Thursday, November 17, 2011

U.S.-China Economic and Security Review Commission Annual Report 2011

http://www.uscc.gov/annual_report/2011/annual_report_full_11.pdf

On behalf of the U.S.-China Economic and Security Review Commission, we are pleased to transmit the Commission’s 2011 Annual Report to the Congress—the ninth major Report presented to Congress by the Commission—pursuant to Public Law 106–398 (October 30, 2000), as amended by Public Law No. 109–108 (November 22, 2005). This report responds to the mandate for the Commission "to monitor, investigate, and report to Congress on the national security implications of the bilateral trade and economic relationship between the United States and the People’s Republic of China." In this Report, the Commission reached a broad and bipartisan consensus; it approved the Report unanimously, with all 12 members voting to approve and submit it.

---------------------------------------------------------------------------------

The "Computer Network Exploitation" section starting on Page 182 discusses the RSA SecurID attack, Operation Shady RAT, Night Dragon, and Targeted Gmail attacks. Here is a little gem from the top of Page 183....
The perpetrators then used information about the compromised RSA security product in order to target a number of the firm’s customers, including at least three prominent entities within the U.S. defense industrial base. Those intrusions and intrusion attempts, according to some reports, also originated in China and appeared to be state sponsored.

Pentagon: Cyber Offense Part of U.S. Strategy

Via Washington Post -

The Pentagon is prepared to launch cyberattacks in response to hostile actions that threaten the government, military or U.S. economy, according to a new policy document submitted to Congress this week.

The report, obtained by The Washington Post, is the most detailed document so far from the government on its emerging cyberwarfare program, and it warns that adversaries attempting cyberattacks against the United States “would be taking a grave risk.”

[...]

The report is more explicit than the Pentagon’s cyberstrategy released in July, which focused on the importance of deterring attacks by building defenses that would “deny” adversaries the benefits of success. In the latest report, the Pentagon states directly that it “has the capability to conduct offensive operations in cyberspace to defend our nation, allies and interests.”

When defense-based deterrence fails to stop a hostile act, the report says, the Pentagon “maintains, and is further developing, the ability to respond militarily in cyberspace and in other domains.”

James E. Cartwright, the recently retired vice chairman of the Joint Chiefs of Staff, said the report “is a good start at documenting how the U.S. will both defend our interests in this vital domain and deter those who would threaten those interests.” Cartwright had publicly stated in July that a strategy dominated by defense would fail.

In May, the White House released an international cyberstrategy declaring that the United States reserves the right to use all necessary means — diplomatic, military and economic — to defend the nation against hostile acts in cyberspace. But it said that the United States will “exhaust all options prior to using force whenever we can” in response to a hostile act in cyberspace.

This week’s report was issued in response to a congressional requirement to answer key cyberwarfare policy questions by March 1, 2011. There was no explanation in the report for why it was months overdue.


--------------------------------------------------------

DoD Cyberspace Policy Report: A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 (Nov 2011)
http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf

Tuesday, November 15, 2011

Stolen Malaysian Government Certificate Signed Malware

Via H-Online -

A governmental digital certificate has been used to sign malware. According to a report by F-Secure, the certificate was used to sign a piece of malware which has been spread through malicious PDF files, dropped after an Acrobat Reader 8 exploit had taken place. It has been signed by "anjungnet.mardi.gov.my" – mardi.gov.my is the Malaysian Agricultural Research and Development Institute. To steal a certificate capable of signing, an attacker would need not just the certificate but also a passphrase; this could have been stolen by use of a key-logger.

The Malaysian authorities told F-Secure that the certificate had been stolen "quite some time ago"; it was valid from 29 September 2009 to 29 September 2011 and has therefore now expired, removing the advantage gained by the malware in being digitally signed in the first place – unsigned applications produce a warning when the user downloads them from the web, but valid signed applications do not. However, it is still very rare to find malware signed with a key that officially belongs to a government.


---------------------------------------------------------------------------------------

With the growth of code-signing technologies and requirements in modern operating system (e.g. Windows 7 64-bit), it is likely that the use of stolen or fraudulent certificates to sign malware will increase.

CCSS Forum - Digital Certificates Used by Malware
http://www.ccssforum.org/malware-certificates.php

Hat-tip to @diocyde for the CCSS Forum link.

APT: Anatomy of a Zero Day Attack

http://www.informationweek.com/video/security/1194518768001

Pacific Northwest National Laboratory (PNNL) CIO, Jerry Johnson, provides some lessons learned from the attacks on his organization in July -- a highly publicized attack on an organization that provides cyber security services for the Dept. of Energy.

-------------------------------------------

It is a long interview, but it is very insightful into these types of ongoing APT attacks.

STRATFOR Dispatch: Countering Iran in the Covert World

http://www.stratfor.com/analysis/20111114-dispatch-countering-iran-covert-world

Director of Analysis Reva Bhalla examines how a recent chain of Iran-related events sheds light on the geopolitical environment in which Iran’s adversaries are operating.

Read more: Dispatch: Countering Iran in the Covert World | STRATFOR

Monday, November 14, 2011

McAfee Labs: Duqu - Consolidated Threat Report

http://download.nai.com/products/mcafee-avert/dil/Duqu_CTR_v1.9.pdf

McAfee Labs Consolidated Threat Reports bring together all the verified and corroborated intelligence on highly relevant and publically critical threats and events. Our researchers and engineers continually monitor the global threat landscape and provide relevant data to both our direct customers and to the public at large. We do this to assist in risk assessment and mitigation, as well as to “serve the greater good” as we cooperate and conduct research with other agencies and communities. Our Consolidated Threat Reports combine all the up-to-the-minute information from various sources (Global Threat Intelligence, blog entries, podcasts, whitepapers, presentations, and more.)

Sunday, November 13, 2011

Iran Says Has Detected Duqu Computer Virus

Via MSNBC -

Iran said on Sunday it had detected the Duqu computer virus that experts say is based on Stuxnet, the so-called "cyber-weapon" discovered last year and believed to be aimed at sabotaging the Islamic Republic's nuclear sites.

The head of Iran's civil defense organization told the official IRNA news agency that computers at all main sites at risk were being checked and that Iran had developed software to combat the virus.

"We are in the initial phase of fighting the Duqu virus," Gholamreza Jalali, was quoted as saying. "The final report which says which organizations the virus has spread to and what its impacts are has not been completed yet.

"All the organizations and centers that could be susceptible to being contaminated are being controlled," he said.

News of Duqu surfaced in October when security software maker Symantec Corp said it had found a mysterious virus that contained code similar to Stuxnet.

While Stuxnet was aimed at crippling industrial control systems and may have destroyed some of the centrifuges Iran uses to enrich uranium, experts say Duqu appeared designed to gather data to make it easier to launch future cyber attacks.

[...]

Iran said in April it had been targeted by a second computer virus which it identified as "Stars." It was not immediately clear if Stars and Duqu were related but Jalali described Duqu as the third virus to hit Iran.

Tehran said Stuxnet had not inflicted serious damage before it was detected and blamed the United States and Israel for the virus which appeared to be aimed at crippling the nuclear program they say is aimed at making atomic weapons, a charge Iran denies.

The International Atomic Energy Agency issued a report last week that contained what it called credible evidence pointing to military dimensions to Iran's atomic activities, fueling demands in Washington and Europe for further sanctions.

Beyond Nuclear: North Korea’s Other Weapons Threat

Via The Diplomat (Nov. 12, 2011) -

North Korea’s latent nuclear weapons program is rightfully the main point of concern for its neighbors and the international community. But far less publicized is Pyongyang’s ongoing efforts to build upon its capabilities to produce and maintain chemical and biological weapons (CBW).

North Korea’s expansion of these programs is no secret to intelligence agencies around the world, and there are a number of reports detailing sites across the country dedicated to the production of CBW. The question, though how, is has Pyongyang been able to circumvent the international CBW regime so easily?

On the question of chemical weapons, this problem is easier to understand – North Korea isn’t a state party to the Chemical Weapons Convention (CWC) and has never been subject to inspections of its chemical industry facilities or sites believed associated with its CW program. Regardless, there’s little debate about the existence of the North’s CW program, with intelligence assessments from Russia, Britain, the United States and South Korea all indicating that Pyongyang continues to produce CW stocks.

Much less clear is the scope of the CW program and its level of advancement. Most assessments concur that the North has produced all of the main chemical agents such as nerve (including VX gas), blood, blister and choking agents. There’s less certainty regarding the amount of chemical agents stockpiled by the regime, although estimates range from 1,000 to 5,000 tons. However, even if the North’s program is at the low end of estimates, its capacity is bolstered by the fact that its military has a variety of sophisticated delivery vehicles for CW attacks including missiles, artillery and airborne bombs.

