Tuesday, August 9, 2011

INFOSEC (without borders)

http://infosecwithoutborders.org/

INFOSEC Without Borders (IWB) started as a simple question between Johnny Long and Marcus Carey: "With all the INFOSEC companies and pros in the business, why are some many charities getting hacked?"

The answer to that question seemed to be relatively simple. Most non-profits could not afford to hire decent security firms. 

Monday, August 8, 2011

Blackhat 2011 & Defcon 19

Please forgive me for the extended radio silence. I have been in Las Vegas, NV for the annual meeting of the hacker community - Blackhat 2011 and Defcon 19.

Always good to hang with old friends in the desert.

I am recovering with a minor case of con flu, but expect to be back in the saddle (and blogging again) this week.

Thank you for your patience.


Wednesday, August 3, 2011

Revealed: Operation Shady RAT

Via WashingtonPost.com -

A leading computer security firm has used logs produced by a single server to trace the hacking of more than 70 corporations and government organizations over many months, and experts familiar with the analysis say the snooping probably originated in China.

Among the targets were the Hong Kong and New York offices of the Associated Press, where unsuspecting reporters working on China issues clicked on infected links in e-mail, the experts said.

Other targets included the networks of the International Olympic Committee, the United Nations secretariat, a U.S. Energy Department lab, and a dozen U.S. defense firms, according to a report released Wednesday by McAfee, a security firm that monitors network intrusions around the world.

McAfee said hundreds of other servers have been used by the same adversary, which the company did not identify.

But James A. Lewis, a cybersecurity expert at the Center for Strategic and International Studies, said “the most likely candidate is China.” The target list’s emphasis on Taiwan and on Olympic organizations in the run-up to the Beijing Games in 2008 “points to China” as the perpetrator, he said. “This isn’t the first we’ve seen. This has been going on from China since at least 1998.”

Another computer expert with knowledge of the study, who spoke on the condition of anonymity out of reluctance to blame China publicly, said the intrusions appear to have originated in China. McAfee dubbed the intrusions “Operation Shady RAT,” with the acronym standing for “remote access tool.”

The intruders were after data on sensitive U.S. military systems, the McAfee report says, as well as material from satellite communications, electronics, natural gas companies and even bid data from a Florida real estate company. Forty-nine of the 72 compromised organizations were in the United States.

“We’re facing a massive transfer of wealth in the form of intellectual property that is unprecedented in history,” said Dmitri Alperovitch, McAfee’s vice president of threat research. He would not name the private entities targeted, but said McAfee helped half a dozen of them investigate intrusions.

Some of the intrusions — such as one into the World Anti-Doping Agency in Montreal — are continuing, he said. Spokesmen for that organization and for the International Olympic Committee said they were not aware of the intrusions. A U.N. spokesman said technicians analyzing the logs have not seen evidence of stolen data. The Energy Department had no comment.


-----------------------------------------------------------

Revealed: Operation Shady RAT (PDF)
http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf

----------------------------------------------------------

Symantec: The Truth Behind the Shady RAT
http://www.symantec.com/connect/blogs/truth-behind-shady-rat

In the Excel files, we have seen the old, but clearly still effective Microsoft Excel 'FEATHEADER' Record Remote Code Execution Vulnerability (detected by Bloodhound.Exploit.306) being exploited. Once the file is opened on an unpatched computer, a clean copy of an Excel file is dropped and opened so that the user is not suspicious. A Trojan is also dropped and executed. One possible tell-tale sign of this exploit is that Excel appears to hang for a short time before it resumes, and the application may even crash and restart....Upon closer inspection of the file and the Trojan code, we can see that there are commands hidden in the image using steganography. These commands are totally invisible to the human eye, since the bits representing the commands are mathematically built into the data representing the image.

Monday, August 1, 2011

The Mission to Get Osama Bin Laden

Via The New Yorker -

Shortly after eleven o’clock on the night of May 1st, two MH-60 Black Hawk helicopters lifted off from Jalalabad Air Field, in eastern Afghanistan, and embarked on a covert mission into Pakistan to kill Osama bin Laden. Inside the aircraft were twenty-three Navy SEALs from Team Six, which is officially known as the Naval Special Warfare Development Group, or DEVGRU. A Pakistani-American translator, whom I will call Ahmed, and a dog named Cairo—a Belgian Malinois—were also aboard. It was a moonless evening, and the helicopters’ pilots, wearing night-vision goggles, flew without lights over mountains that straddle the border with Pakistan. Radio communications were kept to a minimum, and an eerie calm settled inside the aircraft.

