Showing posts with label info warfare. Show all posts
Showing posts with label info warfare. Show all posts

Wednesday, March 09, 2016

The Coming Cyberwar #5 (mini update): Which Nations are the Most Vulnerable to Cyberattack?

Damaging cyberattacks on a global scale continue to surface every day. Some nations are better prepared than others to deal with online threats from criminals, terrorists and rogue nations.

Data-mining experts from the University of Maryland and Virginia Tech recently co-authored a book that ranked the vulnerability of 44 nations to cyberattacks. Lead author V.S. Subrahmanian discussed this research on Wednesday, March 9 at a panel discussion hosted by the Foundation for Defense of Democracies in Washington, D.C.

The United States ranked 11th safest, while several Scandinavian countries (Denmark, Norway and Finland) ranked the safest. China, India, Russia, Saudi Arabia and South Korea ranked among the most vulnerable.

Friday, February 26, 2016

The Coming Cyber War #2

Full Blown Cyber War:

Reports are the US military has launched a cyber attack on IS/Daesh.

The USA had plans to attack many different parts of Iran with cyber weapons if diplomacy had failed.  This planned operation was called Nitro Zeus.   It should be noted from the Times article:

At its height, officials say, the planning for Nitro Zeus involved thousands of American military and intelligence personnel, spending tens of millions of dollars and placing electronic implants in Iranian computer networks to “prepare the battlefield,” in the parlance of the Pentagon.
The cyber weapons are already present in Iran.  The trigger was simply not pressed.

The cutbacks to the US military may cause gaps in the cyber warfare sections.

How will the Navy fight in a cyber war? (part 2)   Part of the answer might be to unplug ships from each other in the event of a cyber attack.  It has released more cyber security guidelines.

The US military service chiefs are rejecting the idea of creating a fifth branch of the military to just handle cyberwarfare.  I could have sworn it already exists and is called the NSA.

Britain is putting an increased emphasis on cyberwarfare.

Australia is, too, adding significant capabilities (paywall), including hiring 1700 people just for its cyberwarfare group.

Hackers:

The Russian cyber espionage group, Pawn Storm, has released a vicious linux centric trojan called Fysbis, one that eats android phones, too.  Yet it will not infect phones and computers is Russia.

The US DHS has determined the power outage in Ukraine in December was definitely a cyber attack, but declined to name the source.  Others have stated it was the Russian group named 'Sandworm.'

Hackers are already making millions from their actions.

The Sony hackers were at it for years prior.

Another set of hackers held a hospital for ransom.  The hospital paid out $17,000 to get their computers back.

In a frightening test, a hospital was hacked.  The drug dispensaries, patient monitoring and elsewhere were found to be hackable.

A major security flaw was found in DNS, the giant 'yellow pages' of the internet, that could allow virtually the entire Internet to be infected.

A simple keylogger malware was released into the wild and, in an amusing twist, ended up infecting the original coders' computers 16 times.   This is the danger of cyberweapons.  They can inadvertently turn against you.

Those Between:

The German police are allowed to use a trojan malware.

CMU developed software to attack TOR for the DOD, but the FBI now ants the software.

Wednesday, February 18, 2015

Meet Babar: The French Government's Spyware/Malware

The NSA, GCHQ, and their allies in the Five Eyes are not the only government agencies using malware for surveillance. French intelligence is almost certainly hacking its targets too—and now security researchers believe they have proof.

On Wednesday, the researchers will reveal new details about a powerful piece of malware known as “Babar,” which is capable of eavesdropping on online conversations held via Skype, MSN and Yahoo messenger, as well as logging keystrokes and monitoring which websites an infected user has visited.

Babar is “a fully blown espionage tool, built to excessively spy” on its victims, according to the research, and which Motherboard reviewed in advance. The researchers are publishing two separate but complementary reports that analyze samples of the malware, and all but confirm that France’s spying agency the General Directorate for External Security (DGSE) was responsible for its creation.

