Monday, June 13, 2011

APT: International Monetary Fund Reportedly Hacked

Via H-Online -

Although no statement has been released on the web site of the International Monetary Fund (IMF), it has been reported by the New York Times and Bloomberg that the IMF has been the victim of a "large and serious" cyber attack. The full extent of the attack has not been revealed, but it has been said that the attackers were able to plant software on a computer within the IMF which enabled them to have some level of external access to its network. The software may well have been planted as a result of a targeted spear phishing attack; the IMF’s chief information officer, Jonathan Palmer, sent out an email warning employees of “increased phishing activity”. The World Bank took the problem seriously and, as a precaution, severed the network connection that allows the two organisations to share data.

According to the Bloomberg report, the attack appears to have been mounted by a foreign government, although no specific country was named. The same report quoted an unnamed source as stating that the IMF lost a "large quantity" of data which included emails and other documents. Some of the information held by the IMF is highly sensitive, much of it dealing with countries suffering financial difficulties and the negotiations in which they are involved. Very large sums of money are involved in these negotiations, around £56 billion last year in emergency loans.


------------------------------------------------------------------------

What Defines an APT?
McAfee Labs summarized it well in their 2011 Threat Predictions whitepaper (PDF). The generally accepted definition of an APT is one that describes a targeted cyber espionage or cyber sabotage attack that is carried out under the sponsorship or direction of a nation-state for something other than a pure financial/criminal reason or political protest. Not all APT attacks are highly advanced and sophisticated, just as not every highly complex and well-executed targeted attack is an APT. The motive of the adversary, not the level of sophistication or impact, is the primary differentiator of an APT attack from a cybercriminal or hacktivist one.

Suspected APT Attacks Against Other Financial Institutions
Other financial institutions such as the French Ministry of Finances and Canadian Finance Department and Treasury Board have also been the victim of hacks this year.

French Ministry of Finances
In December 2010, The French Ministry of Finance detected an attack, which appeared to target documents related to the G20 summit and the French G20 presidency. According to McAfee, over 150 computers in the ministry were infiltrated through targeted spear phishing emails containing a malicious attachments.

Canadian Finance Department and Treasury Board
A federal cabinet minister reported that, hackers, perhaps from China, compromised computers in two Canadian government departments in early January 2011. According to the CBC and other Canadian news organizations, a technique that is sometimes known as “executive spear phishing” was utilized. At the same time, other employees in the departments received e-mails that falsely appeared to come from the senior officials that included malicious Adobe PDF attachments. Reports indicate the attackers were targeting financial records.

Nissan LEAF Cars Leaks Speed, Position, Destination to RSS Feeds

Via H-Online -

A developer has found that the in-car electronics on the Nissan LEAF all-electric car leaks telemetry information to RSS feeds. The in-car electronics, CARWINGS, allows drivers to access their own selected RSS feeds which are then read to them.

But when Casey Halverson added his own feeds to the system, he found that his Apache server logs held more than just a request for the RSS data. The GET request for the RSS feed also included his latitude, longitude, speed, direction, and destination latitude and longitude.

"All of these lovely values are being provided to any third party RSS provider you configure" writes Halverson; there are no warnings that this information is being sent and it is not possible to disable it. The information is only provided when the RSS feed is requested, so it cannot be used as a vehicle tracker but it does offer real-time snapshots. The IP address shown for the request appears to belong to Hitachi Automotive Systems in Japan, which may indicate that the RSS request is being proxied by a Nissan data center; whether this will make the problem easier to fix is unclear.

Halverson has created a demonstration RSS feed for LEAF drivers which will read back the details that are being leaked. He has also created a "less evil" RSS feed which will give weather information for the car's current location. The issue is a good demonstration of the next generation of privacy problems.


---------------------------------------------------------------------

I think Nissan has some serious explaining to do...

Time to pull that Privacy officer out of HR / Marketing and get him/her into the engineering side of the house too ;)

Friday, June 10, 2011

Microsoft's Ten Immutable Laws of Security (v2.0)

http://blogs.technet.com/b/msrc/archive/2011/06/09/june-advance-notification-service-and-10-immutable-laws-revisited.aspx

Ten years ago, Microsoft penned the “Ten Immutable Laws of Security,” which debuted on TechNet. It was written before the rise of – among other technologies and trends – cloud computing, social networking, widespread smartphone adoption, and Windows XP, to name but a few landmarks along the way. Did a decade of change mutate the Immutables? How can understanding the Laws lead to smarter security for everyone from corporations to home users? We invite you to read “Ten Immutable Laws of Security 2.0” and see for yourself.