Fifteen minutes later, the helicopters ducked into an alpine valley and slipped, undetected, into Pakistani airspace. For more than sixty years, Pakistan’s military has maintained a state of high alert against its eastern neighbor, India. Because of this obsession, Pakistan’s “principal air defenses are all pointing east,” Shuja Nawaz, an expert on the Pakistani Army and the author of “Crossed Swords: Pakistan, Its Army, and the Wars Within,” told me. Senior defense and Administration officials concur with this assessment, but a Pakistani senior military official, whom I reached at his office, in Rawalpindi, disagreed. “No one leaves their borders unattended,” he said. Though he declined to elaborate on the location or orientation of Pakistan’s radars—“It’s not where the radars are or aren’t”—he said that the American infiltration was the result of “technological gaps we have vis-à-vis the U.S.” The Black Hawks, each of which had two pilots and a crewman from the 160th Special Operations Aviation Regiment, or the Night Stalkers, had been modified to mask heat, noise, and movement; the copters’ exteriors had sharp, flat angles and were covered with radar-dampening “skin.”

The SEALs’ destination was a house in the small city of Abbottabad, which is about a hundred and twenty miles across the Pakistan border. Situated north of Islamabad, Pakistan’s capital, Abbottabad is in the foothills of the Pir Panjal Range, and is popular in the summertime with families seeking relief from the blistering heat farther south. Founded in 1853 by a British major named James Abbott, the city became the home of a prestigious military academy after the creation of Pakistan, in 1947. According to information gathered by the Central Intelligence Agency, bin Laden was holed up on the third floor of a house in a one-acre compound just off Kakul Road in Bilal Town, a middle-class neighborhood less than a mile from the entrance to the academy. If all went according to plan, the SEALs would drop from the helicopters into the compound, overpower bin Laden’s guards, shoot and kill him at close range, and then take the corpse back to Afghanistan.

Read more http://www.newyorker.com/reporting/2011/08/08/110808fa_fact_schmidle?currentPage=all

Saturday, July 30, 2011

Leader of La Linea Gang Arrested in Mexico

Via CNN -

A purported leader of the infamous La Linea criminal organization has been arrested in Mexico, state-run media reported, citing a military leader.

Jose Antonio Acosta Hernandez, known as El Diego, was taken into custody during an operation in Chihuahua, Emilio Zarate Landeros told Notimex on Saturday.

Zarate, who leads troops in Mexico's Quinta Zona Militar or Fifth Military Zone, said the raid had been carefully planned and coordinated.

Video from CNN affiliate XHIJ shows several armed men going into a Chihuahua building to detain Acosta.

La Linea is the armed branch of the Juarez drug cartel, federal police official Ramon Eduardo Pequeno Garcia has previously told CNN.

This group ordered the March 2010 killing of U.S. consulate employee Lesley Enriquez, the same official added. She and her husband, Arthur Redelfs, were gunned down as they left a birthday party in a white SUV.

Authorities have said that Jesus Ernesto Chavez Castillo -- arrested last summer in connection with various deadly shootings in Ciudad Juarez -- got his orders directly from Acosta.

Acosta, whose other alias is Blablazo, himself worked under La Linea leader Emilia Ramirez Castillo, or El Negro, according to the general prosecutor's office of Mexico. A 15 million-peso reward was being offered for information leading to his arrest.

Friday, July 29, 2011

Officials: Iranian was Nuclear Scientist, Not Student as Tehran Claims

Via Washington Post (AP) -

A man shot dead on a Tehran street by motorcycle-riding gunmen last weekend was a scientist involved in suspected Iranian attempts to make nuclear weapons and not a student as officially claimed, a foreign government official and a former U.N. nuclear inspector have told The Associated Press.

