Showing posts with label Cyber Espionage. Show all posts
Showing posts with label Cyber Espionage. Show all posts

Thursday, 12 November 2015

Apple CEO Opposes British Espionage Legislation


Apple CEO Tim Cook opposes plans by the British government, which wants access to encrypted data via a new espionage laws. Last week, the British government presented a bill which telecom providers are called to work in the interest of national security along with more extensive investigative and intelligence.

During an interview with students of Trinity College in Dublin let Cook know that he wants to persuade the British government to change the plans, reports the Press Association. "We plan to continue to encrypt end-to-end without backdoor", so stated the Apple CEO. "We will cooperate with the authorities to try to convince them that it is also considering the national security is in their interest."

Cook warned that if there backdoors are added to software, anyone can enter. "We find that the safest approach to the world is to encrypt end-to-end, without backdoor. We think this protects most people." Yesterday Cook made ​​his concerns about dealing with encryption already clear. "To protect people using any product you should encrypt. Just look at all the data breaches that occur," he told in an interview with the Daily Telegraph know. Cook also said that the weakening of encryption is not a solution. "You have to strengthen it. You have to stay ahead of the people who want to crack it."

Monday, 26 October 2015

Germany Investigates Espionage Virus On Government Laptop


The German government has launched an investigation into espionage by the US secret service NSA and British intelligence agency GCHQ because of an infected laptop. On the laptop of a department of the Federal Chancellery's highly advanced Regin-espionage virus was discovered, reports Der Spiegel.

According to the Russian anti-virus firm Kaspersky Lab, the relevant NSA or been responsible for the development of the malware. Previously, the virus was already spying on a USB stick found by a staff member of Chancellor Angela Merkel.How infects computers Regin exactly is still unknown, but once active can collect the data in a very sophisticated way.Further details about the study and how the malware was detected not given by Der Spiegel. Earlier, the German authorities decided to investigate eavesdropping on the mobile phone of Merkel by the NSA, but this study was stopped in June because of a lack of evidence.

Tuesday, 20 October 2015

American Company Claims Chinese Espionage Via SQL Injection


An American security company claims it has detected several cases of Chinese cyber espionage via SQL Injection, but concrete details and evidence are given. Does mention Crowd Strike in the blog posting about the cyber espionage frequent own security product.

About three weeks ago, China and the United States decided not to bother with the steal intellectual property via the internet. According Crowd Strike has seen the number of attacks in which the "high degree of certainty" could state that carried out by Chinese attackers. In which this assumption is based not reported by Crowd Strike.

Many of the attacks directed against companies in the technology and pharmaceutical sectors, Web servers via SQL Injection could be hacked. SQL Injection is a problem that has been known since the end of 1998, but is still found in many websites. Through SQL Injection attackers can communicate with the database behind a website and perform various tasks, which should not actually be executed.

In this way, it is possible, among other in order to steal the contents of databases, for example, user names, email addresses, and whether or not encrypted passwords. In this case the attacker SQL Injection eventually use to install a Webshell. Through this Webshell can be obtained access to the internal network of the victim. Despite the report hopes Crowd Strike which progress could be made, and norms and values ​​can be established countries.

Saturday, 10 October 2015

China Arrests Hackers At The Request Of United States



Chinese authorities have arrested at the request of the US government several hackers allegedly broke into US companies. In addition, business secrets were stolen for the purpose by which Chinese enterprises play, so the reports Washington Post.

The arrests were made ​​two weeks before the visit of Chinese President Xi to be the USA, as is now known. Earlier, Susan Rice, National Security Advisor of the United States, announced that cyber espionage by China really had to stop. During his visit, Xi showed that China is not engaged in cyber espionage, and he wants to join forces with the US. In recent weeks, US intelligence and investigation agencies made ​​a list of hackers who were sought.

The list was then given to the Chinese authorities that led to the arrests of a handful of individuals. US officials are now wondering whether the Chinese authorities will prosecute the hackers. Earlier this week, the Financial Times said that the US authorities had three Chinese companies identified that have benefited in the past from cyber espionage. Something that denied two of the three companies.

Friday, 18 September 2015

F-Secure: Espionage Group Working For Russian Government



A group of cyber spies has been working since 2008 for the Russian government and is responsible for various espionage campaigns in which information in the field of foreign policy and security were captured, so claims the Finnish anti-virus firm F-Secure in a comprehensive report (pdf).

