Thursday, October 20, 2011

School of Economic Warfare: Spies like them

Via Canadian Business -

Most business schools offer a variety of specialities, from marketing and accounting to corporate finance. But there is a school in Europe with an MBA program in what faculty members call “defence against the dark arts.” The institution in question is well-known to its stated enemies—greedy corporate executives who attempt to dominate the business world via evil means—but is nearly invisible to the general public. Tucked away in the bowels of Paris, down a side street near where Napoleon once studied the finer points of waging war, its entrance is an unmarked storefront. Window blinds are typically drawn to keep out prying eyes. As a result, most people on the street tend to stroll by without ever gaining awareness of the powerful forces being taught inside.

Don’t be fooled by the reference to fighting dark arts. This isn’t a graduate program offered by Harry Potter’s beloved Hogwarts. The institution out to conquer evil in this case is the deadly serious École de Guerre Économique, known in English circles as the School of Economic Warfare, where students are equipped with a unique and controversial set of skills that school founders insist are required to successfully lead modern corporations on the battlefield of capitalism, 24 hours a day, seven days a week.

When most people talk about industrial espionage in the West, the finger wagging is typically aimed at China and Russia. In emerging markets, more than a few people insist that Uncle Sam somehow manages aggressively to deploy the CIA to steal trade secrets for select U.S. corporations without raising a legal peep from other American companies. But what those concerned talk about when not tossing accusations at China or the United States is France—an aggressive collector of industrial intelligence since the mid-1700s, when the British naively invited French operatives to inspect their mines, smelters and foundries. The British Board of Longitude even foolishly let French operatives examine John Harrison’s revolutionary marine clocks.

Intelligence experts around the world warn the business community not to underestimate the French. But faculty members at the School of Economic Warfare have little time for corporate Boy Scouts. They’re more concerned with warning executives not to underestimate the risks associated with always playing fair. “All is fair in love, war and business” isn’t the school’s official motto, but it fits the bill, insists faculty member Jean-François Bianchi, a specialist in information engineering who teaches courses on the theory and strategy of influence and counter-influence.

[...]

Furthermore, as pointed out by Richard Bejtlich, chief security officer with Mandiant, an information security company based in Washington, D.C., playing defence all the time can be “a losing strategy in more than just hockey.”

[...]

Bejtlich says most unethical acts of corporate espionage are still conducted by governments, or state organs, working on behalf of national champions. But he thinks more and more companies are being tempted to cross the line. And the security expert sees a growing desire to fight back in a far more aggressive manner. Whenever Bejtlich deals with a company that has been attacked, he says executives always want to know, “What can we do to get back at these guys?” Those conversations, he adds, never go anywhere because lawyers quickly get involved. “You will be hard-pressed to find any company with a legal department that allows them to do anything more than defend themselves,” he says.

[...]

The School of Economic Warfare—which charges tuition of between €10,000 and €15,000 per year (depending on support from an employer)—was clearly founded to help French companies get a leg up on the competition. But it is open to students from around the world, although some nationalities can be blacklisted if the school suspects an untrustworthy government behind the application. It offers a one-year program that requires about 800 hours of study and exercises, aimed at the same audience that would undertake a traditional MBA. There is also a part-time program for working professionals, which requires about 350 hours a year. The school attracts students from all sectors, but the student body is typically weighted toward hyper-competitive industries such as energy, auto making and finance.

Wednesday, October 19, 2011

Flashback Trojan Now Disabling Mac XProtect

Via Threatpost.com -

Mac-based malware is still a relatively rare occurrence when compared to the flood of malicious programs aimed at Windows. But, it appears that the attackers who are creating the more recent Mac malware either have experience writing Windows-based malware or are simply paying close attention to what's been working for Windows malware for all of these years. The latest evidence of this being the discovery that the Flashback Mac Trojan has the ability to overwrite the Mac's built-in antimalware component and prevent it from updating.

[...]

Now, researchers have found that a recently discovered piece of Mac malware known as the Flashback Trojan is using a similar technique to hamper the XProtect antimalware system that's included in newer versions of OS X. Once resident on a newly infected Mac, the Flashback malware will decrypt a specific XProtect file and then decrypt the path of the XProtectUpdater binary, according to an analysis by researchers at F-Secure. The next step is for Flashback to unload the XProtectUpdater daemon and then overwrite certain components.

"The action described above wipes out certain files, thus, preventing XProtect from automatically receiving future updates," the analysis says.


---------------------------------------------------------------

For some reason, Apple is failing to learn the lessons of the last 10+ years. They only need to look back of how malware started out and then dominated the Windows world.

Apple has been increasing their use of anti-expoitation mitigations (i.e. ASLR, sandboxing) in each verison of OS X released, but as long the malware authors contiune to see a positive cost benefit in attacking OS X, they will contiune to go after Mac users.

I use Sophos' free home edition (at home of course) and haven't had any issues wth it on MBP.

Sophos Anti-Virus for Mac Home Edition (It's Free)
http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx

Tuesday, October 18, 2011

GTISC: Cybersecurity Threats to Pick Up Steam in 2012

Via Scientific American -

This year has had its share of cybersecurity bombshells. Cybersecurity vendor McAfee revealed widespread theft of government data over the past five years. Now the hacker group Anonymous has threatened to take down the New York Stock Exchange's computers .

Expect more of the same in 2012, maybe even worse. So says a new report (pdf) from the Georgia Tech Information Security Center.

So-called search poisoning will emerge. That's where a cyber attacker inserts a virus or spyware into your search results.

Beware of Mobile Web-based attacks as well. Mobile phones have always been relatively insecure. Now that so many people use them to surf the Web and store sensitive data, they've become a prime target for hackers.

The Georgia Tech report also cautions against the use of hijacked computers, called botnets, to steal personal information from your online accounts and then sell that info to marketers.

Your best defense is common sense. Update your passwords and antivirus software regularly. And play it safe when surfing the Web from your phone. Stick with app stores and other sites you know and trust.


----------------------------------------------------------------------

GTISC: Emerging Cyber Threats Report 2012
http://www.gtisc.gatech.edu/doc/emerging_cyber_threats_report2012.pdf

Analysis: Duqu Targets Certificate Authorities

Via Threatpost.com -

With virus researchers scrambling to decode a new piece of malware that is based on the code of the Stuxnet worm, an analyst at McAfee is speculating that the new worm, Duqu, may have been created to target certificate authorities.

Writing on McAfee's research blog, Guilherme Venere and Peter Szor say that an analysis of the Duqu code by McAfee experts suggests that the worm was created "for espionage and targeted attacks against sites such as Certificate Authorities (CAs)." The McAfee analysis, if accurate, is the first to explicitly mention the type of organization that the Duqu worm targeted, and would suggest that those behind the worm intended to use it as a precursor to subsequent, targeted attacks.

Certificate authorities have been prominent targets of hackers in recent months.

[...]

McAfee said that the Duqu worm has been identified in "professional, targeted attacks" against CAs in parts of Europe, the Middle East, Asia and Africa. The researchers speculate that a digital certificate belonging to the firm C-Media, based in Taipei, was not stolen, but forged by a compromised CA.

The McAfee analysis fills in some details omitted from a longer analysis released by Symantec Corp on Tuesday. That research declined to name the kind of firm targeted by the worm, but provided a detailed analysis of the Duqu code, which bears a close resemblance to Stuxnet, with shared code used for the injection attack and several encryption keys and techniques that were used in Stuxnet.

Like Symantec's report, the analysis from McAfee says that it knows of only a few infections linked to Duqu, and says the worm doesn't appear to be designed to attack industrial control systems, as Stuxnet was.

Java Updates and the BEAST

Oracle Java SE Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html

Oracle released JRE 6 Update 29 and Java 7 Update 1 today. Along with fixing six very serious vulnerabilities (CVSS 10.0), these updates include a fix for CVE-2011-3389 as well.

Beyond the fact that some of those CVSS 10.0 vulnerabilities will end up in exploit kits quickly, the CVE-2011-3389 fix addresses the Same Origin Policy (SOP) bypass used by Rizzo/Duong in their chosen plain text attack on SSL/TLS 1.0, also known as "BEAST".

Of couse, this fix by Oracle does not totally fix weakness in the SSL/TLS 1.0 protocol...therefore it is important for the security industry to keep pushing toward wider adoption of TLS v1.1+.

W32.Duqu: The Precursor to the Next Stuxnet

Via Symantec Security Response Blog -

On October 14, 2011, a research lab with strong international connections alerted us to a sample that appeared to be very similar to Stuxnet. They named the threat "Duqu" [dyü-kyü] because it creates files with the file name prefix “~DQ”. The research lab provided us with samples recovered from computer systems located in Europe, as well as a detailed report with their initial findings, including analysis comparing the threat to Stuxnet, which we were able to confirm. Parts of Duqu are nearly identical to Stuxnet, but with a completely different purpose.

Duqu is essentially the precursor to a future Stuxnet-like attack. The threat was written by the same authors (or those that have access to the Stuxnet source code) and appears to have been created since the last Stuxnet file was recovered. Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility.

Duqu does not contain any code related to industrial control systems and is primarily a remote access Trojan (RAT). The threat does not self-replicate. Our telemetry shows the threat was highly targeted toward a limited number of organizations for their specific assets. However, it’s possible that other attacks are being conducted against other organizations in a similar manner with currently undetected variants.

