Pakistan Cyber Force: Kaspersky

Top stories

Pakistan Cyber Force [Official]

Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts

Tuesday, February 17, 2015

Kaspersky: NSA's Surveillance Backdoor embedded in Hard Disk Firmwares Targets Pakistan, Russia, China

Print Friendly and PDF

Throughout the extended weekend, there had been rumors circulating around the blogosphere that a huge NSA hacking story—not originating via Edward Snowden—was about to break, and it was going to be a doozey. Sure enough, it’s all but “official,” per breaking news from Moscow-based Kaspersky Lab, one of the most highly-regarded cybersecurity firms in the world, via stories over the past few hours in Tuesday’s NY Times, Reuters and ARS Technica, among others, we’re now learning that America is the source of the greatest software exploitation (hacking) travesty ever reported.

As you’ll learn in the excerpted breaking stories, below, apparently, the NSA’s toolbox includes its ability to hack virtually every hard drive on the planet (even including those in “airgap” mode, unconnected to a network, via deviously-hidden code on data sticks); then, embed its code in the hard drive’s firmware, so securely and covertly that even a disk-wipe won’t erase the malware on the drive!

Let’s start off with the NY Times’ downplayed and propagandized version of the story (contrary to the NYT’s headline, a review of the Kaspersky Lab Report, available in full, below, indicates that, indeed, there were/are NSA-related hacks in the U.S. Ars Technica provides the most comprehensive and outstanding coverage of this story, which is linked and excerpted further down. Reuters, also linked and excerpted below, provides extremely convincing proof positive that this is a 14-plus-year-long story about the National Security Agency’s hacking efforts, which ARS Technica references as: “…the most advanced hacking operation ever uncovered…”)…

U.S. Embedded Spyware Overseas, Report Claims By NICOLE PERLROTH and DAVID E. SANGER
New York Times (Page B1)
February 17th, 2015
SAN FRANCISCO — The United States has found a way to permanently embed surveillance and sabotage tools in computers and networks it has targeted in Iran, Russia, Pakistan, China, Afghanistan and other countries closely watched by American intelligence agencies, according to a Russian cybersecurity firm.
In a presentation of its findings at a conference in Mexico on Monday, Kaspersky Lab, the Russian firm, said that the implants had been placed by what it called the “Equation Group,” which appears to be a veiled reference to the National Security Agency and its military counterpart, United States Cyber Command.
It linked the techniques to those used in Stuxnet, the computer worm that disabled about 1,000 centrifuges in Iran’s nuclear enrichment program. It was later revealed that Stuxnet was part of a program code-named Olympic Games and run jointly by Israel and the United States.
Kaspersky’s report said that Olympic Games had similarities to a much broader effort to infect computers well beyond those in Iran. It detected particularly high infection rates in computers in Iran, Pakistan and Russia, three countries whose nuclear programs the United States routinely monitors…

Throughout the extended weekend, there had been rumors circulating around the blogosphere that a huge NSA hacking story—not originating via Edward Snowden—was about to break, and it was going to be a doozey. Sure enough, it’s all but “official,” per breaking news from Moscow-based Kaspersky Lab, one of the most highly-regarded cybersecurity firms in the world, via stories over the past few hours in Tuesday’s NY Times, Reuters and ARS Technica, among others, we’re now learning that America is the source of the greatest software exploitation (hacking) travesty ever reported.
As you’ll learn in the excerpted breaking stories, below, apparently, the NSA’s toolbox includes its ability to hack virtually every hard drive on the planet (even including those in “airgap” mode, unconnected to a network, via deviously-hidden code on data sticks); then, embed its code in the hard drive’s firmware, so securely and covertly that even a disk-wipe won’t erase the malware on the drive!
Let’s start off with the NY Times’ downplayed and propagandized version of the story (contrary to the NYT’s headline, a review of the Kaspersky Lab Report, available in full, below, indicates that, indeed, there were/are NSA-related hacks in the U.S. Ars Technica provides the most comprehensive and outstanding coverage of this story, which is linked and excerpted further down. Reuters, also linked and excerpted below, provides extremely convincing proof positive that this is a 14-plus-year-long story about the National Security Agency’s hacking efforts, which ARS Technica references as: “…the most advanced hacking operation ever uncovered…”)…