The man was shot Saturday by a pair of gunmen firing from motorcycles in an attack similar to recent assassinations of two nuclear scientists that Iran blames on the United States and Israel. State-run media initially identified him as Darioush Rezaei, a physics professor and expert in neutron transport, but backtracked within hours, with officials subsequently naming him as Darioush Rezaeinejad, an electronics student.

An official — from a member nation of the Vienna-based International Atomic Energy Agency — verified that the victim was named Darioush Rezaeinejad, but said he participated in developing high-voltage switches, a key component in setting off the explosions needed to trigger a nuclear warhead. An abstract seen by the AP and bearing the name Darioush Rezaeinejad as a co-author appears to back that claim.

Two other men, both of them nuclear scientists, were killed last year by assassins on motorcycles. While the possibility remained that there may be two Darioush Rezaeinejads, a senior Western diplomat in Vienna said the three assassinations, as well as the “back and forth by the Iranians” on the latest victim’s identity, had sharpened suspicions in his capital of a possible cover-up. He asked for anonymity because he was relaying confidential information.

Thursday, July 28, 2011

EMC and AmCham-China: A Perfect Recipe For A Network Breach

Via Digital Dao (Jeffrey Carr's Blog) -

Here is a classic scenario for how critical technology gets stolen. Take a C-level executive of a company whose focus is high value technology (like Cloud computing) and send him to a country who is spending millions of their currency to acquire that technology (like China) to speak at an event organized by an association that has itself been compromised (like the American Chamber of Commerce in China).

The event I'm writing about is coming up on August 9 in Beijing: USITO/AmCham-China's ICT Breakfast Series: Cloud Meets Big Data

China is heavily investing in Cloud Computing, having set up its own Cloud Valley located in the Beijing Economic Technological Development Area for RMB 500 million.

One of AmCham-China's employees was sending out email messages with malicious attachments in January, 2011. These were not spoofed emails, which means that the entire organization's network had been compromised and probably still is.

The speaker for the event is the CTO of EMC Jeffrey Nick, whose RSA security division suffered a massive breach last March and whose company offers Cloud computing solutions.

This is a textbook case for how executives may be targeted and compromised by a nation state who's interested in their technology. And if this year has taught us anything, it's that everyone is vulnerable - even a top executive at one of the world's largest information security companies.


--------------------------------------------------------------

It is pretty hard to counter his logic on this one....

Hack of South Korean Sites Affects Up to 35 Million Users

Via H-Online.com -

According to a report from Reuters, hackers from China have attacked an internet portal and blogging site operated by South Korea's SK Communications, gaining access to the personal information of up to 35 million users. The news agency says that the cyber attack could be the largest the country has ever experienced.

In a statement, the Korea Communications Commission confirmed that the personal information targeted by the attackers included names, telephone numbers, email addresses and other data from the Nate portal and Cyworld blogging sites run by the SK Telecom subsidiary. An official at the commission told Reuters that the police have started an investigation, but have yet to ask for assistance from Chinese authorities.

--------------------------------------------------------------------

Interestingly enough, Microsoft recently outlined the malware threat landscape in the Republic of Korea - characterizing it as one of the most active in the world. Korea has a malware threat landscape that is characterized by a mix of global threats as well as threats that are targeting users in Korea specifically.

To put this active landscape in a border context, you only need to look at the July 2011 McAfee analysis of the March 2011 South Korean DDoS attacks. McAfee analysis of the March 2011 attacks against South Korean government and U.S. military Websites notes the attacks likely came from North Korea - based on circumstantial evidence. However, the report [PDF] does echo other assessments of North Korea's improving cyber war capabilities.

Wednesday, July 27, 2011

TWR: Advanced Reactor Gets Closer to Reality

Via MIT Technology Review -

Terrapower, a startup funded in part by Nathan Myhrvold and Bill Gates, is moving closer to building a new type of nuclear reactor called a traveling wave reactor that runs on an abundant form of uranium. The company sees it as a possible alternative to fusion reactors, which are also valued for their potential to produce power from a nearly inexhaustible source of fuel.

Work on Terrapower's reactor design began in 2006. Since then, the company has changed its original design to make the reactor look more like a conventional one. The changes would make the reactor easier to engineer and build. The company has also calculated precise dimensions and performance parameters for the reactor. Terrapower expects to begin construction of a 100-megawatt demonstration plant in 2016 and start it up in 2020. It's working with a consortium of national labs, universities, and corporations to overcome the primary technical challenge of the new reactor: developing new materials that can withstand use in the reactor core for decades at a time. It has yet to secure a site for an experimental plant—or the funding to build it.