While Pyongyang publicly denies the need for transparency on its CW program, its production of biological weapons is muddied and concealed by weak international non-proliferation standards. Unlike the Organization for the Prohibition of Chemical Weapons (OPCW), which has robust verification standards, the Biological Weapons Convention (BWC) is plagued by the failure of its members to agree on a universal verification mechanism that would adequately ensure that all state parties are held to account for their treaty commitments.

[...]

The CBW threat emanating from Pyongyang isn’t limited to the Korean Peninsula either. North Korea is widely known for its horizontal proliferation of WMD and related materials to autocratic regimes around the world, such as Syria and Burma. There’s also the terrifying possibility that the government may – or already has – traded chemical or biological agents and suitable delivery vehicles to terrorist groups, which could weaponize them to use in an asymmetric attack. The improved ability of intelligence agencies around the world to determine weapons forensics would in theory deter such an illicit transfer, but it can’t be guaranteed – especially with a desperate leadership starved of cash.

[...]

Seoul’s new biodefense strategy has three central prongs. The first relies on detection, and has been supported by the government’s planned implementation of scanning technology at ports of entry that will be able to detect ten separate disease threats. The second pillar focuses on deterrence, which is based on South Korea’s continued investment in its hard power resources, such as medium and long range surface-to-air missiles. The final ingredient is the much needed investment in protecting South Koreans in the event of a biological attack through the development and stockpiling of vaccines.

South Korea’s CBW policy seems to be focused primarily on containment, which is of course entirely rational. However, it’s lacking a driver that can morph the North’s calculus away from producing and maintaining CBW. Beginning a serious dialogue on CBW with North Korea is necessary, and could facilitate an opening for a smoother resumption to the stalled Six Party Talks on the regime’s nuclear weapons program.

Still, Seoul must be cautious – Kim Jong-il’s regime has displayed its insincerity and belligerence on several previous occasions when such talks resumed. Attempting to include CBW in the Six Party Talks would be counterproductive and would give Pyongyang more avenues to stall and launch salvos against Korea and the United States. Instead, South Korea should dangle the CBW carrot to its neighbor and hope for dialogue, while at the same time maintaining its three-pronged strategy to keep the pressure on.

Friday, November 11, 2011

Report: FTC Nears Deal with Facebook For Opt-In Privacy Changes

Via Threstpost.com -

The deal will settle an FTC case alleging privacy violations on the social network by forcing users to opt in to any changes to default privacy settings, according to a report in the Wall Street Journal.

The FTC inquiry dates back more than two years, and followed changes to the default privacy settings that pushed some formerly private user information into the public domain, the Wall Street Journal reported. Despite efforts to quell controversy over its privacy policies since then, the company has repeatedly ired consumer advocates and some members of Congress since then. In September, Facebook pushed out changes to its 800 million members that made it easier to share information with their Facebook network and made it easier for applications that run on the platform to track and share users activities, as well.

Following the change, users noticed that the company was collecting data not only when users were logged on, but also when they were visiting other sites online, by way of a Facebook plug-in that continued to operate even when there was no active Facebook session. Congressmen Ed Markey (D-MA) and Joe Barton (R-TX), co-Chairs of the Congressional Bi-Partisan Privacy Caucus, sent a letter in September to the FTC to investigate the company's use of tracking cookies.

The exact terms of the rumored settlement aren't known, but reports suggest it would go a long way towards ending those kinds of practices. For one, Facebook would submit to independent privacy audits for 20 years settlement and to get user consent before making retroactive policy changes to its privacy. The agreement will not require users to expressly agree to all changes and feature additions on the site.


-------------------------------------------------------

Opt-in = good (for changes that might negatively impact your privacy level on FB).
Opt-in = bad (for changes that would improve user security, e.g. Default SSL Enabling).

Thursday, November 10, 2011

Music: The Troublemakers - Get Misunderstood



-----------------------------------------

Quality lounge from Supperclub presents Vol. 3 - La Salle Neige.

The Rising Threat from Nigeria's Boko Haram Militant Group

Via STRATFOR (Security Weekly) -

The U.S. Embassy in Abuja, Nigeria, issued a warning Nov. 5 indicating it had received intelligence that the Nigerian militant group Boko Haram may have been planning to bomb several targets in the Nigerian capital during the Muslim holiday of Eid al-Adha, also known as Eid al-Kabir, celebrated Nov. 6-8. The warning specifically mentioned the Hilton, Nicon Luxury and Sheraton hotels as potential targets.

The warning came in the wake of a string of bombings and armed attacks Nov. 4 in the cities of Maiduguri, Damaturu and Potiskum, all of which are located in Nigeria’s northeast. An attack also occurred in the north-central Nigerian city of Kaduna. The sites targeted in the wave of attacks included a military base in Maiduguri and the anti-terrorism court building in Damaturu. Militants reportedly attacked these two sites with suicide vehicle-borne improvised explosive devices (VBIEDs). The Nigerian Red Cross reported that more than 100 people were killed in the attacks, while some media reports claimed the death toll was at least 150.

According to AFP, a spokesman for Boko Haram claimed responsibility for the attacks Nov. 5 and threatened more attacks targeting the Nigerian government until “security forces stop persecuting our members and vulnerable civilians.” On Nov. 7, a Boko Haram spokesman claimed that his group employed only two suicide operatives in the attacks and not 12 as reported by some media outlets.

Though Eid al-Kabir passed without attacks on Western hotels in Abuja, a deeper examination of Boko Haram is called for, with a specific focus on its rapidly evolving tactical capabilities.

Read more: The Rising Threat from Nigeria's Boko Haram Militant Group | STRATFOR


----------------------------------------------------------------------------------

CFR Backgrounder: Boko Haram
http://www.cfr.org/africa/boko-haram/p25739

Boko Haram, an Islamist religious sect, has targeted Nigeria's police, rival clerics, politicians, and public institutions with increasing violence since 2009.

Deloitte: Cyber Intelligence - Tech Trends 2011

http://www.deloitte.com/view/en_US/us/Services/consulting/all-offerings/hot-topics/technology-2011/ec9391571d80e210VgnVCM3000001c56f00aRCRD.htm

In 2010, security and privacy graduated from IT department concerns. C-suites and boardrooms took notice of highly visible incidents, ranging from malware-infected motherboards from top-tier PC manufacturers, to information theft from a leading cloud provider, to the manipulation of the underlying routing tables of the internet redirecting traffic to Chinese networks. At the same time, the regulatory environment around sensitive data protection has become more rigorous, diverse and complex. Organizations are aware of the shifting threat profile and are working to deal with technical barriers as well as sophisticated criminal elements. Incidents are increasingly originating in the trust vector – due to inadvertent employee behavior via the sites they visit, the posts they access on social media sites or even the devices they bring with them to the workplace. A “protect-the-perimeter and respond-when-attacked” mentality is no longer sufficient.

Yet the vast majority of businesses in 2011 have only limited capabilities to detect and react to point-in-time breaches. Vulnerabilities are understood based on past events – not based on emerging cyber threats or on the actual risk profile of the organization.

Cyber intelligence represents a vastly more sophisticated and full set of threat management tactics, providing tools to move to a more proactive "over the horizon" threat awareness posture. Cyber analytics looks to detect patterns across systems, networks, physical security logs and external cyber-threat intelligence analysis to predict future attacks. Cyber forensics is moving beyond root-cause analysis to include tracking of where attacks came from and detailed tracing of what they were doing after the infiltration. Cyber logistics adopts an outside-in view of security, protecting against compromises in the value chain – from upstream suppliers to personnel sourcing. Powerful tools can allow advanced incident response, triaging “how” and “from where” attacks originated. And cyber security remains a key component – creating identity, access and control frameworks to safeguard assets, while embedding enforcement policies and procedures throughout the organization.

In 2011, security incidents remain nearly unavoidable. By building cyber intelligence capabilities, the impact of incidents can be contained, the source of threats understood and learnings codified into controls that can help prevent future incidents. But beyond developing broader disciplines, organizations must embrace security and privacy as foundational to their business. Cyber intelligence efforts need to be championed by the C-suite, funded as a strategic priority and empowered to become part of the operational genome of the company.

Wednesday, November 9, 2011

Your Questions: Kenya's Campaign Against Al-Shabab

Via Voice of America (VOA) News -

Kenya sent troops into Somalia last month in pursuit of al-Shabab, which it blames for a series of cross-border kidnappings. Since then, Kenya has faced the threat (and reality) of retaliation, confusion has emerged over which countries are supporting the military operation, and Eritrea has come under suspicion of arming al-Shabab. Most recently, Kenya said it is moving in on key militant areas in Somalia.

VOA's East Africa correspondent Gabe Joselow answered your questions about Kenya's pursuit of al-Shabab in a live Q&A Wednesday (Video).

Operation Ghost Click - International Cyber Ring That Infected Millions of Computers Dismantled

http://www.fbi.gov/news/stories/2011/november/malware_110911/malware_110911

Six Estonian nationals have been arrested and charged with running a sophisticated Internet fraud ring that infected millions of computers worldwide with a virus and enabled the thieves to manipulate the multi-billion-dollar Internet advertising industry. Users of infected machines were unaware that their computers had been compromised—or that the malicious software rendered their machines vulnerable to a host of other viruses.