U.S. Embedded Spyware Overseas, Report Claims By NICOLE PERLROTH and DAVID E. SANGER
New York Times (Page B1)
February 17th, 2015
SAN FRANCISCO — The United States has found a way to permanently embed surveillance and sabotage tools in computers and networks it has targeted in Iran, Russia, Pakistan, China, Afghanistan and other countries closely watched by American intelligence agencies, according to a Russian cybersecurity firm.
In a presentation of its findings at a conference in Mexico on Monday, Kaspersky Lab, the Russian firm, said that the implants had been placed by what it called the “Equation Group,” which appears to be a veiled reference to the National Security Agency and its military counterpart, United States Cyber Command.
It linked the techniques to those used in Stuxnet, the computer worm that disabled about 1,000 centrifuges in Iran’s nuclear enrichment program. It was later revealed that Stuxnet was part of a program code-named Olympic Games and run jointly by Israel and the United States.
Kaspersky’s report said that Olympic Games had similarities to a much broader effort to infect computers well beyond those in Iran. It detected particularly high infection rates in computers in Iran, Pakistan and Russia, three countries whose nuclear programs the United States routinely monitors…
The extensive NYT report continues on to note: “Some of the implants burrow so deep into the computer systems, Kaspersky said, that they infect the ‘firmware,’ the embedded software that preps the computer’s hardware before the operating system starts. It is beyond the reach of existing antivirus products and most security controls, Kaspersky reported, making it virtually impossible to wipe out.”
The report continues, “In many cases, it also allows the American intelligence agencies to grab the encryption keys off a machine, unnoticed, and unlock scrambled contents. Moreover, many of the tools are designed to run on computers that are disconnected from the Internet, which was the case in the computers controlling Iran’s nuclear enrichment plants.”
The report indicates that Kaspersky tracked  “more than 60 [Equation Group] attack groups…in cyberspace…”, and “…the so-called Equation Group “surpasses anything known in terms of complexity and sophistication of techniques, and that has been active for almost two decades…”

Equation Group victims map (Source: Kaspersky Lab)

The NSA’s Equation Group has hacked the products of the following seven hard drive manufacturers (there were actually more than that on the Kaspersky list, but the other manufacturers have merged with the companies on this short list); essentially, this list represents companies that produce almost all of the hard drives in the world:

Maxtor
Seagate
Western Digital
Samsung
Toshiba
Hitachi
Micron

Forensics software displays some of the hard drives Equation Group was able to commandeer using malicious firmware. (Source: Kaspersky Lab via Ars Technica)

Ars Technica’s coverage of this story is nothing short of superb! I strongly recommend it. Unfortunately, due to usage restraints, I’m only excerpting a small portion of it…

How “omnipotent” hackers tied to NSA hid for 14 years—and were found at last "Equation Group" ran the most advanced hacking operation
ever uncovered.

