Showing posts with label NSA Spying Tool. Show all posts
Showing posts with label NSA Spying Tool. Show all posts

Tuesday, 28 July 2015

Stop Using NSA Collected Phone Records


US intelligence NSA will stop on November 29 with the use of the telephone data collected in recent years through mass surveillance in the United States. Just recently, the US Senate Section 215 of the Patriot Act not to renew . Through this legislation, the NSA was authorized to store massive call data of American citizens and preserve.

In a statement, the Director of National Intelligence now announced that data from November 29 will no longer be used.However, technical staff of the NSA will have three months long to access the data. This would be necessary in order of data which may be collected to verify the new USA under Freedom legislation.

In addition, the NSA would be legally bound to keep the bulk of the collected telephone records, until civil proceedings are related to the eavesdropping program completed or that the court states that the NSA's data no longer need to keep.According to the NSA Data is maintained only because of the civil proceedings and will not be used for other purposes. The data will eventually be destroyed, so the Secret Service says.

Thursday, 19 February 2015

Espionage Firmware In Hard Disks To Detect Barely


The malicious firmware that a group of cyber spies computers permanent commitment to continue spying is hard to detect and extremely difficult to remove. "It is extremely difficult to detect. From the software level, it is impossible," said Vitaly Kamluk, researcher at Kaspersky Lab.

The Russian anti-virus company revealed this week the existence of the spy group who developed all kinds of highly advanced malware. One subset fell on, namely, the ability to infect the firmware of the various popular brands hard disks.Therefore, the malware remains hidden and active, even though the hard disk is formatted or reinstall the operating system.The code ensures that the attackers can create an invisible storage on the hard disk.

"This is unique and the first time we have seen this level of complexity of a sophisticated attacker," said security researcher.However, the module could have been used rarely. "Only a very select list of victims have received this. This is one of the most special modules that I've seen because it is so valuable. They do not want that to be known," Kamluk let know this week during a conference, so reports Threat Mail .

"It is a valuable plug-in that is used only in specific cases for very important people." To detect the malicious firmware should the PC be disassembled and made a dump of the firmware. "And we think that only a few people in the world are able to analyze the malicious code within the firmware, compare and discover," says Kamluk.

According to the researcher takes years to write firmware. But the espionage group would not use vulnerability, but only ride on the way manufacturers roll out firmware updates. "They left the door open and stood possible longtime open. The trick is that you have the full description, the full reference of the current firmware should have and how it works."

Kamluk speculates that the attackers may have access to internal manuals and documentation of the respective suppliers.Manuals that may be stolen by an insider or through another malware attack. "They do not abuse a leak in the code. It is a design flaw." Because of the proprietary communication protocols and algorithms took investigators months before they learned how the malware exactly worked. A truly infected firmware researchers have not been able to find.

Tuesday, 17 February 2015

Fanny Malware: "11.000 Computers Precursor Stuxnet Infected"


Still 11,000 computers worldwide are infected with a sophisticated worm that was developed in 2008 and is considered the forerunner of the infamous Stuxnet worm. The Fanny worm was yesterday already revealed by Kaspersky Lab, and today there are more details disclosed.

The worm used two zero-day vulnerabilities in Windows to spread via USB sticks. Connecting an infected USB drive on a Windows computer, even if it is disabled Autorun, was enough to get infected. The worm the LNK vulnerability used in this case that later was used by the Stuxnet worm. The second vulnerability used Fanny made sure that the malware had administrator rights. The vulnerabilities were patched by Microsoft in 2009 and 2010.

Although Stuxnet known as the first malware that used the LNK vulnerability, a Trojan horse in 2010 it was discovered that already spread through the leak. It was the Zlob Trojan, part of a large family of malware. However, no one paid attention given to this instance of malware in the anti-virus industry. The makers of Fanny used a common method to load the malware while starting Windows, making the creation as Zlob was detected.


Indeed, it was a registry value created to start automatically. According to researchers, the malware writers have done this deliberately, so as automatic control of anti-virus companies and researchers to lead the garden. That would detect the malware and namely because of the widely used starting technique, pay no further attention. Therefore, the deeper operation and functionality of Fanny remained hidden.

The main functionality of the worm is in the mapping of systems and networks that are not connected to the Internet. Where Stuxnet worked only on specific systems, Fanny infected all Windows computers where it landed. Not only could easily infect the worm computers. Once USB drives were connected to an infected computer, which also became infected and could spread the worm further.

The researchers knew the Command & Control server that the attackers used to control infected computers take over. In total still made 11,200 unique IP addresses connecting to this server. Sixty percent of it comes from Pakistan, followed by Indonesia (16%) and Vietnam (14%). Whether Pakistan was the original target of Fanny is unknown. The situation may be different when the worm was used between 2008 and 2010. However, the researchers note that the group that Fanny has also developed other malware made that it had provided to Pakistan.

However, the real targets of Fanny is unknown, say the researchers. Possible that the worm is used to select potential targets for Stuxnet. Another remarkable fact is the large number of infections in Pakistan. The use of USB drives is indeed a slow diffusion method. Therefore, the researchers also think that the first infections occurred in Pakistan.

Monday, 16 February 2015

Espionage Group Reprograms Firmware Drives


Researchers have identified a group of highly sophisticated cyber spies discovered active as possible for 20 years and the same zero-day vulnerabilities used that eventually were used by the creators of the Stuxnetworm. Also developed this super spies malware to reprogram the firmware from popular brands hard drives, which the researchers have never seen before.