-----------------------------------------------------------------------

The 10 Immutable Laws

  • Law #1: If a bad guy can persuade you to run his program on your computer, it's not solely your computer anymore.
  • Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore.
  • Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore.
  • Law #4: If you allow a bad guy to run active content in your website, it's not your website any more.
  • Law #5: Weak passwords trump strong security.
  • Law #6: A computer is only as secure as the administrator is trustworthy.
  • Law #7: Encrypted data is only as secure as its decryption key.
  • Law #8: An out-of-date antimalware scanner is only marginally better than no scanner at all.
  • Law #9: Absolute anonymity isn't practically achievable, online or offline.
  • Law #10: Technology is not a panacea.

Thursday, June 9, 2011

Bin Laden Documents Sharpen US Aim

Via Yahoo! News (AP) -

The U.S. is tracking possible new terror targets and stepping up surveillance of operatives previously considered minor al-Qaida figures after digging through the mountain of correspondence seized from Osama bin Laden's hideout, officials say. The trove of material is filling in blanks on how al-Qaida operatives work, think and fit in the organization, they say.

The new information is the result of five weeks of round-the-clock work by a CIA-led team of data analysts, cyber experts and translators who are 95 percent finished decrypting and translating the years of material and expect to complete the effort by mid-June, two U.S. officials say.


Al-Qaida operatives worldwide are feeling the heat, with at least two of them altering their travel plans in recent weeks in apparent alarm that they might become the targets of another U.S. raid, one official said.

[...]

There is nothing in the bin Laden files so far to indicate an imminent attack, three officials said. The U.S. has increased its vigilance regarding some of the targets bin Laden suggests to his operatives, from smaller U.S. cities to mass transport systems, to U.S. embassies abroad and even oil tankers in the Persian Gulf.

A law enforcement official briefed on the process said investigators have been analyzing raw digital data found on multiple hard drives and flash drives, and that some of it consists of sequences of numbers. Investigators were trying to discern potential bank account or phone numbers that might point to al-Qaida contacts in the United States or elsewhere, or codes that could produce other leads, said the official, who was not authorized to publicly discuss the analysis and spoke on condition of anonymity.


--------------------------------------------------------------------------------------

On June 8, 2011, Al-Qaida's As-Sahab Media Foundation released a new recorded message from Dr. Ayman al-Zawahiri, al-Qaida's longtime No. 2 and presumed operational head, mourning the death of Usama Bin Laden.

Flashpoint Partners has the full translation here [PDF].

Some Top Android Apps Put Data at Risk w/ Insecure Password Storage

via WSJ.com (Digits Blog) -

You’d think the spate of Internet security breaches this spring would have companies on their toes. But when it comes to wireless apps, some are still making rookie mistakes. Computer security firm viaForensics has found the applications for top Internet companies LinkedIn Corp., Netflix, Inc., Foursquare and Square, Inc. stored various forms of users’ personal data in plain text on a mobile device, putting sensitive information at risk to computer criminals.

The Android applications of LinkedIn, Netflix and Foursquare stored user names and passwords in unencrypted form on their Google-powered devices. Storing that data in plain text violates a commonly accepted best practice in computer security. Since many people tend to use the same usernames and passwords across any number of sites, the failing could help hackers penetrate other accounts.

ViaForensics also found the iPhone version of Square’s mobile payments app exposed a user’s transaction amount history and the most recent digital signature of a person who signed an electronic receipt on the app. A hacker would need skill and luck to exploit the vulnerabilities –- either via physical access to a person’s phone or through malicious software that is installed on the device — scenarios that could open bigger security risks than those created by the password problem alone.

Still, the opening is a concern. “Data should not be stored on a phone,” said Andrew Hoog, chief investigative officer of viaForensics, which is based in Chicago. If data is stored on a phone, he said, it should be encrypted.


----------------------------------------------------------------------

Earlier this year, OWASP announced a new "Mobile Security Project" with a new Mobile Top 10 Risks list (currently in draft). This “Top 10” initiative is intended to help organizations determine how to best apply development and security resources to better protect their mobile applications and data. This insecure storage of client-side data is the first risk in the list.