The attackers used Duqu to install another infostealer that could record keystrokes and gain other system information. The attackers were searching for assets that could be used in a future attack. In one case, the attackers did not appear to successfully exfiltrate any sensitive data, but details are not available in all cases. Two variants were recovered, and in reviewing our archive of submissions, the first recording of one of the binaries was on September 1, 2011. However, based on file compile times, attacks using these variants may have been conducted as early as December 2010.

[...]

Duqu shares a great deal of code with Stuxnet; however, the payload is completely different. Instead of a payload designed to sabotage an industrial control system, the payload has been replaced with general remote access capabilities. The creators of Duqu had access to the source code of Stuxnet, not just the Stuxnet binaries. The attackers intend to use this capability to gather intelligence from a private entity to aid future attacks on a third party. While suspected, no similar precursor files have been recovered that predate the Stuxnet attacks.

You can find additional details in our paper here. The research lab that originally found the sample has allowed us to share their initial report as an appendix. We expect to make further updates over the coming days.

Key points:
  • Executables using the Stuxnet source code have been discovered. They appear to have been developed since the last Stuxnet file was recovered.
  • The executables are designed to capture information such as keystrokes and system information.
  • Current analysis shows no code related to industrial control systems, exploits, or self-replication.
  • The executables have been found in a limited number of organizations, including those involved in the manufacturing of industrial control systems.
  • The exfiltrated data may be used to enable a future Stuxnet-like attack.

-----------------------------------------------------------------------------

Whitepaper - W32.Duqu: The Precursor to the Next Stuxnet

http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf

W32.Duqu - Summary
http://www.symantec.com/business/security_response/writeup.jsp?docid=2011-101814-1119-99

Monday, October 17, 2011

U.S. Debated Cyberwarfare in Attack Plan on Libya

Via NY Times -

Just before the American-led strikes against Libya in March, the Obama administration intensely debated whether to open the mission with a new kind of warfare: a cyberoffensive to disrupt and even disable the Qaddafi government’s air-defense system, which threatened allied warplanes.

While the exact techniques under consideration remain classified, the goal would have been to break through the firewalls of the Libyan government’s computer networks to sever military communications links and prevent the early-warning radars from gathering information and relaying it to missile batteries aiming at NATO warplanes.

But administration officials and even some military officers balked, fearing that it might set a precedent for other nations, in particular Russia or China, to carry out such offensives of their own, and questioning whether the attack could be mounted on such short notice. They were also unable to resolve whether the president had the power to proceed with such an attack without informing Congress.

In the end, American officials rejected cyberwarfare and used conventional aircraft, cruise missiles and drones to strike the Libyan air-defense missiles and radars used by Col. Muammar el-Qaddafi’s government.

This previously undisclosed debate among a small circle of advisers demonstrates that cyberoffensives are a growing form of warfare. The question the United States faces is whether and when to cross the threshold into overt cyberattacks.

[...]

“We don’t want to be the ones who break the glass on this new kind of warfare,” said James Andrew Lewis, a senior fellow at the Center for Strategic and International Studies, where he specializes in technology and national security.

That reluctance peaked during planning for the opening salvos of the Libya mission, and it was repeated on a smaller scale several weeks later, when military planners suggested a far narrower computer-network attack to prevent Pakistani radars from spotting helicopters carrying Navy Seal commandos on the raid that killed Osama bin Laden on May 2.

Again, officials decided against it. Instead, specially modified, radar-evading Black Hawk helicopters ferried the strike team, and a still-secret stealthy surveillance drone was deployed.

“These cybercapabilities are still like the Ferrari that you keep in the garage and only take out for the big race and not just for a run around town, unless nothing else can get you there,” said one Obama administration official briefed on the discussions.

The debate about a potential cyberattack against Libya was described by more than a half-dozen officials, who spoke on the condition of anonymity because they were not authorized to discuss the classified planning.

In the days ahead of the American-led airstrikes to take down Libya’s integrated air-defense system, a more serious debate considered the military effectiveness — and potential legal complications — of using cyberattacks to blind Libyan radars and missiles.

“They were seriously considered because they could cripple Libya’s air defense and lower the risk to pilots, but it just didn’t pan out,” said a senior Defense Department official.

After a discussion described as thorough and never vituperative, the cyberwarfare proposals were rejected before they reached the senior political levels of the White House.

Police Find Matching Modus Operandi in Mitsubishi Heavy, Kawasaki Heavy Cases

Via Daily Yomiuri Online (Japan) -

Police increasingly believe the same hacker was responsible for the recent cyber-attacks on Mitsubishi Heavy Industries Ltd. and Kawasaki Heavy Industries Ltd.

A computer virus found in the attack on Kawasaki Heavy Industries, which was sent by e-mail through a computer at the Society of Japanese Aerospace Companies (SJAC), forced infected personal computers to access a Web site in the United States, sources close to the issue said Saturday. Police have found that infected PCs at Mitsubishi Heavy Industries were made to access the same Web site.

The police suspect the hacker used the U.S. site as a so-called springboard, via which the attacker manipulated computer terminals from the outside. Springboards refer to PCs and computer servers used as communication relay points by cyber-attackers to prevent their originating port from being identified.

[...]

According to the sources, Kawasaki Heavy Industries received e-mails whose senders posed as SJAC officials and member company employees at least three times from June to August. Police analyzed viruses hidden in the e-mails and found they contained programs that force infected PCs to access Web sites and exchange data.

The police discovered the Web site involved in this case had an Internet protocol address registered in California.

The virus confirmed to have been used in the attacks against Mitsubishi Heavy Industries performed the same function. In addition to the California-registered site, infected computers had communicated with Web sites in Japan and other countries including China and India.

The U.S. site was likely to have been infected with viruses and manipulated by someone from the outside, investigators said.

The Web site in question appears to have been closed as early as mid-September, when the cyber-attacks on Mitsubishi Heavy Industries came to light.

Information security experts said hackers use such contacts with outside Web sites to have viruses placed in targeted companies' servers send information or to instruct the viruses to reproduce themselves.

Attackers usually abandon such sites once they achieve their goals or their attacks are discovered, the experts said.

The police suspect the person who attacked Mitsubishi Heavy Industries and Kawasaki Heavy Industries used the U.S. Web site to steal information from the companies and then transmitted it to other Web sites.

"In the past, unrelated hacker groups have coincidentally used the same servers as springboards," said Norihiko Maeda, a researcher at Kaspersky Lab Japan, a manufacturer of antiviral software. "Usually, hackers use different springboards for individual attacks, so the same server is rarely used by two or more criminal groups."

"[However, because the police investigation revealed that] the same attacker likely targeted the two companies, it's become clearer that the attacker aimed to steal Japanese defense secrets. Authorities must quickly investigate communication records and other data from the springboards," he said.

Sunday, October 16, 2011

Secure Android Kernel Could Make for 'Classified' Smart Phones

Via GCN -

A research team from Google, George Mason University and the National Security Agency have developed a hardened kernel for the Android 3.0 operating system that could solve the problem of using smart phones in military operations and emergency response.

The kernel, which is in the final stages of certification testing, opens the way for the Army to begin issuing smart phones or tablet-type wireless devices to troops in combat operations.

The White House also is interested because the hardened kernel could help fulfill a government plan to create a secure national wireless network for first responders, Michael McCarthy, operations director of the Army’s Brigade Modernization Command’s Mission Command Complex, said at the AUSA Annual Meeting and Exposition in Washington on Oct. 10. McCarthy also heads the service’s Connecting Soldiers to Digital Applications (CSDA) program, the lead organization involved in selecting handheld wireless technologies for military use.

[...]

There were delays in getting the operating system accredited until NSA came forward several months ago and offered to expedite the approval process, McCarthy said. The new effort kicked off with a series of meetings with CSDA program personnel and representatives from NSA and the National Institute of Standards and Technology.

The Android kernel is now being tested for a Federal Information Processing Standard 140-2 certification, which is expected by mid-October. “That’s the first level of security that we’ve got to get before we start moving onto being able to ultimately do secret [communications],” he said.

[...]

After the testing is complete, it is just a matter of filling out the certification paperwork, McCarthy said. “That is a game-changer for the security business because it then sets the conditions so that in the second quarter [late March 2012] they can do the certification of the Secure Sockets Layer, which then gives us the ability to operate at the classified levels,” he said.

In addition to the Army’s plans to provide troops with smart phones, the Obama administration was attracted to the technology to support two of its initiatives. One is an effort by the White House Communications Office to move the executive branch from BlackBerry devices to Android-based phones. The reason is because Android devices with the new kernel can be secured at a higher clearance level than BlackBerry devices, McCarthy said.

[...]

One of the concerns behind the government’s drive is that the radio communications networks used by federal, state and local response agencies are not very secure. This is a special concern for law enforcement and emergency response organizations’ operational channels, which could be subject to interception, spoofing and jamming. “They’re looking at replacing radio with a smart phone,” he said.

U.S. Sending More Contractors to Secure Libya’s Weapons Stockpile

Via NY Times -

The State Department is sending dozens of American contractors to Libya to help that country’s fledgling efforts to track down and destroy heat-seeking antiaircraft missiles looted from government stockpiles that could be used against civilian airliners.