Details of the two-year FBI investigation called Operation Ghost Click were announced today in New York when a federal indictment was unsealed. Officials also described their efforts to make sure infected users’ Internet access would not be disrupted as a result of the operation.

The indictment, said Janice Fedarcyk, assistant director in charge of our New York office, “describes an intricate international conspiracy conceived and carried out by sophisticated criminals.” She added, “The harm inflicted by the defendants was not merely a matter of reaping illegitimate income.”

Beginning in 2007, the cyber ring used a class of malware called DNSChanger to infect approximately 4 million computers in more than 100 countries. There were about 500,000 infections in the U.S., including computers belonging to individuals, businesses, and government agencies such as NASA. The thieves were able to manipulate Internet advertising to generate at least $14 million in illicit fees. In some cases, the malware had the additional effect of preventing users’ anti-virus software and operating systems from updating, thereby exposing infected machines to even more malicious software.

“They were organized and operating as a traditional business but profiting illegally as the result of the malware,” said one of our cyber agents who worked the case. “There was a level of complexity here that we haven’t seen before.”

[...]

The six cyber criminals were taken into custody yesterday in Estonia by local authorities, and the U.S. will seek to extradite them. In conjunction with the arrests, U.S. authorities seized computers and rogue DNS servers at various locations. As part of a federal court order, the rogue DNS servers have been replaced with legitimate servers in the hopes that users who were infected will not have their Internet access disrupted.

It is important to note that the replacement servers will not remove the DNSChanger malware—or other viruses it may have facilitated—from infected computers. Users who believe their computers may be infected should contact a computer professional. They can also find additional information in the links on this page, including how to register as a victim of the DNSChanger malware.


--------------------------------------------------------------------------------------

Trend Micro: Esthost Taken Down – Biggest Cybercriminal Takedown in History
http://blog.trendmicro.com/esthost-taken-down-%E2%80%93-biggest-cybercriminal-takedown-in-history/

On November 8, a long-living botnet of more than 4,000,000 bots was taken down by the FBI and Estonian police in cooperation with Trend Micro and a number of other industry partners. Two data centers in New York City and Chicago were raided and a command & control (C&C) infrastructure consisting of more than 100 servers was taken offline. At the same time the Estonian police arrested several members in Tartu, Estonia.

Open Source Duqu Analysis Tool Sharing Update

Via NSS Labs -

Last Friday, NSS researchers announced their findings on Duqu on a blog post http://www.nsslabs.com/blog/2011/11/duqu-analysis-and-detection-tool.html. We also pointed to our open source tool https://github.com/halsten/Duqu-detectors that we've shared with the security research community. Since posting, the tool has been viewed over 18,000 times and 45 different forks have been created from the github repository in the few days it has been up.

We've set out to make a positive contribution to the community by giving code because we felt that taking action would yield the most positive results and would help others take action as well.

Today, CrySyS labs has released a great toolkit to detect duqu http://www.crysys.hu/duqudetector.html. It is open source and has compiled binaries ready for usage. They are taking action by helping the community and kudos to them for their contributions to detection for the community.


-----------------------------------------------------------------------------------------------------------------------------

CrySyS Duqu Detector Toolkit
http://www.crysys.hu/duqudetector.html

We developed a detector toolkit that combines simple detection techniques to find Duqu infections on a computer or in a whole network. The toolkit contains signature and heuristics based methods and it is able to find traces of infections where components of the malware are already removed from the system.

The intention behind the tools is to find different types of anomalies (e.g., suspicious files) and known indicators of the presence of Duqu on the analyzed computer. As other anomaly detection tools, it is possible that it generates false positives. Therefore, professional personnel is needed to elaborate the resulting log files of the tool and decide about further steps.

Tuesday, November 8, 2011

U.N. Report Cites Secret Nuclear Research by Iran

Via Washington Post -

The United Nation’s nuclear watchdog said Tuesday it has “serious concerns” that Iran is secretly working toward building a nuclear bomb, citing documents pointing to extensive and possibly ongoing research by Iranian scientists on mastering the technology needed for atomic weapons.

The International Atomic Energy Agency cited “credible” intelligence--provided by 10 countries and extensively vetted over many months--that directly contradicts Iran’s claims that its nuclear intentions are entirely peaceful.

“The information indicates that Iran has carried out activities relevant to the development of a nuclear device,” the IAEA said in report prepared for the U.N. agency’s 35-nation board of directors.

It said Iran’s nuclear research appears to have been conducted through 2003 under a formal, structured program that addressed technical challenges such as warhead design and testing of nuclear detonators. While much of the research was halted that year by order of the country’s top leaders, “some activities may still be ongoing,” the report said.

Iran dismissed the allegations as a politically driven attempt to further isolate the Islamic republic, and said the documents cited by U.N. officials were forgeries.

While the IAEA has previously confronted Iran over alleged weapons research, the agency took the unusual step of releasing a 14-page dossier that describes in sometimes minute detail how Iranian scientists pursued highly specific information, skills and materials used in nuclear warhead design. The dossier was drawn form more 1,000 pages of Iranian documents and reports that were judged by U.N. inspectors to be “sufficiently comprehensive and complex . . . that it is not likely to have been the result of forgery or fabrication,” the report said.

The documents enabled the IAEA to reconstruct what the report describes as a secret command structure overseeing work in technical areas ranging from uranium-metal fabrication to designing an underground chamber where tests could be conducted. Iran appears to have procured parts and critical technical help from weapons experts from other countries, the report said.


-------------------------------------------------------------------------------------------------------------------------------------

IAEA: Implementation of the NPT Safeguards Agreement and relevant provisions of Security Council resolutions in the Islamic Republic of Iran (Nov 8, 2011)
http://isis-online.org/uploads/isis-reports/documents/IAEA_Iran_8Nov2011.pdf

-------------------------------------------------------------------------------------------------------------------------------------

CFR: IAEA Iran Report Decoded
http://www.cfr.org/iran/iaea-iran-report-decoded/p26451

Sunday, November 6, 2011

Microsoft Malware Protection Center Threat Report - Poison Ivy

https://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27871

This Microsoft® Malware Protection Center (MMPC) Threat Report provides an overview of the Win32/Poison (Poison Ivy) family of malware. The Report examines the background and functionality of Poison Ivy, and provides telemetry data and analysis. This Report also discusses how Poison Ivy is detected and removed by Microsoft antimalware products and services.

---------------------------------------------------------------------------------------------------------

Poison Ivy has been identified in a number of APT attacks against corporations (e.g RSA and Chemical Industry Nitro Attacks) and human right organizations. ZXShell is another favorite backdoor.

In one case study, outlined by Mandiant in 2010, they found 10 different Poison Ivy variants (along with other malware, including some custom) on an attack of a smaller enterprise (2000 systems) - all attributed to a single APT group.

http://www.mandiant.com/uploads/presentations/SOH_Infragard_120910.pdf (Case Study starts on Page 44)

Saturday, November 5, 2011

Operation Odysseus: Leader Dies in Colombian Military Operation

Via CNN -

The leader of Colombia's main leftist rebel group -- the Revolutionary Armed Forces of Colombia -- died in a military operation in the country's southwest, President Juan Manuel Santos said Saturday.

"I confirm the death of Alfonso Cano. The No. 1 of FARC is dead," Santos said. "This is the most overwhelming blow given to the FARC in all of Colombia's history."

The military operation that took place Friday in the state of Cauca also killed Cano's communications chief, a female friend and members of his security team, Defense Minister Juan Carlos Pinzon told reporters. Cano's chief of security was captured.

"The death of Alfonso Cano is the most important historical mark of our military forces and our national police in our fight against the FARC organization," Pinzon said. "He was part of the organization for over 33 years. He was their ideologue, their political figure and most importantly, he was a despised terrorist ready to act in a radical way ..."

Cano, an alias for Guillermo Leon Saenz, took over the FARC's top spot in March 2008 after an apparent heart attack killed the former leader, Manuel Marulanda.


----------------------------------------------------------------------------

STRATFOR Dispatch: FARC Leader Killed in Colombia
http://www.stratfor.com/analysis/20111107-dispatch-farc-leader-killed

The Revolutionary Armed Forces of Colombia (FARC or FRAC-EP) is a Marxist–Leninist revolutionary guerrilla organization based in Colombia which is involved in the ongoing Colombian armed conflict. FARC is a violent non-state actor (VNSA), described as a terrorist group by the Colombian government, the United States Department of State, the Canadian government, the Chilean government, the New Zealand Government, and the European Union.

FARC receives most of its funding—which has been estimated to average some $300 million per year—from taxation of the illegal drug trade, ransom kidnappings, bank robberies, and extortion of large landholders, multinational corporations, and agribusiness. Human Rights Watch estimates that the FARC has the majority of child combatants in Colombia, estimating that approximately one quarter of the guerrillas are under 18 years of age.

