Showing posts with label espionage. Show all posts
Showing posts with label espionage. Show all posts

Wednesday, October 23, 2019

Russian Hacking Group 'Cozy Bear' has Been Using Reddit, Other Social Platforms Starting in 2013

Cyber-espionage operations from Cozy Bear, a threat actor believed to work for the Russian government, continued undetected for the past years by using malware families previously unknown to security researchers.

Relying on stealthy communication techniques between infected systems and the command and control (C2) servers, the group managed to keep their activity under the radar for a long time.

Cyber-espionage campaigns that likely started in 2013, collectively named "Operation Ghost," have been attributed to this group, and continued through 2019.

Friday, December 30, 2016

The Coming Cyber War #23

Cyber Warfare:

A US Air Force EC-130H has been attacking the Islamic State in Syria.

The USMC is looking for hackers, or as it has been put, "a few good nerds" for its cyber warfare section.

The US government is sorting out who is in charge of the cyber domain.

Mirai bot nets are now using TOR to hide its control network.

North Korea has denied launching a cyber attack on South Korea.

 OSCE, the group observing the 'cease fire' (or lack thereof) in Eastern Ukraine has been hit with a major cyber attack.

Russian hackers tracked Ukrainian artillery units through android malware.

Was the Russian hacking of the election system the first 'Russo-American cyberwar?'

How to deter Russian (and others) from attempting the cyber attack again.

A Turkish hacker is giving out prizes for conducting DDoS attacks.

Ukraine had another cyber attack on its power grid.

Ukraine has been hit by 3,500 cyber attacks and considers itself in a cyber war with Russia.

Cyber Security:

Airline entertainment system hacks are back.

This is how cellebrite works.

DARPA has given Raytheon a contract to find ways to protect the power infrastructure.

The US FDIC has released guidelines for medical software and hardware cyber security.

Google has released a tool to look for cyrpto bugs that can be exploited.

KillDisk malware has become ransomware.

McAffee has a security bug that has been unaddressed for months.

Netgear Wifi routers are VERY insecure: stop using!  Netgear has a beta patch.

Nevada accidentally revealed the personal details of all those applying for medical cannabis dispensary licenses.

PwC is threatening to sue security researchers.

North Korea's version of Android takes a screen shot every time an app is opened.

Numerous twitter accounts have been hacked by OurMine, a white hat hacker group.

Ubuntu has found customers are terrible at updating their IoT devices.

The UN has warned the threat of cyber attacks on nuclear power plants is rising.

A US think tank wants security built into all IoT devices, but how may be ... problematic.

The US DOT wants to mandate vehicle to vehicle communication: this is a bad idea, IMO.

Zero Day exploits for two diffferent linux distros' desktops have appeared.

Cyber Espionage:

ADUPS Malware infects new Barnes & Noble tablets, reporting data back to Shanghai.

The NSA's best are supposedly leaving in droves due to Trump's election.

Is the NSA pushing to redefine the interpretation of the 4th amendment?

The British 'Snooper's Charter' may give the government permission to lie in court.

The British Snooper's Charter took a blow in the EU court system, but will it matter with Brexit?

The Chinese have reaffirmed their commitment to cyber surveillance.

The EFF is monitoring the surveillance tech being used at the standing rock protest.

The FBI is probing a hack of the FDIC by the Chinese military.

There is a new search engine just for checking if news is fake.

The Russians made attempts to influence the US Presidential election. Trump denies this. Trump even took swipes at the intel agencies.  The intel agencies are feuding with the Republicans over the hacks. McCain states the facts are there. Obama has ordered a review to be done before he leaves office and is VERY sure Russia is behind the attacks while stating Trump won legitimately.. The review will go beyond the election.  Republicans in Congress disagree with Trump and want a probe. The top management of the intel agencies have not endorsed the report.  The FBI does now agree about the Russians.  Some are saying Putin is trying to 'hack' the confidence in the US system. The Germans are stated the Russians are just getting started. Russia says the claims it attempted to influence the election are just infighting between the two sides in US politics. A piece of legislation moving through congress is going to mandate countermeasures. A report claims Putin personally directed the attacks.