The contractors, weapons and explosives specialists, are part of a growing $30 million American program to secure Libya’s conventional weapons arsenal, which was ransacked during the fall of the government of Col. Muammar el-Qaddafi.

American and other Western officials are especially concerned that as weapons slip from state custody, they can be easily sold through black markets to other countries, fueling regional wars or arming terrorist groups. Analysts are particularly worried about the dispersal of the SA-7, an early-generation, shoulder-fired missile in the same family as the more widely known Stinger.

“We are very concerned about the threat that’s posed,” Andrew Shapiro, the assistant secretary of state for political-military affairs, told reporters on Friday after meetings in Brussels.

Mr. Shapiro said he had no estimate as to how many of the roughly 20,000 shoulder-fired antiaircraft missiles that had been in Libya were unaccounted for since the fall of Colonel Qaddafi, but added, “In the wrong hands these systems could pose a potential threat to civil aviation.”

The State Department so far has sent 14 unarmed civilian contractors, many with military experience, to be part of teams led by Libya’s Transitional National Council, according to David I. McKeeby, a department spokesman. Mr. McKeeby said that an additional two to three dozen contractors would join the effort over the coming weeks.

The teams have surveyed and secured 20 of the former government’s 36 known ammunition depots, encompassing several hundred bunkers at each site, and have destroyed or disabled hundreds of the shoulder-fired missiles, he said. The deployment of the American contractors was reported on Friday by The Washington Post.


---------------------------------------------------------------------

FAS: Man-Portable Air Defense System (MANPADS) Proliferation
http://www.fas.org/programs/ssp/asmp/MANPADS.html

Saturday, October 15, 2011

Piracy: Prepare to Repel Boarders

Via The Economist -

SomaliS pirates can be persistent. They have attacked the Maersk Alabama, a container ship owned by an American subsidiary of Denmark’s Maersk Line, no fewer than five times, most recently in May. In the first attack, in 2009, the captain was held hostage until the US Navy rescued him. Then Maersk put private armed guards on the ship. Since then, it has successfully repelled all boarders.

Maersk says it is only arming a few ships plying the pirate-infested waters off East Africa. But the practice is spreading rapidly among shipping firms despite the cost, which can run to $100,000 per voyage for a four-man team. That is because the number of attacks, off Somalia and elsewhere, has kept growing despite the strengthening of naval patrols (see chart). The European Union’s NAVFOR task-force, NATO warships and other navies patrol the waters off Somalia, but this has only pushed the pirates out into the open ocean, extending their attack zone towards India’s coast and as far south as Mozambique’s. This has forced the shipping industry, its insurers, and the national and international authorities that oversee them to accept that private armed guards are a necessity.

[...]

Until February the International Chamber of Shipping (ICS), which represents the world’s merchant shipowners, opposed the use of armed guards—even as some members were discreetly hiring them. Since the chamber changed its line, the number of owners tooling up has accelerated. Now, says Simon Bennett, its spokesman, perhaps 20% of all ships passing through the risky parts of the Indian Ocean have armed guards aboard—typically retired marines or the like.

In recruiting armed security men, some shipowners have defied the laws of the countries where their vessels are registered. But governments, unable to provide the naval cover the shipowners want, are one by one legalising the practice. Spain, one of the earliest to let its fishing-boats carry armed guards, said on September 27th that they would now be allowed to use machineguns and other heavy weapons against the pirates’ AK-47s.

Some countries, such as America and Denmark, have introduced licensing schemes for owners who want to arm their ships. Britain is among those still considering legalisation, and Greece’s shipping industry is pressing its government to do likewise. The UN’s International Maritime Organisation (IMO), while still not endorsing the practice, last month asked Somalia’s neighbours to let armed merchant ships call at their ports. The ICS says it understands Egypt is to lift its ban on armed merchant ships’ passage through the Suez canal. But the Indian government is still said to disapprove of armed merchant ships calling at its ports: their guards either have to go elsewhere or dump their weapons overboard.

[...]

There do not yet seem to have been any claims, or lawsuits, over the use of armed ship guards, says Tom Heinan of International Registries (which runs the Marshall Islands’ shipping register). But shipowners using them could face legal action in various places: their own country, the flag state of their ship, the home countries of injured crewmen, and so on. All the more reason to ensure that the guards are competent and well-insured.

Speedy Neutrino Mystery Likely Solved, Relativity Safe After All

Via Dvice.com (Syfy Network) -

Those weird faster-than-light neutrinos that CERN thought they saw last month may have just gotten slowed down to a speed that'll keep them from completely destroying physics as we know it. In an ironic twist, the very theory that these neutrinos would have disproved may explain exactly what happened.

Back in September, physicists ran an experiment where they sent bunches of neutrinos from Switzerland to Italy and measured how long the particles took to make the trip. Over 15,000 experiments, the neutrinos consistently arrived about 60 nanoseconds early, which means 60 nanoseconds faster than the speed of light. Einstein's special theory of relativity says this should be impossible: nothing can travel faster than light.

The fact that the experiment gave the same result so many times suggested that one of two things was true: either the neutrinos really were speeding past light itself and heralding a new era of physics, or there was some fundamental flaw with the experiment, which was much more likely. It's now looking as though the faster-than-light result was a fundamental flaw, and appropriately enough, it's a flaw that actually helps to reinforce relativity rather than question it.


------------------------------------------------------------

Faster-than-Light Neutrino Puzzle Claimed Solved by Special Relativity
http://www.technologyreview.com/blog/arxiv/27260/

Friday, October 14, 2011

Austin's Power: The Texas Capital Is A Model For Clean Power Adoption

Via Fast Company -

How do you get people to use renewable energy when it’s more expensive than fossil-fueled power?

For answers to that question, you might want to look at places with high adoption rates for renewables. Austin, for instance.

This month, Texas’s capital became the largest municipality in the country to use only renewable energy. That's 100% of all of its energy. All the city’s public buildings, including its airport and water treatment plants, are now powered using wind from West Texas. In the last nine years, Austin Energy, the city’s publicly-owned utility, has produced more renewable energy than any in the country. And, the city is well on the way to sourcing 35% of all energy from renewables by 2020.

And yet Austin's consumers sometimes pay 15 to 25% more for electricity under the utility’s Greenchoice program than other customers. And the city government has paid $9 million a year extra to make the switch (from a total of bill of about $28 million). How come they’re willing to pay such a premium?

Well, not everyone has been that willing. Some voters and businesses have decried the move, saying it adds to living costs at a time when people can't afford expensive choices.

But Ed Clark, a spokesperson for Austin Energy, points to a long history of green activity, and the city’s high number of tech companies as supportive. “Austin has a tremendous emphasis on quality of life. There is not a single significant polluting industry in this entire community,” he says.


-------------------------------------------------------

Read more of the story @ Fast Compnay

Thursday, October 13, 2011

US Air Force: Flying Operations of Remotely Piloted Aircraft Unaffected by Malware

http://www.afspc.af.mil/news1/story.asp?id=123275647

To correct recent reporting, the malware detected on stand-alone systems on Creech Air Force Base, Nev., in September, has not affected Remotely Piloted Aircraft operations.

On 15 September, 24th AF first detected and subsequently notified Creech AFB regarding the malware on their portable hard drives approved for transferring information between systems. It was detected and isolated by the 24th Air Force using standard tools and processes for monitoring and protecting Air Force computer systems and networks. The Air Force then began a forensic process to track the origin of the malware and clean the infected systems.

The malware was detected on a stand-alone mission support network using a Windows-based operating system. The malware in question is a credential stealer, not a keylogger, found routinely on computer networks and is considered more of a nuisance than an operational threat. It is not designed to transmit data or video, nor is it designed to corrupt data, files or programs on the infected computer. Our tools and processes detect this type of malware as soon as it appears on the system, preventing further reach.

The infected computers were part of the ground control system that supports RPA operations. The ground system is separate from the flight control system Air Force pilots use to fly the aircraft remotely; the ability of the RPA pilots to safely fly these aircraft remained secure throughout the incident.

"It's standard policy not to discuss the operational status of our forces," said Colonel Kathleen Cook, spokesperson for Air Force Space Command. "However, we felt it important to declassify portions of the information associated with this event to ensure the public understands that the detected and quarantined virus posed no threat to our operational mission and that control of our remotely piloted aircraft was never in question."

"We continue to strengthen our cyber defenses, using the latest anti-virus software and other methods to protect Air Force resources and assure our ability to execute Air Force missions. Continued education and training of all users will also help reduce the threat of malware to Department of Defense systems."


------------------------------------------------------------------

Some of the recent reporting, they were looking to correct....

New Mac Trojan Variant is VMware-Aware

Via Virus Bulletin -

Researchers at F-Secure have found a variant of the 'Flashback' trojan for Mac (a fake Adobe Flash Player update) that is capable of detecting whether it is run in a virtual environment.

Virtualization is a technique commonly used by malware researchers as it allows them to run the malware in a safe environment. To frustrate researchers and to avoid detection, malware authors regularly build in anti-virtualization techniques: the malware tries to detect whether it is running in a virtual environment and does not run if this is the case, thus hiding its malicious activity.