France’s Defense Ministry did not respond to a request for comment by the time of publication.



I am waiting for the first German and Brazilian government malwares to be uncovered (I am 100% sure they exist). Then their hypocrisy can be unmasked.  The NSA might be the best at it, but it does not mean the other nation states are not doing this, too.  This is definitely not a case where the Russians, Chinese and Anglosphere are the sole naughty children online.

Monday, February 16, 2015

The Equation Group: Your Hard Drive is Watching you

The U.S. National Security Agency has figured out how to hide spying software deep within hard drives made by Western Digital, Seagate, Toshiba and other top manufacturers, giving the agency the means to eavesdrop on the majority of the world's computers, according to cyber researchers and former operatives.

That long-sought and closely guarded ability was part of a cluster of spying programs discovered by Kaspersky Lab, the Moscow-based security software maker that has exposed a series of Western cyberespionage operations.

Kaspersky said it found personal computers in 30 countries infected with one or more of the spying programs, with the most infections seen in Iran, followed by Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria. The targets included government and military institutions, telecommunication companies, banks, energy companies, nuclear researchers, media, and Islamic activists, Kaspersky said.

The firm declined to publicly name the country behind the spying campaign, but said it was closely linked to Stuxnet, the NSA-led cyberweapon that was used to attack Iran's uranium enrichment facility. The NSA is the agency responsible for gathering electronic intelligence on behalf of the United States.

A former NSA employee told Reuters that Kaspersky's analysis was correct, and that people still in the intelligence agency valued these spying programs as highly as Stuxnet. Another former intelligence operative confirmed that the NSA had developed the prized technique of concealing spyware in hard drives, but said he did not know which spy efforts relied on it.

NSA spokeswoman Vanee Vines declined to comment.

link.

There's a lot more to this than just the hard drives.

Thursday, January 08, 2015

2nd Confirmed Kinetic CyberAttack Caused Physical Damage at German Steel Mill

Amid all the noise the Sony hack generated over the holidays, a far more troubling cyber attack was largely lost in the chaos. Unless you follow security news closely, you likely missed it.

I’m referring to the revelation, in a German report released just before Christmas (.pdf), that hackers had struck an unnamed steel mill in Germany. They did so by manipulating and disrupting control systems to such a degree that a blast furnace could not be properly shut down, resulting in “massive”—though unspecified—damage.

This is only the second confirmed case in which a wholly digital attack caused physical destruction of equipment. The first case, of course, was Stuxnet, the sophisticated digital weapon the U.S. and Israel launched against control systems in Iran in late 2007 or early 2008 to sabotage centrifuges at a uranium enrichment plant. That attack was discovered in 2010, and since then experts have warned that it was only a matter of time before other destructive attacks would occur. Industrial control systems have been found to be rife with vulnerabilities, though they manage critical systems in the electric grid, in water treatment plants and chemical facilities and even in hospitals and financial networks. A destructive attack on systems like these could cause even more harm than at a steel plant.

It’s not clear when the attack in Germany took place. The report, issued by Germany’s Federal Office for Information Security (or BSI), indicates the attackers gained access to the steel mill through the plant’s business network, then successively worked their way into production networks to access systems controlling plant equipment. The attackers infiltrated the corporate network using a spear-phishing attack—sending targeted email that appears to come from a trusted source in order to trick the recipient into opening a malicious attachment or visiting a malicious web site where malware is downloaded to their computer. Once the attackers got a foothold on one system, they were able to explore the company’s networks, eventually compromising a “multitude” of systems, including industrial components on the production network.

“Failures accumulated in individual control components or entire systems,” the report notes. As a result, the plant was “unable to shut down a blast furnace in a regulated manner” which resulted in “massive damage to the system.”