Mobile Code Security: Guide to Improving the Security of Your Mobile Application
http://www.veracode.com/security/mobile-code-security

Wednesday, June 8, 2011

EFF: How to Disable Facebook's Facial Recognition Feature & Control Photo Tagging



EFF shows you three ways to delete your facial fingerprint data from Facebook and shows you a privacy setting that lets you ensure that you are the only person who can see tags identifying you in photographs.

-----------------------------------------------------

As always Facebook would "love" for everyone to share everything with the world (and with them), therefore this new feature is enabled by default (aka opt-out).

Privacy advocates and security professionals [i.e. those paid to be paranoid] and Europe greatly prefer features which are disabled by default (aka opt-in).

Tuesday, June 7, 2011

Java SE Critical Patch Update - June 2011

http://www.oracle.com/technetwork/topics/security/javacpujune2011-313339.html

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply CPU fixes as soon as possible. This Critical Patch Update contains 17 new security fixes across Java SE products.

---------------------------------------------------------

The updated version is Java SE/JRE 6 Update 26.

Verify Your Java Version (if enabled in your browser)
http://java.com/en/download/installed.jsp?detect=jre&try=1

You can update your Java by using the automatic update feature in the "Update" tab of the Java Control Panel in Windows.

Hackers Exploit Flash Bug in New Attacks Against Gmail Users

Via CSO Online -

Adobe today confirmed that the Flash Player bug it patched Sunday is being used to steal login credentials of Google's Gmail users.

The vulnerability was patched yesterday in an "out-of-band," or emergency update. The fix was the second in less than four weeks for Flash, and the fifth this year. A weekend patch is very unusual for Adobe.

"We have reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message," said Adobe spokeswoman Wiebke Lips in response to questions today. "The reports we received indicate that the current attacks are targeting Gmail specifically. However, we cannot assume that other Web mail providers may not be targeted as well."

According to Adobe's advisory, the Flash vulnerability is a cross-site scripting bug.

Cross-site scripting flaws are often used by identity thieves to hijack usernames and passwords from vulnerable browsers. In this case, browsers themselves are not targeted; rather, attackers are exploiting the Flash Player browser plug-in, which virtually every user has installed.

Adobe said that Google reported the Flash Player flaw to its security team.

Targeted attacks that try to steal account information are commonplace, but they've been prominent in the news since last Wednesday, when Google accused Chinese hackers of targeting senior U.S. government officials and others in a long-running campaign to pilfer Gmail usernames and passwords.

China has denied Google's allegations. The Federal Bureau of Investigation (FBI) is looking into Google's charges.


--------------------------------------------------------------------------

Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX / IE).

Verify Your Flash Player Version
To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe (or Macromedia) Flash Player" from the menu. If you use multiple browsers, perform the check for each browser you have installed on your system.

China's View Is More Important Than Yours

Via Tao Security (Richard Bejtlich) -

In my post Review of Dragon Bytes Posted I wrote the following to summarize analysis of Chinese thoughts on cyberwar, as translated from original Chinese publications:
The Chinese military sees Western culture, particularly American culture, as an assault on China, saying "the West uses a system of values (democracy, freedom, human rights, etc.) in a long-term attack on socialist countries...

Marxist theory opposes peaceful evolution, which... is the basic Western tactic for subverting socialist countries" (pp 102-3). They believe the US is conducting psychological warfare operations against socialism and consider culture as a "frontier" that has extended beyond American shores into the Chinese mainland.

The Chinese therefore consider control of information to be paramount, since they do not trust their population to "correctly" interpret American messaging (hence the "Great Firewall of China"). In this sense, China may consider the US as the aggressor in an ongoing cyberwar.
[...]

As you can see, the Chinese think an information war is already being waged. The US started it, and the US continues it (in the Chinese view) as demonstrated by turbulence in the Middle East.

China's view is more important than yours, because China is acting on its view while too many in the West and the US in particular argue about whether or not a cyberwar is happening. The Chinese believe cyberwar is ongoing, and that the US started it. From what I can tell, the Chinese intend to win it.


----------------------------------------------------------

Such good insight from the new CSO @ Mandiant.

