Showing posts with label Turla. Show all posts
Showing posts with label Turla. Show all posts

Friday, 13 March 2015

Kaspersky Would Have Hesitation About Revealing Cyber Attacks


The Russian anti-virus firm Kaspersky Lab would have hesitation about revealing two cyber attacks attributed to the Russian regime, as were sources within the company across Reuters have announced.According to founder Eugene Kaspersky, the company never asked by government to refrain from investigating a cyber attack.

The researchers would not be guided by the political interests of a country. Yet, say several current and former employees of the company Kaspersky Lab about publishing at least two alleged cyber attacks has hesitated. Kaspersky Lab as published last year under paying customers a report on a sophisticated espionage campaign that had discovered it.

The report, however, was only five months later publicly disclosed once had a British defense company about the espionage campaign published . According to the British BAE Systems were likely to be a campaign of the Russian government, which mainly computers in the Ukraine were infected. Eugene Kaspersky, however, denied that political motives played a role. "We were late," as he announced. According to the virus fighter is not possible to win everything.

Discussion

In 2013, Kaspersky Lab researchers discovered another espionage campaign called Red October , by Russian-speaking programmers would be created and focused on governmental and diplomatic organizations in Europe, Central Asia and North America. Only after a heated internal debate virus fighter still decided to publish a report on the operation. According to several current and former employees of Kaspersky Lab, who wished to remain anonymous, it was probably an operation of a Russian military intelligence.

Update

Kaspersky Lab said in a statement that the company has never doubted about publishing studies because of political reasons. "We have no political ties," said the virus fighter, who noted further with various countries and international investigative agencies to work together. In case an attack campaign is discovered the anti-virus company follows a special procedure whereby the investigative services are warned in the countries concerned, as well as partners and customers before the investigation appears.

Saturday, 13 December 2014

Linux espionage virus first made possible for Solaris


This week researchers announced that they had a spy virus for Linux discovered , but the Finnish anti-virus firm F-Secure says that the malware is possible first developed for Solaris. The Turla backdoor, also known as Snake or Urburos, was known only deployed against Windows.

Now Kaspersky Lab reported that it had discovered a Linux variant. The malware, according to researchers, a number of interesting features, with the ability to sniff the network interface is most striking. The malware can namely the Command & Control server, which controls the infected machine, adjust according to the network traffic. The attackers only need to send a special packet to the machine to activate the malware.

Furthermore, the malware acts as a normal "remote access trojan" (RAT) and allows attackers to download and upload files and execute commands. Researchers at F-Secure discovered in the code some remarkable system paths. It went to directories that are normally used in a Solaris environment.

Researchers have therefore questioned whether the backdoor is not first developed to attack Solaris servers. The code rates can be easily adjusted for other platforms. "It is no surprise if we malware the coming days also find on Solaris servers," says Jarkko Palviainen F-Secure.

Tuesday, 9 December 2014

"Turla Linux Malware" - Researchers discover espionage virus for Linux


Researchers from the Russian anti-virus firm Kaspersky Lab have discovered a spy virus for Linux that may go unnoticed for years, although for the latter is no proof yet. It is a variant of the Turla malware, also known as Snake or Urburos which all other known specimens have been developed only for Windows.

The researchers knew that there are Linux versions of Turla existed but had never yet found in the "wild" so far. Turla according to Kaspersky Lab is one of the most sophisticated espionage campaigns ever discovered . Among others, the Belgian Ministry of Foreign Affairs would have become the victim of the campaign. The now discovered Turla variant supports Linux so that there can be infected with more systems attacked organizations.

"We suspect that this part years was active in an organization attacked, but have no concrete evidence to prove it," said Costin Raiu of Kaspersky Lab. Through the malware an attacker can communicate with infected systems and execute arbitrary code. Thereby Turla do not need elevated privileges. Also, the malware can not be found via netstat, a tool that system administrators use to get an overview of open network connections.

"It uses techniques that do not require root access, so it can move freely on the system of a victim. Even if it's a regular limited user launches can continue to intercept the incoming packets and execute commands on the system," says Raiu . He notes that the Linux malware especially in other public source code is based, in which the attackers a number of things have been added. How the malware spreads exactly is not reported.

Sunday, 16 March 2014

Connection Link Between Turla, Uroburos & Agent.BTZ

Experts from G-Data and BAE Systems recently released information about a persistent cyber espionage operation codenamed Turla (also referred to as Snake or Uroburos). Further to this, Kaspersky Lab's research and analysis team have now found an unexpected connection between Turla and an existing piece of malware known as Agent.BTZ.

The company "Kaspersky Lab" program analysed the relationship Turla, which is also known as Snake or Uroburos, with other known kibershpionami. After the release of reports on this threat a number of companies working in the field of IT security, many experts in the field were made ​​with the conclusion of the relationship Turla and other acclaimed at the time of malicious software - so-called Agent.BTZ.


