full story here.

Saturday, June 9, 2012

Mossad: "Stuxnet is our Baby" Pres Obama disclosed it for electoral reasons.





Mossad: "Stuxnet is our Baby" Pres Obama disclosed it for electoral reasons.(TA).Israel’s officials have a message for anyone praising the CIA for its sophisticated cyber attack on Iran: It was our baby. The Stuxnet computer worm, described by David Sanger in The New York Times last week as an invention by the Bush administration, was actually developed by Mossad, according to Israeli officials speaking with Haaretz journalist Yossi Melman on condition of anonymity:
The Israeli officials actually told me a different version. They said that it was Israeli intelligence that began, a few years earlier, a cyberspace campaign to damage and slow down Iran’s nuclear intentions. And only later they managed to convince the USA to consider a joint operation — which, at the time, was unheard of.
The irony of course is that both U.S. and Israeli officials spent years denying knowledge of who carried out the attacks, which reportedly destroyed thousands of Iran’s centrifuges, ever since it became public in 2010. Now that it’s out, it’s time to claim credit! Of course, if you read Sanger’s account, he certainly doesn’t diminish the expertise of Israel’s spies:
Israel’s Unit 8200, a part of its military, had technical expertise that rivaled the N.S.A.’s, and the Israelis had deep intelligence about operations at Natanz that would be vital to making the cyberattack a success.
Regardless, these Israeli officials say Sanger’s account was too generous to the CIA. Amusingly, one of the officials tries to play it cool, in his remark to Melman:
My Israeli sources understand the sensitivity and the timing of the issue and are not going to be dragged into a battle over taking credit. “We know that it is the presidential election season,” one Israeli added, ”and don’t want to spoil the party for President Obama and his officials, who shared in a twisted and manipulated way some of the behind-the-scenes secrets of the success of cyberwar.”
Translation: We don’t need to tell anyone we’re the ones responsible for Stuxnet, but just so you know, we’re responsible for Stuxnet.Read the full story here.

Wednesday, May 30, 2012

U.N. agency plans major warning on ‘Flame’ virus risk.





U.N. agency plans major warning on ‘Flame’ virus risk.(AA).A United Nations agency charged with helping member nations secure their national infrastructures plans to issue a sharp warning about the risk of the Flame computer virus that was recently discovered in Iran and other parts of the Middle East, as Israel stepped up its supervision over computer systems of commercial banks. “This is the most serious (cyber) warning we have ever put out,” said Marco Obiso, cyber security coordinator for the U.N.’s Geneva-based International Telecommunications Union. The confidential warning will tell member nations that the Flame virus is a dangerous espionage tool that could potentially be used to attack critical infrastructure, he told Reuters in an interview on Tuesday. “They should be on alert,” he said, adding that he believed Flame was likely built on behalf of a nation state. The warning is the latest signal that a new era of cyber warfare has begun following the 2010 Stuxnet virus attack that targeted Iran’s nuclear program. The United States explicitly stated for the first time last year that it reserved the right to retaliate with force against a cyber-attack. A top Israeli minister said on Tuesday the use of cyber weapons, such as the newly uncovered Flame virus, to counter Iran’s nuclear plans would be “reasonable,” hinting at Israel’s possible involvement, AFP reported. “For anyone who sees the Iranian threat as significant, it is reasonable that he would take different steps, including these, in order to hobble it,” Vice Prime Minister Moshe Yaalon told army radio, just hours after the virus was discovered by Russia’s Kaspersky Lab. “Israel is blessed with being a country which is technologically rich, and these tools open up all sorts of possibilities for us,” said Yaalon, who is also Israel's strategic affairs minister. Evidence suggests that the Flame virus may have been built on behalf of the same nation or nations that commissioned the Stuxnet worm that attacked Iran’s nuclear program in 2010, according to Kaspersky Lab, the Russian cyber security software maker that took credit for discovering the infections. “I think it is a much more serious threat than Stuxnet,” Obiso said. He said the ITU would set up a program to collect data, including virus samples, to track Flame’s spread around the globe and observe any changes in its composition. Kaspersky Lab said it found the Flame infection after the ITU asked the Russian company to investigate recent reports from Tehran that a mysterious virus was responsible for massive data losses on some Iranian computer systems. So far, the Kaspersky team has not turned up the original data-wiping virus that they were seeking and the Iranian government has not provided Kaspersky a sample of that software, Obiso said. A Pentagon spokesman asked about Flame referred reporters to the Department of Homeland Security.Jeff Moss, a respected hacking expert who sits on the U.S. government’s Homeland Security Advisory Council, said that the ITU and Kaspersky were “over-reacting” to the spread of Flame. “It will take time to disassemble, but it is not the end of the Net,” said Moss, who serves as chief security officer of the Internet Corporation for Assigned Names and Numbers, or ICANN, which manages some of the Internet’s key infrastructure. “We seem to be getting to a point where every time new malware is discovered it’s branded ‘the worst ever,’” said Marcus Carey, a researcher at with cyber security firm Rapid7.Read the full story here.