Monday, June 6, 2011

Protective Intelligence Lessons from an Ambush in Mexico

Via STRATFOR (Security Weekly) -

On the afternoon of May 27, a convoy transporting a large number of heavily armed gunmen was ambushed on Mexican Highway 15 near Ruiz, Nayarit state, on Mexico’s Pacific coast. When authorities responded they found 28 dead gunmen and another four wounded, one of whom would later die, bringing the death toll to 29. This is a significant number of dead for one incident, even in Mexico.

According to Nayarit state Attorney General Oscar Herrera Lopez, the gunmen ambushed were members of Los Zetas, a Mexican drug cartel. Herrera noted that most of the victims were from Mexico’s Gulf coast, but there were also some Guatemalans mixed into the group, including one of the wounded survivors. While Los Zetas are predominately based on the Gulf coast, they have been working to provide armed support to allied groups, such as the Cartel Pacifico Sur (CPS), a faction of the former Beltran Leyva Organization that is currently battling the Sinaloa Federation and other cartels for control of the lucrative smuggling routes along the Pacific coast. In much the same way, Sinaloa is working with the Gulf cartel to go after Los Zetas in Mexico’s northeast while protecting and expanding its home turf. If the victims in the Ruiz ambush were Zetas, then the Sinaloa Federation was likely the organization that planned and executed this very successful ambush.

Photos from the scene show that the purported Zetas convoy consisted of several pickup trucks and sport utility vehicles (two of which were armored). The front right wheel on one of the armored vehicles, a Ford Expedition, had been completely blown off. With no evidence of a crater in the road indicating that the damage had been caused by a mine or improvised explosive device (IED), it would appear that the vehicle was struck and disabled by a well-placed shot from something like a rocket-propelled grenade (RPG) or M72 LAW rocket, both of which have been seen in cartel arsenals. Photos also show at least one heavy-duty cattle-style truck with an open cargo compartment that appears to have been used as a troop transport. Many of the victims died in the vehicles they were traveling in, including a large group in the back of the cattle truck, indicating that they did not have time to react and dismount before being killed.

[...]

Most of the victims were wearing matching uniforms (what appear to be the current U.S. Marine Corps camouflage pattern) and black boots. Many also wore matching black ballistic vests and what appear to be U.S.-style Kevlar helmets painted black. From the photos, it appears that the victims were carrying a variety of AR-15-variant rifles. Despite the thousands of spent shell casings recovered from the scene, authorities reportedly found only six rifles and one pistol. This would seem to indicate that the ambush team swept the site and grabbed most of the weapons that may have been carried by the victims.

A convoy of this size could have been dispatched by Los Zetas and CPS on a military raid into hostile Sinaloa territory, but there is also a possibility that the gunmen were guarding a significant shipment of CPS narcotics passing through hostile territory. If that was the case, the reason for the ambush may have been not only to kill the gunmen but also to steal a large shipment, which would hurt the CPS and could be resold by Sinaloa for a substantial profit.

Whether the objective of the ambush was simply to trap and kill a Zetas military team conducting a raid or to steal a high-value load of narcotics, a look at this incident from a protective intelligence point of view provides many lessons for security professionals operating in Mexico and elsewhere.

Read more: Protective Intelligence Lessons from an Ambush in Mexico | STRATFOR


---------------------------------------------------------------------------------------------------------

Recent examples of both huge weapon caches and armored vehicles seized by the Mexican Army:

Mexican Military Finds Huge Weapons Cache (June 4, 2011)
http://www.voanews.com/english/news/americas/Mexican-Military-Finds-Huge-Weapons-Cache-123155388.html
Authorities said they found more than 150 rifles and shotguns, 92,000 rounds of ammunition, four mortar shells, two rocket-propelled grenades and assorted other weaponry. The cache was found at a ranch near the industrial city Monclova in the northern state Coahuila that borders the United States. They believe the cache belonged to the Zetas cartel, which has been battling the Sinaloa cartel and other drug gangs for control of Coahuila.
Army Seizes Armored Vehicles in Northern Mexico (June 6, 2011)
http://www.laht.com/article.asp?ArticleId=396419&CategoryId=14091
Two armored trucks, known as “monsters,” outfitted with 2.5-centimeter (one-inch) steel plates, two other partially completed trucks and 23 tractor-trailers awaiting modification were found in the garage. The vehicles, which are used for patrols and smuggling drugs into the United States, have air conditioning, armored diesel engines and steel plates to protect occupants, the 4th Military Region said. The armored trucks, which can only be taken out with 20 mm anti-tank grenades, are being used in the war between the Gulf cartel and Los Zetas for control of the border region, the army said.