Tuesday, December 09, 2014

Waltzing to Skynet: Automated Terrain and Maneuver in Cyber Warfare


In real-world warfare, troops and tanks maneuver to take advantage of the terrain. In the looking-glass world of cyberspace, however, “maneuver” may mean changing the terrain itself. If the enemy’s invading your country, you can dig a trench or blow a bridge, but otherwise you go to war with the landscape you have.

If the enemy’s invading your network, however, you can rebuild it in an eyeblink to block their avenue of attack — provided you know how they’re getting in. You can reject incoming data from suspicious IP addresses, for example, or disable your users’ ability to download files (a common Trojan Horse), or, in the worst case, shut everything down before too much damage is done.

There are lots of options — too many, in fact, for the human brain to track of all of them, let alone decide which one is best, the Pentagon’s chief cybersecurity officer said Thursday. Think of all the different settings you have on whatever device you’re using to read this article. It’s not just about the obvious options like whether you accept cookies and block pop-ups. It’s not even the configuration of your firewall (you do have a firewall, don’t you?). It’s every program that has can take data from the Internet. Think of trying to choose the right settings across all those programs — keeping in mind how they all interact! — to stop a specific attack. Then do it again the next day when a new threat shows up. Now multiply that by thousands of computers interacting in a global network.

Tuesday, October 14, 2014

Tsk, tsk, Russia. Sandworm? Really?

A cyberespionage campaign believed to be based in Russia has been targeting government leaders and institutions for nearly five years, according to researchers with iSight Partners who have examined code used in the attacks.

The campaign, dubbed “Sandworm” is believed to have been running since 2009, and used a wide-reaching zero-day exploit uncovered by the researchers that affects nearly every version of the Windows operating system released since Windows Vista.

Although iSight only has a small view of the number of victims targeted in the campaign, the victims include among others, the North Atlantic Treaty Organization, Ukrainian and European Union governments, energy and telecommunications firms, defense companies, as well as at least one academic in the US who was singled out for his focus on Ukrainian issues. The attackers also targeted attendees of this year’s GlobSec conference, a high-level national security gathering that attracts foreign ministers and other top leaders from Europe and elsewhere each year.

It appears Sandworm is focused on nabbing documents and emails containing intelligence and diplomatic information about Ukraine, Russia and other topics of importance in the region. But it also attempts to steal SSL keys and code-signing certificates, which iSight says the attackers probably use to further their campaign and breach other systems.

The researchers dubbed the operation “Sandworm” because the attackers make multiple references to the science fiction series Dune in their code. Sandworms, in the Frank Herbert books, are desert creatures on the planet Arrakis who are worshipped as god-like entities.

iSight is not the first to spot the attackers in the wild. Other security firms, including F-Secure in Finland, have uncovered victims over the years. But iSight was able to tie various attacks together to expose commonalities in the five-year campaign. It was encoded references to Dune—which appear in URLs for the attackers’ command-and-control servers—that helped tie some of the attacks together. The URLs include base64 strings that when decoded translate to “arrakis02,” “houseatreides94,” and “epsiloneridani0,” among others.

“Some of the references were very obscure so whoever was writing the malware was a big Dune geek,” says John Hultquist, senior manager for iSight’s Cyber Espionage Threat Intelligence team.

link.

I wonder what Snowden would think.

Wednesday, September 03, 2014

Google's VirusTotal Being Used by Chinese Cyberwarfare Units to Test Malware

Before companies like Microsoft and Apple release new software, the code is reviewed and tested to ensure it works as planned and to find any bugs.

Hackers and cybercrooks do the same. The last thing you want if you’re a cyberthug is for your banking Trojan to crash a victim’s system and be exposed. More importantly, you don’t want your victim’s antivirus engine to detect the malicious tool.

So how do you maintain your stealth? You submit your code to Google’s VirusTotal site and let it do the testing for you.

It’s long been suspected that hackers and nation-state spies are using Google’s antivirus site to test their tools before unleashing them on victims. Now Brandon Dixon, an independent security researcher, has caught them in the act, tracking several high-profile hacking groups—including, surprisingly, two well-known nation-state teams—as they used VirusTotal to hone their code and develop their tradecraft.