NSS Labs: Duqu Analysis & Detection Tool

http://www.nsslabs.com/blog/2011/11/duqu-analysis-and-detection-tool.html

NSS engineers have developed a scanning tool that can be used to detect all DuQu drivers installed on a system. This tool was developed in the hopes that additional drivers can be discovered to allow us to learn more about the functionality, capabilities and ultimate purpose of DuQu.

Based on layout of the drivers discovered so far, the NSS tool is capable of detecting 100% of drivers with zero false positives. Because it is using advanced pattern recognition techniques, it is also capable of detecting new drivers as they are discovered. Two new drivers were discovered after the tool was completed, and both were detected by the NSS tool with no updates required.

Thursday, November 3, 2011

In Report, U.S. Accuses China, Russia of Cyber Espionage

Via Threatpost -

In its most blunt statement to date, the U.S. government accused both China and Russia of conducting far flung cyber espionage campaigns against U.S. and other Western firms in an effort to promote domestic interests.

The report, "Foreign Spies Stealing US Economic Secrets in Cyberspace" was prepared by the Office of the National Counterintelligence Executive. It found that cyber espionage on the part of China and Russia - and even from U.S. allies - is a "pervasive threat" to U.S. interests that surpasses even the threat posed by traditional forms of spying.

[...]

"We judge that the governments of China and Russia will remain aggressive and capable collectors of sensitive US economic information and technologies, particularly in cyberspace," the report says.

Foreign governments engaged in cyber espionage are interested in a wide range of information, including information and communications technologies, information on the location of scarce natural resources that can benefit foreign firms, as well as military and civilian technologies.

The report, part of an annual assessment of foreign economic data collection and industrial espionage, accumulates the work of a slew of military branches as well as the FBI, Department of Energy, State Department, and intelligence agencies like the NSA and CIA. It is a departure from earlier reports in that it focuses on cyber espionage. The advent of the Internet and digital technology has made it easy for foreign entities to collect enormous quantities of data quickly and with little risk, the report concludes.

While foreign entities use malicious software and Web- and network based attacks to gain a foothold on sensitive networks, cyber is by no means the only vector used. Foreign governments have been known to use Requests for Information (RFI), solicitation of marketing, conferences and joint research projects to gather information.


--------------------------------------------------------------------------------------

ONCIX: FOREIGN ECONOMIC AND INDUSTRIAL ESPIONAGE (2011 Report)
http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf

Wednesday, November 2, 2011

Supercomputers Used to Analyze Stockpile-to-Target Sequence in Nuclear Weapons

Via Washington Post -

A group of nuclear weapons designers and scientists at the Lawrence Livermore National Laboratory conducted a what-if experiment several years ago, deploying supercomputers to simulate what happens to a nuclear weapon from the moment it leaves storage to the point when it hits a target.

They methodically worked down a checklist of all the possible conditions that could affect the B-83 strategic nuclear bomb, the most powerful and one of the most modern weapons in the U.S. arsenal, officials said. The scientists and designers examined how temperature, altitude, vibration and other factors would affect the bomb in what is called the stockpile-to-target sequenceSuch checks typically have been carried out by taking bombs and warheads apart; scrutinizing them using chemistry, physics, mathematics, materials science and other disciplines; and examining data from earlier nuclear explosive tests. This time, however, the scientists and designers relied entirely on supercomputer modeling, running huge amounts of code.

Then came a surprise. The computer simulations showed that at a certain point from stockpile to target, the weapon would “fail catastrophically,” according to Bruce T. Goodwin, principal associate director at Livermore for weapons programs. Such a failure would mean that the weapon would not produce the explosive yield expected by the military — either none at all, or something quite different than required to properly hit the target.

“So we went in and thoroughly investigated that, and determined that the way the weapon is handled by the military had to be changed, or you would be susceptible to having the weapons fail catastrophically when, God forbid, they should ever be used,” Goodwin said. He added that the fault occurred in the “real dynamics of the vehicle” — a term describing the weapon’s trajectory and behavior — and could not have been revealed by underground explosive testing or by examining the components.

Following the discovery and a multi-year effort, the B-83 bombs and the military’s handling procedures for the weapons have been fixed, officials said.

Tuesday, November 1, 2011

Duqu: Status Updates Including Installer with Zero-Day Exploit Found

Via Symantec Security Response Blog -

The group that initially discovered the original Duqu binaries, CrySyS, has since located an installer for the Duqu threat. Thus far, no-one had been able to recover the installer for the threat and therefore no-one had any idea how Duqu was initially infecting systems. Fortunately, an installer has recently been recovered due to the great work done by the team at CrySyS.

The installer file is a Microsoft Word document (.doc) that exploits a previously unknown kernel vulnerability that allows code execution. We contacted Microsoft regarding the vulnerability and they're working diligently towards issuing a patch and advisory. When the file is opened, malicious code executes and installs the main Duqu binaries.

[...]

The Word document was crafted in such a way as to definitively target the intended receiving organization. Furthermore, the shell-code ensured that Duqu would only be installed during an eight-day window in August. Please note that this installer is the only installer to have been recovered at the time of writing—the attackers may have used other methods of infection in different organizations. Unfortunately, no robust workarounds exist at this time other than following best practices, such as avoiding documents from unknown parties and utilizing alternative software. Fortunately, most security vendors already detect and block the main Duqu files, thereby preventing the attack.

Once Duqu is able to get a foothold in an organization through the zero-day exploit, the attackers can command it to spread to other computers. In one organization, evidence was found that showed the attackers commanding Duqu to spread across SMB shares. Interestingly though, some of the newly infected computers did not have the ability to connect to the Internet and thereby the command-and-control (C&C) server. The Duqu configuration files on these computers were instead configured not to communicate directly with the C&C server, but to use a file-sharing C&C protocol with another compromised computer that had the ability to connect to the C&C server. Consequently, Duqu creates a bridge between the network's internal servers and the C&C server. This allowed the attackers to access Duqu infections in secure zones with the help of computers outside the secure zone being used as proxies.

While the number of confirmed Duqu infections is still limited, using the above techniques we have seen Duqu spread across several countries. At the time of writing, Duqu infections have been confirmed in six possible organizations in eight countries.

The confirmed six possible organizations and their countries of presence include:
  • Organization A - France, Netherlands, Switzerland, Ukraine
  • Organization B - India
  • Organization C - Iran
  • Organization D - Iran
  • Organization E - Sudan
  • Organization F - Vietnam

Note that some organizations are only traceable back to an ISP and therefore all six may not be separate organizations. Furthermore, due to grouping by IP addresses, we cannot definitively identify the organizations.

Other security vendors have reported infections in the following countries:
  • Austria
  • Hungary
  • Indonesia
  • United Kingdom
  • Iran - infections different from those observed by Symantec

[...]

You can find our updated whitepaper (version 1.3) here. In addition to further technical details we have added a 'Diagnostics' appendix for system administrators, which contains Duqu traces that may indicate an infection.

Evidence of Advanced Persistent Threat: A Case Study of Malware for Political Espionage

https://sites.google.com/site/valkyriexsecurityresearch/announcements/aptpaperacceptedbymalware2011conference/Final_Paper_v3.1.pdf

Abstract

A political figure in Hong Kong continuously receives spear-phishing emails that encourage clicking on shortcuts or opening attachments with file extensions, such as .pdf, .doc(x), .xls(x), .chm, and so on. He suspects that such emails were actively sent from seemingly known parties during the pre- and postelection periods. The emails and samples were sent to us for investigation, and two nearly identical samples were chosen for the case study. These malwares appear to be the first Advanced Persistent Threat (APT) incident to undergo detailed study in Hong Kong. APT is defined by MANDIANT as a cyber attack launched by a group of sophisticated, determined, and coordinated attackers who systematically compromise the network of a specific target or entity for a prolonged period. The malware performs the following functions similar to those of “Operation Shady RAT”, it attempts to hide itself from known anti-virus programs, downloads and executes additional binaries, enumerates all file information in the hard disk, gathers email and instant messaging passwords from victims, collects screen captures, establishes outbound encrypted HTTP connections, sends all gathered intelligence to a Command and Control, and deletes all temporary files of the collected information from the victims’ machine after uploading. The forensic findings lead us to believe that APT is a real threat in Hong Kong.

Frankie Li, Anthony Lai, DDL
Valkyrie-X Security Research Group
{ran2,drakfloyd,dll}@vxrl.org

Monday, October 31, 2011

Operation Ghost Stories: FBI Releases Russian Spy Ring Papers, Video

Via Fox News -

The FBI on Monday released surveillance tapes, photos and hundreds of pages of documents that shed new light on operation "Ghost Stories," the bureau's investigation of a ring of Russian sleeper agents that ended after more than a decade in the biggest spy swap since the Cold War.