While such techniques are commonly seen in Windows malware, Mac malware using anti-virtualization techniques had not hitherto been seen. This is yet another example that shows that Mac malware is not only becoming more prevalent but also more advanced.

More at F-Secure's blog here.


----------------------------------------------------------------------------

While anti-virutalization is nothing new for Windows malware, it is a new development for Mac malware....and thus resembles an evolution in the complexity and the feature set of Mac malware.

Similar to Android malware research recently conducted by Symantec, we should expect malware authors to continue to incorporate features from the Windows malware world into the Mac malware world. They will continue to explore the capabilities of this emerging malware ecosystem, especially if the revenue-per-infection ratio improves.

STRATFOR: Increased Cartel Violence in Mexico City

http://www.stratfor.com/analysis/20111012-above-tearline-increased-cartel-violence-mexico-city

Vice President of Intelligence Fred Burton examines two recent violent incidents in Mexico City that could indicate a tactical shift in cartel strategy.

Top Zetas Drug Cartel Leader Accused in Deadly Casino Attack Arrested

Via CNN -

A top Zetas drug cartel leader -- who allegedly ordered the attack and arson at a casino that killed 52 -- has been captured, Mexican defense officials said Thursday.

Carlos Oliva Castillo, alias "La rana," or frog, was arrested Wednesday at a safehouse without a single shot being fired, the country's Ministry of Defense said.

Possibly the No. 3 man in the criminal organization, Oliva Castillo allegedly oversaw criminal operations for the cartel in three Mexican states. He was captured in Saltillo, Mexico.

Though he was arrested without incident, the cartel tried to distract troops by attacking security forces in different parts of the city, the defense ministry said.

The Zetas' rescue ploy failed.

According to officials, Oliva Castillo was "the principal manager" of the ruthless Zetas in the states of Coahuila, Nuevo Leon and Tamaulipas. He was also described as a confidant of Zetas boss Heriberto Lazcano Lazcano.

Oliva Castilo began working for the Zetas in 2005 in Tamaulipas, the defense ministry said, and rose through the ranks quickly. By 2009 he was in charge of the cartel's finances in Nuevo Leon, before taking charge of all operations in that state, the ministry said. This year he assumed a wider role, the ministry said.

The three northeastern states that Oliva Castillo allegedly oversaw are some of the Zetas' strongest-held territory. Authorities say that much of the violence registered in these states is the result of the Zetas fighting rival groups such as the Gulf cartel and Sinaloa cartel, for access to lucrative smuggling routes.

But the Zetas -- especially in their strongholds -- have branched out from drug trafficking and into extortion of businesses, kidnappings, and human smuggling.


------------------------------------------------

This follows last week's arrest of Jose Alberto Loera Rodriguez, nicknamed "el Voltaje," (the Jock).

Wednesday, October 12, 2011

Operation Hackerazzi: Scarlett Johansson Hacker Used ‘Publicly Available Data' To Target Celebrities

Via International Business Times (Entertainment & Stars) -

The FBI held a press conference Wednesday announcing the arrest of Christopher Chaney, a 35-year-old Jacksonville, Fla., man arrested on hacking and wiretapping charges in connection with the Scarlett Johansson nude photo scandal in September.

The arrest was the result of an investigation dubbed "Operation Hackerazzi."

The press conference doubled as something of a public safety seminar, with FBI officials warning celebrities and mortals alike how easy it is for hackers to get access to private, personal information and turn it around for profit or gain.

One FBI official called technology hacking "a disturbing and rising trend," adding that "celebrity information is highly marketable."

The FBI also posted a visual aid titled "The Anatomy of a Hack," which explained the steps a hacker takes to infiltrate personal accounts. Among these steps are using open source information to reset passwords, breaching an account and changing the password, communicating with contacts in the account holder's address book, and using the contact list to harvest new targets.

Cheney allegedly "mined through publicly available data" to figure out passwords and security information on his targets.

An FBI spokesperson insisted that Chaney's was a singular arrest, but added that the FBI is following other leads.

According to The Associated Press, Chaney began hacking into Google, Apple and Yahoo email accounts November and December, then used the forwarding feature to ensure that every email received was sent, "virtually instantaneously," to an email account he controlled, according to an indictment handed by a federal grand jury in Los Angeles.

Chaney allegedly used the hacker names "trainreqsuckswhat," ''anonygrrl" and "jaxjaguars911".


-----------------------------------------------------------------------------

FBI: Florida Man Arrested in “Operation Hackerazzi” for Targeting Celebrities with Computer Intrusion, Wiretapping, and Identity Theft

US: Treasury Designates Iranian Commercial Airline Linked to Iran's Support for Terrorism

http://www.treasury.gov/press-center/press-releases/Pages/tg1322.aspx

The U.S. Department of the Treasury announced today the designation of Iranian commercial airline Mahan Air pursuant to Executive Order (E.O.) 13224 for providing financial, material and technological support to the Islamic Revolutionary Guard Corps-Qods Force (IRGC-QF). Based in Tehran, Mahan Air provides transportation, funds transfers and personnel travel services to the IRGC-QF.

“Mahan Air’s close coordination with the IRGC-QF – secretly ferrying operatives, weapons and funds on its flights – reveals yet another facet of the IRGC’s extensive infiltration of Iran’s commercial sector to facilitate its support for terrorism,” said Under Secretary for Terrorism and Financial Intelligence David S. Cohen. “Following the revelation about the IRGC-QF’s use of the international financial system to fund its murder-for-hire plot, today’s action highlights further the undeniable risks of doing business with Iran.”

Mahan Air provided travel services to IRGC-QF personnel flown to and from Iran and Syria for military training. Mahan Air also facilitated the covert travel of suspected IRGC-QF officers into and out of Iraq by bypassing normal security procedures and not including information on flight manifests to eliminate records of the IRGC-QF travel.

Mahan Air crews have facilitated IRGC-QF arms shipments. Funds were also transferred via Mahan Air for the procurement of controlled goods by the IRGC-QF.

In addition to the reasons for which Mahan Air is being designated today, Mahan Air also provides transportation services to Hizballah, a Lebanon-based designated Foreign Terrorist Organization. Mahan Air has transported personnel, weapons and goods on behalf of Hizballah and omitted from Mahan Air cargo manifests secret weapons shipments bound for Hizballah.

As a result of today’s action, U.S. persons are prohibited from engaging in commercial or financial transactions with Mahan Air and any assets it may hold under U.S. jurisdiction are frozen.

Identifying Information:

Entity: Mahan Air
AKA: Mahan Travel Company
Address: Mahan Air Tower, 21st Floor, Azadeghan Street, Karaj Highway, P.O. Box 14515-411, Tehran, Iran
Alt. Address: Mahan Air Tower, Azadegan St., Karaj Highway, Tehran 1481655761, Iran P.O. Box 411-14515

CFR: Backgrounder - Iran's Revolutionary Guards (IRGC)

http://www.cfr.org/iran/irans-revolutionary-guards/p14324

Introduction

Iran's Revolutionary Guard Corps (IRGC) was founded in the aftermath of the 1979 Islamic Revolution to defend the regime against internal and external threats, but has since expanded far beyond its original mandate. Today, the Guards has evolved into a socio-military-political-economic force with influence reaching deep into Iran's power structure. The Guards' involvement in politics has grown to unprecedented levels since 2004, when IRGC veterans won at least 16 percent of the 290 seats. Analysts say the organization, with its control of strategic industries, commercial services, and black-market enterprises, has evolved into one of the country's most influential domestic institutions.

Crackdowns on protestors in the wake of the disputed June 2009 presidential elections have brought new scrutiny of the Guards' role. Some analysts believe IRGC influence in the political arena amounts to the irreversible militarization of Iran's government (NYT). Others, like Abbas Milani, director of Iranian studies at Stanford University, suggest the Guards' power has grown to exceed (New Republic) that of Supreme Leader Ayatollah Khamenei, who legally has final say on all state matters. But Frederic Wehrey, an adjunct senior policy analyst at the RAND Corporation and the co-author of a study on the IRGC, notes that the Revolutionary Guard is far from a cohesive unit of likeminded conservatives. Instead, he says, it's a heavily factionalized institution with a mix of political aspirants unlikely to turn on their masters.

[...]

International Adventurism

Military analysts say the Guards began deploying fighters (NPR) abroad during the Iran-Iraq War of 1980 to 1988, "export[ing] the ideals of the revolution throughout the Middle East." The Quds Force, a paramilitary arm of the Revolutionary Guard with less than a thousand people, emerged as the de facto external-affairs branch during the expansion. Its mandate was to conduct foreign policy missions--beginning with Iraq's Kurdish region--and forge relationships with Shiite and Kurdish groups. A Quds unit was deployed to Lebanon in 1982, where it helped in the genesis of Hezbollah. Another unit was sent to Bosnia to back Bosnian Muslims in their civil war in the early and mid-1990s. Some experts say the Quds Force has shipped weapons to Lebanon-based Hezbollah, Gaza-based Hamas, and Palestinian Islamic Jihad, and is also supplying munitions to the Taliban in Afghanistan and Shiite militias in Iraq. In the wake of anti-government protests throughout the Middle East in 2011, the United States and the European Union accused the Quds Force of providing equipment and support to help the Syrian regime suppress revolts in Syria. In October 2011, Washington accused the Quds Force of plotting the assassination of the Saudi ambassador (NYT) to the United States, and plotting to bomb the Israeli Embassy in Washington and the Saudi and Israeli Embassies in Argentina. Tehran denied the accusations.