The reactor is designed to be safer than conventional nuclear reactors because it doesn't require electricity to run cooling systems to prevent a meltdown. But the new reactor doesn't solve what is probably the biggest problem facing nuclear power today: the high cost of building them. John Gilleland, Terrapower's CEO, says the company expects the reactors to cost about as much to build as conventional ones, "but the jury is still not in on that."

Conventional reactors generate heat and electricity as a result of the fission of a rare form of uranium—uranium 235. In a traveling wave reactor, a small amount of uranium 235 is used to start up the reactor. The neutrons the reactor produces then convert the far more abundant uranium 238 into plutonium 239, a fissile material that can generate the heat needed for nuclear power. Uranium 238 is readily available in part because it's a waste product of the enrichment processes used to make conventional nuclear fuel. It may also be affordable in the future to extract uranium 238 from seawater if demand for nuclear fuel is high. Terrapower says there's enough of this fuel to supply the world with power for a million years, even if everyone were to use as much power as people in the United States do.

[...]

One challenge with this design is ensuring that the steel cladding that contains the fuel in the fuel rods can survive exposure to decades of radiation. Current materials aren't good enough: for one thing, they start to swell, which would close off the spaces between the fuel rods through which coolant is supposed to flow. To last 40 years, the materials need to be made two to three times more durable, Terrapower says.

[...]

Terrapower has also developed designs for a passive cooling system. Like many other advanced reactor designs, Terrapower's uses molten sodium metal as the coolant. Sodium takes much longer to boil than water, which gives plant operators more time to respond to accidents. It would also be possible to use natural convection in the event of a power outage—coolant wouldn't have to be continuously pumped into the reactor, as was the case at Fukushima. One danger of using sodium, however, is that it reacts violently when it's exposed to air or water.


--------------------------------------------------------------------

http://en.wikipedia.org/wiki/Traveling_wave_reactor
TWRs differ from other kinds of fast-neutron and breeder reactors in their ability to, once started, reach a state whereafter they can achieve very high fuel utilization while using no enriched uranium and no reprocessing, instead burning fuel made from depleted uranium, natural uranium, thorium, spent fuel removed from light water reactors, or some combination of these materials.

Tuesday, July 26, 2011

Analysts Expect Mexican Drug Violence to Continue

Via texastribune.org -

A prediction that one of the most notorious cartels operating on the Texas-Mexico border could soon meet its demise was premature, according to a new report on Mexican cartels. Instead, its authors caution that daily bloodshed may continue unabated.

Though it’s not expected to reach the record highs witnessed in 2010, this year’s death toll in Ciudad Juárez is still expected to be in the thousands as multiple massacres continue as a weekly occurrence. At least 1,230 have been murdered there this year, and about 8,670 since 2008, according to local media reports.

The assessment is part of global intelligence firm STRATFOR’s latest quarterly report on Mexico. In April it forecast that the Juárez cartel — the Vicente Carrillo Fuentes organization that has operated under the family’s direction for decades across from El Paso — might meet its end at the hands of its rival, Joaquin “El Chapo” Guzman’s Sinaloa cartel. The prediction was a result of intelligence stating the Sinaloa outfit was successfully choking off the hometown gang in the city and surrounding areas, squeezing off its eastern and western supply routes.

STRATFOR estimated then that the violence in the border city might escalate as the Juárez cartel sought ways to replenish its lost revenue, mainly through kidnappings, thefts and extortions. The Juárez cartel has proven more resilient, and Juárez has seen a surge in murders after some observers thought the death toll there would subside.

“Though STRATFOR previously reported that the VCF was hemmed in on all sides by the Sinaloa Federation and essentially confined to downtown Ciudad Juárez, STRATFOR sources have recently indicated that this is no longer quite the case,” the report states.


-----------------------------------------------------------------------------------------------

In somewhat related news....