Sunday, June 5, 2011

Absolute Sownage: A Concise History of Recent Sony Hacks

http://attrition.org/security/rants/sony_aka_sownage.html

Over the last two months, the multi-national Sony Corporation has come under a wide range of attacks from an even wider range of attackers. The backstory about what event prompted who to attack and why will make a mediocre made-for-TV movie someday. This article is not going to cover the brief history of hacks; readers can find details elsewhere. Instead, the following only serves to create an accurate and comprehensive timeline regarding the recent breaches, a cliff notes summary for easy reference.

------------------------------------

Good concise list of recent attacks against Sony. They were happening so quickly recently, it has been hard to keep them separate sometimes.

Flash Player Patch Fixes Zero-Day Flaw

Via krebsonsecurity.com -

Adobe released an emergency security update today to fix a vulnerability that the company warned is being actively exploited in targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.

The vulnerability — a cross-site scripting bug that could be used to take actions on a user’s behalf on any Web site or Webmail provider, exists in Flash Player version 10.3.181.16 and earlier for Windows, Macintosh, Linux and Solaris. Adobe recommends users update to version 10.3.181.22 (on Internet Explorer, the latest, patched version is 10.3.181.23). To find out what version of Flash you have, go here.


----------------------------------------------------------------------------------------

APSB11-13: Security Update Available for Adobe Flash Player
http://www.adobe.com/support/security/bulletins/apsb11-13.html
This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user's behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.

Ilyas Kashmiri: Drone Strike Kills Top Pakistani Terrorist

Via VOA News -

On Saturday, Pakistani intelligence sources said that senior al-Qaida leader Ilyas Kashmiri died along with eight other militants in an attack on a location in South Waziristan.

Kashmiri's own militant group, Harakat-ul-Jihad al-Islami, or HUJI, confirmed his death in a fax to news organizations, saying Kashmiri was "martyred" Friday.

The United States had designated Kashmiri a "Specially Designated Global Terrorist" and offered a $5 million reward for information leading to his capture.

Intelligence officials regarded Kashmiri as one of the most dangerous and highly trained terrorist operatives. Pakistani officials suspected him of masterminding last month's attack on a naval base in Karachi, in which a handful of militants held off Pakistani forces for about 17 hours.

Officials have also tied Kashmiri to the 2008 Mumbai terror attacks that killed 166 people. The U.S. blames Kashmiri's group for the March 2006 bombing of the U.S. consulate in Karachi that killed four people and wounded 48 others. A U.S. grand jury indicted Kashmiri in 2010 in connection with a plot to attack a Danish newspaper.


---------------------------------------------------------------

FYI, the Specially Designated Global Terrorist (SDGT) designation has been superseded by the similar Specially Designated Nationals (SDN) list, published by the US Treasury's Office of Foreign Assets Control (OFAC). Muhammad/Mohammad Ilyas Kashmiri is listed in the full OFC SDN list on page 233, near the bottom of the first column.

LWJ: Top al Qaeda Leader Ilyas Kashmiri Killed in US Predator Strike
http://www.longwarjournal.org/archives/2011/06/top_al_qaeda_leader_2.php
Kashmiri is said to be one of nine members of the al Qaeda-linked Harkat-ul Jihad Islami, or HUJI, who were killed in yesterday's Predator airstrike that leveled a compound in the Wana area of South Waziristan.
Strike two: Ilyas Kashmiri dead – again
http://tribune.com.pk/story/182727/strike-two-ilyas-kashmiri-dead--again/
“The strike took place in the Karikot area on the outskirts of Wana, the main town in South Waziristan, before midnight on Friday,” local sources said. “Some ‘guests’ were sitting in an apple orchard when a loud explosion took place.”

An intelligence official in Peshawar endorsed this version.

“Kashmiri was having tea with his men in the orchard when the strike took place. All nine militants, all of them from Punjab, were killed in the attack,” he told The Express Tribune.

[...]