Called illegals because they took civilian jobs instead of operating inside Russian embassies and military missions, the spies, including New York real estate agent Anna Chapman, mostly settled into quiet lives in middle-class neighborhoods.

Their long-range assignment from Moscow: burrow deep into U.S. society and cultivate contacts with academics, entrepreneurs and government policymakers on subjects from defense to finance.

The heavily-edited files provide a glimpse into the intensive surveillance the deep cover agents were under, in some cases for almost a decade, showing the middle-class spies with their children, shopping or in one case attending a graduation ceremony.

The code name Ghost Stories appears to refer to the ring's efforts to blend invisibly into the fabric of American society. An FBI spokesman said the decision to release the material on Halloween was coincidental.

[...]

The U.S. swapped the 10 deep cover agents for four Russians imprisoned for spying for the West at a remote corner of a Vienna airport on July 9, in a scene reminiscent of the carefully-choreographed exchange of spies at Berlin's Glienicke Bridge during the Cold War.

While freed Soviet spies typically kept a low profile after their return to Moscow, Chapman became a lingerie model, corporate spokeswoman and television personality. Donald Heathfield, whose real name is Andrey Bezrukov, lists himself as an adviser to the president of a major Russian oil company on his LinkedIn account. President Dmitry Medvedev awarded all 10 of the freed deep-cover operatives Russia's highest honors at a Kremlin ceremony.

------------------------------------------------------------------------------

FBI: Operation Ghost Stories - Inside the Russian Spy Case
http://www.fbi.gov/news/stories/2011/october/russian_103111/russian_103111
The arrests of 10 Russian spies last year provided a chilling reminder that espionage on U.S. soil did not disappear when the Cold War ended. The highly publicized case also offered a rare glimpse into the sensitive world of counterintelligence and the FBI’s efforts to safeguard the nation from those who would steal our vital secrets.

Our case against the Russian Foreign Intelligence Service (SVR) operatives—dubbed Operation Ghost Stories—went on for more than a decade. Today we are releasing dozens of still images, surveillance video clips, and documents related to the investigation as part of a Freedom of Information Act request.

Libya's Prime Minister Confirms Presence of Chemical Weapons

Via Fox News (Oct 30, 2011) -

Libya's interim prime minister has confirmed the presence of chemical weapons in Libya and says foreign inspectors would arrive later this week to deal with the issue.

Prime Minister Mahmoud Jibril said Sunday that Libya has no interest in keeping such weapons.

Last week, Ian Martin, the top U.N. envoy to Libya, told the U.N. Security Council that undeclared chemical weapons sites have been located in Libya.

Jibril did not provide any details about the chemical weapons.

In August, Fox News interviewed Rep. Mike Rogers, R.-Mich., who said he saw a chemical weapon stockpile in the country during a 2004 trip. At the time, he said the U.S. was concerned about "thousands of pounds of very active mustard gas."

He also said there is some sarin gas that is unaccounted for.

A Russian-drafted U.N. resolution, to be voted on this week, calls on Libyan authorities to destroy stockpiles of chemical weapons in coordination with international authorities.

In February, the U.S. State Department told reporters that some chemical weapons remained in the country and the U.S. government was encouraging the Libyans to secure the sites.

Read more: http://www.foxnews.com/world/2011/10/30/libyas-prime-minister-confirms-presence-chemical-weapons/

Sunday, October 30, 2011

CSIS Report: Canada Spy Agency Warned Gov Weeks Before Crippling Cyber Attack

Via The Globe and Mail (Canada) -

Canada's spy agency warned the government that federal departments were under assault from rogue hackers just weeks before an attack crippled key computers.

A newly released intelligence assessment, prepared last November, sounded a security alarm about malicious, targeted emails disguised as legitimate messages — the very kind that shut down networks two months later.

“The systems and networks used by various Canadian government departments have been attacked directly or indirectly,” says the Canadian Security Intelligence Service report.

A declassified copy of the top secret intelligence assessment, Cyberattacks on Canadian Government Departments: An Overview, was obtained by The Canadian Press under the Access to Information Act.

Extensive portions of the Nov. 4, 2010, report — including what are likely direct references to foreign suspects — have been excised due to ongoing sensitivity of the material.

“Canada has been engaged in detecting, monitoring and mitigating a series of ongoing and evolving ... cyberattacks directed against the computer systems and networks used by Canadian government departments,” says the CSIS document.

[...]

Employee Internet access at the Treasury Board and Finance departments — whose systems are shared — was cut off in January after what officials called “an unauthorized attempt” to break into the networks.

A routine evaluation of both departments last year revealed they had not been following all of the government's information technology security requirements.

Records previously released under the access law show government employees in a number of departments were advised last January of attempts to break into their systems, only days before one of the attempts succeeded.

The CSIS assessment notes the “tools and techniques used in these attacks are in a constant state of development and incorporate new computer-related technologies and Internet-related capabilities.”

[...]

In its annual public report last June, the spy service said cyberattacks launched through the Internet were the fastest growing form of espionage.

Attackers target computer systems in search of technology, intellectual property, military strategy and commercial or weapons-related information, the annual report said.

Why a Cybersecurity Treaty Is a Pipe Dream

Via Council on Foreign Relations (Op-Ed for CNN) -

With companies and governments seemingly incapable of defending themselves from sophisticated cyber attacks and infiltration, there is almost universal belief that any durable cybersecurity solution must be transnational. The hacker – a government, a lone individual, a non-state group – stealing valuable intellectual property or exploring infrastructure control systems could be sitting in Romania, China, or Nigeria, and the assault could transit networks across several continents. Calls are therefore growing for a global treaty to help protect against cyber threats.

As a step in that direction, the British government is convening next week the London Conference on Cyberspace to promote new norms of cybersecurity and the free flow of information via digital networks. International diplomacy like this among states and private stakeholders is important and will bring needed attention to these issues. But the London summit is also likely to expose major fault lines, not consensus, on the hardest and most significant problems. The idea of ultimately negotiating a worldwide, comprehensive cybersecurity treaty is a pipe dream.


Read more: Why a Cybersecurity Treaty Is a Pipe Dream

Saturday, October 29, 2011

Anonymous Threatens to Expose Zeta Cartel's Secrets

Via Houston Chronicle (Oct 28, 2011) -

An international group of online hackers is warning a Mexican drug cartel to release one of its members, kidnapped from a street protest, or it will publish the identities and addresses of the syndicate's associates, from corrupt police to taxi drivers, as well as reveal the syndicates' businesses.

The vow is a bizarre cyber twist to Mexico's ongoing drug war, as a group that has no guns is squaring off against the Zetas, a cartel blamed for thousands of deaths as well as introducing beheadings and other frightening brutality.

[...]

He also implies that the group will expose mainstream journalists who are somehow in cahoots with the Zetas by writing negative articles about the military, the country's biggest fist in the drug war.

"We demand his release," says the Anonymous spokesman, who is wearing a mask like the one worn by the shadowy revolutionary character in the movie V for Vendetta, which came out in 2006. "If anything happens to him, you sons of (expletive) will always remember this upcoming November 5."

The person reportedly kidnapped is not named, and the video does not share information about the kidnapping other than that it occurred in the Mexican state of Veracruz during a street protest.

Anonymous draws its roots from an online forum dedicated to bringing sensitive government documents and other material to light.

If Anonymous can make good on its threats to publish names, it will "most certainly" lead to more deaths and could leave bloggers and others open to reprisal attacks by the cartel, contends Stratfor, an Austin-based global intelligence company.

"In this viral world on the Internet, it shows how much damage could be done with just one statement on the Web," said Fred Burton of Stratfor, which published a report Friday that probes the implications of the cartel drawing the activists' ire.

Mike Vigil, the retired head of international operations for the Drug Enforcement Administration, said the Zetas must take Anonymous seriously.

"It is a gutsy move," Vigil said. "By publishing the names, they identify them to rivals, and trust me, they will go after them."

The Nitro Attacks: Stealing Secrets from the Chemical Industry

http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_nitro_attacks.pdf

Introduction

This document discusses a recent targeted attack campaign directed primarily at private companies involved in the research, development, and manufacture of chemicals and advanced materials. The goal of the attackers appears to be to collect intellectual property such as design documents, formulas, and manufacturing processes. In addition, the same attackers appear to have a lengthy operation history including attacks on other industries and organizations. Attacks on the chemical industry are merely their latest attack wave. As part of our investigations, we were also able to identify and contact one of the attackers to try and gain insights into the motivations behind these attacks. As the pattern of chemical industry targets emerged, we internally codenamed the attack campaign Nitro.

The attack wave started in late July 2011 and continued into mid-September 2011. However, artifacts of the attack wave such as Command and Control (C&C) servers are also used as early as April 2011 and against targets outside the chemical industry. The purpose of the attacks appears to be industrial espionage, collecting intellectual property for competitive advantage.