More information on the attack by the Russians on the US Presidential election  The election agency was hacked. Why there is a debate about the hack in the US at all?  The Russians are stating to prove they did the hack or shut up.  Obama is threatening to counterattack Russia.  The CIA head is advising against retaliation.  The Russian fake news bots are the same stuff done in Ukraine, but amped up for the globe.

The American retaliation is to ban several russians from the US, release info on Russian cyber activities and more.  Russia has vowed to attack in return.

A report released by Congress claims Snowden was in contact with Russian intelligence in 2013.

The Russians are trying to unlock the Iphone of the assassin of the Russian ambassador in Turkey.

Twitter is blocking intel agencies' access to its data.

The US Congress has concluded encryption backdoors won't work.

A US Court is demanding information on the collaboration between ATT and the police to spy.

The US House is urging the passage of a bill restricting and regulating the use of Stingray and other cell phone interception devices by the police.

What the US intelligence agencies think of Trump.

The US NIST is seeking help to protect computers from hacking by the up and coming quantum computers.

Did a typo lead to the Podesta email hack?

Cyber Crime:

In a bizarre twist on cyber "crime," Arkansas police are seeking the data from an Amazon Echo to help solve a murder.

Chinese stock traders have been arrested on suspicion of profiting based on hacked insider information.

The FBI has started arresting users of DDoS bot networks.

Here's a guide to hacks in 2016.

Hackers defaced Thai websites over restrictive internet laws.

IBM found most businesses pay when hit by ransomware.

The Leet botnet is bigger than Mirai.

New malicious advertising (malware hiding as advertising) is infecting users' routers rather than their desktop or tablets.

Malware has been found in 26 low cost android devices; resellers are suspected to be adding it.

A Nigerian man has been arrested and charged with hacking the Los Angeles County email system.

A new website found has all the NSA exploits for sale.

The Popcorn Time malware will give you the keys to get rid of it IF you spread it to your friends.  

Quest Diagnostics was hacked and 34,000 customers' data was exposed.

Ransomware infected an LG smart tv.

A Russian cybergang may have scammed millions through the use of fake websites and clicks.

A Swedish hacker posted the specs for a device to hack Mac passwords.

SWIFT was hacked again.

Twitter is cooperating with a journalist who is hunting for someone who sent him a video that induced a seizure.  

Uber is being sued by a former officer in the company allegedly stating employees stalked ex gf/bfs, celebrities and politicians using the data from the app.  Uber claims it has safeguards against that.

Occupied Ukraine has become a hot spot for cybercriminals.

A US citizen surrendered to face charges for a cyber attack.

The US Government is targeting the torrent sites like Pirate's Bay.

Yahoo has reported 1 billion of its accounts have been compromised.  Verizon is considering killing its acquisition of Yahoo.  The database of user information may have sold for as little as $300k.

 META:

The US attempted to and failed to get a change in a treaty to allow for cyber weapons export in a treaty.

Friday, December 09, 2016

Coming Cyber War #22

Cyber Warfare:

The US Air Force's future war network just doubled in price.

How the use of enlisted personnel in cyberwarfare is helping in the US Army.

The US Army is building its electronic/cyber warfare teams.

The first ever electronic warfare strategy is headed for the US SecDef's desk.

A cyber attack on the British using the Mirai bot net left 100,000 homes without internet.

A device designed to destroy computers by plugging into the USB port is available online for $50.

The Japanese Ministry of Defense was hit with a serious cyber attack.

You can now rent a Mirai botnet of 400,000.

The Philippines is investing in cyber defenses.

The Russians are claiming foreign spies are attacking its banks.

Saudi Arabia has been cyber attacked, supposedly by Iran.

Cyber Security:

AirDroid can be hacked.

More than 1 million Android devices have been compromised by Googligan malware.