The group is called "Duke" and is assured seven years running. To infect targets are mainly used spear phishing emails.The messages contain infected attachments, such as a monkey movie, or links to a website that tries to install malware via a non patches vulnerability. After one vulnerability in Adobe Reader, all the vulnerabilities that the group attacked at the time of the attacks already patched.

Victims were then also can protect themselves by installing security updates timely. The only time there is no spear phishing was used was in the "Onion Duke 'malware. This malware was via a malicious Tor server and torrent files distributed. Once Tor users a program through the Tor network inside was pulled in real-time malware added to the file.

Russia

Attributing attacks to a specific country is very difficult, but in this case, F-Secure says that the espionage group is sponsored by the Russian government. Therefore the virus fighter relies on the motivation and goals of the group. "Based on what we now know about the targets that Duke chose the last seven years, it is consistent to entities with foreign policy and security issues associated," said the Finnish anti-virus company.

The main party that benefits from the work of the cyber spies is the Russian government, according to F-Secure. There are Russian words in the Duke-malware detected and the group is active during office hours in Russia. Further targets include the Eastern European Ministries of Foreign Affairs, Western think tanks and government agencies and even Russian-speaking drug dealers. "All available evidence suggests we believe that the group is working for Russia and we are not aware of evidence that shows otherwise see."

Thursday, 20 August 2015

Developer Encryption Software Targeted By Cyber Espionage



The director of a Russian company that develops encryption software has been attacked by a group who are more concerned with attacking NATO, the White House and the German parliament. It claims the Japanese anti-virus company Trend Micro. It would go to a group of Russian spies.

Although several organizations abroad were the target group, there are attacks carried out in Russia. This involves phishing attacks whereby refined manner attempts to steal login details for email accounts. According to Trend Micro, members of the rock band Pussy Riot, politicians, journalists and software developers have been targeted. Besides the director of the company that develops encryption software was also a developer of web mail service Mail.ru attacked.

Phishing

The attacks on the Russian people were part of a larger campaign involving tens of thousands of people were targeted with phishing emails. This relates to users of well-known webmail providers such as Gmail, Yahoo, Hushmail, Outlook and other providers in the Ukraine, Iran, Norway and China. The way the attacks occur varies. Some campaigns use malware and vulnerabilities. The group of attackers have used at least six zero-day vulnerabilities in the past.

In addition, also targeted phishing attacks used to obtain login details. The phishing e-mails claim, for example that a new service is to deliver guaranteed emails. It then attempts to get through OAuth, an open authentication protocol for example, Yahoo offers to app developers to access the user's mailbox. The links in the phishing email while pointing to a legitimate website of Yahoo for OAuth. So users may think that it is a harmless link. What is the goal of the attackers know Trend Micro, but they may try to keep potential threats to Russia in the eye.

Friday, 31 July 2015

Infected Version TrueCrypt Used For Cyber Spying


A Russian website has years of an infected version of the popular encryption program TrueCrypt offered, which in reality turned out to be a Trojan horse that has been used for cyber-espionage. That leaves the Slovak anti-virus company ESET in a report published today ( pdf ) know.

The website was a truecryptrussia.ru offered in Russian translated version of TrueCrypt. Visitors who met but were offered an infected version specific criteria. What criteria were precisely known. Once installed on the system was also installed a backdoor that allows the attackers had full control over the computer. At least since June 2012 was offered via truecryptrussia.ru malware.

As a select number of victims were attacked in this way, could also backed by long time undetected, according to ESET. The TrueCrypt website also served as Command & Control domain. Communication between the attackers and infected computers ran through the website. Researchers also think the site was managed by the attackers and that it is not a hacked website.

Apart from the TrueCrypt website spread the malware, called Potao, also via e-mail attachments and USB sticks. This was done on a simple but effective way. The malware placed himself on the USB stick and made all other files invisible. In addition, the malware got the name of the USB stick and a disk icon. Users would have thought that it was a disk or shortcut while they opened the malware in reality.

Most targets of the malware were located in the Ukraine. It was among other things the Ukrainian government, the Ukrainian army and a major Ukrainian news agency. Members of the Russian and Ukrainian popular pyramid games were spied by the malware. So were victims of infectious TrueCrypt version mainly in Russia.