The spies by the Russian anti-virus firm Kaspersky Lab called the "Equation Group". The first domains which date the group used to control infected computers in 2001, while the first malware copies were made ​​in 2002. Other areas that the group used to control the infected computers were already registered in 1996. This could possibly mean that the spies are active for almost two decades.

Equation Group developed several malware platforms that are more advanced than the last year revealed Regin malware.Thus, among other things, developed a computer worm that gathered all kinds of information about targets in Asia and the Middle East in 2008. This worm, named "Fanny", used two zero-day vulnerabilities. Vulnerabilities that were eventually used for Stuxnet. According to Kaspersky, this means that the Equation Group also developed Stuxnet or worked with the developers of the worm.

The Fanny worm probably had as goal to bring networks card that were not connected to the Internet. The malware was distributed through USB sticks. On infected USB sticks Fanny made a hidden storage area to which the information about infected systems preserved. Also intercepted the group of physical goods and replaced by versions with Trojans.

One example involved the participants in a scientific conference in Houston to return some of the participants had received a copy of the conference proceedings on CD-ROM, which was then used to install the Double Fantasy implant of the group on the machine the target. The exact manner in which these CDs were intercepted is unknown.


In addition to USB sticks and CDs espionage group also used a web-based exploits. Thus, among other leaks in Java and Internet Explorer to infect victims. There were also unknown exploits, possibly zero days, against the Firefox 17 version of Tor Browser deployed. Tor Browser uses a custom Firefox version that was attacked by the Equation Group.

Since 2001, the cyber spies would have infected thousands of computers in a variety of sectors including government, telecommunications, energy, nanotechnology, financial institutions, oil and gas and aviation. Most victims are in Iran and Russia. In total, Kaspersky Lab counted 500 victims, but the real number is probably much higher, because the malware has a self-destruct mechanism. It is therefore possible that there may be tens of thousands of computers were infected.

What really makes the group stand out is the ability to reprogram the firmware of all branded hard drives. The researchers were able to secure two modules that were used to reprogram the firmware. Through this method, the attackers could install it again and survive reformatting of the hard drive. In addition, could be created an invisible storage on the hard disk. However, the module would be used on a very limited scale, probably at the most valuable targets.

"Another dangerous consequence is that it is impossible to scan the firmware when the hard disk is once infected with this malicious payload simply:. For most hard disks, there are functions to write the firmware portion of the hardware, but there No functions to read it back. This means that we are virtually blind and can not detect hard drives that have been infected with this malware, "warns Costin Raiu, research director at Kaspersky Lab.

The ability to create an invisible and persistent area in the hard disk is used to store collected information that can be later retrieved by the attackers. In some cases it may also help to crack the encryption of the group: "Given the fact that their Gray Fish implant is activated immediately from the startup of the system, they have the ability to intercept the encryption password and store it in secret area, "explains Raiu.


Although all detected malware worked for Windows, there are also found traces indicating Mac OS X malware. One of the domains, which was used for the control of the infected computers received a variety of compounds of Chinese Mac OS X computers. Therefore, it is assumed that there is at least one of the platforms is also a malware-Mac version. It would also have the group the ability to infect iPhones.

Despite the level of the malware writers have they still left their mark. So were encountered several keywords in the studied modules, such DESERT WINTER, STRAIT SHOOTER and GROK. This last term appeared in NSA documents published by Der Spiegel. Kaspersky Lab discovered the Equation Group during the investigation into the Regin malware. This malware was the NSA by the virus fighter attributed . Additionally, labels the group malware as "implants", a term earlier in the NSA documents appeared Snowden. In addition, the development of Stuxnet is attributed to the NSA.

The next few days will be the Russian anti-virus company publish more details about the group and applied method.Meanwhile, there is already a document published online ( pdf ) with directions and details so that researchers and administrators can check machinery in place within their organization or environment. "The more we investigate this kind of cyber-espionage operations, the more we realize how little we know about it. Together we can uncover these practices and safer (cyber) world works," said the researchers.

Below are the MD5 with Sample Names & VT Checked:

_SD_IP_CF_dll\866f94f30d9865995494a0f7228329c26149eef2960500b2177c736c5c846035

Disk from Houston\868eb363f32beacd8bcdc7a114e020d4cfe67913a15275f4e7493d87db643ff2 

DoubleFantasy\1e55abb94951cedc548fd8d67bd1b50476808f1d0ae72f9842181761ff92f83f 

EquationDrug\1b0eb1a1591140175d1ac111a98c89472b196599baf13ef67ee7f63d0052b00e 

EquationLaser\9412a66bc81f51a1fa916ac47c77e02ac1a7c9dff543233e
d70aa265ef6a1e76 

Fanny\003315b0aea2fcb9f77d29223dd8947d0e6792b3a0227e054be8eb2a11f443d9 

GrayFish\df4bbd02dcd8b8b9e1374c6f71f2e2da8518d39337b35983874266e8fff055e1 
9B1CA66AAB784DC5F1DFE635D8F8A904
GROK\441f2a6775621af8c5d1ead7082e9573ad878bc90675ed55f86abfc8a9e8cc6f 

nls_933w_dll\83d14ce2dcfc852791d20cd78066ba5a2b39eb503e12e33f2ef0b1a46c68de73

TripleFantasy\112d70111fef5e5e072b17e0d5d9312a0826cb85304a17bb51330d9800936c4a 

TripleFantasy\24b7e7553b1aa241997e28775d3952c4cb885056c4606cbed9b450320b601255