The US DOD is asking white hat hackers to take a crack at all its websites.

President-elect Trump's nominee for SecDef is advocating using analog systems to avoid hacking.

Dronejacking might become a threat.

How a hacker took over Tel Aviv's public wifi system. 

Insurance companies are grappling with cyber attacks that cause physical damage.

The IoT needs a lot more security.

A malicious video link can freeze IOS devices.  

San Francisco's Muni was hacked and gave free rides. 

Security flaws have been found in implantable medical devices.

Security researchers found a way to turn speakers into microphones.

The new Stegano exploit is worrisome.

The Wordpress autoupdate server had a flaw that allowed anyone to access any website in the world (using Wordpress) to do anything.

Cyber Espionage:


Tech firms in Britain are trying to frustrate compliance with the new onerous and 1984ish surveillance law there.

That British law apparently has an exemption for politicians in Parliament: you cannot snoop on them!

That same British law put in place a required encryotion backdoor for the police.

Many inexpensive Android phones have been found to have a secret Trojan built into their firmware updating software.  This provides data back to servers in China.  Originally, it was just Shanghai Adups Technology's system, but now also includes the Ragentek Group.

The FBI hacked over 8,000 computers in 120 countries with one warrant. 

The Feds can hack you anywhere now, legally.

Geofeedia laid off half its staff after losing its feeds from Twitter and Facebook.

Google has been sending notices to journalists (and others) of state sponsored hacking attempts on their accounts.

A journalist tied to Anonymous has been released from jail. 

Reuters developed a bot to spot fake news.

Russian propogandists helped make the fake news epidemic this last presidential cycle much worse.  Some dispute that.

The Sony hack may have encouraged Russian hackers according to one California Congressman.

Snowden can be asked to testify in the German probe of the NSA espionage, but cannot use Norway for safe passage.

Cyber Crime:

 Australia found their biggest software pirates were also their best purchasers of software.

 The Avalanche botnet has been taken down.

The Daily Motion was hacked, exposing millions of user accounts.

More than a dozen European countries have seen their ATMs hacked.

Hackers stole $131 million from the Russian Central Bank.

The Locky ransomware uses decoy images to hack linkedin and facebook accounts.

A sysadmin was sentenced to two years in jail for sabotaging a internet service provider.

Android malware was used to hack and steal a Tesla.

META:

The world needs a set of cyber norms.

Is a multilateral approach needed to curb the cyber threat from North Korea?

Friday, November 04, 2016

The Coming Cyber War #20

Cyber Warfare:

The next American President is predicted to face a cyber crisis within 100 days of taking office.

An American vigilante hacker defaced the Russian Ministry of Foreign Affairs' website and issued a warning if there is further cyber attacks on the US. 

The cyber attack against the DNS company Dyn that took down the internet in the US gets profiled.  A little more info here.

Dyn responded to the attack with a press release.


The attack was supposedly done by 'script kiddies.'

Mirai and Bashlight were the software bots used against the DNS company Dyn.

The Mirai software makes the DDOS attacks much easier. 

What were the lessons learned from the DDOS attack? 

Is there anything that can be done about the DDOS attacks?

How vigilante hackers could stop IoT botnets like the ones in the attack on Dyn.

The Mirai bot attackers are now trying to take down Liberia.

A new more powerful botnet infected 3,500 IoT devices in 7 days.

The British are investing over $2 billion in cyber defense.

Two British hospitals were taken out by a virus.

Here's a look at Russia's attack on the American election system.

Putin has stated cyber attacks are unacceptable and called the interference in the election system by Russia nothing more than hysteria.

The Rocky Mountain Cyberspace Symposium was held.

The Shadow Brokers, those hackers who attacked the NSA and tried (but failed) to sell those secrets, revealed more info.

US military cyber attack teams have reached initial operating capability.

Cyber Security:

The US is said to be boosting cyber defenses for the election.

Drones are now hackable.