SHA1 hashes: Early Potao versions: 

8839D3E213717B88A06FFC48827929891A10059E
5C52996D9F68BA6FD0DA4982F238EC1D279A7F9D 
CE7F96B400ED51F7FAB465DEA26147984F2627BD 
D88C7C1E465BEA7BF7377C08FBA3AAF77CBF485F 
81EFB422ED2631C739CC690D0A9A5EAA07897531 
18DDCD41DCCFBBD904347EA75BC9413FF6DC8786 
E400E1DD983FD94E29345AABC77FADEB3F43C219 
EB86615F539E35A8D3E4838949382D09743502BF 
52E59CD4C864FBFC9902A144ED5E68C9DED45DEB 
642BE4B2A87B47E77814744D154094392E413AB1 

Debug versions: 

BA35EDC3143AD021BB2490A3EB7B50C06F2EA40B 
9D584DE2CCE6B654E62573938C2C824D7CC7D0EB 
73A4A6864EF68C810C7C699ED51B759CF1C4ADFB 
1B3437C06CF917920688B25DA0345749AA1A4A46 

Droppers with decoy documents: 

FBB399568E0A3B2E461A4EB3268ABDF07F3D5764 
4D5E0808A03A75BFE8202E3A6D2920EDDBFC7774 
BCC5A0CE0BCDFEA2FD1D64B5529EAC7309488273 
F8BCDAD02DA2E0223F45F15DA4FBAB053E73CF6E 
2CDD6AABB71FDB244BAA313EBBA13F06BCAD2612 
9BE3800B49E84E0C014852977557F21BCDE2A775 
4AC999A1C54AE6F54803023DC0FCF126CB77C854 
59C07E5D69181E6C3AFA7593E26D33383722D6C5 
E15834263F2A6CCAE07D106A71B99FE80A5F744B 
A62E69EF1E4F4D48E2920572B9176AEDB0EEB1C6 
900AD432B4CB2F2790FFEB0590B0A8348D9E60EB 
856802E0BD4A774CFFFE5134D249508D89DCDA58 
A655020D606CA180E056A5B2C2F72F94E985E9DB 
04DE076ACF5394375B8886868448F63F7E1B4DB9 31 

Droppers from postal websites:

94BBF39FFF09B3A62A583C7D45A00B2492102DD7 
F347DA9AAD52B717641AD3DD96925AB634CEB572 
A4D685FCA8AFE9885DB75282516006F5BC56C098 
CC9BDBE37CBAF0CC634076950FD32D9A377DE650 
B0413EA5C5951C57EA7201DB8BB1D8C5EF42AA1E 
0AE4E6E6FA1B1F8161A74525D4CB5A1808ABFAF4 
EC0563CDE3FFAFF424B97D7EB692847132344127 
639560488A75A9E3D35E4C0D9C4934295072DD89 

USB-spreaders:

850C9F3B14F895AAA97A85AE147F07C9770FB4C7 
BB0500A24853E404AD6CA708813F926B90B38468 
71A5DA3CCB4347FE785C6BFFF7B741AF80B76091 
7664C490160858EC8CFC8203F88D354AEA1CFE43 
92A459E759320447E1FA7B0E48328AB2C20B2C64 
BB7A089BAE3A4AF44FB9B053BB703239E03C036E 
DB966220463DB87C2C51C19303B3A20F4577D632 
37A3E77BFA6CA1AFBD0AF7661655815FB1D3DA83 
181E9BCA23484156CAE005F421629DA56B5CC6B5 
A96B3D31888D267D7488417AFE68671EB4F568BD 
224A07F002E8DFB3F2B615B3FA71166CF1A61B6D 
5D4724FBA02965916A15A50A6937CDB6AB609FDD 
8BE74605D90ED762310241828340900D4B502358 
5BE1AC1515DA2397A7C52A8B1DF384DD938FA714 
56F6AC6197CE9CC774F72DF948B414EED576B6C3 
F6F290A95D68373DA813782EF4723E39524D048B 
48904399F7726B9ADF7F28C07B0599717F741B8B 
791ECF11C04470E9EA881549AEBD1DDED3E4A5CA 
E2B2B2C8FB1996F3A4A4E3CEE09028437A5284AE 
5B30ECFD47988A77556FE6C0C0B950510052C91E 
4EE82934F24E348696F1C813C24797618286A70C 
B80A90B39FBA705F86676C5CC3E0DECA225D57FF 
971A69547C5BC9B711A3BB6F6F2C5E3A46BF7B29 
C1D8BE765ADCF76E5CCB2CF094191C0FEC4BF085 
2531F40A1D9E50793D04D245FD6185AAEBCC54F4