In 2008 worm infected Agent.BTZ LANs Central Command of U.S. forces in the Middle East and was named the worst event in the history of U.S. military computer. According to some sources, the Pentagon has spent nearly 14 months to eliminate the effects of infection networks sun, and as a result of this incident provided the impetus for the creation of the U.S. Cyber ​​Command, U.S. Army internal divisions.

A malicious program supposedly created in 2007, contains the functionality to search and send valuable information from the infected computer to a remote control center. "Kaspersky Lab" first encountered the aforementioned malicious programs for Turla in March 2013 during an investigation of another incident involving the use of highly complex rootkit.


Map of infections caused by different modifications of “Agent.btz” in 2011-2013


Then in the course of the investigation specialists "Kaspersky Lab" found interesting facts indicating that apparently served as a model Agent.BTZ worm creators most technically advanced cyber weapons - Red October, Turla, as well as Flame and Gauss. Careful analysis showed that the creators of Red October, obviously knew about the functionality of the worm Agent.BTZ. Written by them in 2010-2011 module USB Stealer inter alia seeking and copies with USB-media archives with information accumulated worm and its log files. Turla, in turn, uses the same as Agent.BTZ, file names for logging their own actions, and the exact same key for encryption.



Finally, the program adheres Flame worm similar to file extensions and also stores the stolen information on USB-devices. Taking this into account, it can be argued that the creators of the aforementioned cyber-espionage campaigns thoroughly studied worm Agent.BTZ work and adopted the experience to develop their own malicious programs with similar goals. However, this makes it impossible to talk about a direct connection between the two groups of intruders.

 "Based on the data that we have, it is impossible to make such a statement. All information used by the developers of these malicious programs, was opened to the public for at least the time of creation and Flame Red October . were also not a secret and the names of files in which information accumulated worm from infected systems. Finally, the encryption key, which is identical in cases and Turla Agent.BTZ, was launched back in 2008. unknown, since when it has been applied in Turla. On the one hand, we found it in samples that were created in this and last year, on the other hand, there is information that Turla creation began in 2006, before the sample was found Agent.BTZ. Consequently, the question of communication development of cyber weapons is still open, "- concluded Aleks, the main anti-virus expert" Kaspersky Lab ".

Detail from Kaspersky Report is available: Here

Sunday, 9 March 2014

Hackers attacked government computer in the U.S. and E.U, said the attack came from Russia



Detailed Report


Hundreds of government computers in Europe and the USA in silence infected sophisticated malicious applications. According to Reuters, it is one of the most comprehensive programs for cyber espionage, which has so far been discovered. Some security analysts and Western intelligence agencies have concluded that this so-called spyware, known as Turla is the work of the Russian government, and that is related to software used for massive hacking U.S. military, which was unveiled in 2008.

Hackers using Spyware Turla building in the contested networks "focal points", thanks to which the computer searches for data, save your information and, where necessary data to send to their servers. 

"It's sophisticated malware, which is associated with another Russian malicious program. It uses encryption and targeting Western governments.Shows traces of Russian work, "said Jim Lewis, who previously worked in the diplomatic service for the U.S. State Department, and now works at the Center for Strategic and International Studies in Washington.


They watch them in years

Security experts warn that can not be proven truly Russian origin.
Experts from established security companies monitor turly several years. Symantec estimates that malware Turla with relatives Trojan Horse to infect Agent.BTZ thousand networks. Symantec has not communicated the names of the victims, said only that it is mostly a government computer.
Anti-virus firm F-Secure with truly met for the first time last year, when examined contested organization. "Although it looks like the Russians, there is no way to determine with certainty," said Mikko Hypponen of F-Secure. Nor did he mention the names affected.
Reuters addressed this matter in several European governments, many of them, but the malware Turla refused to comment. Government sources from the Czech Republic, Estonia, Poland and Romania, however, indicated that this malicious program were not affected immediately.

The threat of a snake


On the question of public threats in connection with this program came this week when the less well known German company G Data Antivirus published a report on the virus identified as Uroburos.
The name is derived from part of the program code and the ancient symbol that shows a snake or dragon devouring its own tail.
British company BAE Systems Applied Intelligence, formerly known as Detica, which is a cybernetic arm of a prominent British defense contractor, has issued its own report on this malware, which it describes as "a snake". The sheer sophistication of the software goes much further than what we have encountered so far, says a British document without mentioning one's responsibility for the attack.
Detail from BAE System Report is available: Here
Více na: http://e-svet.e15.cz/internet/hackeri-napadli-vladni-pocitace-v-usa-i-eu-utok-pry-prisel-z-ruska-1067660#utm_medium=selfpromo&utm_source=e15&utm_campaign=copylinkVíce na: http://e-svet.e15.cz/internet/hackeri-napadli-vladni-pocitace-v-usa-i-eu-utok-pry-prisel-z-ruska-1067660#utm_medium=selfpromo&utm_source=e15&utm_campaign=copylink