Showing posts with label Italian Hacking Team. Show all posts
Showing posts with label Italian Hacking Team. Show all posts

Sunday, 26 July 2015

US Government Attacked Via Flash Player Flaw


Several agencies of the US government in June and July attacked via a Flash Player vulnerability that was discovered by the Italian Hacking Team and true at the time of the attacks had no patch yet, says the FBI. Details about the vulnerability were found in the data that were stolen from the Italian surveillance company. However, the break-in at Hacking Team was made ​​public on July 6.

Now, according to information from the FBI's Flash Player flaw had been since June 8 by assailants known and actively used to penetrate US government agencies. Previously had anti-virus company Trend Micro already know that the vulnerability before the disclosure in targeted attacks against targets in Korea and Japan had begun, namely July 1 . The FBI goes in the case for the attacks against US government agencies for two campaigns which probably gathering information aim.

Campaigns

The first phishing campaign took place on 8, 9 and 11 June, the second was observed on July 8, according to a warning that spread the FBI and by Public Intelligence online ( pdf is put). Both attacks emails were sent with a link. The link pointed to an exploit that took advantage of the vulnerability in Flash Player. The attack on July 8, the FBI more information mentioned in the warning. Thus, the government received a spear phishing e-mail with a link to a PDF document. When users opened a website loaded there the link containing JavaScript code. This code then loaded a malicious Flash file that vulnerability in Flash Player attacked to infect your computer with malware.

The spear phishing emails had different topics such as 'BBW Analysis report - 2015', 'Tomorrow Morning New Starts', "Perry Dale Club for Leadership: Financial Literacy 101", "FAS Analysis Report - 2015", "AEP Energy Program Update: 2015 Program Year Kick Off ',' Review Link "and" PLS Account A42660861. All spear phishing emails that were submitted in July had the same sender. The timing of the attack in July is remarkable, because on July 8 wrote poetry namely the vulnerability in Adobe Flash Player version 18.0.0.194 and earlier on an emergency patch . In the warning, the FBI also recorded several IP addresses and domains that were used by the attackers and can help detect a possible attack.

Wednesday, 22 July 2015

Free Tools Detect Hacking Team Backdoors



Both Facebook and the US security Smoke Security have developed a free tool that allows users and administrators to detect backdoors on their systems which come from the data that was stolen by the Italian Hacking Team.

Smoke Security analyzed the more than 400GB of data stolen and discovered herein 40 files that could be used to attack users or could assist. To detect these files, the security company developed the " Milano "tool. The tool features a 'quick scan' and 'deep scan'.

The quick scan checks for file name. If the retrieved file name matches the name of one of the found Hacking Team files, it is then also the MD5 hash compared with that of the stolen Hacking Team file. The deep scan compares the hash of all files on the computer with that of Hacking Team files.

Facebook

Last year, Facebook launched " osquery ", an open source project to monitor multiple platforms including Ubuntu, CentOS and Mac OS X. The current state of the operating system can be viewed on the basis of SQL based queries and tables, such as processes, loaded kernel modules and open network connections. According to Facebook's osquery for putting all kinds of things, such as intrusion detection, compliance and vulnerability management.

Facebook now has a new version of osquery launched which should be more user friendly. So are used "query packs", which basically clustered SQL queries are being offered as a file. One of the packs offered by Facebook specifically targets Mac OS X backdoors. Through the "OS X attacks pack" Organizations can now check whether a Mac computer in their area is infected with malware. It therefore comes to the Mac backdoor that was found in the stolen data of Hacking Team.

Criticism Windows Leak Was Already Known To Hacking Team


The critical flaw in Windows which Microsoft yesterday an emergency patch released was already known to the Italian Hacking Team, which previously had also developed an exploit, as reported anti-virus company Trend Micro. Through the vulnerability an attacker could completely take over Windows computers when the user opens a malicious document or visits a malicious or hacked website. There is no further interaction is required.

"Because of this vulnerability, attackers could use to infect the computer with system privileges by rootkits or boat kits without this was reported by any means," said analyst Li Moony. He argues that attackers can remotely control vulnerable computers over the leak. Trend Micro reported the problem to Microsoft. Something that also involved researchers from Google and the American security company FireEye.

According to Li contains the dataset by Hacking Team was looted exploit code to make use of the vulnerability, but no attacks are still found in the wild. However, this seems a matter of time. Earlier there were already vulnerabilities found in the stolen data of Hacking Team, which were then used by cyber criminals to infect computers with malware. Users also get the urgent advice to security MS15-078 to install. However, this will happen automatically on most computers.

An attacker recently managed to break into the Italian company and made it more than 400GB of data captured and then put the data online. The data have been found so far six so-called zero-day vulnerabilities. Vulnerabilities in which at the time of the discovery for no update was available yet. These are three vulnerabilities in Adobe Flash Player, two Windows and one in Internet Explorer.

Saturday, 18 July 2015

Google Removes Backdoor App From Play Store


Google has removed a rogue app from Google Play posing as a news app, but in reality it was a backdoor. The app used the name 'BeNews "of the now vanished news site with the same name, to look legitimate, say researchers at the Japanese anti-virus company Trend Micro . The researchers discovered the app in the data that was stolen by the Italian Hacking Team.

The app seems to have been developed in order to circumvent the monitoring of the Play Store. To protect Android users Google checks the content of applications for malicious code. Initially, the app asks for three permissions. Via dynamic loading technology, the app can also download and execute code from the Internet. The downloaded code will not be loaded when Google carries out the checks, but only when the app is used by a victim. The app can then use an exploit to increase its rights on the device. The exploit works on Android version 2.2 to 4.4.

In the stolen data, the researchers found also the source code of the backdoor and the server that can be used to communicate with contaminated devices. Trend Micro believes Hacking Team offered the app to customers, but there is no evidence. The app on Google Play downloaded between 10 and 50 times before it was removed by Google. The developer of the app on the Play Store has placed no other apps in the App Store Google. Google Plus account by this developer also contains no further information except a link to a "testing" area of ​​the app on Google Play.