Google revealed a Windows security flaw just 10 days after notifying Microsoft.  Hackers have pounced on the reported flaw.  Microsoft has stated Russians have especially.

Yet Google hid a security flaw in Apple's IOS.

A google security engineer claims Android is now as secure as IOS.

A controversial Chinese cyber security law is closer to passing.

Chinese firm Hangzhou Xiongmai Technology had several of its products sold in the US hacked and is recalling them.

How hackable are your IoT devices? 

The Israeli company noted for being able to hack phone has had its firmware leaked online.

All LTE cell phone calls and messages can be intercepted and blocked.

The Rowhammer attack can now root Android devices. 

It might be possible to hack machines via ultrasound.

VeraCrypt has been found to be very flawed.

Cyber Espionage:

Apple has been sharing data with governments.

One of Putin's aides had his email account hacked by a supposed Ukrainian hacker.  It showed just how tight the relationship is between the supposed rebels in eastern Ukraine and Moscow.

The scan order for Yahoo's email is likely to never see the light of day.

Cyber Crime:

A member of Anonymous has been indicted for hacking Boston's Children Hospital.

An American bank regulator was 'hacked' by a former employee.

The Dark Web may not be as dark or as illegal as we think.

The Red Cross was hacked.

The Russian accused of hacking linkedin has been indicted.

A teenager supposedly launched an DDOS attack by accident?!

Weebly has been hacked and 43 million credentials stolen.

Friday, September 30, 2016

The Coming Cyberwar #18

Cyber Warfare:

This is the 21st century info warfare and where the 3rd offset strategy intersects with it.

The US Army is getting in on the hacking domain.

The NSA cyber weapons were compromised by the Russians through an operator error.

An hacker who was working for ISIS has been sentenced to 20 years in prison.

After the hacks by the Russians, the US must decide how to react.


Cyber Security:

Cisco is scrambling to patch another vulnerability in its firewalls.

Chinese researchers found a security problem in Tesla S, but Tesla patched it already.

Malware has starting checking to see if it is in a virtual machine.

Another malware masquerades as Street Fighter V updates.

Yahoo was hacked and 500 million users data has been exposed.  Phone companies whose users used Yahoo ought to be concerned.  That Yahoo waited two years to report the attack is being called unacceptable.  The party who hacked Yahoo is in dispute.

Cyber Espionage:

An autistic Briton who hacked the Pentagon and whatnot looking for proof of UFOs has been given clearance, finally, to be extradited to the US for prosecution.

How DID the FBI crack the San Bernardino terrorist's phone?  Some news organizations are suing to find out how.

The FBI is investigating another hack of the DNC.

Putin claims the hacks of the antidoping agency prove the ban of Russian athletes was unwarranted.

Russian hackers have been linked to attacks on German political parties and governments.

Russian hackers are being accused of attempting to disrupt the US elections.

The US is pretty sure Russia is shielding hackers who attacked the US.

Cyber Crime:

A college hacker compromised United Airlines.

An FBI agent busted folks using the Dark Web.

Hackers are spreading malware over the torrents.

A journalist was attacked by a massive DDOS attack and was kicked off the server farm where he was hosted.  Google rehosted the site.  The DDOS attack reached 1 TB per second and had over 150k hosts participating.

Michelle Obama's passport has been leaked online.

Friday, September 16, 2016

The Coming Cyber War #17

Cyber Warfare:

For the last year, someone has been probing the critical infrastructure of the internet.

Obama wishes to avoid a cyber warfare arms race.

What is the US Navy's version of information warfare? 

Should the NSA and US military's cyber command be split?  Senator McCain strongly opposes.

The Pentagon is continuing to reach out to Silicon Valley.

Cyber Security:

Google is offering $200k to hack its Nexus Android phones.

Singapore is pulling its public servants off the net for security reasons. 

A former USAF general has been named the US cyber security chief. 

The US 911 emergency system can be crippled by a mobile bot net.