“There’s certainly irony” in their use of the site, Dixon says. “I wouldn’t have expected a nation state to use a public system to do their testing.”

Wednesday, August 13, 2014

The NSA has Weaponized Bro and Called it MonsterMind

Edward Snowden has made us painfully aware of the government’s sweeping surveillance programs over the last year. But a new program, currently being developed at the NSA, suggests that surveillance may fuel the government’s cyber defense capabilities, too.

The NSA whistleblower says the agency is developing a cyber defense system that would instantly and autonomously neutralize foreign cyberattacks against the US, and could be used to launch retaliatory strikes as well. The program, called MonsterMind, raises fresh concerns about privacy and the government’s policies around offensive digital attacks.

Although details of the program are scant, Snowden tells WIRED in an extensive interview with James Bamford that algorithms would scour massive repositories of metadata and analyze it to differentiate normal network traffic from anomalous or malicious traffic. Armed with this knowledge, the NSA could instantly and autonomously identify, and block, a foreign threat.


This sounds like they weaponized bro and gave it teeth.

Monday, May 12, 2014

Indonesian Army Establishing Cyberwarfare Center

The Indonesian Army (Tentera Nasional Indonesia - Angkatan Darat: TNI-AD) signed a memorandum of understanding (MoU) on 12 May with local institution Institut Teknologi Del (ITD) to develop a cyber-defence and warfare centre.

The MoU, signed by TNI Chief of Staff General Budiman and ITD Rector Dr Roberd Saragih, covers training and development of new offensive and defensive technologies that can be used by TNI-AD in conducting cyber warfare operations. Also present during the MoU signing ceremony were representatives from Indonesia's State Intelligence Agency (BIN).

ITD representative Deni Lumbantoruan told reporters that the cyber warfare centre will be hosted at ITD's campus located in Samosir, North Sumatra.

Thursday, March 13, 2014

NSA's Cyber Warfare Tactics Being Outed by Snowden

Top-secret documents reveal that the National Security Agency is dramatically expanding its ability to covertly hack into computers on a mass scale by using automated systems that reduce the level of human oversight in the process.

The classified files – provided previously by NSA whistleblower Edward Snowden – contain new details about groundbreaking surveillance technology the agency has developed to infect potentially millions of computers worldwide with malware “implants.” The clandestine initiative enables the NSA to break into targeted computers and to siphon out data from foreign Internet and phone networks.

The covert infrastructure that supports the hacking efforts operates from the agency’s headquarters in Fort Meade, Maryland, and from eavesdropping bases in the United Kingdom and Japan. GCHQ, the British intelligence agency, appears to have played an integral role in helping to develop the implants tactic.

Tuesday, March 04, 2014

Are the Russians Behind the Uroburos Malware?


Russian government hackers are suspected of creating a highly-sophisticated piece of malware designed to steal files from nation states’ digital infrastructure.

The Uroburos malware, named after an ancient symbol depicting a serpent or dragon eating its own tail that recently appeared in the Broken Sword 5 video game, worked in in peer-to-peer mode, meaning it can move across machines even if they’re not connected to the public Internet.

G-Data said Uroburos was “one of the most advanced rootkits we have ever analysed in this environment”.

Friday, February 28, 2014

If Government or Other American Networks are Destroyed, This is an Act of War

On the day that China’s president took personal charge of his country’s new cyber body, pledging to make the People’s Republic of China a “cyber power,” the outgoing head of America’s Cyber Command laid out a clear red line that, if crossed, could lead to war.

“If it destroys government or other networks, I think it would cross that line,” Army Gen. Keith Alexander, head of both Cyber Command and the National Security Agency, told the Senate Armed Services Committee today when asked what level of cyber “attack” would potentially cause America to go to war.