Targets

The attackers have changed their targets over time. From late April to early May, the attackers focused on human rights related NGOs. They then moved on to the motor industry in late May. From June until mid-July no activity was detected. At this point, the current attack campaign against the chemical industry began. This particular attack has lasted much longer than previous attacks, spanning two and a half months.

A total of 29 companies in the chemical sector were confirmed to be targeted in this attack wave and another 19 in various other sectors, primarily the defense sector, were seen to be affected as well. These 48 companies are the minimum number of companies targeted and likely other companies were also targeted. In a recent two week period, 101 unique IP addresses contacted a command and control server with traffic consistent with an infected machine. These IPs represented 52 different unique Internet Service Providers or organizations in 20 countries.

Companies affected include:

  • Multiple Fortune 100 companies involved in research and development of chemical compounds and advanced materials.
  • Companies that develop advanced materials primarily for military vehicles.
  • Companies involved in developing manufacturing infrastructure for the chemical and advanced materials industry.

[...]

Attribution

The attacks were traced back to a computer system that was a virtual private server (VPS) located in the United States. However, the system was owned by a 20-something male located in the Hebei region in China. We internally have given him the pseudonym of Covert Grove based on a literal translation of his name. He attended a vocational school for a short period of time specializing in network security and has limited work experience, most recently maintaining multiple network domains of the vocational school.

Covert Grove claimed to have the U.S.-based VPS for the sole purpose of using the VPS to log into the QQ instant message system, a popular instant messaging system in China. By owning a VPS, he would have a static IP address. He claims this was the sole purpose of the VPS. And by having a static IP address, he could use a feature provided by QQ to restrict login access to particular IP addresses. The VPS cost was RMB200 (US$32) a month. While possible, with an expense of RMB200 a month for such protection and the usage of a U.S.-based VPS, the scenario seems suspicious. We were unable to recover any evidence the VPS was used by any other authorized or unauthorized users. Further, when prompted regarding hacking skills, Covert Grove immediately provided a contact that would perform ‘hacking for hire’. Whether this contact is merely an alias or a different individual has not been determined.

We are unable to determine if Covert Grove is the sole attacker or if he has a direct or only indirect role. Nor are we able to definitively determine if he is hacking these targets on behalf of another party or multiple parties.


------------------------------------------------------------------------------------

Here is a little gem (missed by many) in Symantec's Nitro Attacks Report....

Page 3:
"Figure 2 shows the country of origin of the organizations targeted by these attacks. While the US and UK again figure highly here, overall the geographical spread is different. This means that the infected computers are rarely located within the organizations’ headquarters or country of origin."
In attempting to explain this, Symantec misses one another option: attackers like to target people that share their native language - making for easier social engineering attacks.

Friday, October 28, 2011

Android Orphans: Visualizing a Sad History of Support

http://theunderstatement.com/post/11982112928/android-orphans-visualizing-a-sad-history-of-support

The announcement that Nexus One users won’t be getting upgraded to Android 4.0 Ice Cream Sandwich led some to justifiably question Google’s support of their devices. I look at it a little differently: Nexus One owners are lucky. I’ve been researching the history of OS updates on Android phones and Nexus One users have fared much, much better than most Android buyers.

I went back and found every Android phone shipped in the United States1 up through the middle of last year. I then tracked down every update that was released for each device - be it a major OS upgrade or a minor support patch - as well as prices and release & discontinuation dates. I compared these dates & versions to the currently shipping version of Android at the time. The resulting picture isn’t pretty - well, not for Android users....


-------------------------------------------------------------------------

This is one case where Apple's full vertical market control of their phone product is a positive.

Carriers have never been good about applying OS patches on mobile phones. It was less important when each carrier had a different OS, but as they increasingly converge toward Android...the bad guys are watching the number of mobile devices that can be exploited with one attack plan increasing in front of them very quickly - all thanks to the carriers themselves.

STRATFOR: Dissecting a Mexican Cartel Bombing in Monterrey

Via STRATFOR (Security Weekly) -

Early Oct. 20, a small sedan apparently filled with cartel gunmen rapidly pulled in front of a military vehicle, drawing the military patrol into a car chase in downtown Monterrey, Mexico. After a brief pursuit, the vehicle carrying the cartel gunmen turned at an intersection. As the military vehicle slowed to negotiate the turn, an improvised explosive device (IED) concealed in a parked car at the intersection detonated. The incident appears to have been intended to lure the military patrol into a designated attack zone. While the ambush did not kill any soldiers, it did cause them to break off their chase.

Though this IED ambush is interesting in itself for a number of reasons, we would like to use it as a lens to explore a deeper topic, namely, how STRATFOR analyzes a tactical incident like this.

Read more: Dissecting a Mexican Cartel Bombing in Monterrey | STRATFOR


-------------------------------------------------------------------------------------

STRATFOR Dispatch: Implications of a Mexican Drug Lord's Capture
http://www.stratfor.com/analysis/20111027-dispatch-implications-mexican-drug-lords-capture
Vice President of Tactical Intelligence Scott Stewart discusses the arrest of Rafael Cardenas Vela and what it means for the Gulf Cartel and for security in Mexico’s northeast.

Thursday, October 27, 2011

U.S. Drone Base in Ethi­o­pia is Operational

Via Washington Post -

The Air Force has been secretly flying armed Reaper drones on counterterrorism missions from a remote civilian airport in southern Ethi­o­pia as part of a rapidly expanding U.S.-led proxy war against an al-Qaeda affiliate in East Africa, U.S. military officials said.

The Air Force has invested millions of dollars to upgrade an airfield in Arba Minch, Ethi­o­pia, where it has built a small annex to house a fleet of drones that can be equipped with Hellfire missiles and satellite-guided bombs. The Reapers began flying missions earlier this year over neighboring Somalia, where the United States and its allies in the region have been targeting al-Shabab, a militant Islamist group connected to al-Qaeda.

[...]

The Washington Post reported last month that the Obama administration is building a constellation of secret drone bases in the Arabian Peninsula and the Horn of Africa, including one site in Ethi­o­pia. The location of the Ethio­pian base and the fact that it became operational this year, however, have not been previously disclosed. Some bases in the region also have been used to carry out operations against the al-Qaeda affiliate in Yemen.

The Air Force confirmed Thursday that drone operations are underway at the Arba Minch airport. Master Sgt. James Fisher, a spokesman for the 17th Air Force, which oversees operations in Africa, said that an unspecified number of Air Force personnel ­are working at the Ethio­pian airfield “to provide operation and technical support for our security assistance programs.”

The Arba Minch airport expansion is still in progress but the Air Force deployed the Reapers there earlier this year, Fisher said. He said the drone flights “will continue as long as the government of Ethi­o­pia welcomes our cooperation on these varied security programs.”

China's Internet Users Targeted in Online Rumour Probes

Via BBC -

China is intensifying restrictions on internet use after official reports revealed that three people have been "punished for spreading false rumours" online.

Authorities say they are carrying out inquiries into other suspected cases.

The news comes just over a week after Communist Party leaders agreed a list of "cultural development guidelines".

They include increased controls over social media and penalties for those spreading "harmful information".

The Xinhua news agency quotes regulators as saying that efforts will be stepped up "to stop rumours and punish individuals and websites spreading rumours".

It says a university student was detained after being accused of posting a fake news story about a man killing eight village chiefs in the south-western province of Yunnan.

It goes on to report that a website editor was issued with a warning after publishing a story about an air force fighter crash without confirming the facts.

And it says that a Shanghai resident was held in police custody for 15 days after accusations he had posted a falsified income tax document online.

The agency says China has 485 million registered web users.

"We have seen a tightening of control under the Hu Jintao government," said Sarah McDowall, Asia-Pacific regional manager at IHS Global Insight.

"Officials are particularly worried by the rise in popular protests and will have observed the fall of Gaddafi last week. With China facing a leadership change next year, the government feels it cannot soften its stance."

SecureWorks: Duqu Trojan Questions and Answers

http://www.secureworks.com/research/threats/duqu/

The Dell SecureWorks Counter Threat UnitSM (CTU) research team has been analyzing an emerging malware threat identified as the Duqu trojan. This Trojan horse has received a great deal of attention because it is similar to the infamous Stuxnet worm of 2010. This report includes answers to questions about this threat. CTU researchers have put countermeasures in place to detect Duqu C2 traffic, and they continue to monitor for new Duqu samples and update protections as needed.

Chinese Military Suspected in Hacker Attacks on U.S. Satellites

Via Bloomberg BusinessWeek -

Computer hackers, possibly from the Chinese military, interfered with two U.S. government satellites four times in 2007 and 2008 through a ground station in Norway, according to a congressional commission.

The intrusions on the satellites, used for earth climate and terrain observation, underscore the potential danger posed by hackers, according to excerpts from the final draft of the annual report by the U.S.-China Economic and Security Review Commission. The report is scheduled to be released next month.

