Showing posts with label espionage. Show all posts
Showing posts with label espionage. Show all posts

Monday, April 14, 2014

Germany's aeronautics and space research centre (DLR): China espionage attack

The logo of the Germany's aeronautics and space research centre (DLR) in Oberpfaffenhofen, southern Germany 

Germany's aeronautics and space research centre (DLR) has for months been the target of a suspected cyber attack by a foreign intelligence service, a German news weekly reported Sunday.

Der Spiegel said that several computers used by scientists and systems administrators at the Cologne-based DLR centre had been infiltrated by spy programmes.

"The government classes the attack as extremely serious because it, among other things, is aimed at armament and rocket technolgies," Spiegel said.

In some computers IT experts found traces of spy programmes that were set up to destroy themselves on discovery, while others only activated themselves after months of lying in wait.

Spiegel said the attacks were "coordinated and systematic" and all the centre's operation systems were affected.

IT forensic experts probing who could be behind the assault have turned up clues that seem to point to China, but Spiegel quoted an unidentifed "insider" as saying they could also simply be "camouflage".

Government sources said the case was being investigated but declined to confirm any details.

The German aeronautics and space research centre is active in the fields of aeronautics, space, energy, transport and security and is involved in international cooperative ventures, according to its website.

Monday, May 28, 2012

Meet "Flame", The Massive Spy Malware Infiltrating Iranian Computers

A massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation.

The malware, discovered by Russia-based anti-virus firm Kaspersky Lab, is an espionage toolkit that has been infecting targeted systems in Iran, Lebanon, Syria, Sudan, the Israeli Occupied Territories and other countries in the Middle East and North Africa for at least two years.

Dubbed “Flame” by Kaspersky, the malicious code dwarfs Stuxnet in size – the groundbreaking infrastructure-sabotaging malware that is believed to have wreaked havoc on Iran’s nuclear program in 2009 and 2010.

Although Flame has both a different purpose and composition than Stuxnet, and appears to have been written by different programmers, its complexity, the geographic scope of its infections and its behavior indicate strongly that a nation-state is behind Flame, rather than common cyber-criminals — marking it as yet another tool in the growing arsenal of cyberweaponry.

The researchers say that Flame may be part of a parallel project created by contractors who were hired by the same nation-state team that was behind Stuxnet and its sister malware, DuQu.

“Stuxnet and Duqu belonged to a single chain of attacks, which raised cyberwar-related concerns worldwide,” said Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, in a statement.

“The Flame malware looks to be another phase in this war, and it’s important to understand that such cyber weapons can easily be used against any country.”

Early analysis of Flame by the Lab indicates that it’s designed primarily to spy on the users of infected computers and steal data from them, including documents, recorded conversations and keystrokes. It also opens a backdoor to infected systems to allow the attackers to tweak the toolkit and add new functionality.

The malware, which is 20 megabytes when all of its modules are installed, contains multiple libraries, SQLite3 databases, various levels of encryption — some strong, some weak — and 20 plug-ins that can be swapped in and out to provide various functionality for the attackers.

It even contains some code that is written in the LUA programming language — an uncommon choice for malware.

Kaspersky Lab is calling it “one of the most complex threats ever discovered.”

“It’s pretty fantastic and incredible in complexity,” said Alexander Gostev, chief security expert at Kaspersky Lab.

Flame appears to have been operating in the wild as early as March 2010, though it remained undetected by antivirus companies.

“It’s a very big chunk of code. Because of that, it’s quite interesting that it stayed undetected for at least two years,” Gostev said. He noted that there are clues that the malware may actually date back to as early as 2007, around the same time-period when Stuxnet and DuQu are believed to have been created.

Gostev says that because of its size and complexity, complete analysis of the code may take years.

“It took us half-a-year to analyze Stuxnet,” he said. “This is 20-times more complicated. It will take us 10 years to fully understand everything.”

Kaspersky discovered the malware about two weeks ago after the United Nations’ International Telecommunications Union asked the Lab to look into reports in April that computers belonging to the Iranian Oil Ministry and the Iranian National Oil Company had been hit with malware that was stealing and deleting information from the systems.