32 Other droppers:

D8837002A04F4C93CC3B857F6A42CED6C9F3B882 
BA5AD566A28D7712E0A64899D4675C06139F3FF0 
FF6F6DCBEDC24D22541013D2273C63B5F0F19FE9 
76DA7B4ABC9B711AB1EF87B97C61DD895E508232 
855CA024AFBA0DC09D336A0896318D5CC47F03A6 
12240271E928979AB2347C29B5599D6AC7CD6B8E 
A9CB079EF49CEE35BF68AC80534CBFB5FA443780 
1B278A1A5E109F32B526660087AEA99FB8D89403 
4332A5AD314616D9319C248D41C7D1A709124DB2 
5BEA9423DB6D0500920578C12CB127CBAFDD125E 

Plugins: 

2341139A0BC4BB80F5EFCE63A97AA9B5E818E79D 
8BD2C45DE1BA7A7FD27E43ABD35AE30E0D5E03BC 
54FEDCDB0D0F47453DD65373378D037844E813D0 
CC3ECFB822D09CBB37916D7087EB032C1EE81AEE 
F1C9BC7B1D3FD3D9D96ECDE3A46DFC3C33BBCD2B 
9654B6EA49B7FEC4F92683863D10C045764CCA86 
526C3263F63F9470D08C6BA23E68F030E76CAAF3 
E6D2EF05CEDCD4ABF1D8E3BCAF48B768EAC598D7 
CEBAB498E6FB1A324C84BA267A7BF5D9DF1CF264 
324B65C4291696D5C6C29B299C2849261F816A08 
C96C29252E24B3EEC5A21C29F7D9D30198F89232 
CDDDE7D44EFE12B7252EA300362CF5898BDC5013 
84A70CDC24B68207F015D6308FE5AD13DDABB771 

Fake TrueCrypt setup: 

82F48D7787BDE5B7DEC046CBEF99963EEEB821A7 
9666AF44FAFC37E074B79455D347C2801218D9EA 
C02878A69EFDE20F049BC380DAE10133C32E9CC9 
7FBABEA446206991945FB4586AEE93B61AF1B341 

Fake TrueCrypt extracted exe: 

DCBD43CFE2F490A569E1C3DD6BCA6546074FD2A1 
422B350371B3666A0BD0D56AEAAD5DEC6BD7C0D0 
88D703ADDB26ACB7FBE35EC04D7B1AA6DE982241 
86E3276B03F9B92B47D441BCFBB913C6C4263BFE

Saturday, 18 July 2015

Zero-Day Vulnerability In Microsoft Office Used For Cyber-Espionage


Last Tuesday, Microsoft patched a zero-day vulnerability in Office, which recently has been actively used by a group engaged in cyber espionage. The group sent at least one RTF document on the nuclear negotiations with Iran. The document, which was discovered in Georgia, contained an exploit for a critical vulnerability in Microsoft Office 2013 Service Pack 1 and earlier versions of Office.

Once users opened the paper exploits document was replaced by a genuine document with information on the nuclear negotiations. In the background, however, was installed a backdoor that attackers had full control over the computer, says security firm iSIGHT Partners . According to the company, the group behind the attacks also associated with a recently patched zero-day vulnerability in Java that was also used in targeted attacks.

The group would in April two zero-day vulnerabilities in Flash Player and Windows have used and the recently unveiled Flash exploits which was available to the Italian Hacking Team. The group would have to cater for the collection of military and diplomatic intelligence, although telecoms and defense companies have been targeted. The Office leak that the group is used patched by MS15-070 .

Tuesday, 16 June 2015

Attackers used Kaspersky certificate Foxconn


The attackers internal network anti-virus firm Kaspersky Lab infiltrated using a valid digital certificate from the Chinese company Foxconn to sign their malware. Foxconn is the largest electronics manufacturer in the world and produces, among other products for Apple, Dell and Cisco.

Last week Kaspersky Lab announced that attackers had managed to get malware on the internal network. It was a new variant of the highly advanced Duqu malware called Duqu 2.0. Duqu 2.0 hides the memory of infected computers. If the machine is restarted and malware consequently disappears, the computer via a compromised server again infected. For this, the attackers use special drivers.

During the operations, the attackers installed these drivers on firewalls, gateways and other servers with direct access to the Internet on one side and access to the company on the other side. In this way, the attackers managed to achieve various goals, such as accessing the internal infrastructure from the Internet, ensure that they appeared in the logs of the proxy servers and computers could contaminate permanently.