Cyber Espionage:


The US intelligence agencies are concerned about the threat of Russia throwing doubt on the US election via hackers.

British firms are selling software allowing for anyone to see what's on a smart phone.

GovRAT malware is designed to target US government officials.

Guccifer 2.0, the suspected Russian hacking team, has released more DNC documents.

Watch a leaked video demonstrating how an Italian company's spyware infects computers.

Smartphones can steal 3d printing designs by listening to the printer in action.

New leaked Snowden files show what the NSA could do for satellite eavesdropping.  

Cyber Crime:

18 to 24 year olds are the most likely to use the DARKNET.

Britain is supposedly edging closer to having 10 year prison terms for online pirating.

An FBI agent posed as a journalist to deliver malware to a suspect.

Hackers that broke into the CIA Director's personal email account have been arrested.

An Israeli group,vDOS, claimed to have made $600k doing mercenary DDoS attacks.  The supposed coowners have been since arrested.

PhotoMiner, a cryptocurrency mining malware, has infected Seagate NAS boxes.

Russian hackers are targeting the anti doping agency with hopes of getting US athletes' data.

A teenager figured out how to get free data on his phone.

Thursday, July 07, 2016

The Coming Cyber War #13

Cyber Warfare:


Here's a proposed approach to cyber warfare.

An NSA hacker was interviewed by the Intercept.

Cyber warfare is a major domain for the NATO summit.

Cyber Espionage:

How India was targeted by Pakistani hackers (warning, video).

Cyber Crime:

One Congressman wants to have randsomware attacks to be reported to those potentially affected.

Nations & Terrorists are teaming up with organized crime to do cyber thefts.

There is a new malware that is pretending to be different apps like Google Play & Uber.

US Healthcare records are being offered for sale online by hackers.  Why are the hackers doing so?


Ten million android devices have been infected by a Chinese malware.  Just imagine the IOT.

The EU has passed its first cyber security law. 

Friday, June 24, 2016

The Coming Cyber War #12

Cyber Warfare: 

NATO is considering the stance that a massive cyber attack would be considered an attack that would invoke article 5; therefore, invoking the entire alliance to defend that nation.

Some are calling for a global cyber warfare treaty.

Tactical cyber warfare gets profiled.

There is a new algorithm designed to predict ISIL/Daesh attacks.

New York magazine imagines what would happen if hackers attacked New York City.

West Point cadets were trained in a cyber warfare exercise.

A recommendation is expected shortly that the US military have a unified cyber command.  Why they are not just calling it the NSA, IDK.

There are concerns the current DOD acquisition rules are hobbling American cyber warfare operations.

Cyber Security:

Hackers have breached the Pentagon's firewalls at least 130 times as part of a bounty program.

A Russian bill before the Duma will require all messenger apps to have a backdoor for the FSB.

It seems it is possible for malware to exfiltrate data from air gapped systems via modulating the rate of the spinning fans on the system.

The US & Israel have signed a cyber security pact.

Cyber Espionage:

Chinese cyber espionage seems to have greatly dropped.

The Russian hacker released info from the DNC about the Clinton Foundation.

Cyber Crime:

One million IP addresses were used to attack two banks.

There is a new randsomware written purely in javascript.


Tuesday, June 14, 2016

The Coming Cyberwar #12

Cyber Warfare:

India is being encouraged to develop a cyber command after recent attacks.

The American Cyber Command is a mystery.

The USAF is working to secure its airborne systems from cyber attack.

The US Navy has changed course on cyber warfare.

A cyber attack on a satellite could be considered an act of war.

Belgium is the single most vulnerable country to hacking (China is 5th, USA is 14th).

NATO has declared cyber a whole domain of combat separate from the rest.

Cyber Espionage:

North Korea stole the plans for the F-15 through hacking.

The NSA is looking at exploiting the internet of things.

The US & China are having a summit over cyber security.

Russian hackers supposedly hacked the Democratic National Committee and stole research on Trump. Moscow denies involvement. 