Mexico Arrests 1K In Human Trafficking Raids
http://www.ksat.com/news/28655561/detail.html
Authorities in Ciudad Juarez arrested more than 1,000 people over the weekend in an operation aimed at cracking down on human trafficking, police said. Federal police said raids in two dozen bars, hotels and boarding houses netted arrests of 500 men and 530 women they suspect are connected with human trafficking and sexual exploitation. In addition, 20 female minors were rescued, police said.
----------------------------------------------------------------------------------------------

And as a reminder of the activity that is happening in US cities right now...

http://twitter.com/#!/STRATFOR/status/95917111058243584
35 LFM [La Familia Michoacana] cartel members arrested in Austin Texas 7/21. Police say Austin used as drug-trafficking hub.

Monday, July 25, 2011

DJ Fenner & Quazzer - I Was Wrong (Dubstep Remix)

An Analysis of Anonymity in the Bitcoin System

http://anonymity-in-bitcoin.blogspot.com/2011/07/bitcoin-is-not-anonymous.html

TL;DR

Bitcoin is not inherently anonymous. It may be possible to conduct transactions is such a way so as to obscure your identity, but, in many cases, users and their transactions can be identified. We have performed an analysis of anonymity in the Bitcoin system and published our results in a preprint on arXiv.

Report: Iran Resorts to Rip And Replace To Kill Off Stuxnet

Via Threatpost.com -

Reports that Iran had recovered from the infection of the Stuxnet worm may have been overblown, as a new report suggests the country is being forced to replace thousands of expensive centrifuges damaged by the worm.

The report from the Web site DEBKAfile cites "intelligence sources" in claiming that Stuxnet was not purged from Iran's nuclear sites and that the country was never able to return its uranium enrichment operation to "normal operation." Instead, the country has said in recent days that it is installing newer and faster centrifuges at its nuclear plants and intends to speed up the uranium enrichment process, according to the country's foreign ministry.

Iran was believed to have 8,700 centrifuges in operation at the country's Natanz facility the time the Stuxnet worm was released, which is believed to be around June, 2009. A recent report from Wired's ThreatLevel blog cites International Atomic Energy Agency (IAEA) officials who inspected the plant in January 2010 as saying up to a quarter of those centrifuges were disabled at that point, just months after the worm was released, and a full six months before it would be publicly identified by researchers at the Belarussian antivirus firm VirusBlokAda.

A report from the Institute for Science and International Security (PDF), dating from February, 2011, as well as contemporary news reports at the time that assessed the damage caused to Iran's uranium enrichment program to be limited. Debkafile, citing Western intelligence sources, reports that Iran failed to eradicate the worm, which resurfaced and began spreading within the Iranian facilities, prompting the government to replace an estimated 5,000 working centrifuges.


------------------------------------------------------------------------------------

It definitely is within the scope of possibility that Iran would have difficult in eradicating the sophisticated Stuxnet worm. Most corporations have just as much trouble eradicating much less sophisticated malware on a daily basis.

Interesting story if true, but I would advise taking the it with a grain of salt at this point.

Friday, July 22, 2011

Apple Laptops Vulnerable To Hack That Kills Or Corrupts Batteries

Via Fobes.com (Firewall Blog) -

Your laptop’s battery is smarter than it looks. And if a hacker like security researcher Charlie Miller gets his digital hands on it, it could become more evil than it appears, too.

At the Black Hat security conference in August, Miller plans to expose and provide a fix for a new breed of attack on Apple laptops that takes advantage of a little-studied weak point in their security: the chips that control their batteries.

Modern laptop batteries contain a microcontroller that monitors the power level of the unit, allowing the operating system and the charger to check on the battery’s charge and respond accordingly. That embedded chip means the lithium ion batteries can know when to stop charging even when the computer is powered off, and can regulate their own heat for safety purposes.

When Miller examined those batteries in several Macbooks, Macbook Pros and Macbook Airs, however, he found a disturbing vulnerability. The batteries’ chips are shipped with default passwords, such that anyone who discovers that password and learns to control the chips’ firmware can potentially hijack them to do anything the hacker wants. That includes permanently ruining batteries at will, and may enable nastier tricks like implanting them with hidden malware that infects the computer no matter how many times software is reinstalled or even potentially causing the batteries to heat up, catch fire or explode. “These batteries just aren’t designed with the idea that people will mess with them,” Miller says. “What I’m showing is that it’s possible to use them to do something really bad.”