Certifications


For 64-bit Windows versions is mandatory that drivers digitally signed are. Researchers from Kaspersky Lab also looked surprised when she saw that one of the drivers discovered had been signed by a valid certificate of Foxconn. The same certificate in February 2013 was still used by the manufacturer for the signings of several drivers for Dell laptops. Using valid digital certificates is not new. Previously this was discovered Stuxnet and the first version of Duqu.

"The steal of digital certificates and signing of malware in the name of legitimate businesses is a proven method of Duqu attackers," said researchers at Kaspersky Lab. How the attackers managed to get the Foxconn certificate is unknown.However, the researchers attackers seem to have a preference for hardware manufacturers, as were used in Stuxnet and Duqu 1.0 certificates from Realtek and Jmicron.

Confidence

What is also striking is that the attackers did not use the same certificate twice. Something that at first Duqu version was the case. "If this is the case, this means that the attackers may have sufficient alternative digital certificates stolen from other manufacturers that are ready to be used in the next targeted attack," said the researchers. Which warn that it would be very worrying, as it undermines confidence in digital certificates. Meanwhile, would both certificate issuer Verisign Foxconn been notified of the certificate in question.

Iran Bans Smartphones Officials For Spying


Fearing espionage going on the Iranian authorities prohibit the use of smartphones for work related matters by officials with confidential information. According to Brigadier General Gholamreza Jalali, these types of phones does not secure since the data is backed up on the device.

The new rule is still waiting for the last approval, but would mean that officials must use other phones for work where confidential information is involved. The ban would not apply to personal use as reported AFP. The measure follows reports that sophisticated malware called Duqu2 was used for nuclear talks with Iran was involved in spying.

The malware would be used at the hotels where the participants stayed at the talks. Because of the incident both the Austrian and Swiss authorities have started an investigation. However, not been the case according to the US government is the security around nuclear talks. "We have taken during the negotiations measures to ensure that confidential details and discussions behind closed doors continued," US spokesman Jeff Rathke said earlier during a press conference to know.

Thursday, 11 June 2015

Anti-virus Firm Kaspersky Victim Of Cyber Espionage


The Russian anti-virus firm Kaspersky Lab earlier this year become victims of cyber espionage in which various internal systems with advanced malware became infected. For spreading the malware, which was discovered during an internal security check with a new product, the attackers used an unknown vulnerability in the Windows kernel, which Microsoft patched yesterday. In addition, the virus-fighter does not exclude that there are two different zero-day vulnerabilities used have been patched at this time.

The original attack vector is as yet unknown, although the attackers probably used a spear phishing email. In one of the first casualties which showed that his mailbox and browsing history was erased to hide traces of the attack. Since the infected machines were fully patched Kaspersky believes that an unknown vulnerability is attacked. The attack on the corporate network would have no impact on the anti-virus software or the company's customers.

According to Kaspersky the attackers were interested in the intellectual property of the virus fighter, as well as the company's technology to the espionage attacks detects and analyzes. Kaspersky said in a statement that the decision of the attackers to carry out the attack was probably very difficult, as it would certainly be discovered. "Attacking security companies indicate that they have a lot of confidence that they will not get caught, or maybe they do not care if they are discovered."

To be discovered malware mainly hid in the memory of infected computers. Restarting the computer would mean in this case is that the infection disappeared. In order to infect computers still infected permanently attackers servers in the network with a high up-time, which then infected computers in the domain. This approach has the disadvantage that all computers and servers would be disinfected by a power failure. Therefore, drivers installed on a small number of computers. These drivers can traffic from outside the network tunneling toward the inside. The attackers were so connect via remote desktop sessions or from previously stolen credentials to login servers.

United States

The attack is according to Kaspersky Lab performed by the group that previously made ​​it very sophisticated Duqu virus. The Duqu virus was linked to the organization that developed Stuxnet. According to several experts, Stuxnet made ​​by the US government to disrupt Iran's nuclear program. Several sophisticated espionage operations that have been attributed to the US government in recent years were published by Kaspersky Lab.

Also in the case of Duqu 2.0, such as used malware is mentioned, there is according to the Russian anti-virus company existence of an attack performed by a state. This type of campaign could be only a costly and require a lot of resources. The framework in which Duqu 2.0 is built is estimated to cost $ 50 million. In addition, the dependence of the platform of zero-day vulnerabilities remarkable. Duqu 2.0 is also not designed for financial motives, as with much malware cybercriminals is the case.