by Dan Goodin -
Ars Technica
Feb 16, 2015 11:00am PST
CANCUN, Mexico — In 2009, one or more prestigious researchers received a CD by mail that contained pictures and other materials from a recent scientific conference they attended in Houston. The scientists didn't know it then, but the disc also delivered a malicious payload developed by a highly advanced hacking operation that had been active since at least 2001. The CD, it seems, was tampered with on its way through the mail.
It wasn't the first time the operators—dubbed the "Equation Group" by researchers from Moscow-based Kaspersky Lab—had secretly intercepted a package in transit, booby-trapped its contents, and sent it to its intended destination…
Ars Technica lists the six pieces of Equation Group malware discovered by Kaspersky (from the Kaspersky Lab report; see full report, farther down)…
EquationLaser: an early implant in use from 2001 to 2004. DoubleFantasy: a validator-style trojan designed to confirm if the infected person is an intended target. People who are confirmed get upgraded to either EquationDrug or GrayFish.
EquationDrug: also known as Equestre, this is a complex attack platform that supports 35 different modules and 18 drivers. It is one of two Equation Group malware platforms to re-flash hard drive firmware and use virtual file systems to conceal malicious files and stolen data.
GrayFish: the successor to EquationDrug and the most sophisticated of all the Equation Group attack platforms. It resides completely in the registry and relies on a bootkit to take hold each time a computer starts. Whereas EquationDrug re-flashed hard drives for six models, GrayFish re-flashed 12 classes of hard drives. GrayFish exploits a vulnerability in the CloneCD driver ElbyCDIO.sys—and possibly drivers of other programs—to bypass Windows code-signing requirements.
Fanny: A computer worm that exploited what in 2008 were two zero-day vulnerabilities in Windows to self-replicate each time an infected USB stick was inserted into a targeted computer. The main purpose of Fanny was to conduct reconnaissance on sensitive air-gapped networks. After infecting a computer not connected to the Internet, Fanny collected network information and saved it to a hidden area of the USB drive. If the stick was later plugged in to an Internet-computer, it would upload the data to attacker servers and download any attacker commands. If the stick was later plugged into the air-gapped machine, the downloaded commands would be executed. This process would continue each time the stick was switched between air-gapped and Internet-connected machines.
TripleFantasy: A full-featured backdoor sometimes used in tandem with GrayFish.
More from Ars Technica...
Hacking without a budget The money and time required to develop the Equation Group malware, the technological breakthroughs the operation accomplished, and the interdictions performed against targets leave little doubt that the operation was sponsored by a nation-state with nearly unlimited resources to dedicate to the project. The countries that were and weren't targeted, the ties to Stuxnet and Flame, and the Grok artifact found inside the Equation Group keylogger strongly support the theory the NSA or a related US agency is the responsible party, but so far Kaspersky has declined to name a culprit.
Update: Reuters reporter Joseph Menn said the hard-drive firmware capability has been confirmed by two former government employees. He wrote:
…A former NSA employee told Reuters that Kaspersky's analysis was correct, and that people still in the intelligence agency valued these spying programs as highly as Stuxnet. Another former intelligence operative confirmed that the NSA had developed the prized technique of concealing spyware in hard drives, but said he did not know which spy efforts relied on it…
Update: Several hours after this post went live, NSA officials e-mailed the following statement to Ars:
We are aware of the recently released report. We are not going to comment publicly on any allegations that the report raises, or discuss any details. On January 17, 2014, the President gave a detailed address about our signals intelligence activities, and he also issued Presidential Policy Directive 28 (PPD-28). As we have affirmed publicly many times, we continue to abide by the commitments made in the President’s speech and PPD-28. The U.S. Government calls on our intelligence agencies to protect the United States, its citizens, and its allies from a wide array of serious threats - including terrorist plots from al-Qaeda, ISIL, and others; the proliferation of weapons of mass destruction; foreign aggression against ourselves and our allies; and international criminal organizations.
What is safe to say is that the unearthing of the Equation Group is a seminal finding in the fields of computer and national security, as important, or possibly more so, than the revelations about Stuxnet. "The discovery of the Equation Group is significant because this omnipotent cyber espionage entity managed to stay under the radar for almost 15 years, if not more," Raiu said.  [Diarist’s Note: Reference is to Costin Raiu, director of Kaspersky Lab's global research and analysis team.] "Their incredible skills and high tech abilities, such as infecting hard drive firmware on a dozen different brands, are unique across all the actors we have seen and second to none. As we discover more and more advanced threat actors, we understand just how little we know. It also makes us reflect about how many other things remain hidden or unknown."

And, last but not least, Reuters

Russian researchers expose breakthrough
U.S. spying program

By Joseph Menn
Reuters (SAN FRANCISCO)
Mon Feb 16, 2015 5:10pm EST
(Reuters) - The U.S. National Security Agency has figured out how to hide spying software deep within hard drives made by Western Digital, Seagate, Toshiba and other top manufacturers, giving the agency the means to eavesdrop on the majority of the world's computers, according to cyber researchers and former operatives.
That long-sought and closely guarded ability was part of a cluster of spying programs discovered by Kaspersky Lab, the Moscow-based security software maker that has exposed a series of Western cyberespionage operations.
Kaspersky said it found personal computers in 30 countries infected with one or more of the spying programs, with the most infections seen in Iran, followed by Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria. The targets included government and military institutions, telecommunication companies, banks, energy companies, nuclear researchers, media, and Islamic activists, Kaspersky said. (reut.rs/1L5knm0)
The firm declined to publicly name the country behind the spying campaign, but said it was closely linked to Stuxnet, the NSA-led cyberweapon that was used to attack Iran's uranium enrichment facility. The NSA is the agency responsible for gathering electronic intelligence on behalf of the United States.
A former NSA employee told Reuters that Kaspersky's analysis was correct, and that people still in the intelligence agency valued these spying programs as highly as Stuxnet. Another former intelligence operative confirmed that the NSA had developed the prized technique of concealing spyware in hard drives, but said he did not know which spy efforts relied on it…
Here’s the entire Kaspersky Lab report: “Equation Group Questions and Answers


