Showing posts with label NSA Equation Group. Show all posts
Showing posts with label NSA Equation Group. Show all posts

Monday, 9 March 2015

EFF Provides Alarm About Effects Of Firmware Malware


The discovery of malware that can modify the firmware of hard drives is a "wake up call" for manufacturers and the security industry that the risk is real and will increase the number of firmware-based attacks. Before that warns the American civil rights movement EFF. The organization argues that even if the problems are not resolved, the consequences "disastrous" can be.

Firmware is the software that runs on all kinds of computer components, such as the video card, network card and hard drive, and makes it possible to control these components. The reason for the cry of the EFF is the discovery of the Equation Group . This group of cyber spies had developed malware that could modify the firmware of all hard drives. The malware could thus reinstall or reformat survive the hard drive. Also made ​​it a hidden container for stolen files on the hard drive and was barely detect .

Firmware is next to computer components in a variety of other electronics available from auto parts to televisions. The big problem with firmware is that the code is closed. Most manufacturers make the source code of their firmware not public. In some cases, they even take steps to counter the "reverse engineer" their firmware. According to Cooper Quintin of the EFF, it is also not possible to see from the computer or the firmware of certain components has been modified or not.

Firmware-based malware is in comparison to other types of malware is still a fairly unexplored area. Attacking the firmware is not only beneficial for cyber spies, but for cybercriminals. The malware would be namely to detect and difficult to remove.Also, most firmware never publicly controlled and closed source code. Thus, according Quintin a "rich source" for zero-day vulnerabilities. Many devices the firmware is not updated, so malware or exploits for a long time may remain.

EFF urges manufacturers also to publish their firmware well as auditing for vulnerabilities and then the results. In addition, firmware updates are digitally signed and finally there should be a mechanism to check the integrity of installed firmware. "We have given up control over our computers. We trust too many different devices. Devices that we should not trust, given that they without us knowing can be compromised," said Quintin.

According to him, it is therefore high time to take control and thus to take back the security. "We need to encourage manufacturers so that they can ensure that their products are reliable, even and especially when they leave the factory floor. We must act now for a future where the foundation of our computers are safe."

Saturday, 28 February 2015

US Spy Chief Calls "Cyber Armageddon" Unlikely


Although some politicians, military officials , businesses and interest groups for years for a digital "Pearl Harbor" warn the risk of a catastrophic attack by one party at this time is unlikely. That left James Clapper, head of US intelligence, yesterday at a hearing before a committee of the US Senate to know.

"Instead of a" cyber Armageddon "scenario that the entire US infrastructure disrupted, we foresee something else," said Clapper. It is then to form a continuous series of small to moderate cyber attacks from various parties that an increasing burden on the competitiveness of the US economy and national security.

According Clapper Various studies indicate that a number of countries, including Iran and North Korea, from economic and political motives offensive cyber operations conducted against the US private sector. Furthermore Clapper also warned of the risk of compromised hardware and software that is sabotaged anywhere in the supply chain. Also, malicious insiders in the coming years pose a risk to IT systems.

In addition to Iran and North Korea Clapper also named Russia and China as countries engaged in offensive cyber operations and cyber espionage. Finally, the head of intelligence for terrorists who will use the Internet to carry out attacks. "Terrorist groups will continue to experiment with hacking, which can serve as the basis for the development of more advanced capabilities."

The statements of Clapper follow the revelations of the Equation Group . According to experts, one of the most advanced cyber-espionage operations ever that would be carried out by the NSA or the NSA affiliated group during a period of several years.

Thursday, 19 February 2015

Espionage Firmware In Hard Disks To Detect Barely


The malicious firmware that a group of cyber spies computers permanent commitment to continue spying is hard to detect and extremely difficult to remove. "It is extremely difficult to detect. From the software level, it is impossible," said Vitaly Kamluk, researcher at Kaspersky Lab.

The Russian anti-virus company revealed this week the existence of the spy group who developed all kinds of highly advanced malware. One subset fell on, namely, the ability to infect the firmware of the various popular brands hard disks.Therefore, the malware remains hidden and active, even though the hard disk is formatted or reinstall the operating system.The code ensures that the attackers can create an invisible storage on the hard disk.

"This is unique and the first time we have seen this level of complexity of a sophisticated attacker," said security researcher.However, the module could have been used rarely. "Only a very select list of victims have received this. This is one of the most special modules that I've seen because it is so valuable. They do not want that to be known," Kamluk let know this week during a conference, so reports Threat Mail .