The Guards' alleged involvement in Iraq has been a particular point of contention between Washington and Tehran. Former President Bush accused Iran in February 2007 of providing roadside bombs to "networks inside Iraq." A month later, coalition forces captured Ali Musa Daqduq, a Lebanese-born member of Hezbollah operating in Iraq, and Pentagon officials said Daqduq was working with the Quds Force to train Iraqi extremists in logistics, firearms, and explosives. General David Petraeus, then the top U.S. commander in Iraq, told lawmakers in September 2007 that the Quds Force was aiding militias in Iraq to "serve its interests and fight a proxy war" with coalition forces. And in a September 2007 interview with military reporters, former Multi-National Force-Iraq spokesman Major General Kevin J. Bergner said six operatives with Quds Force links had been arrested in 2007. Despite repeated Iranian denials, U.S. congressional leaders in late 2007 designated the Guards as a foreign terrorist organization, cutting off Iranian companies and individuals from the U.S. financial system.

Yet, not everyone is convinced Iran's role in Iraq is as direct as U.S. officials suggest, or its pursuit of nuclear technology is as clear-cut, as this Backgrounder explains. Likewise, some experts see the Guards' role in Afghanistan as exaggerated. While U.S. military officials have accused Iran of supplying the Afghan Taliban with weapons, CFR International Affairs Fellow George Gavrilis says there is a lack of evidence to support the charges. "Iran has a vested interest in a stable, well-governed Afghanistan," Gavrilis writes, "an interest that it has protected since the fall of the Taliban."

Syrian-born American Held for Spying

Via CNN -

A 47-year-old Syrian-born naturalized American has been charged for his alleged role in spying on Syrian protesters in the United States, the Justice Department said on Wednesday.

Mohamad Anas Haitham Soueid of Leesburg, Virginia has been charged in a conspiracy to collect video and audio recordings and other information about people "in the United States and Syria who were protesting the government of Syria and to provide these materials to Syrian intelligence agencies in order to silence, intimidate and potentially harm the protestors."

A federal grand jury charged Soueid October 5 in a six-count indictment in the Eastern District of Virginia and he was arrested on Tuesday. He will make an initial appearance before a U.S. magistrate Wednesday afternoon.

He is charged with conspiring to act and acting as an agent of the Syrian government in the United States without notifying the attorney general as required by law; two counts of providing false statements on a firearms purchase form; and two counts of providing false statements to federal law enforcement, the Justice Department said.

This comes amid Syria's seven-month-long crackdown against protesters
.

------------------------------------------------------------------------------------

US DoJ: Virginia Man Accused of Acting as Unregistered Agent of Syrian Government and Spying on Syrian Protestors in America

Soueid, aka “Alex Soueid” or “Anas Alswaid,” a Syrian-born naturalized U.S. citizen, was charged by a federal grand jury on Oct. 5, 2011, in a six-count indictment in the Eastern District of Virginia. Soueid is charged with conspiring to act and acting as an agent of the Syrian government in the United States without notifying the Attorney General as required by law; two counts of providing false statements on a firearms purchase form; and two counts of providing false statements to federal law enforcement.

[...]

The indictment states that in late June 2011, the Syrian government paid for Soueid to travel to Syria, where he met with intelligence officials and spoke with President Bashar al-Assad in private.

[...]

"In addition to the recordings, Soueid is accused of providing the Mukhabarat contact information, including phone numbers and e-mail addresses, for protesters in the United States. In a handwritten letter sent to UCC-1, Soueid allegedly expressed his belief that violence against protesters -- including raiding their homes -- was justified and that any method should be used to deal with the protesters. The indictment also alleges that Soueid provided information regarding U.S. protesters against the Syrian regime to an individual who worked at the Syrian Embassy in Washington, D.C."

Tuesday, October 11, 2011

U.S. Accuses Iranians of Plotting to Kill Saudi Envoy

Via NYTimes -

Federal authorities foiled a plot by men linked to the Iranian government to kill the Saudi Arabian ambassador to the United States and to bomb a Saudi embassy, Attorney General Eric H. Holder Jr. said in a news conference on Tuesday.

Mr. Holder said the plot began with a meeting in Mexico in May, “the first of a series that would result in an international conspiracy by elements of the Iranian government” to pay $1.5 million to murder the ambassador on United States soil.

The Saudi Arabian Embassy in Washington called the plot “a despicable violation of international norms.”

The men accused of plotting the attacks were Manssor Arbabsiar and Gholam Shakuri, both originally from Iran, according to a criminal complaint filed in federal court in Manhattan.

Mr. Holder said the men were connected to the secretive Quds Force, a division of Iran’s elite Islamic Revolutionary Guards Corps that has carried out operations in other countries. He said that money in support of the plot was transferred through a bank in New York, but that the men had not yet obtained explosives.

The Justice Department said in a statement that Mr. Shakuri, a member of the Quds force, remained at large. Mr. Arbabsiar, a naturalized American citizen, was arrested on Sept. 29. There is “no basis to believe that any other co-conspirators are present in the U.S.,” Mr. Holder said.

“In addition to holding these individual conspirators accountable for their alleged role in this plot, the United States is committed to holding Iran accountable for its actions,” he said.

A senior administration official said on Tuesday that the Treasury Department planned to announce new sanctions against the Islamic Revolutionary Guard Corps, which is already the target of heavy sanctions for its role in overseeing Iran’s nuclear program. The new sanctions will single out five senior leaders of the Guards Corps and the Quds force, the official said.

-----------------------------------------------------------------------------

FBI: Two Men Charged in Alleged Plot to Assassinate Saudi Arabian Ambassador to the United States

-----------------------------------------------------------------------------

US Treasury: Treasury Sanctions Five Individuals Tied to Iranian Plot to Assassinate the Saudi Arabian Ambassador to the United States
The U.S. Department of the Treasury today announced the designation of five individuals, including four senior Islamic Revolutionary Guard Corps-Qods Force (IRGC-QF) officers connected to a plot to assassinate the Saudi Arabian Ambassador to the United States Adel Al-Jubeir, while he was in the United States and to carry out follow-on attacks against other countries’ interests inside the United States and in another country. As part of today’s action, Treasury also designated the individual responsible for arranging the assassination plot on behalf of the IRGC-QF.

Designated today pursuant to Executive Order (E.O.) 13224 for acting for or on behalf of the IRGC-QF were: Manssor Arbabsiar, a naturalized U.S. citizen holding both Iranian and U.S. passports who acted on behalf of the IRGC-QF to pursue the failed plot to assassinate the Saudi ambassador; IRGC-QF commander Qasem Soleimani; Hamed Abdollahi, a senior IRGC-QF official who coordinated aspects of the plot and oversaw the other Qods Force officials directly responsible for coordinating and planning this operation; Abdul Reza Shahlai, an IRGC-QF official who coordinated this operation; and Ali Gholam Shakuri, an IRGC-QF official and deputy to Shahlai, who met with Arbabsiar on several occasions to discuss the assassination and other planned attacks.

McAfee Whitepaper: Combating Advanced Persistent Threats

http://www.mcafee.com/us/resources/white-papers/wp-combat-advanced-persist-threats.pdf

Advanced persistent threats (APTs)—sophisticated, covert attacks bent on surreptitiously
stealing valuable data from targeted and unsuspecting companies—can inflict serious
harm to your business. Their relentless, persistent intrusions typically target key users
within organizations to gain access to trade secrets, intellectual property, state and
military secrets, computer source code, and any other valuable information available.
And no one—from government agencies to start-ups—is immune today. You can,
however, take proactive and rigorous steps to detect APT in their early stages and
implement asset-protecting remediation.

New Symantec Research: The Motivations of Recent Android Malware

Via Symantec Connect Blog -

For years now, we in the cyber security industry have been saying an explosion of mobile malware is just around the corner. Beginning in earnest this year, we have indeed observed a marked increase in threats targeting mobile devices – particularly the Android platform. However, it’s probably not accurate to say the expected explosion has in fact occurred. The reality is that cybercriminals are still very much in the exploratory phase of figuring out how to monetize the exploitation of mobile devices. This is the topic of Symantec’s latest research. You can read the whitepaper in its entirety here (PDF).

Above all else, our analysis highlights how most current efforts to monetize mobile malware have only a low revenue-per-infection ratio. This has severely limited the return on investment achievable by attackers. It also offers detailed insight into the top current mobile malware monetization schemes observed by Symantec, including how each works and examples of the malware presently being used to carry them out. These schemes are:
  • Premium-rate number billing scams
  • Spyware
  • Search engine poisoning
  • Pay-per-click scams
  • Pay-per-install schemes
  • Adware
  • Stealing mobile transaction authentica¬tion numbers (mTAN)
However, the research also points out that the currently struggling revenue-per-infection ratio is primed to improve. The trigger will likely be advances in mobile payment-type technology and the widespread adoption of using mobile devices for both payment and accepting payment. The key is that these applications rely on devices to transmit financial information —such as mobile banking credentials—backed by real monetary funds. We’ve learned in the PC world just how lucrative the exploitation and sale of this kind of information can be for enterprising cyber criminals.