President Xi Takes Personal Leadership of Chinese Cyber Forces

President Xi Jinping will head the central Internet security and informatization leading group, according to a statement released after the first meeting of the group on Thursday.

Xi presided over the meeting, stressing that Internet security and informatization is a major strategic issue concerning a country's security and development as well as people's life and work.

"Efforts should be made to build our country into a cyber power," he said.

Thursday, February 20, 2014

French Jet Engine Maker Snecma Targeted by Hackers

French aerospace engine maker Snecma, a unit of Safran, was attacked by hackers who exploited a vulnerability in Microsoft Corp's Internet Explorer, according to a computer security researcher.

It was not clear how successful the hackers had been in their efforts to breach Snecma's network, according to the researcher, who has studied malicious software and infrastructure used by the hackers.

A spokeswoman for Snecma's parent, Safran, said she had no immediate comment.

The researcher said the malicious software used by the hackers contained code that identified Internet domain names belonging to Snecma. The researcher declined to be identified by name as he was not authorized to publicly discuss the matter.

Wednesday, February 19, 2014

How Susceptible is the F-35 to Being Hacked?


A recent “60 Minutes” segment on the Defense Department’s F-35 focused on some of the high-tech features of the future fighter jet.

The Pentagon’s most advanced — and most expensive — acquisition program isn’t just another stealth aircraft with angled lines and sharp contours. It’s a “flying computer,” with 24 million lines of software code and a $500,000-plus helmet-mounted display that lets pilots see through the floor of the cockpit, according to the report.

[...]

In addition, the plane’s reliance on software and information technology makes it a target for hackers, Schmidle said. “It’s kind of like you using your smart phone to do banking,” he told Martin. “You are taking a greater risk than if you walk down to the teller at the bank and say, ‘Hey, this is what I wanted to do.”

While Schmidle said he’s “confident” that the military will be able to protect the aircraft’s data networks, he also acknowledged that “it’s not going to be easy and it’s not going to happen overnight.”

Thursday, November 07, 2013

Chinese Hacking Continues Unabated

The disclosure early this year of a secretive Chinese military unit believed to be behind a series of hacking attacks has failed to halt the cyber intrusions, a U.S. computer security company and congressional advisory panel said on Wednesday.

A report by the cybersecurity company Mandiant in February identified the People's Liberation Army's Shanghai-based Unit 61398 as the most likely culprit in hacking attacks on a wide range of industries. China's Defense Ministry denied the accusations.

The U.S.-China Economic and Security Commission, a panel which advises the U.S. Congress on China policy, said Mandiant's revelations brought only a brief pause in cyber intrusions by that PLA unit.

"There are no indications the public exposure of Chinese cyber espionage in technical detail throughout 2013 has led China to change its attitude toward the use of cyber espionage to steal proprietary economic and trade information," the commission said in a draft of their annual report to Congress.

The draft report, made available to Reuters on Wednesday, said Mandiant's revelations "merely led Unit 61398 to make changes to its cyber 'tools and infrastructure' (to make) future intrusions harder to detect and attribute."

The commission's report, to be released in final form later this month, quoted Mandiant experts as saying the Chinese military hackers decreased their activities for about a month following the February publication of that report.

link.

Wednesday, May 02, 2007

At What Point is Something Like This an Act of War?

In a move potentially repeatable against other countries, top-level Russian authorities are sabotaging the Estonian state’s web servers since April 27. According to Justice Minister Rein Lang and Foreign Affairs Minister Urmas Paet, the cyber attacks on April 29 and 30 were traced to IP addresses in Moscow owned by the Russian presidential administration and government (Estonian TV, Eesti Paevaleht, April 30, May 1). The attacks have perturbed the entire information network of Estonia’s state administrations, government and presidency. The effects are particularly disruptive on a country like Estonia, a European leader regarding the generalization of electronic governance.


Makes you wonder what is the threshold of info warfare being turned into the bullet slinging kind. An interesting theoretical question taht goes beyond teh Russian-Estonian goofiness.