[...]

Miller says he’s received messages from several other researchers asking him not proceed with the battery work because it could be too dangerous. But Miller has worked to fix the problems he’s exposing. At Black Hat he plans to release a tool for Apple users called “Caulkgun” that changes their battery firmware’s passwords to a random string, preventing the default password attack he used. Miller also sent Apple and Texas Instruments his research to make them aware of the vulnerability. I contacted Apple for comment but haven’t yet heard back from the company.

Implementing Miller’s “Caulkgun” prevents any other hacker from using the vulnerabilities he’s found. But it would also prevent Apple from using the battery’s default passwords to implement their own upgrades and fixes. Those who fear the possibilities of a hijacked chunk of charged chemicals in their laps might want to consider the tradeoff.

Thursday, July 21, 2011

APT: Attack On Pacific Northwest National Lab Started At Public Web Servers

Via Dark Reading (July 20, 2011) -

The cyberattack discovered at Pacific Northwest National Laboratory (PNNL) during the Fourth of July holiday weekend used a combination of a Web server vulnerability and a payload that delivered a zero-day Adobe Flash attack, according to officials at the Department of Energy-contracted facility.

PNNL, a research and development facility operated under contract to the Department of Energy, discovered what it described as a "sophisticated" targeted attack on its systems the Friday before the holiday, compelling the organization to temporarily shut down most of its internal network services, including email, SharePoint, its wireless LAN, voicemail, and Internet access. PNNL also blocked internal traffic while investigating and mitigating the attack. The lab says no classified or sensitive information was accessed in the attack.

Now more details are emerging on just how the attackers got into the Richland, Wash.-based lab, which employs around 4,900 people and handles homeland security analysis and research, as well as smart grid and environmental development.

Jerry Johnson, chief information officer for Pacific Northwest National Laboratory, said in an interview with Dark Reading that the attackers at first infiltrated some of PNNL's public-facing Web servers that contained publicly available information. These servers are considered "low impact" by government security standards, meaning that they require only minimal security under NIST standards.

The attackers exploited an undisclosed bug in the server, and then rigged it with a malicious payload that planted an Adobe Flash zero-day exploit on victims' machines. Johnson declined to elaborate on the Flash bug and exploit.

Another DOE facility, Newport News, Va.-based Thomas Jefferson National Lab, was also hit around the same time frame as PNNL, according to published reports. The attacks have been described as having the earmarks of advanced persistent threat (APT) actors, typically nation-state sponsored and focused on cyberespionage.

[...]

Even though the attackers used such a blanketed method of drive-by Web attack, Johnson says it was obvious they were zeroing in on PNNL. They netted non-PNNL workstations in their attack as well, but that wasn't their focus. "There were some workstations compromised by other DOE contractors we had on-site, but they were never exploited. [The attackers] didn’t care about them, only about the ones inside the lab. It was very clear that they knew what they wanted," and that was to target PNNL, he says.

Meanwhile, the more serious part of the breach against PNNL came in a second-wave attack that originated from another laboratory, which has not been identified but sources say was not Jefferson Lab.


------------------------------------------------------------------------------

Like targeted spear-phishing, this technique appears to be increasingly used by APT actors: attack a company's public website(s), plan malicious exploits on the public sites (mostly 0-days), and wait for employees to visit the site (likely), thus infecting internal / trusted PCs by exploiting public websites.

This exact technique has been outlined in various attacks against human rights organizations since 2009 as well, which are also common targets for specific APT actors.

Wednesday, July 20, 2011

ICSR Insight: AQAP Releases Sixth Edition of Inspire Magazine

Via ICSR -

ICSR Senior Research Fellow, Shiraz Maher, has written a summary and analysis of the sixth edition of Inspire Magazine released by Al-Qaeda in the Arabian Peninsula.

To read this in full, please click here.

Tuesday, July 19, 2011

FBI: Pakistani Spies Spent Millions Lobbying US

Via WTOP.com (AP) -

For years, the Pakistani spy agency funneled millions of dollars to a Washington non-profit group in a secret effort to influence Congress and the White House, the Justice Department said Tuesday in court documents that are certain to complicate already strained relations between the U.S. and Pakistan.