Cyber Crime:

The Mitsubishi Outlander can easily be hacked remotely. Including turning off its alarm.

The University of Calgary paid off hackers when hit by ransomware.

Ransomware can now hit smart tvs too.

There is a VERY alarming rise in the incidents of ransomware.

A new device has hit the darkweb that can clone 15 contactless cards a second.

Hackers have released info on 51 million accounts from iMesh.

ISIS hacked Arkansas libraries.

Someone hacked Texas' highway signs with anti Hillary and anti Trump messages.

Monday, April 11, 2016

US Navy Lt Commander Charged With Spying for China

A U.S. naval flight officer with an extensive signals intelligence background was accused by the service of passing secrets to China, USNI News has learned.

Lt. Cmdr. Edward C. Lin, who served on some of the Navy’s most sensitive intelligence gathering aircraft, faces several counts of espionage and other charges outlined during a Friday Article 32 hearing in Norfolk, Va.

Lin, originally a Taiwanese national before his family moved to the U.S., had a career as a signals intelligence specialist on the Navy’s Lockheed Martin EP-3E Aries II reconnaissance aircraft, several sources confirmed to USNI News.

Several sources familiar with the case told USNI News the country to which Lin passed secrets was China, however, few other details are known about the case given much of the evidence is classified.

Tuesday, March 01, 2016

The Coming Cyber War #3

Cyberwar:

The dangerous diffusion of cyber operations.

The US is intending to use cyber attacks to expose Islamic State/Daesh's communications and is significantly expanding it's operations against IS.  Its being called a massive attack now. 

The US cyber ops against IS/Daesh are honing skills for use against other nations, namely Russia and China.

Obama wants to renegotiate the 1996 Wassenaar Agreement to allow for easier export of cyber weapons and hacking tools.

The US Defense Secretary draws parallels between China's behavior online and its actions in the South China Sea.

Putin has options using cyber attacks to escalate the Donbass War.

Espionage:

The Chinese are being formally accused by Norway of hacking and stealing military secrets.

Hacking:

The hackers that took down the Ukrainian electrical system, at least in part, were very sophisticated.

Sunday, May 17, 2015

Ukraine Captures two Russian GRU Soldiers

Ukrainian troops have arrested two Russian servicemen in the country's separatist eastern territories, a Ukrainian military spokesman said on Sunday, reporting further casualties in rebel attacks despite a three-month-old ceasefire deal.

Ukraine and NATO accuse Moscow of supporting pro-Russian separatists with troops and military supplies, a charge the Kremlin has repeatedly denied.

"Two Russian servicemen are under arrest - our investigators are working with them," spokesman Andriy Lysenko said in a briefing, without giving further details.

Three Ukrainian servicemen were killed and 17 wounded in the past 24 hours, he said. Two of the deaths were a result of a mortar attack near the town of Svitlodarsk, northeast of separatist-controlled Donetsk.


This was not a walk up and arrest them sort of situation.  They were VERY badly wounded in the process of the capture (pix here, but not safe for lunch).  They were picked up in Shchastya.  Note: this is on the Ukrainian side of the ceasefire line.  For those which don't know the Russian aphabet soup of agencies, this is the GRU.

If it were not for the fact this family of acronyms has been abused so badly already and often by folks I don't care for, I'd say Ukraine as a Ceasefire In Name Only.  The difference between now and before is while both sides have been pounding the crap out of each other, neither has launched an offensive to take ground.  Its just WW1 without the over the top mass attacks right now.    frex.

Thursday, February 19, 2015

Introducing Darkleaks: a Bitcoin Block Chain Derived Distributed Market for Secrets

Whistleblowers and those individuals that are simply out to make a buck out of any confidential and valuable information, can now offer it for sale on Darkleaks, a decentralized, anonymous black market on the Internet.

The Darkleaks project is built on top of the Bitcoin blockchain, and can be used by downloading this software package (source code is open).