In addition to Kaspersky Lab, the malware was also used against other targets. Worldwide, would have been observed less than one hundred infections. The Duqu first version it was less than fifty goals. Victims of version 2.0 are located in Western countries, the Middle East and Asia. As in 2011, would Duqu 2.0 and aim to spy on Iran's nuclear program. Symantec reports that include European and North African telecom provider via the malware attacked, as well as a manufacturer of electronic equipment in South East Asia.

DUQU 2.0 Indicators:

Action loaders:


C&C IPs:

Wednesday, 20 May 2015

Digital Attacks On Oil Traders Without Malware


Researchers from the Spanish anti-virus company Panda Security discovered a digital attack on oil traders with no malware was used and the traders also were not the ultimate target. The attack starts with an executable file that looks like a PDF document.

In reality, it is a self-extracting archive file with several files, including various scripts, batch files and .exe files. Yet these files themselves are not malicious. "These are all legitimate applications that anyone can use," the researchers said that the threat of "The Phantom Menace" ( pdf call). The applications are created to store user names and passwords in the e-mailcient and browser in a text file and send it via FTP.

On the FTP server of the attackers, the researchers discovered more than 80,000 text files. It turned out to be files from ten companies in the oil sector. However, these companies were not the ultimate target. These are namely oil buyers. And especially oil buyers seeking special oil from the Nigerian city of Bonny. This oil is very popular because of its composition.In Nigeria holds the Nigerian National Petroleum Corporation (NNPC) on each transaction oil supervision.

Anyone who wants to sell in Nigeria oil must also be registered with the NNPC. Fraudsters operating in this market approaching traders and brokers and, for example offer a large amount of oil from Bonny at a very attractive rate. The potential buyer requests for documents that the product also exists. For this, several documents can be issued by the NNPC.

To use to inform the buyers on the scammers legitimate documents they captured at the previously attacked oil traders. Then the buyer will see this document and pay a deposit, for example, 50,000 to 100,000 dollars, but gets its oil never see.Eventually Panda Security was able to trace the possible culprit behind the attacks. The problem is that none of the attacked oil traders will report it, for fear of damage to reputation and the fact that they themselves have become a victim. This allows the police can not start investigation and the alleged perpetrator is still at large.

Saturday, 2 May 2015

China Concerned About Cyber Strategy Pentagon


The Chinese Ministry of Defense is concerned about the new cyber strategy ( pdf ) from the Pentagon, which was presented recently. In the strategy, the Pentagon states that cyber attacks may retaliate with their own cyber weapons. According to the Chinese Defense spokesman Geng Yansheng this will cause the voltage on cyber security will only increase and encourage a race of cyber weapons.

"This worries us," as he announced. The spokesman added that the United States in the report do not need to point to China when it comes to cyber espionage, and that this criticism is hypocritical anyway given the PRISM spying program by the NSA, said Reuters . According to Geng China might just be the victim of cyber attacks and the opponent of any kind of hacking. The spokesman also called on the US to adopt a double standard, reports the Chinese news agency Xinhua .

Thursday, 16 April 2015

Target Cyber Espionage Strikes Back With Backdoor



An organization that was the target of an attack by cyber spies have beaten back with its own attack to infect the cyber spies. Researchers from the Russian anti-virus firm Kaspersky Lab saw several emails from a known group called Naikon espionage, which is very active mainly in Asia. The group sends documents from a three year old vulnerability in Microsoft Office use to infect computers.

One of the targets, however, sent an e-mail back to the attackers to confirm the authenticity of the message. The attackers left them know that it was a legitimate message that they had to send. The target responded again with a second e-mail, provide a RAR file. The RAR file containing several documents, but also an SCR file. This proved to be a backdoor which could take over the target computer cyber spies.

Further research from Kaspersky Lab revealed that the target was in fact a group of cyber spies, who was named Hellsing.This group focuses on targets in Malaysia, the Philippines and Indonesia. Countries where the Group operates Naikon. The Hellsing group was unknown to Kaspersky Lab, but could be discovered thanks to the remarkable communication with other espionage group.

Internet users who want to protect against these types of attacks are advised not to open attachments from strangers, be careful with password protected archive files that contain SCR or other executable files and keep all software up to date. In case users do not trust, they can choose to open the attachment in a sandbox.

Monday, 13 April 2015

Southeast Asia: State Cyber Spies Operate Ten Years Undetected


For a decade, spying a group of hackers governments and companies in Southeast Asia and India. According to one report, China is said to have instructed the snooping.