"It is a valuable plug-in that is used only in specific cases for very important people." To detect the malicious firmware should the PC be disassembled and made a dump of the firmware. "And we think that only a few people in the world are able to analyze the malicious code within the firmware, compare and discover," says Kamluk.

According to the researcher takes years to write firmware. But the espionage group would not use vulnerability, but only ride on the way manufacturers roll out firmware updates. "They left the door open and stood possible longtime open. The trick is that you have the full description, the full reference of the current firmware should have and how it works."

Kamluk speculates that the attackers may have access to internal manuals and documentation of the respective suppliers.Manuals that may be stolen by an insider or through another malware attack. "They do not abuse a leak in the code. It is a design flaw." Because of the proprietary communication protocols and algorithms took investigators months before they learned how the malware exactly worked. A truly infected firmware researchers have not been able to find.

Tuesday, 17 February 2015

Fanny Malware: "11.000 Computers Precursor Stuxnet Infected"


Still 11,000 computers worldwide are infected with a sophisticated worm that was developed in 2008 and is considered the forerunner of the infamous Stuxnet worm. The Fanny worm was yesterday already revealed by Kaspersky Lab, and today there are more details disclosed.

The worm used two zero-day vulnerabilities in Windows to spread via USB sticks. Connecting an infected USB drive on a Windows computer, even if it is disabled Autorun, was enough to get infected. The worm the LNK vulnerability used in this case that later was used by the Stuxnet worm. The second vulnerability used Fanny made sure that the malware had administrator rights. The vulnerabilities were patched by Microsoft in 2009 and 2010.

Although Stuxnet known as the first malware that used the LNK vulnerability, a Trojan horse in 2010 it was discovered that already spread through the leak. It was the Zlob Trojan, part of a large family of malware. However, no one paid attention given to this instance of malware in the anti-virus industry. The makers of Fanny used a common method to load the malware while starting Windows, making the creation as Zlob was detected.


Indeed, it was a registry value created to start automatically. According to researchers, the malware writers have done this deliberately, so as automatic control of anti-virus companies and researchers to lead the garden. That would detect the malware and namely because of the widely used starting technique, pay no further attention. Therefore, the deeper operation and functionality of Fanny remained hidden.

The main functionality of the worm is in the mapping of systems and networks that are not connected to the Internet. Where Stuxnet worked only on specific systems, Fanny infected all Windows computers where it landed. Not only could easily infect the worm computers. Once USB drives were connected to an infected computer, which also became infected and could spread the worm further.

The researchers knew the Command & Control server that the attackers used to control infected computers take over. In total still made 11,200 unique IP addresses connecting to this server. Sixty percent of it comes from Pakistan, followed by Indonesia (16%) and Vietnam (14%). Whether Pakistan was the original target of Fanny is unknown. The situation may be different when the worm was used between 2008 and 2010. However, the researchers note that the group that Fanny has also developed other malware made that it had provided to Pakistan.

However, the real targets of Fanny is unknown, say the researchers. Possible that the worm is used to select potential targets for Stuxnet. Another remarkable fact is the large number of infections in Pakistan. The use of USB drives is indeed a slow diffusion method. Therefore, the researchers also think that the first infections occurred in Pakistan.

Monday, 16 February 2015

Espionage Group Reprograms Firmware Drives


Researchers have identified a group of highly sophisticated cyber spies discovered active as possible for 20 years and the same zero-day vulnerabilities used that eventually were used by the creators of the Stuxnetworm. Also developed this super spies malware to reprogram the firmware from popular brands hard drives, which the researchers have never seen before.

The spies by the Russian anti-virus firm Kaspersky Lab called the "Equation Group". The first domains which date the group used to control infected computers in 2001, while the first malware copies were made ​​in 2002. Other areas that the group used to control the infected computers were already registered in 1996. This could possibly mean that the spies are active for almost two decades.

Equation Group developed several malware platforms that are more advanced than the last year revealed Regin malware.Thus, among other things, developed a computer worm that gathered all kinds of information about targets in Asia and the Middle East in 2008. This worm, named "Fanny", used two zero-day vulnerabilities. Vulnerabilities that were eventually used for Stuxnet. According to Kaspersky, this means that the Equation Group also developed Stuxnet or worked with the developers of the worm.

The Fanny worm probably had as goal to bring networks card that were not connected to the Internet. The malware was distributed through USB sticks. On infected USB sticks Fanny made a hidden storage area to which the information about infected systems preserved. Also intercepted the group of physical goods and replaced by versions with Trojans.