The process of releasing and buying the released information works like this (as explained by Zozan Cudi, a member of the Kurdish People's Defense Units):

"When the leaker selects a document, it is broken up into segments. Each of the segments is hashed, and a Bitcoin address is generated using the hash as the secret key. From this public key, a new key is generated to encrypt the segments. The encrypted segments are released for public download with the list of Bitcoin addresses.

To prove the authenticity of the document, the system uses a trustless provably fair mechanism. When announcing the leak, the leaker chooses a date and number of the chunks to be released. Based on the Bitcoin block hash at that time, some provably fair random numbers are chosen to select segments to be unlocked. This allows the community to verify the veracity of the file and decide whether they want to pay for the remaining encrypted segments.

The buyers then send Bitcoins to these addresses. When the leaker decides to claim the Bitcoins from the private key, due to how Bitcoin is designed he must release the public key which allows the buyers to decrypt the document."

The marketplace is supposed to offer anonymity for both the leaker and the buyer - the two don't interact, and there is no central operator who might somehow discover their identities.

Wednesday, November 26, 2014

Is China Cracking Down on Military Photographers?

Chinese news media have reported that a resident of the port city of Qingdao, the location of the North Sea Fleet's headquarters, has been arrested and is awaiting trial for taking photographs of the naval base from which aircraft carrier Liaoning operates.

He is accused of passing the photos to the editor of a military magazine who the Chinese authorities consider to be a foreign spy. This follows the conviction of another individual in May for selling information and photographs to a foreigner, for which he was sentenced to 10 years imprisonment. In October President Xi Jinping directed the Central Military Commission to take steps to protect military information more effectively and earlier this month China's first counter-espionage law was enacted.

Tuesday, October 14, 2014

Tsk, tsk, Russia. Sandworm? Really?

A cyberespionage campaign believed to be based in Russia has been targeting government leaders and institutions for nearly five years, according to researchers with iSight Partners who have examined code used in the attacks.

The campaign, dubbed “Sandworm” is believed to have been running since 2009, and used a wide-reaching zero-day exploit uncovered by the researchers that affects nearly every version of the Windows operating system released since Windows Vista.

Although iSight only has a small view of the number of victims targeted in the campaign, the victims include among others, the North Atlantic Treaty Organization, Ukrainian and European Union governments, energy and telecommunications firms, defense companies, as well as at least one academic in the US who was singled out for his focus on Ukrainian issues. The attackers also targeted attendees of this year’s GlobSec conference, a high-level national security gathering that attracts foreign ministers and other top leaders from Europe and elsewhere each year.

It appears Sandworm is focused on nabbing documents and emails containing intelligence and diplomatic information about Ukraine, Russia and other topics of importance in the region. But it also attempts to steal SSL keys and code-signing certificates, which iSight says the attackers probably use to further their campaign and breach other systems.

The researchers dubbed the operation “Sandworm” because the attackers make multiple references to the science fiction series Dune in their code. Sandworms, in the Frank Herbert books, are desert creatures on the planet Arrakis who are worshipped as god-like entities.

iSight is not the first to spot the attackers in the wild. Other security firms, including F-Secure in Finland, have uncovered victims over the years. But iSight was able to tie various attacks together to expose commonalities in the five-year campaign. It was encoded references to Dune—which appear in URLs for the attackers’ command-and-control servers—that helped tie some of the attacks together. The URLs include base64 strings that when decoded translate to “arrakis02,” “houseatreides94,” and “epsiloneridani0,” among others.

“Some of the references were very obscure so whoever was writing the malware was a big Dune geek,” says John Hultquist, senior manager for iSight’s Cyber Espionage Threat Intelligence team.

link.

I wonder what Snowden would think.

Tuesday, June 10, 2014

Did the Russians Trick Snowden into Going to Moscow?

Ex-KGB Major Boris Karpichko told Nigel Nelson of The Mirror that spies from Russia’s SVR intelligence service, posing as ­diplomats in Hong Kong, convinced Snowden to fly to Moscow last June.