FBI agents arrested Syed Ghulam Nabi Fai, the executive director of the Kashmiri American Council, on Tuesday morning and charged him with being an unregistered agent of a foreign government. Under the supervision of a senior member of Pakistan's spy agency, Inter-Services Intelligence, Fai worked to influence Congress and develop contacts at the White House and State Department, prosecutors said.

"I believe that Fai has received approximately $500,000 to $700,000 per year from the government of Pakistan," FBI agent Sarah Webb Linden said in documents filed at the federal court in Alexandria, Va.

The Pakistani Embassy in Washington quickly denied any knowledge of such an arrangement.

A second man, Zaheer Ahmad, was also charged. Prosecutors said he recruited people to act as straw donors who would give money that really was coming from the Pakistani government. Ahmad is not under arrest and is in Pakistan, prosecutors said. Both men are U.S. citizens.

A soft-spoken man, Fai is a leading voice in the debate over the future of Kashmir, the mountainous border area that India and Pakistan have fought over for years. He supports the pro-Pakistan viewpoint that Kashmiris should vote on whether to be part of Pakistan or India. India claims the territory as its own.

Prosecutors said the Kashmiri American Council was being run in secret by the Pakistani government. Government officials reviewed Fai's budget and directed him to make campaign donations to Congress, meet with lawmakers and attend political events. The group's phone rang unanswered and a doorman said Tuesday that nobody from the organization had arrived at the office building, a few blocks from the White House in the heart of Washington's lobbying district.

Israr Mirza, the former president of the Pakistani Student Association at George Mason University, recalled hearing Fai speak at a February event his organization hosted on India-Pakistan relations.

"I don't see him as a spy or anything. He's an old gentleman," said Mirza, who has since graduated from George Mason. "He seemed like a very collected guy. He was speaking just to promote peace."

Though the charges are not related to espionage, the arrest adds new strain to the already difficult relationship between the U.S. and Pakistan, which suffered after the U.S. found Osama bin Laden hiding inside Pakistan and killed him without telling the government there.

In Court Papers, U.S. Openly Suggests Pakistan Interested in Thermonuclear Weapon

Via nationaljournal.com -

The United States in federal court documents offered its first open suggestion that nuclear-armed Pakistan could be seeking to build a thermonuclear weapon, the Pittsburgh Tribune-Review reported.

The Justice Department has charged a Chinese woman living in the United States with illegally exporting high-tech paint coatings that could aid Pakistan's nuclear-weapons development. As the ex-managing director of a Chinese branch of PPG Industries, Xun Wang is accused of shipping the material five years ago in direct disobedience of the Pittsburgh-based company and of nonproliferation guidelines issued by the Commerce Department.

Pakistan holds nuclear arms outside the Nuclear Nonproliferation Treaty and is a known past proliferator of sensitive technology and information through the black-market operation once led by scientist Abdul Qadeer Khan. As such, the United States has placed a number of restrictions on the trade of sensitive goods with the South Asian nation.

The U.S. Justice Department questions in court filings whether the paint-coating shipments could "aid Pakistan in developing thermonuclear weapons," the first instance in which Washington has formally in an open forum raised the issue of Islamabad's potential interest in a hydrogen weapon, according to Hans Kristensen, the Federation of American Scientists' nuclear information project director.

Although Pakistan has carried out nuclear tests using uranium-based weapons, it is not definitively known whether the country is recycling used atomic fuel to build a thermonuclear bomb, he said.

Wang holds permanent residency status in the United States. Before she joined PPG in 2006, the company had exported 290 gallons of the sophisticated coating to Pakistan to be used in building the nation's second atomic energy reactor at the Chashma complex, court filings state.

Chinese firms assisted Pakistan in constructing the first and second reactors at Chashma.

Two different deliveries totaling 360 gallons of epoxy coatings were also sent to Pakistan, while a fourth containing 265 gallons was stopped in Shanghai, records show.

Pakistan needed extra epoxy to complete covering the inside of the reactor. Otherwise, it would have been forced to conduct the costly work of stripping the PPG coating that had already been applied and replacing it with a different product.

Company officials besides Wang are believed to have tried to assist China's atomic work in Pakistan, government documents state.