[...]

Additional potential revenue-generating schemes likely to be seen in the near future are discussed as well. These include:
  • Selling stolen International Mobile Equipment Identity (IMEI) numbers for use on previously blocked or counterfeit phones.
  • Peddling fake mobile security products—another tactic that has been highly successful in the PC realm.
The paper surmises that only if the current monetization schemes, and those likely to be seen in the near future, succeed will attackers continue to invest in the creation of Android malware.

RSA Chief Says Two Groups Responsible for SecurID Breach

Via ComputerWorld -

Six weeks after EMC's RSA security division saw its SecurID system hit by hackers, RSA president Tom Heiser met with the CIO of a large global medical device company.

The CIO wasn't happy. SecurID, an authentication system used by 40 million people in at least 30,000 organizations worldwide to securely access IT systems, had been compromised. RSA had posted a vague letter on its website on March 17, shortly after the intrusion, but details of the attack were scarce.

"The CIO was very upset," Heiser said. "It wasn't a pleasant conversation, I can assure you that."

The company was one of hundreds that RSA directly reached out to following the attack, which prompted questions about how safe it was to still use SecurID. Many corporate users have a SecurID device, which displays a temporary one-time passcode that allows them access to an IT system.

On Tuesday at RSA's security conference in London, Heiser revealed more details than have so far been known about of the attack, which RSA insists did not undermine the integrity of the entire system.

RSA, which has worked with the U.S. Federal Bureau of Investigation, the U.S. Department of Homeland Security, U.K. law enforcement and other agencies, believes that two groups were responsible for the attack. EMC Executive Chairman Art Coviello declined to identify the groups, but said that due to the sophistication of the intrusion "we can only conclude it was a nation-state sponsored attack."

Heiser said both groups had been known to authorities before, although they were not known to work together.

"What does this tell us?" Heiser asked. "Our adversary was determined, persistent and very well coordinated. They knew what to look for and where to go."

[...]

Heiser said the attacks were sophisticated: they used advanced techniques to connect to RSA's systems and used different malware, some of which was compiled just hours before an attack. The information stolen was compressed and encrypted before it was exfiltrated, making it more difficult to identify.

----------------------------------------------------------------

So you have two groups from one nation-state? Sounds like neither of them knew what the other was doing. This sounds very familiar (think Operation Aurora).

Who were these groups? I have my feelings ;)

Monday, October 10, 2011

German 'Government' R2D2 Trojan FAQ

Via Naked Security Blog (Sophos) -

What has happened?
A Trojan horse has been discovered that is capable of spying on Skype internet calls, monitoring the online activity of infected computers, logging keystrokes, and updating its functionality via the net. The Trojan, which most anti-virus vendors are calling "R2D2", but is also referred to as "0zapftis" or "Bundestrojaner", was announced by the famous Chaos Computer Club (CCC).
Why is the Trojan called R2D2?
The name comes from a string of characters embedded inside the Trojan's code: C3PO-r2d2-POE
Where did the CCC get the malware from?
German lawyer Patrick Schladt has told the media that the Trojan horse was found on the hard disk of one of his client's computers.

The malware was allegedly installed onto the computer as it passed through customs control at Munich Airport.

Schaldt was defending his client against charges that fall under German law related to pharmaceuticals.

When the suspect and his legal team examined the digital evidence against them they found evidence that suggested a Trojan had been present - and the hard disk was shared with the CCC with the permission of Schladt's client.

The CCC were able to use forensic software to restore deleted files from the hard drive, uncovering the R2D2 Trojan horse.
Why is the Trojan so newsworthy?
The CCC implies that the malware was created for, and is being used by, German law enforcement authorities such as the BKA and LKA. Furthermore, Schaldt claims that the Customs department was also involved in the planting of the malware.
[...]

Shouldn't you guys work with the law enforcement agencies and deliberately not detect their malware?
We detect all the malware that we know about - regardless of who its author may be. So, SophosLabs adds protection against attacks on our customers' computers regardless of whether they may be state-sponsored or not.

If you think about it - there is no sensible alternative. What's to stop a cybercriminal commandeering a law enforcement Trojan and using it against an innocent party?

Our customers' protection comes first. If the authorities want us to not detect their malware, the onus is on them to try to write something that we can't detect, not for us to cripple our software.

---------------------------------------------------------------------------------------------

Several German States Admit Use of Controversial Spy Software
http://www.dw-world.de/dw/article/0,,15449054,00.html

Three additional German states have admitted to deploying spyware in order to investigate serious criminal offenses, according to regional media sources.

The interior ministers of the states of Baden-Württemberg, Brandenburg and Lower Saxony said that regional police had used the software within the parameters of the law. In Lower Saxony, the software has been in use for two years, according to the public broadcaster NDR.

Authorities in Brandenburg, meanwhile, told the daily Berliner Morgenpost that they are currently using the spyware in a single, on-going investigation. Baden-Württemberg has also used such software to investigate "individual cases," according to the Badische Zeitung.

Officials in the southern German state of Bavaria were the first to confirm late Monday that their agencies have been using a spyware program since 2009. It remains unclear whether all four states had been using the same software or not.


-------------------------------------------------------------------------------

On Oct 10th, Microsoft added signatures for the R2D2 trojan, following the lead of most other AV vendors.

Three samples outlined by Sophos on VirusTotal...

Sample 1: SHA-1 = 7bd8d737460c1dbbfc4b250fb1b6b906ed643a2d
Sample 2: SHA-1 = e4f07b5a443cd99fd45cb5e1445ac2c1be4b455e
Sample 3: SHA-1 = a6a0f45180f5b3390ee2ef21fe4b89813ed641f4

Sunday, October 9, 2011

State Dept Uses Social Networks to Counter Radicalization

Via Washington Times (Oct 5, 2011) -

Anwar al-Awlaki may be dead, but the war he helped al Qaeda wage for the hearts and minds of Muslims continues — and on the battlefield of social media, the United States is fighting back with what critics say is a tiny and ineffectual army.

Fewer than 10 diplomats make up the State Department’s digital-outreach team, which is charged with countering al Qaeda’s recruitment efforts via social networks, blog posts and Internet videos, according to current and former officials.

The “eight or nine” team members hang out online with angry young Muslims to steer them away from terrorist radicalization, a senior State Department official said on background.

“We’re in the business of trying to cut down the supply of people who want to kill Americans,” the official said.

The team is part of a new interagency initiative at the State Department called the Center for Strategic Counterterrorism Communications, which President Obama established last month by executive order.

Team members declare up front that they represent the U.S. government before joining Internet bulletin boards and chat rooms where young men discuss current events and religion, the State Department official said.

The team has Urdu and Arabic speakers and is “adding Somali to the mix,” the official said. They are “focused on those people that al Qaeda is trying to recruit those young men who are vulnerable to al Qaeda’s mythologization of itself.”

Top Cartel Figure Arrested In Mexico Casino Attack

Via KSat.com (Oct 4, 2010) -

Federal authorities have arrested one of the alleged leaders of a drug cartel thought to be behind the August attack and arson at a Monterrey casino that left 52 people dead, Mexico's news agency reported Tuesday.

Jose Alberto Loera Rodriguez, nicknamed "el Voltaje," (the Jock), 28, is one of the four reputed leaders of Los Zetas, and allegedly was one of those responsible for planning and carrying out the August 25 attack on the Casino Royale, according to Notimex.

The news agency quoted Luis Cárdenas Palomino, head of the Regional Security Division of the Federal Police, as saying a reward of up to 15 million pesos (about $1 million U.S.) was offered for information leading to Loera Rodriguez's capture.

So far, 14 people have been arrested in connection with the attack.

Five suspects, all suspected Zetas members, were arrested shortly after the incident. Investigators said the men told them they carried out the attack, which occurred in an upscale section of Monterrey, because the owners of the casino had not complied with their extortion demands.

On September 2, a Nuevo Leon state police officer, Miguel Angel Barraza Escamilla, was arrested and accused of being one of the occupants of three getaway cars parked outside, based on surveillance video footage of the entrance to the casino. (On September 15, three of Barraza's family members -- his father, stepmother and stepbrother -- were killed in what a state security spokesman said was "a revenge attack" by a local cartel).

Authorities said the casino's security video shows armed men arriving in the vehicles and carrying what appear to be gallons of gasoline. They burst into the casino and, seconds later, dozens of people flee the smoke and fire. The attack appeared to last 2½ minutes, based on the video.


-------------------------------------------------------------------

STRATFOR: Reconstructing the Monterrey Arson Attack from Surveillance Footage

Russia Claims it has Detained Chinese Spy in S-300 Case

Via Guardian UK -

Russia's security service has revealed that it arrested a suspected Chinese spy who posed as a translator while seeking sensitive information on an anti-aircraft system.

The man, identified as Tun Sheniyun, was arrested on 28 October last year, the federal security service (FSB) said in a statement cited by RIA-Novosti news agency.

It was unclear why the FSB disclosed the arrest on Wednesday, less than one week before the prime minister, Vladimir Putin, travels to China on an official visit.

The alleged spy was acting "under the guise of a translator of official delegations", the statement said.

He had "attempted to obtain technological and maintenance documents on the S-300 anti-aircraft missile system from Russian citizens for money", it added. That information is a state secret, it said.