The malware was named alternatively in news articles as “Wiper” and “Viper,” a discrepancy that may be due to a translation mixup.

Kaspersky researchers searched through their reporting archive, which contains suspicious filenames sent automatically from customer machines so the names can be checked against whitelists of known malware, and found an MD5 hash and filename that appeared to have been deployed only on machines in Iran and other Middle East countries.

As the researchers dug further, they found other components infecting machines in the region, which they pieced together as parts of Flame.

Kaspersky, however, is currently treating Flame as if it is not connected to Viper, and believes it is a separate infection entirely. The researchers dubbed the toolkit “Flame” after the name of a module inside it.

Read more here

Tuesday, November 24, 2009

China sponsors Cyberwar against USA

A US government report warned Thursday that China is sharply stepping up espionage against the United States as the rising Asian power invests in cyber warfare and grows more sophisticated in recruiting spies.

"China is changing the way that espionage is being done," said Carolyn Bartholomew, the chair of the US-China Economic and Security Review Commission.

In its wide-ranging annual report to Congress, the commission reported a steep rise in the disruption and infiltration of websites of the US government and perceived Beijing rivals such as Tibet's exiled leader the Dalai Lama.

Colonel Gary McAlum, a senior military officer, told the commission the US Defense Department detected 54,640 malicious cyber incidents to its systems in 2008, a 20 percent rise from a year earlier. The figure is on track to jump another 60 percent this year.

While the attacks came from around the world, the commission said China was the largest culprit. Some Chinese "patriotic hackers" may not receive official support, but the report said the government likely planned to deploy them in a conflict to disrupt a foreign adversary's computers.

The bipartisan commission found that China was the most aggressive nation in spying on the United States and was trying to recruit more American spies.

While China historically tried to tap Chinese Americans -- believing, often incorrectly, that they would be sympathetic -- it was now turning to the Soviet model of seeking to bribe informants with cash and gifts, the report said.

It said the Chinese were expanding "false flag" operations, in which sources are deceived into thinking they are providing information elsewhere.

It pointed to the case of Tai Shen Kuo, a furniture salesman in New Orleans arrested last year after persuading two retired US military officials to give sensitive information by telling them it was headed to Taiwan, not mainland China.

The commission also found that China has launched an effort to influence US think-tanks and academia by rewarding scholars with access and depriving visas to more critical voices.

"It becomes self-censorship. If you're in graduate school and want to become a China scholar, you need to go to China. And if you criticize the Chinese government on certain things, you won't get in," said Bartholomew, a former top aide to House Speaker Nancy Pelosi.

"What it means is that we have a generation of China analysts who are being created who don't necessarily have the freedom or the ability to think through a broader range of questions," she said.

The commission also criticized China on its trade policy, recommending that the United States press Beijing to make its yuan more flexible and to turn to the World Trade Organization to fight what it termed predatory trade practices.

Shortly after the release of the report, two lawmakers called for an investigation into China's "currency manipulation," which would set the stage for slapping import duties on Chinese goods.

President Barack Obama this week paid his first visit to China, which is now the top holder of the ballooning US debt. His administration has sought cooperation with China on battling the global slowdown.

The commission paid a field trip to Rochester in upstate New York, where it said core industries such as machine tools, auto parts and optoelectronics were struggling against Chinese competition that often enjoys state support.

"For 20 years we have watched China policy be controlled really by a handful of large multinational corporations. They're the ones who determine the interests," Bartholomew said.

"But there are a lot of constituency interests out there -- particularly small and medium-sized enterprises -- that are being hurt by the current US-China policy," she said.

Separately, the report recommended that the United States "continue to work with Taiwan to modernize its armed forces," saying China was rapidly expanding its military advantage despite easing tensions with the island.

The Obama administration has yet to decide on Taiwan's requests to buy arms, including F-16 jet fighters. Such a step would almost certainly anger China, which considers the island its territory.