“It was a trick and he fell for it," Karpichko, who reached the rank of Major as a member of the KGB's prestigious Second Directorate while specializing in counter-intelligence, told Nelson. "Now the Russians are extracting all the intelligence he possesses.”

Karpichko fled Moscow in 1998 after spying on his native Latvia for the KGB and the post-Soviet FSB. The 55-year-old says he is still in contact with several of his old spy pals.

Snowden flew from Hawaii to Hong Kong on May 20, 2013 and identified himself to the world on June 9. The 30-year-old American became stranded in Moscow on June 23 after he landed with a void U.S. passport and an unsigned travel Ecuadorian document obtained by WikiLeaks founder Julian Assange.

Karpichko said that the Kremlin leaked Snowden’s planned flight to Moscow to provoke the U.S. into revoking Snowden's passport, which Washington did on June 22. Assange also advised Snowden that "he would be physically safest in Russia."

Snowden has been living under the protection of the post-Soviet security services (FSB) since at least receiving asylum on Aug. 1. Karpichko told The Mirror that Snowden lives in an FSB-controlled neighborhood in Moscow's suburbs.

"His flat is heavily alarmed to stop anything happening to him," Karpichko said. "He meets the FSB twice a week over plenty of food and drink.”

Former KGB General Olig Kalugin recently told VentureBeat that “the Russians are very pleased with the gifts Edward Snowden has given them. He’s busy doing something. He is not just idling his way through life."

Monday, May 12, 2014

Has Iran Cloned the RQ-170 Sentinel? Or More FUD From Tehran?



Iran said on Sunday it has succeeded in copying a US drone it captured in December 2011, with state television broadcasting images apparently showing the replicated aircraft.

Tehran captured the US RQ-170 Sentinel in 2011 while it was in its airspace, apparently on a mission to spy on the country's nuclear sites, media in the United States reported.

"Our engineers succeeded in breaking the drone's secrets and copying them. It will soon take a test flight," an officer said in the footage.

The broadcast showed supreme leader Ayatollah Ali Khamenei's visit to an exhibition organised by the powerful Revolutionary Guards air wing about Iran's military advances, particularly regarding ballistic missiles and drones.

Footage showed two nearly identical drones.

"This drone is very important for reconnaissance missions," Khamenei said, standing in front of the Iranian copy of the American unmanned aircraft.

Thursday, May 08, 2014

Israel Spies on America More Than Any Other American Ally

Israel spies on the United States more than any other ally does and these activities have reached an alarming level, Newsweek magazine reported on Tuesday.

The main targets are US industrial and technical secrets, the weekly said, quoting classified briefings on legislation that would make it easier for Israeli citizens to get visas to enter America.

Newsweek said a congressional staffer familiar with a briefing last January called the testimony "very sobering ... alarming ... even terrifying", and quoted another as saying the behavior was "damaging."

"No other country close to the United States continues to cross the line on espionage like the Israelis do," said a former congressional staffer who attended another classified briefing in late 2013, according to Newsweek.

It said that briefing was one of several in recent months given by the Department of Homeland Security, the State Department, the FBI and the National Counterintelligence Directorate.

Thursday, April 24, 2014

Putin Claims Internet a CIA Project

President Vladimir Putin on Thursday called the Internet a CIA project and made comments about Russia's biggest search engine Yandex, sending the company's shares plummeting.

The Kremlin has been anxious to exert greater control over the Internet, which opposition activists — barred from national television — have used to promote their ideas and organize protests.

Russia's parliament this week passed a law requiring social media websites to keep their servers in Russia and save all information about their users for at least half a year. Also, businessmen close to Putin now control Russia's leading social media network, VKontakte.

Speaking Thursday at a media forum in St. Petersburg, Putin said that the Internet originally was a "CIA project" and "is still developing as such."

To resist that influence, Putin said, Russia needs to "fight for its interests" online.


tsk.  its an NSA project, Putty-pie.  ;)