Atomic analysts think it is highly likely that Islamabad constructed a facility close to the second Chashma reactor that could recycle used atomic fuel into weapon-usable plutonium.

Satellite photographs taken in the last decade reveal building taking place at the site of an unfinished Chashma-area plutonium reprocessing facility that had been abandoned in the 1970s, according to a 2007 analysis by Paul Brannan and David Albright, nuclear experts at the Institute for Science and International Security. As recently as 2006, construction vehicles and materials could be viewed at the site, and pavement had been laid on roads leading up to the unfinished processing plant.

The ISIS analysts speculated that the plutonium facility was close to finished and that China possibly aided Pakistan in the project. If they are correct, the analysts asserted that used nuclear fuel rods from the first and second Chashma energy reactors "would aid Pakistan in developing thermonuclear weapons as well as increasing the size of its nuclear arsenal."

RSA FraudAction News Flash: Trojan Add-On Forces Zombie PCs into Slavery to Mine Bitcoins

Via RSA Blog -

The RSA FraudAction Research Lab recently discovered a novel Trojan feature annexed to SpyEye Trojan variants (v1.03.45) and to Zeus Trojan variants (v2.0.8.9), made to maliciously target the Bitcoin e-currency system. The Trojans are now being used by their operators in a practice designed to leverage the extended botnet in order to mine Bitcoins.

This innovation is not to be confused with the hacking or stealing of the Bitcoin wallet; (which is likely also stolen by the Trojan), but rather a way to have the zombie computers on the botnet be part of a joint resource used for mining – and thus earning – Bitcoins.

This blog elaborates on what Bitcoins are, on the technical aspect of this new Trojan module as well on some of the possible implications this may have in the near future.


--------------------------------------------------------------------

Recently, Symantec released a write-up on the possibility of mining Bitcoins (BTC) using botnets.
"One of the selling points of the Bitcoin currency is that anyone with a computer can begin to earn Bitcoin blocks by using his or her computer’s computational power, along with open source Bitcoin software, to solve a difficult cryptographic proof-of-work problem. This is referred to as Bitcoin mining and, if successful in solving a block, it will lead to a reward of up to 50 Bitcoins per block...Taking this information into account, Bitcoin botnet mining as an attractive and profitable venture for cybercriminals is very questionable. However, with recent spikes in the valuation of Bitcoins reaching as high as $26, it may become more appealing in the future to cybercriminals as another source of illegal earnings from their botnets. Based, as the stability and value of Bit increase, as does the attractiveness of bitcoin botnet mining."
Looks like the developers of ZeuS and SpyEye are looking to get ahead of the curve.

Internet's Memory Effects Quantified in Computer Study

Via BBC (Science and Environment) -

Computers and the internet are changing the nature of our memory, research in the journal Science suggests.

Psychology experiments showed that people presented with difficult questions began to think of computers.

When participants knew that facts would be available on a computer later, they had poor recall of answers but enhanced recall of where they were stored.

The researchers say the internet acts as a "transactive memory" that we depend upon to remember for us.

Lead author Betsy Sparrow of Columbia University said that transactive memory "is an idea that there are external memory sources - really storage places that exist in other people".

"There are people who are experts in certain things and we allow them to be, [to] make them responsible for certain kinds of information," she explained to BBC News.

Co-author of the paper Daniel Wegner, now at Harvard University, first proposed the transactive memory concept in a book chapter titled Cognitive Interdependence in Close Relationships, finding that long-term couples relied on each other to act as one another's memory banks.

"I really think the internet has become a form of this transactive memory, and I wanted to test it," said Dr Sparrow.

[...]

"This suggests that for the things we can find online, we tend keep it online as far as memory is concerned - we keep it externally stored," Dr Sparrow said.

She explained that the propensity of participants to remember the location of the information, rather than the information itself, is a sign that people are not becoming less able to remember things, but simply organising vast amounts of available information in a more accessible way.

"I don't think Google is making us stupid - we're just changing the way that we're remembering things... If you can find stuff online even while you're walking down the street these days, then the skill to have, the thing to remember, is where to go to find the information. It's just like it would be with people - the skill to have is to remember who to go see about [particular topics]."