One example involved the participants in a scientific conference in Houston to return some of the participants had received a copy of the conference proceedings on CD-ROM, which was then used to install the Double Fantasy implant of the group on the machine the target. The exact manner in which these CDs were intercepted is unknown.


In addition to USB sticks and CDs espionage group also used a web-based exploits. Thus, among other leaks in Java and Internet Explorer to infect victims. There were also unknown exploits, possibly zero days, against the Firefox 17 version of Tor Browser deployed. Tor Browser uses a custom Firefox version that was attacked by the Equation Group.

Since 2001, the cyber spies would have infected thousands of computers in a variety of sectors including government, telecommunications, energy, nanotechnology, financial institutions, oil and gas and aviation. Most victims are in Iran and Russia. In total, Kaspersky Lab counted 500 victims, but the real number is probably much higher, because the malware has a self-destruct mechanism. It is therefore possible that there may be tens of thousands of computers were infected.

What really makes the group stand out is the ability to reprogram the firmware of all branded hard drives. The researchers were able to secure two modules that were used to reprogram the firmware. Through this method, the attackers could install it again and survive reformatting of the hard drive. In addition, could be created an invisible storage on the hard disk. However, the module would be used on a very limited scale, probably at the most valuable targets.

"Another dangerous consequence is that it is impossible to scan the firmware when the hard disk is once infected with this malicious payload simply:. For most hard disks, there are functions to write the firmware portion of the hardware, but there No functions to read it back. This means that we are virtually blind and can not detect hard drives that have been infected with this malware, "warns Costin Raiu, research director at Kaspersky Lab.

The ability to create an invisible and persistent area in the hard disk is used to store collected information that can be later retrieved by the attackers. In some cases it may also help to crack the encryption of the group: "Given the fact that their Gray Fish implant is activated immediately from the startup of the system, they have the ability to intercept the encryption password and store it in secret area, "explains Raiu.


Although all detected malware worked for Windows, there are also found traces indicating Mac OS X malware. One of the domains, which was used for the control of the infected computers received a variety of compounds of Chinese Mac OS X computers. Therefore, it is assumed that there is at least one of the platforms is also a malware-Mac version. It would also have the group the ability to infect iPhones.

Despite the level of the malware writers have they still left their mark. So were encountered several keywords in the studied modules, such DESERT WINTER, STRAIT SHOOTER and GROK. This last term appeared in NSA documents published by Der Spiegel. Kaspersky Lab discovered the Equation Group during the investigation into the Regin malware. This malware was the NSA by the virus fighter attributed . Additionally, labels the group malware as "implants", a term earlier in the NSA documents appeared Snowden. In addition, the development of Stuxnet is attributed to the NSA.

The next few days will be the Russian anti-virus company publish more details about the group and applied method.Meanwhile, there is already a document published online ( pdf ) with directions and details so that researchers and administrators can check machinery in place within their organization or environment. "The more we investigate this kind of cyber-espionage operations, the more we realize how little we know about it. Together we can uncover these practices and safer (cyber) world works," said the researchers.

Below are the MD5 with Sample Names & VT Checked:

_SD_IP_CF_dll\866f94f30d9865995494a0f7228329c26149eef2960500b2177c736c5c846035

Disk from Houston\868eb363f32beacd8bcdc7a114e020d4cfe67913a15275f4e7493d87db643ff2 

DoubleFantasy\1e55abb94951cedc548fd8d67bd1b50476808f1d0ae72f9842181761ff92f83f 

EquationDrug\1b0eb1a1591140175d1ac111a98c89472b196599baf13ef67ee7f63d0052b00e 

EquationLaser\9412a66bc81f51a1fa916ac47c77e02ac1a7c9dff543233e
d70aa265ef6a1e76 

Fanny\003315b0aea2fcb9f77d29223dd8947d0e6792b3a0227e054be8eb2a11f443d9 

GrayFish\df4bbd02dcd8b8b9e1374c6f71f2e2da8518d39337b35983874266e8fff055e1 
9B1CA66AAB784DC5F1DFE635D8F8A904
GROK\441f2a6775621af8c5d1ead7082e9573ad878bc90675ed55f86abfc8a9e8cc6f 

nls_933w_dll\83d14ce2dcfc852791d20cd78066ba5a2b39eb503e12e33f2ef0b1a46c68de73

TripleFantasy\112d70111fef5e5e072b17e0d5d9312a0826cb85304a17bb51330d9800936c4a 

TripleFantasy\24b7e7553b1aa241997e28775d3952c4cb885056c4606cbed9b450320b601255