Kashmiri and other militants were meeting an Afghan Taliban who worked in liaison with the Tehreek-i-Taliban Pakistan (TTP) when the drone missile struck, he added.
Aftermath Footage of Ilas Kashmiri's Drone Attack Site
http://tribune.com.pk/multimedia/videos/182884/

Saturday, June 4, 2011

Lockheed Says Hacker Used Stolen SecurID Data

Via New York Times (June 3, 2011) -

Lockheed Martin said Friday that it had proof that hackers breached its network two weeks ago partly by using data stolen from a vendor that supplies coded security tokens to tens of millions of computer users.

Lockheed’s finding confirmed the fears of security experts about the safety of the SecurID tokens and heightened concerns that other companies or government agencies could be vulnerable to hacking attacks.

The tokens, which are used to protect remote access to computer networks, are sold by the RSA Security Division of the EMC Corporation. RSA officials said Friday that they accepted Lockheed’s findings and were working with customers to offset the risks through other measures.

RSA disclosed in March that hackers had stolen data that could compromise a company’s SecurID system in a broader attack, and the breach of Lockheed, the nation’s largest defense contractor, is the first time that is known to have occurred.

A rash of prominent breaches has brought new attention to an increase in the frequency and sophistication of computer hacking. Google said this week that it believed an effort to steal hundreds of Gmail passwords for accounts of prominent people, including senior American government officials, had originated in China.

The Pentagon, which has long been concerned about efforts by China and Russia to obtain military secrets, announced separately that it would soon view serious computer attacks from foreign nations as acts of war that could result in a military response.

RSA officials noted that Lockheed said it planned to continue using the SecurID tokens, and they said they believed other customers would as well. But security experts said RSA’s reputation had most likely been seriously damaged, and many of its 25,000 customers, including Fortune 500 companies and government agencies around the world, could face difficult decisions about what to do next.

RSA’s prospects for holding on to some of those customers “certainly seems bleak,” said Harry Sverdlove, the chief technology officer at Bit9, a firm that provides other types of security products and does not compete with RSA.

He and other experts said RSA might need to reprogram many of its security tokens or create an upgraded version to rebuild confidence in its systems.

In response to questions on Friday, Lockheed said in an e-mail that its computer experts had concluded that the breach at RSA in March was “a direct contributing factor” in the attack on its network. Government and industry officials said the hackers had used some of the RSA data and other techniques to piece together the coded password of a Lockheed contractor who had access to Lockheed’s system.

Lockheed, which makes fighter planes, spy satellites and other confidential equipment, said it had detected the attack quickly and blocked it before any important data was compromised.


--------------------------------------------------------------

Impressive timeframe. This means the attackers weaponized the stolen data from RSA very very quickly and used it to target high-value target(s).

The stolen RSA (leading to cloned tokens) could have been used as an initial attack vector or as an alternative entry method to maintain persistence....or both (my guess).

While APT should be categorized as such based more on the motives and objectives of the attackers [and less on techniques used], this shows the actors have the capability to push beyond standard exploitation techniques to achieve their objectives.

This is industrial / military espionage.

Friday, June 3, 2011

China's Blue Army: When Nations Harness Hacktivists for Information Warfare

Via ZDNet Zero Day Blog (Dancho Danchev) -

China has recently announced the existence of the Blue Army, a government sponsored cyber warfare unit similar to those launched by the U.S, the United Kingdom, Australia and Israel.

Although the majority of the cyber warfare units have been established for defensive purposes, it’s the offensive cyber capabilities that are worth discussing in the context of establishing a borderline for offensive cyber operations. The methodology used in offensive cyber warfare operations is fairly simple - if you’re attacking us we reserve ourselves the rights to strike back at you.

[...]

It’s been a decade since the release of the Chinese “Unconventional warfare” book, and a lot has changed from a conceptual perspective. From symmetric to asymmetric shift in the concepts, to the currently in progress of implementation unrestricted warfare military doctrines, the Chinese has proven that they they’re not just able to keep up with the developing environment, but to dominate it with new concepts in cyberspace.

What constitutes unrestricted warfare in the cyberspace realm, really? Basically, it’s the reliance on civilians for executing government sponsored or government tolerated cyber operations, the so called people’s information warfare concept. The concept is fairly simple. Instead of establishing a dedicated cyber warfare unit, a country such as China is actively harnessing the potential of its hacktivist community for executing military operations and activities across the Web.