Prosecutors sent the case to court on Tuesday, the statement said. Tun faces charges of attempted espionage.

Last year, Russia delivered 15 S-300 systems to China, a popular Soviet-era arms export, as part of a deal signed several years earlier. Yet Beijing has recently turned to more modern systems.

Putin's two-day visit to China next Tuesday will be his first foreign trip since he announced his planned return to the Russian presidency next year.

Ruslan Pukhov, director of the centre for analysis of strategies and technologies, a defence thinktank in Moscow, said: "They [the Chinese] are trying to copy this system illegally. They've already copied a whole series of our weapons.

"They're trying to clone the S-300, to serve their interests and also to export. As I understand it, it's not all working out. They probably wanted extra documentation to better deal with this task of reverse engineering.

Saturday, October 8, 2011

Operation Swiper: 111 Indicted in One of the Largest Identity-Theft Cases in the U.S.

Via International Business Times (Business & Law) -

Indictments of 111 people were handed up Friday in one of the largest identity-theft busts of its kind in the United States, with thousands of victims in Europe, the Middle East, and China. Thus far, 86 people are in custody and the rest are being sought.

Five criminal enterprises operating in the Queens borough of New York have been dismantled. The theft ring included workers ranging from bank tellers to restaurant employees to other service workers. The thieves lifted credit-card data from residents and foreign tourists.

[...]

Authorities used court-approved wiretaps on dozens of phones to eavesdrop on thieves speaking Russian, Mandarin, and Arabic. The $13 million theft enterprise has been running since 2010, and specialized in selling Apple Inc. products overseas.

[...]

Police said they seized $850,000 worth of computer equipment that had been stolen from the Citigroup Building in Queens, $650,000 in cash, thousands of dollars' worth of Apple computer products, seven handguns, as well as designer watches, shoes, clothes, and bags.

"Thieves have an amazing knowledge of how to use technology," Kelly told Reuters. "The schemes and the imagination that is developing these days are days are really mind-boggling."

The Associated Press reported that bank workers, restaurant staffers, and retail employees were taught to steal credit-card numbers through a process called "skimming." After a card was swiped for payment, a worker would copy the credit-card number and additional data. This information would then be provided to a so-called manufacturer. Similar information was also stolen online.

The team of manufacturers then forged American Express, Discover, MasterCard, and Visa cards with the stolen credit-card numbers. Fake identifications were given with the stolen information.

The cards were lastly distributed to so-called criminal shoppers to make high-end purchases at stores such as Apple, Bloomingdale's, and Macy's. The items purchased would be resold in Europe, the Middle East, and China.

[...]

The criminal charges against the 111 suspects include forgery, identity theft, and robbery.


-------------------------------------------------------------------------------

Reuters: Biggest Identity Theft Bust of its Type in U.S. History
http://www.reuters.com/article/2011/10/07/us-crime-idtheft-idUSTRE7965TS20111007

Friday, October 7, 2011

Computer Virus Hits U.S. Drone Fleet

Via Wired.com -

A computer virus has infected the cockpits of America’s Predator and Reaper drones, logging pilots’ every keystroke as they remotely fly missions over Afghanistan and other warzones.

The virus, first detected nearly two weeks ago by the military’s Host-Based Security System, has not prevented pilots at Creech Air Force Base in Nevada from flying their missions overseas. Nor have there been any confirmed incidents of classified information being lost or sent to an outside source. But the virus has resisted multiple efforts to remove it from Creech’s computers, network security specialists say. And the infection underscores the ongoing security risks in what has become the U.S. military’s most important weapons system.

“We keep wiping it off, and it keeps coming back,” says a source familiar with the network infection, one of three that told Danger Room about the virus. “We think it’s benign. But we just don’t know.”

Military network security specialists aren’t sure whether the virus and its so-called “keylogger” payload were introduced intentionally or by accident; it may be a common piece of malware that just happened to make its way into these sensitive networks. The specialists don’t know exactly how far the virus has spread. But they’re sure that the infection has hit both classified and unclassified machines at Creech. That raises the possibility, at least, that secret data may have been captured by the keylogger, and then transmitted over the public internet to someone outside the military chain of command.

[...]

Use of the drives is now severely restricted throughout the military. But the base at Creech was one of the exceptions, until the virus hit. Predator and Reaper crews use removable hard drives to load map updates and transport mission videos from one computer to another. The virus is believed to have spread through these removable drives. Drone units at other Air Force bases worldwide have now been ordered to stop their use.

In the meantime, technicians at Creech are trying to get the virus off the GCS machines. It has not been easy. At first, they followed removal instructions posted on the website of the Kaspersky security firm. “But the virus kept coming back,” a source familiar with the infection says. Eventually, the technicians had to use a software tool called BCWipe to completely erase the GCS’ internal hard drives. “That meant rebuilding them from scratch” — a time-consuming effort.

The Air Force declined to comment directly on the virus. “We generally do not discuss specific vulnerabilities, threats, or responses to our computer networks, since that helps people looking to exploit or attack our systems to refine their approach,” says Lt. Col. Tadd Sholtis, a spokesman for Air Combat Command, which oversees the drones and all other Air Force tactical aircraft. “We invest a lot in protecting and monitoring our systems to counter threats and ensure security, which includes a comprehensive response to viruses, worms, and other malware we discover.”

However, insiders say that senior officers at Creech are being briefed daily on the virus.

“It’s getting a lot of attention,” the source says. “But no one’s panicking. Yet.”

Thursday, October 6, 2011

Yemen: Fallout from the al-Awlaki Airstrike

Via STRATFOR (Security Weekly) -

U.S.-born Yemeni cleric Anwar al-Awlaki, an ideologue and spokesman for al Qaeda in the Arabian Peninsula (AQAP), al Qaeda’s franchise in Yemen, was killed in a Sept. 30 airstrike directed against a motorcade near the town of Khashef in Yemen’s al-Jawf province. The strike, which occurred at 9:55 a.m. local time, reportedly was conducted by a U.S. unmanned aerial vehicle (UAV) and may have also involved fixed-wing naval aircraft. Three other men were killed in the strike, one of whom was Samir Khan, the creator and editor of AQAP’s English-language magazine Inspire.

Al-Awlaki has been targeted before; in fact, he had been declared dead on at least two occasions. The first time followed a December 2009 airstrike in Shabwa province, and the second followed a May 5 airstrike, also in Shabwa. In light of confirmation from the U.S. and Yemeni governments and from statements made by al-Awlaki’s family members, it appears that he is indeed dead this time. We anticipate that AQAP soon will issue an official statement confirming the deaths of al-Awlaki and Khan.

As STRATFOR noted Sept. 30, the deaths of both al-Awlaki and Khan can be expected to greatly hamper AQAP’s efforts to radicalize and equip English-speaking Muslims. The group may have other native English speakers, but individuals who possess the charisma and background of al-Awlaki or the graphics and editorial skills of Khan are difficult to come by in Yemen. The al Qaeda franchise’s English-language outreach is certain to face a significant setback.

This deaths of al-Awlaki and Khan and the impact their deaths will have on AQAP’s outreach efforts provide an opportunity to consider the importance of individuals — and their personal skill sets — to militant organizations, especially organizations seeking to conduct transnational media and ideological operations.

Read more: Yemen: Fallout from the al-Awlaki Airstrike

Wednesday, October 5, 2011

Delphic - Doubt (DYM Remix)



DYM (Damn You Mongolians) dubstep rework of Delphic's breakthrough single 'Doubt'

Tuesday, October 4, 2011

Insider Threat: Guard Indicted for Chinese Espionage

Via infosecisland.com -

Bryan Underwood, a former contract guard working at a U.S. Consulate in China, has been charged in a superseding indictment with one count of attempting to communicate national defense information to a foreign government, two counts of making false statements, and one count of failing to appear in court pursuant to his conditions of release.

[...]

According to the superseding indictment, from about March 1, 2011, to about Aug. 5, 2011, Underwood knowingly and unlawfully attempted to communicate photographs and other information relating to the national defense to representatives of the People’s Republic of China (PRC), with the intent and reason to believe that these materials would be used to the injury of the United States and to the advantage of a foreign nation.

The indictment further alleges that on Aug. 5, 2011, Underwood made a false statement when he stated to an FBI representative that he was intending to assist the FBI when he wrote a letter stating his “interest in initiating a business arrangement” with the PRC.

Underwood also made a false statement, according to the indictment, when he stated to an FBI representative that he was intending to assist the FBI when he took certain photographs of his place of work. Finally, the indictment alleges that Underwood failed to appear in court on Sept. 21, 2011 in accordance with the conditions of his release, after his initial arrest on Aug. 31, 2011.


-----------------------------------------------------------------

FBI: Former Guard Charged with Attempting to Communicate National Defense Information to People’s Republic of China

Monday, October 3, 2011

HTC Android Phones Leak Private User Data

Via Threatpost.com -

There is a serious security issue with a variety of HTC Android phones that enables any app with Internet permissions to access a huge amount of private data on the device, including call logs, email addresses, SMS messages, last known GPS location and more. The problem was introduced via an update to the HTC phones that installed a tool called HTCLogger that collects the data.