“Such interference poses numerous potential threats, particularly if achieved against satellites with more sensitive functions,” according to the draft. “Access to a satellite‘s controls could allow an attacker to damage or destroy the satellite. An attacker could also deny or degrade as well as forge or otherwise manipulate the satellite’s transmission.”

A Landsat-7 earth observation satellite system experienced 12 or more minutes of interference in October 2007 and July 2008, according to the report.

Hackers interfered with a Terra AM-1 earth observation satellite twice, for two minutes in June 2008 and nine minutes in October that year, the draft says, citing a closed-door U.S. Air Force briefing.

The draft report doesn’t elaborate on the nature of the hackers’ interference with the satellites.


-----------------------------------------------------------------------------

Hackers Targeted U.S. Government Satellites
http://www.wired.com/threatlevel/2011/10/hackers-attack-satellites/

Wednesday, October 26, 2011

Google Funded Project Confirms Vast Potential for Geothermal Energy

Via Forbes -

When people talk about alternative energy, they typically discuss the potential of wind and solar projects. Don’t get me wrong – there’s a vast potential in those technologies. But often left out of the discussion is the vast potential for geothermal energy – using the natural heat under the Earth’s surface to produce electricity. Harnessing that energy is one of the cleanest, sustainable ways to produce electricity, and it also has the benefit of being more space efficient than, say, a wind farm.

Of course, like any natural resource, the question becomes – where best to build geothermal plants? To answer that question, researchers at Southern Methodist University, funded by Google.org, compiled data from over 35,000 sites to build a complete picture of geothermal potential in the United States. Their findings? There is a vast potential for geothermal energy that can be tapped with technology existing today. You can check out the mapping for yourself on Google Earth by going here and downloading the info.

How much energy? you ask. Well, the researchers based their estimates on what current technology is able to extract – not any hypothetical future advances. Even so, it turns out that there is three million megawatts of potential geothermal energy below the surface of the United States. That’s ten times the energy of every coal plant in the United States online today.

That’s an enormous potential for much cleaner energy than what we use today.

Mitsubishi Heavy Industries Admits Hackers May Have Snatched Secrets

Via Computerworld (Oct 25, 2011) -

Japan's largest defense contractor backpedaled yesterday, saying it's possible some secrets had been stolen by hackers who broke into the company's network and planted malware in August. The acknowledgement came several weeks after Mitsubishi Heavy Industries, confirming that scores of its servers and PCs had been infected, denied any information had been pilfered.

Previously, a U.S.-based Mitsubishi Heavy spokesman had said that although attackers had uncovered company IP (Internet Protocol) addresses, the attack "was caught at an early stage." But yesterday the company changed its tune, saying that more investigation had revealed a possible loss of information.

"The company recently confirmed unintended transferring of some information on the company's products and technologies between servers within the company," said Mitsubishi Heavy in a statement. "Based on the finding, the company investigated the incident further and recognized the possibility of some data leakage from the server in question."

The company declined to confirm that any diversion of data related to defense or nuclear technologies took place. Mitsubishi Heavy's admission came on the same day that the Japanese newspaper Asahi Shimbun cited unnamed sources who said data on company-built fighter jets, helicopters and nuclear power plants had apparently been stolen during the attack.

Tuesday, October 25, 2011

McAfee Says Duqu No Threat To Utilities

Via CRN -

Security vendor McAfee has told utilities that the Duqu malware posed no threat, a concern raised by its similarities to the Stuxnet worm that attacked industrial control systems in Iran’s nuclear facility last year.

In a conference call Monday, David Hatchell, utilities account manager for McAfee, said there was “nothing to worry about at this point.”

“It (Duqu) is not targeting industrial control systems that we know of, and it’s not targeting any energy (companies) as far as we know,” Hatchell said.

[...]

“We can clearly see that this is used for espionage,” Peter Szor, senior director of research at McAfee Labs, said during the conference call. Very different industries have been targeted, including a hotel chain. While there was no confirmation from Iran, military industries in the country also could have been targeted. “Basically the goal of the malware is speculation at this point,” he said.

[...]

Szor said the company believes the drivers for Duqu were compiled in November 2010. The keylogger portion of Duqu, which records keyboard strokes, was compiled three months earlier. Szor believes earlier variants of Duqu may have been used to steal data in preparation for the Stuxnet attack. “That’s why I think personally that Duqu was a bit earlier than Stuxnet,” he said.

Variations of Duqu have been confirmed in England, Iran and the U.S., with reports of the Trojan in Austria, Hungary and Indonesia, McAfee said. Similarities to Stuxnet include the same malware-hiding rootkit, use of a stolen certificate authority from Taiwan to enable installation and a set timeframe for operation. Duqu was timed to delete itself after 36 days and the certificate was stolen from C-Media Electronics, according to McAfee.

-----------------------------------------------------------------

McAfee Labs: Duqu – Threat Research and Analysis
http://blogs.mcafee.com/wp-content/uploads/2011/10/Duqu1.pdf

Hackers Likely Have Japanese Warplane, Nuclear Data

Via InformationWeek -

Hackers targeting Japan's defense industry likely obtained sensitive information relating to military warplanes, missiles, as well as design and safety information for nuclear power plants.

On Monday, sources close to the Japanese defense ministry said that while data relating to confidential national security matters didn't appear to have been breached, sensitive information had been stolen, reported the Japan Times.

[...]

Earlier this month, both Mitsubishi Heavy and Kawasaki Heavy Industries suffered attacks after hackers stole email addresses for senior executives at defense contractors, reported the Daily Yomiuri. The email addresses were stolen earlier this year from the Society of Japanese Aerospace Companies (SJAC), an industry association that counts numerous Japanese aeronautics, space, and defense-related import businesses as members and partners.

The recent attack against Mitsubishi Heavy and Kawasaki Heavy Industries followed attacks against numerous Japanese defense contractors over the summer. They came to light when Mitsubishi Heavy filed a complaint to Tokyo police in September, saying that its website had been breached by an attack that targeted 45 company servers, resulting in 38 computers in 11 locations being infected with more than 50 different types of viruses.

Those viruses apparently enabled the attackers to steal data from Mitsubishi Heavy relating to warplanes, nuclear plants, as well as Japan's Type 80 ASM-1 missile, which can be used against ships. Notably, the locations infected by the viruses included the Kobe and Nagasaki shipyards, which build submarines and destroyers, as well a facility in Nagoya that's building a guided missile system, reported Asahi Shimbun.

Meanwhile, in the most recent attack--involving SJAC--the attacker used the industry association as a stepping stone to the defense contractors. "The hacker targeted the industry association, which has inadequate security. We assume the hacker attempted to use it to spread computer viruses throughout the nation's defense industry," a senior Japanese police official told the Daily Yomiuri. Similar attacks were launched against Kawasaki Heavy Industries, and the attacker appeared to have stolen at least some of that company's emails.

But police said that before breaching SJAC, the attacker first exploited a PC at an international telephone service company located in Tokyo. The attacker used that PC to send an email--presumably with a malicious attachment--to someone at SJAC. The malicious attachment was opened, and a PC at SJAC compromised. From there, the attacker used the PC to access an internal server containing the names and email addresses for senior executives at Japanese defense contractors.

Next, the attacker sent one or more emails from the exploited PC at SJAC, supposedly from an SJAC executive, to defense contractors. In the case of Kawasaki Heavy Industries, the email subject line read, "Prior distribution of documents," and the message included a malicious file attachment titled "Comments on lump sum procurement." Interestingly, the email's subject line and contents were virtually identical to a message that the executive had sent, just 10 hours prior.

Japan's defense contractors aren't the only institutions being targeted by attackers. On Tuesday, Asahi Shimbun reported that a Trojan application sent as an email attachment to Japanese legislators had enabled attackers to spy on lawmakers for at least a month. Once the Trojan application had infected a targeted PC, it downloaded malware from a server in China, enabling the attackers to steal usernames and passwords.

---------------------------------------------------------------

Sophos: Japanese Parliament Hit By Cyber Attack
http://nakedsecurity.sophos.com/2011/10/25/japanese-parliament-hit-by-cyber-attack/

STRATFOR: Mexican Cartel Smuggling Routes


Source: http://www.stratfor.com/content/areas-mexican-cartel-smuggling-routes

Linux 'Tsunami' Backdoor Ported to Target OS X Systems

Via ESET Blog -

We’ve just come across an IRC controlled backdoor that is enables the infected machine to become a bot for Distributed Denial of Service attacks. The interesting part about it is that it’s a Mach-O binary – targeting Mac OS X.

ESET’s research team compared this to samples in our malware collection and discovered that this code is derived from something we’ve seen before. It is actually an OS X port of the Linux family of backdoors that we have been detecting since 2002 as Linux/Tsunami.

The analyzed sample contains a hardcoded list of IRC servers and channel that it attempts to connect to. This client then listens and interprets commands from the channel.

[...]