[...]

The Chinese underground and hacktivist community is developed well enough to manage the tasks of a fully operational cyber warfare unit, because it relies on the people not on the department.

MI6 Attacks Al-Qaeda in 'Operation Cupcake'

Via telegraph.co.uk -

The cyber-warfare operation was launched by MI6 and GCHQ in an attempt to disrupt efforts by al-Qaeda in the Arabian Peninsular to recruit “lone-wolf” terrorists with a new English-language magazine, the Daily Telegraph understands.

When followers tried to download the 67-page colour magazine, instead of instructions about how to “Make a bomb in the Kitchen of your Mom” by “The AQ Chef” they were greeted with garbled computer code.

The code, which had been inserted into the original magazine by the British intelligence hackers, was actually a web page of recipes for “The Best Cupcakes in America” published by the Ellen DeGeneres chat show.

[...]

By contrast, the original magazine featured a recipe showing how to make a lethal pipe bomb using sugar, match heads and a miniature lightbulb, attached to a timer.

The cyber attack also removed articles by Osama bin Laden, his deputy Ayman al-Zawahiri and a piece called “What to expect in Jihad.”

British and US intelligence planned separate attacks after learning that the magazine was about to be issued in June last year.

They have both developed a variety of cyber-weapons such as computer viruses, to use against both enemy states and terrorists.

A Pentagon operation, backed by Gen Keith Alexander, the head of US Cyber Command, was blocked by the CIA which argued that it would expose sources and methods and disrupt an important source of intelligence, according to a report in America.

However the Daily Telegraph understands an operation was launched from Britain instead.

Al-Qaeda was able to reissue the magazine two weeks later and has gone on to produce four further editions but one source said British intelligence was continuing to target online outlets publishing the magazine because it is viewed as such a powerful propaganda tool.

The magazine is produced by the radical preacher Anwar al-Awlaki, one of the leaders of AQAP who has lived in Britain and the US, and his associate Samir Khan from North Carolina.

Both men who are thought to be in Yemen, have associated with radicals connected to Rajib Karim, a British resident jailed for 30 years in March for plotting to smuggle a bomb onto a trans-Atlantic aircraft.

At the time Inspire was launched, US government officials said “the packaging of this magazine may be slick, but the contents are as vile as the authors.”

Bruce Reidel, a former CIA analyst said it was “clearly intended for the aspiring jihadist in the US or UK who may be the next Fort Hood murderer or Times Square bomber.”


-------------------------------------------------------------------------------------

The takedown question is one of the biggest when it comes to counter-radicalization operations in cyberspace. The enemy exposes themselves (both physically and virtually) to publish...is the benefit of the takedown worth losing the self-exposure?

Replacing the content is a nice middle ground ;)

However, the reverse is true as well....we expose ourselves to conduct the operation (mostly virtually)... does the benefit outweigh our own exposure?

These questions are tough to answer in many cases.

Gmail Hackers Phished Victims for Months

Via Threatpost.com -

An independent security researcher who was among the first to investigate a large scale phishing attack aimed at U.S. government and military personnel says that attackers controlled victim accounts for months and repeatedly phished victims during that time.

Mila Parkour, a Washington D.C. based independent says that victims of the account takeovers were repeatedly phished over almost a year by attackers believed to be located in China. Parkour said in an instant message conversation with Threatpost on Thursday that the group or individuals responsible for the attack controlled those accounts for more than a year and repeatedly targeted both the legitimate account owner and his or her associates during that time.

Victims of the attack included government and military personnel in the U.S. and Asian nations, as well as human rights activists and journalists in China and elsewhere, Google said on Wednesday.

Parkour is an IT administrator who lives in Washington D.C. She does malware research in her free time. Her blog, Contagiodump, was credited by Google with bringing the spear phishing e-mails to light. Parkour told Threatpost that she "collects samples from victims and other researchers" then posts them on the blog for sharing and analysis. She posted on the spear phishing e-mails in February not because they were unusual, but because of the sensitive nature of who they targeted.

According to Parkour, the attackers used spoofed e-mail addresses and information harvested from the victims' accounts to engage in "mini conversations" with their victims.

"They used personal knowledge for some phishes...they were very persistent and invasive," she said, tailoring the spoofed sender address to the recipient based on knowledge gleaned from the compromised accounts.

