Showing posts with label Uroburos. Show all posts
Showing posts with label Uroburos. Show all posts

Friday, 13 March 2015

Kaspersky Would Have Hesitation About Revealing Cyber Attacks


The Russian anti-virus firm Kaspersky Lab would have hesitation about revealing two cyber attacks attributed to the Russian regime, as were sources within the company across Reuters have announced.According to founder Eugene Kaspersky, the company never asked by government to refrain from investigating a cyber attack.

The researchers would not be guided by the political interests of a country. Yet, say several current and former employees of the company Kaspersky Lab about publishing at least two alleged cyber attacks has hesitated. Kaspersky Lab as published last year under paying customers a report on a sophisticated espionage campaign that had discovered it.

The report, however, was only five months later publicly disclosed once had a British defense company about the espionage campaign published . According to the British BAE Systems were likely to be a campaign of the Russian government, which mainly computers in the Ukraine were infected. Eugene Kaspersky, however, denied that political motives played a role. "We were late," as he announced. According to the virus fighter is not possible to win everything.

Discussion

In 2013, Kaspersky Lab researchers discovered another espionage campaign called Red October , by Russian-speaking programmers would be created and focused on governmental and diplomatic organizations in Europe, Central Asia and North America. Only after a heated internal debate virus fighter still decided to publish a report on the operation. According to several current and former employees of Kaspersky Lab, who wished to remain anonymous, it was probably an operation of a Russian military intelligence.

Update

Kaspersky Lab said in a statement that the company has never doubted about publishing studies because of political reasons. "We have no political ties," said the virus fighter, who noted further with various countries and international investigative agencies to work together. In case an attack campaign is discovered the anti-virus company follows a special procedure whereby the investigative services are warned in the countries concerned, as well as partners and customers before the investigation appears.

Sunday, 16 March 2014

Connection Link Between Turla, Uroburos & Agent.BTZ

Experts from G-Data and BAE Systems recently released information about a persistent cyber espionage operation codenamed Turla (also referred to as Snake or Uroburos). Further to this, Kaspersky Lab's research and analysis team have now found an unexpected connection between Turla and an existing piece of malware known as Agent.BTZ.

The company "Kaspersky Lab" program analysed the relationship Turla, which is also known as Snake or Uroburos, with other known kibershpionami. After the release of reports on this threat a number of companies working in the field of IT security, many experts in the field were made ​​with the conclusion of the relationship Turla and other acclaimed at the time of malicious software - so-called Agent.BTZ.


In 2008 worm infected Agent.BTZ LANs Central Command of U.S. forces in the Middle East and was named the worst event in the history of U.S. military computer. According to some sources, the Pentagon has spent nearly 14 months to eliminate the effects of infection networks sun, and as a result of this incident provided the impetus for the creation of the U.S. Cyber ​​Command, U.S. Army internal divisions.

A malicious program supposedly created in 2007, contains the functionality to search and send valuable information from the infected computer to a remote control center. "Kaspersky Lab" first encountered the aforementioned malicious programs for Turla in March 2013 during an investigation of another incident involving the use of highly complex rootkit.


Map of infections caused by different modifications of “Agent.btz” in 2011-2013


Then in the course of the investigation specialists "Kaspersky Lab" found interesting facts indicating that apparently served as a model Agent.BTZ worm creators most technically advanced cyber weapons - Red October, Turla, as well as Flame and Gauss. Careful analysis showed that the creators of Red October, obviously knew about the functionality of the worm Agent.BTZ. Written by them in 2010-2011 module USB Stealer inter alia seeking and copies with USB-media archives with information accumulated worm and its log files. Turla, in turn, uses the same as Agent.BTZ, file names for logging their own actions, and the exact same key for encryption.



Finally, the program adheres Flame worm similar to file extensions and also stores the stolen information on USB-devices. Taking this into account, it can be argued that the creators of the aforementioned cyber-espionage campaigns thoroughly studied worm Agent.BTZ work and adopted the experience to develop their own malicious programs with similar goals. However, this makes it impossible to talk about a direct connection between the two groups of intruders.

 "Based on the data that we have, it is impossible to make such a statement. All information used by the developers of these malicious programs, was opened to the public for at least the time of creation and Flame Red October . were also not a secret and the names of files in which information accumulated worm from infected systems. Finally, the encryption key, which is identical in cases and Turla Agent.BTZ, was launched back in 2008. unknown, since when it has been applied in Turla. On the one hand, we found it in samples that were created in this and last year, on the other hand, there is information that Turla creation began in 2006, before the sample was found Agent.BTZ. Consequently, the question of communication development of cyber weapons is still open, "- concluded Aleks, the main anti-virus expert" Kaspersky Lab ".

Detail from Kaspersky Report is available: Here

Sunday, 9 March 2014

Hackers attacked government computer in the U.S. and E.U, said the attack came from Russia



Detailed Report


Hundreds of government computers in Europe and the USA in silence infected sophisticated malicious applications. According to Reuters, it is one of the most comprehensive programs for cyber espionage, which has so far been discovered. Some security analysts and Western intelligence agencies have concluded that this so-called spyware, known as Turla is the work of the Russian government, and that is related to software used for massive hacking U.S. military, which was unveiled in 2008.