The issue was discovered late last week and researchers developed a proof-of-concept app that shows how much data any arbitrary app can access on the affected devices, which include the EVO 4G, EVO3D, Thunderbolt and others. The leak of what should be private data is enabled by the presence of the HTCLogger tool, according to a report on the Android Police site, and any app installed on an affected device that has Internet permissions can then access the data cache via a local port. Many Android apps have the android.permission.INTERNET permission by default.

[...]

HTC did not immediately respond to a request for comment on the issue.

The list of functions and information that the HTCLogger app can access is long, and includes both coarse and fine location data, network information, IP address, WiFi state, detailed data on the OS version and kernel, account information on the device, system logs and other data. The HTC tool was apparently meant as a way for developers to get detailed information about what is causing problems on a device. However, as the Android Police research shows, that data also can be accessed by a long list of other apps and used for other purposes.

The problem only affects HTC Android phones with the stock Sense firmware installed. Users who have rooted their phones may be able to delete the logging tool themselves. The file is located at /system/app/HtcLoggers.apk, according to the Android Police report.


-------------------------------------------------------------------

It would seem that HTC totally screwed up and didn't consider the security impact of their new application development helper tool.

Facebook and Websense Partner to Protect Users from Malicious Links

Via WebSense Security Labs -

Today, we have some exciting news. Some of you may have already heard about it, because it is big!

Starting today, we have implemented a partnership with Facebook, arguably the largest, most important platform on the globe, to better protect users against malicious links leading to malware-embedded websites and fraud.

A platform as popular as Facebook is naturally a target for attackers. We have been working with Facebook and their security teams for a number of years in order to keep their users safe, but now we have integrated directly into the platform for an unprecedented security combination.

Soon, when a user clicks on a URL that has been posted within Facebook, that link will be sent to Websense for security classification. The Websense® ThreatSeeker® Cloud, an advanced classification and malware identification platform, will then analyze the link in real time. If the destination site is considered unsafe, the user is presented with a warning page that offers the choice to continue at their own risk, return to the previous screen, or get more information on why it was flagged as suspicious.

In this way, we are helping Facebook continue their proactive fight to keep malicious links off of their platform and allow safe use for all of its members.

At Websense, we are all about innovation and changing the security game. We were the first company to promote and enable our customers to embrace safe, productive use of social with our web security gateway, the first to deliver security and anti-spam to protect companies presence within Facebook with Defensio, and now we are assisting in the protection of all users on the platform with our cloud integration.

[...]

For more information, you can view the news release here.


-----------------------------------------------------------

Kudos to Facebook for making a serious move to protect its users against malicious scams and links on the FB platform.

This should be pretty effective against the basic scams and malicious stuff that are so pervasive on the platform right now.

But it is also possible this will force the current FB platform attackers to move toward more complex scams and malware attacks on the FB platform - as they look for a way to counter the protection offered by Websense.

Sunday, October 2, 2011

Targeted Attacks and the Need to Keep Document Parsers Updated

Via Microsoft Security Blog -

Over the past few years there has been a lot of concern about “advanced persistent threat” and targeted attacks such as “spear-phishing” and “whaling”. In my discussions with security professionals in different parts of the world I have encountered many different views on the risks associated with these attacks, ranging from disbelief that they actually happen to the belief that every email with an attachment contains an exploit.

The Microsoft Security Engineering Center (MSEC) studies such attacks looking for ways to mitigate the threats to current products, such as Microsoft Office, and help engineer mitigations into future products currently under development. We have published data and insights on some of the methods attackers use to perform targeted attacks, in past volumes of the Microsoft Security Intelligence Report (SIR).

For example, in SIR volume 8 we published a study the MSEC did on document file format exploits. I want to highlight this study here because I think it helps add a little context to the topic of targeted attacks and provides actionable guidance to help manage some of the associated risks.

Document File Format Exploits

Increasingly, attackers are using common file formats as transmission vectors for exploits. Most modern e-mail and instant messaging programs are configured to block the transmission of potentially dangerous files by extension, such as .exe, .com, and .scr, which have historically been misused to transmit malware. However, these same programs typically permit the transmission of many popular file formats, like .doc, .pdf, .ppt, and .xls. These formats are used legitimately by many people every day to share information and get work done, so blocking them is often not practical. This has made them an attractive target for exploitation.

[...]

To assess the use of Microsoft Office system file formats as an attack vector, Microsoft analyzed a sample of several hundred files that were used for successful attacks in 2H09 (the second half of 2009). The data set was taken from submissions of malicious code sent to Microsoft from customers worldwide.

[...]

All nine of these vulnerabilities had security updates available at the time of attack. The affected users were exposed because they had not applied the updates. Office 2000, Office XP, Office 2003, and the 2007 Microsoft Office system were each affected by at least one of the nine vulnerabilities.

Most of the vulnerabilities exploited in the data sample were several years old, with a third of them first identified in 2006.


[...]

Users who do not keep their Office program installations up to date with service packs and security updates are at increased risk of attack.

[...]

The key things to take away from this study are:

  • Once attackers figure out how to exploit a document parser vulnerability, they will try to use that exploit for years to come.
  • Newer is better: running the latest version of document parsers and the latest service pack is a very effective mitigation against these types of attacks.
  • Keep all of your software up to date including document parsers such as Microsoft Office, Adobe Acrobat, Adobe Reader, and others.
  • Use Microsoft Update to keep your Windows based systems up to date, instead of Windows Update. Microsoft Update will help keep all of your Microsoft software updated including Windows operating systems and Microsoft Office, where Windows Update only keeps Windows operating systems up to date.
  • If you haven’t updated the document parsers you have installed on your systems, you should give serious consideration to doing so.
  • Don’t open email attachments or documents hosted on the Internet if you don’t know and trust their source.

-------------------------------------------------------------------------------------------

As a former Microsoft Systems Management Server (SMS) admin, I can tell you that patching isn't easy as it sounds and it isn't as flashy as some other threat mitigation processes....but it is critically important for organizations to have a patch process in place - it is truly the last line of defense.

In today's threat landscape, patching just IE isn't enough anymore. You have to patch OS, browser, browser plug-ins and other programs that are being used in targeted attacks (like Office) against employee endpoints.

In large enterprises, the 'patchable' software surface can be daunting to patch management administrators. Combine that feeling with the reality that many employees have the ability to install whatever they want on my corporate endpoints (due to admin rights and/or a less managed endpoint posture) and you have a patch management nightmare that seems impossible.

So what can you do?

Use threat and exploit intelligence to focus your efforts on the vulnerabilities that you know are being exploited. Patch those now...and use that protection space generated by those efforts to evaluate your specific environment and identify the next subset of programs which should be patched - using a risk-based approach.

Deadverse Recordings: iconAclass



iconAclass is the new project from MC/producer Will Brooks best known as Dälek. As front person and co-producer in the group Dälek he explored the left of center/ wall of noise world ala My Bloody Valentine meets Public Enemy on 6 studio albums.

iconAclass, his newest solo project, see him maintaining the gritty view of boom-bap he is know for, while returning to his roots. For the Ones is pure hip-hop, hypnotic heavy beats serve as more than just a backdrop for this MC. They focus a spotlight squarely on the lyrics, and iconAclass has a lot on his mind!

Pushing forward into the new millennia with DJ Motiv providing the cuts, iconAclass is the next chapter for this ever evolving musician.


http://deadverse.bandcamp.com/album/for-the-ones

Saturday, October 1, 2011

Special Op Forces Capture Haqqani Network's Top Commander in Afghanistan

Via The Long War Journal -

Coalition and Afghan special operations forces today announced the capture of the Haqqani Network's commander for Afghanistan during a raid in Paktia province on Sept. 27.

Haji Mali Khan, who is described by the International Security Assistance Force as "one of the highest ranking members of the Haqqani Network and a revered elder of the Haqqani clan," was captured during a raid in the Jani Khel district of Paktia. Security forces also captured his deputy, his bodyguard, and "multiple additional insurgents." Khan was "heavily armed" but he "submitted to the security force without incident or resistance," ISAF stated.

Khan "worked directly under Siraj Haqqani," the operational commander of the al Qaeda-linked Haqqani Network. Khan is Siraj's uncle and the brother of Jalaluddin Haqqani, the patriarch of the Haqqani family, who "consistently placed Mali Khan in positions of high importance," ISAF said.

One of Khan's duties included acting as an "an emissary between the late Baitullah Mehsud and senior leaders within the Haqqani leadership." Baitullah led the Movement of the Taliban in Pakistan before he was killed in a US Predator airstrike in August 2009.

As the top commander in Afghanistan, Khan "managed bases and had oversight of operations in both Afghanistan and Pakistan," ISAF stated. In the past year, Khan established bases for Haqqani Network fighters in the Mangal tribal areas of Paktia. He also facilitated the movement of forces from Pakistan to Afghanistan, financed terrorist operations, and served as a logistics coordinator for forces in the field.


----------------------------------------------------------------------------------

The Haqqani Network is an independent insurgent group originating in Afghanistan that is closely allied with the Taliban. Maulvi Jalaluddin Haqqani along with his son Sirajuddin Haqqani lead the Haqqani network, which is based in the Afghanistan–Pakistan border areas. According to US military commanders it is "the most resilient enemy network" and one of the biggest threats to NATO and United States forces in Afghanistan.