(dailykos.com)
Pakistan Cyber Force

Wednesday, January 16, 2013

Kaspersky Lab Uncovers Cyber-Espionage Plot By Russian & Chinese Hackers

Print Friendly and PDF


Kaspersky Lab has uncovered Operation Red October, (Rocra) a 5 year scheme by the Chinese and Russians to steal diplomatic, industrial and scientific data from Eastern Europe, North America and Asian organizations. Beginning in 2007, intelligence gathering operations were conducted in the form of attacks by cyber criminals toward Western nations. The thought is that this is in retribution on behalf of Iran for the damage caused to their country.

Encrypted files and decryption keys used by the European Union and NATO have been compromised. The countries under attack are:

• The Russian Federation
• Kazakhstan
• Azerbajian
• Belgium
• India
• Afghanistan
• Armenia
• Ukraine
• Turkmenistan

Kaspersky said: “The information we have collected so far does not appear to point toward any specific location; however, two important factors stand out: The exploits appear to have been created by Chinese hackers, (and) the Rocra malware modules have been created by Russian-speaking operatives.”

Rocra appears to have been controlled by 60 command-and-control servers that were held in Germany and Russia. It is suspected that there is another “mother ship” server based in an unknown location.

Some of the attacks appear to be tailor-made for the victim with an estimated 1,000 different modules that preformed specific attacks. Kaspersky explained: “For instance, the initial documents are customized to make them more appealing and every single module is specifically compiled for the victim with a unique victim ID inside (and) later, there is a high degree of interaction between the attackers and the victim. Compared to Flame and Gauss, which are highly automated cyber-espionage campaigns, Rocra is a lot more ‘personal’ and finely tuned for the victims.”

The software is broken down to continually run within the system until triggered to activate. Examples are stealing information from a connection made by a mobile phone or syphoning mail servers and downloading emails.

Although Kaspersky Lab admits that these attacks have not definitively been connected to China or Russia, it is assumed that the data collected would be yield a high price on the black market.

Kaspersky stated: “The information stolen by the attackers is obviously of the highest level and includes geopolitical data which can be used by nation states. Such information could be traded in the underground and sold to the highest bidder, which can be, of course, anywhere.”

Rocra is able map out the internal layout of a network and information routes taken by computer software to take files with the use of thumb drives and smartphones.

In 2012, the US House Intelligence Committee (USHIC) warned American corporations in a new report against conducting business with 2 Chinese firms because of national security threats. Both Huawei Technologies and ZTE, two of the world’s largest telecommunications corporations and suppliers of cellular phones and technology are being highlighted by the US government and blamed for cyber-attacks. It is also claimed by the USHIC that they are involved in digital espionage.

According to the report, “China has the means, opportunity, and motive to use telecommunications companies for malicious purposes. . . . The investigation concludes that the risks associated with Huawei’s and ZTE’s provision of equipment to U.S. critical infrastructure could undermine core U.S. national-security interests.”

It is claimed that former industry insiders provided intelligence to the US concerning Huawei’s violations of US laws such as immigration, bribery and corruption as well as an alleged “pattern and practice” using pirated software in its US satellites.

The report stated that the Chinese corporations were employing intelligence sources as well as private sector companies and other unnamed entities that could and assumedly did steal trade secrets, sensitive information and prehistory data while simultaneously shipped infected hard ware and software to the US with the intent to cause disruptions in national security during war time.

Around the same time as the release of the report, an anonymous White House official said there was an attempt to hack into the executive branch’s computer system through an unclassified network. No data were removed, proving that this was not an actual hack. The nameless official said that the experiment was a “spear-phishing”.

The supposition is that China is behind these attacks because of a phishing expedition against Gmail accounts wherein several senior US government officials and military personnel were affected.

According to the other mainstream media outlets, “hackers linked to China’s government broke into one of the U.S. government’s most sensitive computer networks, breaching a system used by the White House Military Office for nuclear commands, according to defense and intelligence officials familiar with the incident.”

The official questioned explained that a connection to Bejing in the case of the cyber attack “highlights a failure of the Obama administration to press China on its persistent cyber attacks.”

In January, analysts at the Council on Foreign Relations (CFR) have confirmed that hackers traced to China attacked their system. The “drive-by” hacking utilized a pirated computer. To compound the problem, the analysts said that the hackers removed their malware and traces of their presence from CFR computer systems.