In 2005, the group of hackers APT would have 30 started successfully spy on government and economic institutions in Southeast Asia and India. These have targeted political, economic and military information the attacker. In the course of journalists came into the focus of hackers. That's according to a report of IT security firm FireEye , which shines through the operation of APT 30. Responsible for Cyber ​​espionage is China, the researchers suggest.

The security researchers from FireEye have analyzed over 200 spy tools and software for planning the attacks, monitoring of targets and execution of the attacks. The tools were tailored according FireEye with clearly defined objectives. A derivative of espionage tools have successfully hidden on infected computers before anti-virus programs.

Attacked first computer behind an Air Gap

In the wake of the attacks it was the hacker group also managed to penetrate into independent, non-affiliated security reasons with the Internet company networks, as a descendant of espionage tools has spread through removable media. The infiltration of computers behind an Air Gap succeeded APT 30 FireEye According back in 2006 - the first such attacks were documented in 2008.

In order to sneak on target computers, put the hacker group on phishing e-mails with supposedly important documents in the appendix. Opened an employee a file, an espionage tool that searched the computer for relevant information and related documents sent secretly to the attackers installed.

The assumption on the part of FireEye that China is behind the espionage activities, based on the evaluation of the goals. Among other journalists were monitored, reported on the Chinese dissident movement. In addition, the graphical user interface of attack planning software was written in Chinese and also the spy tools reported Chinese terms on.

Friday, 13 March 2015

Kaspersky Would Have Hesitation About Revealing Cyber Attacks


The Russian anti-virus firm Kaspersky Lab would have hesitation about revealing two cyber attacks attributed to the Russian regime, as were sources within the company across Reuters have announced.According to founder Eugene Kaspersky, the company never asked by government to refrain from investigating a cyber attack.

The researchers would not be guided by the political interests of a country. Yet, say several current and former employees of the company Kaspersky Lab about publishing at least two alleged cyber attacks has hesitated. Kaspersky Lab as published last year under paying customers a report on a sophisticated espionage campaign that had discovered it.

The report, however, was only five months later publicly disclosed once had a British defense company about the espionage campaign published . According to the British BAE Systems were likely to be a campaign of the Russian government, which mainly computers in the Ukraine were infected. Eugene Kaspersky, however, denied that political motives played a role. "We were late," as he announced. According to the virus fighter is not possible to win everything.

Discussion

In 2013, Kaspersky Lab researchers discovered another espionage campaign called Red October , by Russian-speaking programmers would be created and focused on governmental and diplomatic organizations in Europe, Central Asia and North America. Only after a heated internal debate virus fighter still decided to publish a report on the operation. According to several current and former employees of Kaspersky Lab, who wished to remain anonymous, it was probably an operation of a Russian military intelligence.

Update

Kaspersky Lab said in a statement that the company has never doubted about publishing studies because of political reasons. "We have no political ties," said the virus fighter, who noted further with various countries and international investigative agencies to work together. In case an attack campaign is discovered the anti-virus company follows a special procedure whereby the investigative services are warned in the countries concerned, as well as partners and customers before the investigation appears.

Wednesday, 11 March 2015

Microsoft Patches 45 Vulnerabilities, Including Stuxnet And FREAK


Microsoft has during Patch Tuesday of March 14 released updates, which together 45 vulnerabilities in Windows, Office, Exchange and Internet Explorer fix, including the Stuxnet leak from 2010 and the recently discovered FREAK leak. Especially re-patching the Stuxnet leak creates experts in amazement.Through the vulnerability knew the Stuxnet worm and the Fanny-espionage worm to spread.

Only connect a USB stick that made ​​the leak abuse was sufficient to infect Windows, even stood Autorun and Autoplay disabled. It was in fact a whole new way to attack Windows computers. In 2010, Microsoft came up with an update for the leak, but this patch showed the vulnerable code is not corrected, allowing Windows computers all the time were vulnerable, so warn researchers from HP.

There is also an update to the " FREAK-leak "in SSL / TLS appeared. Through the vulnerability, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

Other vulnerabilities

In addition to the update for the Stuxnet leak four other updates are labeled as critical. Through these updates fix vulnerabilities that an attacker in the worst case can take over the entire system. It comes to vulnerabilities in Internet Explorer, the VBScript Scripting Engine in Windows, Adobe Font Driver and Office. In the case of one of the IE-leakage was the vulnerability already publicly known before the patch appeared. Through other vulnerabilities that Microsoft patched attackers could increase their rights to systems retrieve information, cause a denial of service and bypass security measures.Can update via Windows Update .