Monday, May 28, 2012

Iran detects new kind of Stuxnet virus





Iran detects new kind of Stuxnet virus.(Taz).Iran's National Computer Emergency Response Team has detected an attack of a new computer virus close to Stuxnet and Duqu malwares. CERT announced on Sunday that following the continuous research on the targeted attacks of Stuxnet and Duqu since 2010, it detected a new attack, codenamed "Flamer" and launched by a new malware. The virus features show that there is a close relation to the Stuxnet virus, it said. According to CERT, the research results show that the recent incidents of mass data loss in Iran could be the outcome of the new virus' attack. For the past couple of years, Iran has been targeted by Stuxnet and Duqu viruses. Iran claimed that country's network grid managed to withstand the attacks, however a lot of computers in the country, mainly the industrial ones, were infected or damaged. Recently Iranian oil and education ministries and banking system came under cyber-attacks.Read the full story here.more here @ Wired.

Stealth Backdoor key found in a US military China-made chip.





Stealth Backdoor key found in a US military China-made chip.(TNW).By Jon Russell.A team of researchers from Cambridge University say they have found evidence that a Chinese-manufactured chip used by US armed forces contains a secret access point that could leave it vulnerable to third party tampering.
The researchers tested an unspecified US military chip — used in weapons, nuclear power plants to public transport – and found that a previously unknown ‘backdoor’ access point had been added, making systems and hardware open to attack, the team says.
Cambridge University researcher, Sergei Skorobogatov, explains:
We scanned the silicon chip in an affordable time and found a previously unknown backdoor inserted by the manufacturer. This backdoor has a key, which we were able to extract. If you use this key you can disable the chip or reprogram it at will, even if locked by the user with their own key.
This particular chip is prevalent in many systems from weapons, nuclear power plants to public transport. In other words, this backdoor access could be turned into an advanced Stuxnet weapon to attack potentially millions of systems. The scale and range of possible attacks has huge implications for National Security and public infrastructure.
While the initial research is a concern, a number of question marks remain over the findings before further conclusions can be drawn.
It is unclear if the access point is isolated to the chip that was tested or whether Skorobogatov and his colleagues have stumbled upon a larger trend. Likewise, it remains possible that the modified back door access could have been created by the US armed forces themselves.
The news comes at a time when Chinese cyber-spying threats are a particular concern. Chinese telecom manufacturers ZTE and Huawei are already under investigation from the US government, which is assessing whether the duo’s telecom businesses pose a national security threat.
The Cambridge researchers did not name the company that developed the chip tested, nor did they provide more specific details of its usage. We’ve contacted Skorobogatov for further details and will provide any more information that we’re given.Read the full story here, more here.
Related Posts Plugin for WordPress, Blogger...