Recognizing China as becoming a formidable replacement to the US as the world’s super power, the CFR has outlined specific responses to this crisis of supremacy. Citing Chinese internet policy, their disdain for freedom of speech in social media, and influence in global cyberspace, the CFR appreciates that this rising “foe” must be confronted indirectly with propaganda to distract from the obvious.

This attack marked a new level of attack by international hackers who aim to steal information from government websites and computers. The “drive-by” tactic covertly plants malware, then the website itself is used to attack visitors to the site. Visitors can be infected as hackers will them attempt to hack into other computers as visitors are passing by. The hackers use the main site as a “watering hole” that attacks users to it for the hackers to steal information from their computers.


Pakistan Cyber Force

Tuesday, October 16, 2012

Global cyber war: New Flame-linked malware detected

Print Friendly and PDF


A new cyber espionage program linked to the notorious Flame and Gauss malware has been detected by Russia's Kaspersky Lab. The anti-virus giant’s chief warns that global cyber warfare is in “full swing” and will probably escalate in 2013. The virus, dubbed miniFlame, and also known as SPE, has already infected computers in Iran, Lebanon, France, the United States and Lithuania. It was discovered in July 2012 and is described as “a small and highly flexible malicious program designed to steal data and control infected systems during targeted cyber espionage operations,” Kaspersky Lab said in a statement posted on its website.

The malware was originally identified as an appendage of Flame – the program used for targeted cyber espionage in the Middle East and acknowledged to be part of joint US-Israeli efforts to undermine Iran’s nuclear program.

But later, Kaspersky Lab analysts discovered that miniFlame is an “interoperable tool that could be used as an independent malicious program, or concurrently as a plug-in for both the Flame and Gauss malware.” The analysis also showed new evidence of cooperation between the creators of Flame and Gauss, as both viruses can use miniFlame for their operations.

“MiniFlame’s ability to be used as a plug-in by either Flame or Gauss clearly connects the collaboration between the development teams of both Flame and Gauss. Since the connection between Flame and Stuxnet/Duqu has already been revealed, it can be concluded that all these advanced threats come from the same 'cyber warfare' factory,” Kaspersky Lab said.

High-precision attack tool

So far just 50 to 60 cases of infection have been detected worldwide, according to Kaspersky Lab. But unlike Flame and Gauss, miniFlame in meant for installation on machines already infected by those viruses. “MiniFlame is a high-precision attack tool. Most likely it is a targeted cyber weapon used in what can be defined as the second wave of a cyber attack,” Kaspersky's Chief Security Expert Alexander Gostev explained.

“First, Flame or Gauss are used to infect as many victims as possible to collect large quantities of information. After data is collected and reviewed, a potentially interesting victim is defined and identified, and miniFlame is installed in order to conduct more in-depth surveillance and cyber-espionage.”
The newly-discovered malware can also take screenshots of an infected computer while it is running a specific program or application in such as a web browser, Microsoft Office program, Adobe Reader, instant messenger service or FTP client.

Kaspersky Lab believes miniFlame's developers have probably created dozens of different modifications of the program. "At this time, we have only found six of these, dated 2010-2011," the firm said.

‘Cyber warfare in full swing’

Meanwhile, Kaspersky Lab’s co-founder and CEO Eugene Kaspersky warned that global cyber warfare tactics are becoming more sophisticated while also becoming more threatening. He urged governments to work together to fight cyber warfare and cyber-terrorism, Xinhua news agency reports. Speaking at an International Telecommunication Union Telecom World conference in Dubai, the anti-virus tycoon said, "cyber warfare is in full swing and we expect it to escalate in 2013."

"The latest malicious virus attack on the world's largest oil and gas company, Saudi Aramco, last August shows how dependent we are today on the Internet and information technology in general, and how vulnerable we are," Kaspersky said. He stopped short of blaming any particular player behind the massive cyber attacks across the Middle East, pointing out that "our job is not to identity hackers or cyber-terrorists. Our firm is like an X-ray machine, meaning we can scan and identify a problem, but we cannot say who or what is behind it."

Iran, who confirmed that it suffered an attack by Flame malware that caused severe data loss, blames the United States and Israel for unleashing the cyber attacks.

(RT)

Pakistan Cyber Force

Related Posts Plugin for WordPress, Blogger...