Saturday, 28 February 2015

US Spy Chief Calls "Cyber Armageddon" Unlikely


Although some politicians, military officials , businesses and interest groups for years for a digital "Pearl Harbor" warn the risk of a catastrophic attack by one party at this time is unlikely. That left James Clapper, head of US intelligence, yesterday at a hearing before a committee of the US Senate to know.

"Instead of a" cyber Armageddon "scenario that the entire US infrastructure disrupted, we foresee something else," said Clapper. It is then to form a continuous series of small to moderate cyber attacks from various parties that an increasing burden on the competitiveness of the US economy and national security.

According Clapper Various studies indicate that a number of countries, including Iran and North Korea, from economic and political motives offensive cyber operations conducted against the US private sector. Furthermore Clapper also warned of the risk of compromised hardware and software that is sabotaged anywhere in the supply chain. Also, malicious insiders in the coming years pose a risk to IT systems.

In addition to Iran and North Korea Clapper also named Russia and China as countries engaged in offensive cyber operations and cyber espionage. Finally, the head of intelligence for terrorists who will use the Internet to carry out attacks. "Terrorist groups will continue to experiment with hacking, which can serve as the basis for the development of more advanced capabilities."

The statements of Clapper follow the revelations of the Equation Group . According to experts, one of the most advanced cyber-espionage operations ever that would be carried out by the NSA or the NSA affiliated group during a period of several years.

Thursday, 19 February 2015

Espionage Firmware In Hard Disks To Detect Barely


The malicious firmware that a group of cyber spies computers permanent commitment to continue spying is hard to detect and extremely difficult to remove. "It is extremely difficult to detect. From the software level, it is impossible," said Vitaly Kamluk, researcher at Kaspersky Lab.

The Russian anti-virus company revealed this week the existence of the spy group who developed all kinds of highly advanced malware. One subset fell on, namely, the ability to infect the firmware of the various popular brands hard disks.Therefore, the malware remains hidden and active, even though the hard disk is formatted or reinstall the operating system.The code ensures that the attackers can create an invisible storage on the hard disk.

"This is unique and the first time we have seen this level of complexity of a sophisticated attacker," said security researcher.However, the module could have been used rarely. "Only a very select list of victims have received this. This is one of the most special modules that I've seen because it is so valuable. They do not want that to be known," Kamluk let know this week during a conference, so reports Threat Mail .

"It is a valuable plug-in that is used only in specific cases for very important people." To detect the malicious firmware should the PC be disassembled and made a dump of the firmware. "And we think that only a few people in the world are able to analyze the malicious code within the firmware, compare and discover," says Kamluk.

According to the researcher takes years to write firmware. But the espionage group would not use vulnerability, but only ride on the way manufacturers roll out firmware updates. "They left the door open and stood possible longtime open. The trick is that you have the full description, the full reference of the current firmware should have and how it works."

Kamluk speculates that the attackers may have access to internal manuals and documentation of the respective suppliers.Manuals that may be stolen by an insider or through another malware attack. "They do not abuse a leak in the code. It is a design flaw." Because of the proprietary communication protocols and algorithms took investigators months before they learned how the malware exactly worked. A truly infected firmware researchers have not been able to find.

Victim Fanny-Espionage Worm Early In 2010 Already To Help


A victim of this week unveiled Fanny spy worm, which through two zero-day vulnerabilities in Windows spread that later were used by Stuxnet, early in 2010, all Internet users for help. However, they received no answer. That discovered Maarten van Dantzig Fox-IT.

A Malaysian forum posted a user with the alias "dkk" a call on July 13, 2010 how he could prevent his computer became infected with this virus. The user notes that he is infected via its USB stick, even though they are Autorun and Autoplay disabled. Much to the surprise of the user, different files found on the USB stick and the names also mentioned this, including Fanny.bmp. He also added a copy of the virus. However, there was no response.

Fanny.bmp is the same file that the report ( pdf ) from anti-virus firm Kaspersky Lab is known about the malware. The report also stated that Malaysia is among the countries where the worm is still active. Opposite Ars Technica confirms Kaspersky Lab that files who names the forum user match those of the Fanny worm. The worm was developed by a highly sophisticated espionage group and would have been deployed since 2008.