Among other things, the attackers continued to try to harvest other online credentials from victims - user names and passwords - using the same technique they used, successfully, to gain access to- and control over the users' Gmail accounts.

[...]

Google said in a blog post on Wednesday that it had disrupted the campaign, which it traced to Jinan, China. The campaign affected hundreds of Gmail users, using malware and phishing attacks to harvest user login credentials. The campaign appears to have been designed to monitor the content of users' email correspondence.

Parkour said she felt that Google did a good job unraveling the scheme and to find other victims of it. "It looks like they exhausted all the leads and found out as much as they could to address it before going public," she said.


-------------------------------------------------------------------------------

Related stories....

Thursday, June 2, 2011

Some Insight into Apple's Anti-Virus Signatures

Via SANS ISC Diary -

Now with Apple pushing out its first daily update to combat the latest MacDefender variant, its a good time to take a closer look at "XProtect", the Snow Leopard Anti Malware engine (or to use the Apple euphemism: "safe download list").

OS X heavily relies on XML files for configuration. These "plist" files are easy to read. The same is true for the XProtect configuration, which includes the currently valid signatures.


---------------------------------------------------------------

Nice and quick look into Apple's Anti-Malware XProtect feature (officially called File Quarantine) of OS X.

Apple to Malware Authors: Tag, you're It!

Via NakedSecurity.com (Sophos) -

Last night the malware authors behind the Mac Guard fake anti-virus changed their methods again to bypass the updates Apple released yesterday afternoon to protect OS X Snow Leopard users. Apple fired back shortly after 2 p.m. Pacific Daylight Time today with a new update to XProtect. Computers that have Apple update 2011-003 for Snow Leopard now check for updates every 24 hours.

As the cat-and-mouse game continues it will be interesting to see how the attackers proceed. The major change to bypass Apple's detection yesterday was to use a small downloader program to do the initial infection, then have that program retrieve the actual malware payload.

This approach may be successful as it will be easier for the malware authors to continually make small changes to the downloader program to evade detection while leaving the fake anti-virus program largely unchanged.

Why is this important? Apple's XProtect is not a full anti-virus product with on-access scanning. XProtect only scans files that are marked by browsers and other tools as having been downloaded from the internet.

If the bad guys can continually mutate the download, XProtect will not detect it and will not scan the files downloaded by this retrieval program. Additionally, XProtect is a very rudimentary signature-based scanner that cannot handle sophisticated generic update definitions.


---------------------------------------------------------------------------

These criminals behind the FakeAV scams are rapidly adapting in order to protect a real revenue stream, therefore it is highly unlikely they will walk away without a serious fight.

Apple is allowing itself to be pulled into a cat-and-mouse game of malicious whack-a-mole. A game which highlights the well-known weakness of pure signature-based detection. This is a lesson AV companies learned long long ago.

Apple's XProtect isn't up for the battle and in short order, updates every 24 hours won't be enough....a full-time scanning solution will be needed - enter on-access AV on Apple.

Wednesday, June 1, 2011

Apple Adds Daily Malware Updates to OS X, Attackers Adapt Quickly

Via Threatpost.com -

Apple on Tuesday shipped the promised update to help remove the MacDefender malware, and in a surprise move, also added functionality to Mac OS X that will now check for new malware definitions daily.

The move by Apple to add daily malware checks is a significant shift in the way that the company handles malware and potential infections of its customers. Until now, Apple has handled such incidents on a case by case basis and pushed OS changes when it needed to address a new problem. But now the company has essentially included an auto-updating anti-malware system with OS X.

The security update that Apple released Tuesday performs several specific tasks. It adds a new definition to the existing anti-malware checks in OS X, and also will automatically remove any instances of the MacDefender malware that it finds on the machine. But most significantly, security update 2011-003 adds the automatic daily checks for new malware signatures.


----------------------------------------------------------------------------

Apple's move to add daily update ability to its anti-malware XProtect List means it will be better suited to react to future variants of Apple malware.

However, there are now reports, the criminals adapted within hours and are now pushing out a new MacDefender FakeAV variant which bypasses the original signature protection from Apple.

The next move is on Apple - will it allow it to be pulled into a game of whack-a-mole with monetized crimeware or will it finally suggest all users install AV?