In addition to enabling DDoS attacks, the backdoor can enable a remote user to download files, such as additional malware or updates to the Tsunami code. The malware can also execute shell commands, giving it the ability to essentially take control of the affected machine.

In terms of functionality, the Mac variant of the backdoor is similar to its older Linux brother, with only the IRC server, channel and password changed and the greatest difference being that it’s a 64-bit Mach-O binary instead of an ELF binary.

Monday, October 24, 2011

Tunisia's Voters Go to the Polls in Arab Spring's First Election

Via The Guardian UK -

People queue to vote as candidates from 110 political parties and scores of independents bid to join Tunisia's new 217-seat government. Turnout in the first free election in Tunisian history was thought to have been high. The Islamist An-Nahda party is expected to win the biggest share of the vote.



-----------------------------------------------------------------------

CFR: Tunisia at the Crossroads
http://www.cfr.org/tunisia/tunisia-crossroads/p26254

"In many ways, the election process may be just as important as the results. A free and fair election would be a first in Tunisia, and strong voter turnout will signal public support for the transition process. As long as voting proceeds without significant irregularities, the international community should applaud the elections as a significant step toward democracy."

Sunday, October 23, 2011

SpyEye Changes Phone Numbers to Hijack Out of Band SMS Security

Via Trusteer Blog (Oct 5, 2011) -

The Trusteer research team recently uncovered a stealth new attack carried out by the SpyEye Trojan that circumvents mobile SMS (short message service) security measures implemented by many banks. Using code we captured while protecting a Rapport user, we discovered a two-step web-based attack that allows fraudsters to change the mobile phone number in a victim’s online banking account and reroute SMS confirmation codes used to verify online transactions. This attack, when successful, enables the thieves to make transactions on the user’s account and confirm the transactions without the user’s knowledge.

[...]

Out-of-Band is not a Panacea

This latest SpyEye configuration demonstrates that out-of-band authentication (OOBA) systems, including SMS-based solutions, are not fool-proof. Using a combination of MITB (man in the browser injection) technology and social engineering, fraudsters are not only able to bypass OOBA but also buy themselves more time since the transactions have been verified and fly under the radar of fraud detection systems. The only way to defeat this new attack once a computer has been infected with SpyEye is using endpoint security that blocks MITB techniques. Without a layered approach to security, even the most sophisticated OOBA schemes can be made irrelevant under the right circumstances.

Suspected Russian Spy Couple Arrested in Germany

Via New York Post -

A married couple were arrested in Germany accused of spying for Russia's foreign intelligence service for more than 20 years.

German federal police arrested the two suspected spies in Marburg, central Germany, and Balingen, southwestern Germany, last Tuesday, German magazine Der Spiegel reported Saturday.

Police, who believe the alleged spies had been working in Germany since the KGB was still in operation, reportedly walked in on the woman while she was listening to encoded radio transmissions. Both suspects deny the allegations.

Authorities began investigating the couple after the FBI busted a Russian spy ring in the US last year.


----------------------------------------------------------

According to a rough translation of the original Der Spiegel article, the couple are suspected SVR 'illegals', just like the spy ring busted by the FBI in June 2010.

http://www.spiegel.de/politik/deutschland/0,1518,793325,00.html (German)

Friday, October 21, 2011

STRATFOR: Reflections on the Iranian Assassination Plot

Via STRATFOR (Security Weekly) -

On Oct. 11, the U.S. Department of Justice announced that two men had been charged in New York with taking part in a plot directed by the Iranian Quds Force to kill Saudi Arabia’s ambassador to the United States, Adel al-Jubeir, on U.S. soil.

Manssor Arbabsiar and Gholam Shakuri face numerous charges, including conspiracy to use a weapon of mass destruction (explosives), conspiracy to commit an act of terrorism transcending national borders and conspiracy to murder a foreign official. Arbabsiar, who was arrested Sept. 29 at John F. Kennedy International Airport in New York, is a U.S. citizen with both Iranian and U.S. passports. Shakuri, who remains at large, allegedly is a senior officer in Iran’s Quds Force, a special unit of the Islamic Revolutionary Guard Corps (IRGC) believed to promote military and terrorist activities abroad.

Between May and July, Arbabsiar, who lives in the United States, allegedly traveled several times to Mexico, where he met with a U.S. Drug Enforcement Administration (DEA) confidential informant who was posing as an associate of the Mexican Los Zetas cartel. The criminal complaint charges that Arbabsiar attempted to hire the DEA source and his purported accomplices to kill the ambassador. Arbabsiar’s Iranian contacts allegedly wired two separate payments totaling $100,000 in August into an FBI-controlled bank account in the United States, with Shakuri’s approval, as a down payment to the DEA source for the killing (the agreed-upon total price was $1.5 million).

Much has been written about the Arbabsiar case, both by those who believe the U.S. government’s case is valid and by those who doubt the facts laid out in the criminal complaint. However, as we have watched this case unfold, along with the media coverage surrounding it, it has occurred to us that there are two aspects of the case that we think merit more discussion. The first is that, as history has shown, it is not unusual for Iran to employ unconventional assassins in plots inside the United States. Second, while the DEA informant was reportedly posing as a member of Los Zetas, we do not believe the case proves any sort of increase in the terrorist threat emanating from the United States’ southern border.

Read more: Reflections on the Iranian Assassination Plot | STRATFOR


---------------------------------------------------------------------------------

While many foreign policy and terrorism experts look at the recent alleged Iranian plot with skepticism, STRATFOR outlines similarities between the recent plot and previous Iranian assassination plots in both the US and Europe.

ETA Declares Peace. Is Spain Ready to Believe It?

Via Time.com (World) -

The words Spaniards have waited 43 years to hear finally came on Thursday evening. In a video sent to a handful of media outlets, three masked figures wearing the typical beret of the Basque country appeared on screen and declared, "ETA has decided to bring its armed activity to a definitive cessation." And with that, the separatist violence that has plagued Spain for more than four decades — and left 829 people dead — appeared to end.

It was, in many ways, a death foretold. In the past several years, ETA, which was formed in 1959 to fight for an independent Basque homeland and committed its first attack in 1968, has grown progressively weaker, while the demands for peace have only increased, spreading even to the group's historical allies. But the news still left Spaniards debating the reasons for the declaration and, perhaps more significantly for the peace process, wondering if they could trust it.

It's no surprise that this happened," says Ignacio Sánchez-Cuenca, political scientist at Madrid's Juan March Institute and author of several books about ETA. "I'm simplifying here, but you can see two basic causes: the fact that as ETA has diminished, it has been easier for the police to control, while at the same time, the support for a political solution among the Basque nationalist left has grown."

Cooperation between Spanish, French, and Portuguese authorities has decimated ETA's leadership in recent years, leaving the band with what experts estimate are only 50 active members. Seven hundred convicted members of the separatist group are currently serving prison sentences, and ETA has staged no attacks since March 2010, and none on Spanish soil since June 2009.

For security expert Ignacio Cosidó, member of parliament for the opposition Popular Party, those efforts explain why ETA has said it is abandoning violence. "The declaration is due above all to the efficiency of police and security forces," he says. "ETA finds itself so weak that it really had no other choice."

Read more: http://www.time.com/time/world/article/0,8599,2097522,00.html


------------------------------------------------------------------------

ETA or Euskadi Ta Askatasuna ("Basque Homeland and Freedom") is an armed Basque nationalist and separatist organization. The group was founded in 1959 and has since evolved from a group promoting traditional Basque culture to a paramilitary group with the goal of gaining independence for the Greater Basque Country. ETA is the main organisation of the Basque National Liberation Movement and is the most important participant in the Basque conflict. ETA declared ceasefires in 1989, 1996, 1998 and 2006, but subsequently broke them. However, on 5 September 2010, ETA declared a new ceasefire that is still in force — moreover, on 20 October 2011 ETA announced a "definitive cessation of its armed activity".

The European Union and the United States list ETA as a terrorist organization in their relevant watch lists. The United Kingdom lists ETA as a terrorist group under the Terrorism Act 2000. The Canadian Parliament listed ETA as a terrorist organization in 2003.

Symantec: Duqu Status Update #1

Via Symantec Security Response Blog -

As mentioned in our previous blog, W32.Duqu was first brought to our attention by a research lab who had been investigating a targeted attack on another organization. This research was conducted by the Laboratory of Cryptography and System Security (CrySyS) in the Department of Telecommunications, Budapest University of Technology and Economics. CrySyS identified the infection and observed its similarity to W32.Stuxnet. They stated that no data was leaked as part of this attack.

We are grateful to CrySyS—sharing their findings allowed us to identify further attacks taking place. We have now determined that the originally targeted organization was one of a limited number of targets which include those in the industrial infrastructure industry. CrySyS has issued a statement regarding their analysis here: http://www.crysys.hu/.

The latest version of our white paper includes new information, such as details on further components we observed being downloaded onto a compromised machine. We will continue to provide updates to our white paper as further information comes to light.