Hackers using Spyware Turla building in the contested networks "focal points", thanks to which the computer searches for data, save your information and, where necessary data to send to their servers. 

"It's sophisticated malware, which is associated with another Russian malicious program. It uses encryption and targeting Western governments.Shows traces of Russian work, "said Jim Lewis, who previously worked in the diplomatic service for the U.S. State Department, and now works at the Center for Strategic and International Studies in Washington.


They watch them in years

Security experts warn that can not be proven truly Russian origin.
Experts from established security companies monitor turly several years. Symantec estimates that malware Turla with relatives Trojan Horse to infect Agent.BTZ thousand networks. Symantec has not communicated the names of the victims, said only that it is mostly a government computer.
Anti-virus firm F-Secure with truly met for the first time last year, when examined contested organization. "Although it looks like the Russians, there is no way to determine with certainty," said Mikko Hypponen of F-Secure. Nor did he mention the names affected.
Reuters addressed this matter in several European governments, many of them, but the malware Turla refused to comment. Government sources from the Czech Republic, Estonia, Poland and Romania, however, indicated that this malicious program were not affected immediately.

The threat of a snake


On the question of public threats in connection with this program came this week when the less well known German company G Data Antivirus published a report on the virus identified as Uroburos.
The name is derived from part of the program code and the ancient symbol that shows a snake or dragon devouring its own tail.
British company BAE Systems Applied Intelligence, formerly known as Detica, which is a cybernetic arm of a prominent British defense contractor, has issued its own report on this malware, which it describes as "a snake". The sheer sophistication of the software goes much further than what we have encountered so far, says a British document without mentioning one's responsibility for the attack.
Detail from BAE System Report is available: Here
Více na: http://e-svet.e15.cz/internet/hackeri-napadli-vladni-pocitace-v-usa-i-eu-utok-pry-prisel-z-ruska-1067660#utm_medium=selfpromo&utm_source=e15&utm_campaign=copylinkVíce na: http://e-svet.e15.cz/internet/hackeri-napadli-vladni-pocitace-v-usa-i-eu-utok-pry-prisel-z-ruska-1067660#utm_medium=selfpromo&utm_source=e15&utm_campaign=copylink

Thursday, 6 March 2014

G Data found Russian cyber weapon - rootkit Uroburos

Uroburos RootKit Malware
Because of its complexity, Uroburos impossible to detect or destroy conventional methods 

Ouroboros - a classic antique symbol of the serpent devouring its own continuously tail. Like taking off her example, «Uroburos» - a new kind of malware which tends to absorb the network - in this case, perhaps as part of a spyware plan.





According to experts, the rootkit that steals confidential information used by hackers since 2011.

The specialists of the German company G Data found a new malicious program designed to steal confidential information. According to the data of professionals engaged in the development of malware Russian special services. Rootkit Uroburos got its name from a mythical dragon, as well as the sequence of characters within the code of the malware: Ur0bUr () sGotyOu #.

Uroburos steals files from infected computers and intercepts network traffic. A malicious program designed to work in P2P mode to establish communication between the infected systems. This feature allows you to remotely access the same computer with an Internet connection in order to control other PCs on a LAN.

It is interesting that in order to hide their activities rootkit uses two virtual file system - NTFS and FAT, which locally are on the infected machine. These file systems could allow attackers to be stored on the victim's PC party tools, tools for post-operation, temporary files, and binary output. Access to virtual file system can be accessed through the device: Device \ RawDisk1 and Device \ RawDisk2, as well as CDs \ \. \ Hd1 and \ \. \ Hd2.

G Data experts say: "The creation of such structures as Uroburos requires huge investments. The development team of this malware, obviously consists of highly qualified IT-specialists. Such a conclusion can be drawn by analyzing the structure and modern design of the rootkit. We believe that the developers are also improved versions Uroburos, which will appear in the future. "

Finding certain specifications (file name, encryption keys, behavior, etc.), representatives of the G Data suggested that a group of authors Uroburos intruders, which in 2008 carried out an attack on the computer systems of the U.S. with the help of malware Agent.BTZ.

Experts say that before installing the system on its victims Uroburos checks for the presence of Agent.BTZ. If present, the new rootkit remains inactive. Evidence that the creation of Russian Uroburos can stand is that in the code of the malware is present Cyrillic.

Recall that after the attack on the system Agent.BTZ United States banned the use of American military USB-drives and other removable media. While it was assumed that infection of the Ministry of Defence was through USB-drive.

According to statements made by G Data, the authors aim Uroburos are large enterprises, the state intelligence agencies and other organizations. Presumably, the rootkit has been used for three years, as the most long-standing version of the program were written in 2011.

Technical details SHA256: BF1CFC65B78F5222D35DC3BD2F0A87C9798BCE5A48348649DD271CE395656341 MD5: 320F4E6EE421C1616BD058E73CFEA282 Filesize: 210944

Detail from G Data Report is available: Here