30 August 2012

Cyber War Envelops Middle East

Iran has already been hit by Flame, Duqu, and Stuxnet. Now we are learning of a more mysterious attack against Iran's oil infrastructure by malware called "Wiper:"
Wiper was an aggressive piece of malware that targeted machines belonging to the Iranian Oil Ministry and the National Iranian Oil Company in April.

...No one has ever found a sample of Wiper in order to study its code and determine exactly what it did to machines in Iran, but Kaspersky did obtain mirror images of “dozens” of hard drives that had been hit by the malware.

Although the disks were thoroughly wiped in most cases, leaving no malware behind – or much of anything else – the researchers did find evidence of its previous existence on some of the systems that weren’t completely wiped. The evidence came in the form of a registry key that pointed to files that had been on the machines before being erased.

According to Kaspersky, the wiping activity occurred between April 21 and April 30. Wiper’s erase operation focused initially on destroying data on the first half of a disk, then systematically erasing system files, causing the systems to crash and preventing them from rebooting... _Wired
Spread of Duqu

But Iran has not been entirely passive in this cyber-war. A recent cyber attack against Saudi Aramco -- Saudi Arabia's state energy company -- is thought to have originated with groups allied with Iran.
Saudi Aramco, Saudi Arabia's national energy company, said on Sunday it had repaired 30,000 workstations infected with a malicious virus earlier this month....

...A group calling itself the "Cutting Sword of Justice" claimed responsibility for the attacks. The group accused the Saudi Arabian government of supporting "crimes and atrocities" in countries such as Syria and Egypt, according to a post on Pastebin.

Saudi Aramco said it expected further intrusions. "Saudi Aramco is not the only company that became a target for such attempts, and this was not the first nor will it be the last illegal attempt to intrude into our systems, and we will ensure that we will further reinforce our systems with all available means to protect against a recurrence of this type of cyber-attack." _CW

Saudi Aramco is right to expect further attacks, just as the Iranian Oil Ministry should expect further attacks. In fact, all middle eastern oil production in and around the Persian Gulf is vulnerable to one type of malware or another. Whoever controls the flow of oil will be able to hold global oil markets hostage to potentially devastating price swings.
Earlier this year, a group of international experts at the Herzliya Conference imagined a very different scenario — a far more drastic one — in which a sophisticated attack on Abqaiq was directed by Iran and carried out from within. In the simulation, a series of explosions, along with a cyber-weapon, crippled the facility...

...The results of this simulated attack, detailed here in full for the first time, were profoundly disturbing. The price of oil skyrocketed to over $200 per barrel. The House of Saud, and the territorial integrity of the kingdom, were existentially threatened. Saudi Arabia’s neighbors — Jordan, Iraq, the UAE, Bahrain, Qatar, Kuwait and Oman — were destabilized. Developing countries that use oil for electricity were propelled into war, both civil and external.

And Iran, the world’s third-largest producer of oil, authoritatively recognized as the perpetrator of the attack, reaped the rewards, its influence growing throughout the Middle East as the demand for oil outpaced the supply, and the Shiite populations in the Gulf — increasingly unrestful throughout the Arab Spring revolutions — rose up in arms.

“The simulation showed that global over-reliance on Saudi oil and our over-reliance on Saudi stability, would give Iran, in the case of such an attack, carte blanche in the Middle East — and that’s without a nuclear weapon,” said Tommy Steiner, the author of the report... _How Iran Might Triumph Even Without Nukes

The evolution of increasingly sophisticated cyber attacks has just begun, and every industrial facility and information network is clearly at risk.

There is a limit to how well protected large networks can be and still function. In this situation, resilient backups will be increasingly important.

Labels: , , ,

Bookmark and Share

12 March 2012

Et Tu, Duqu?

Duqu, a trojan of unknown purpose spread by tainted Microsoft Word files, is supposedly the follow up to the Stuxnet worm, the self-replicating USB-stick-distributed malware that wrecked 400 uranium centrifuges with overspeed commands at Iran's Natanz nuclear fuel enrichment facility in 2010. Duqu is a remote access trojan (a RAT) and is waiting on instructions from a remote commander to activate it and tell it which files to steal, corrupt or run.

Stuxnet and Duqu are thought to have come from the same programming teams because they share whole chunks of code.... In a section of the malware called 'payload dll', and sandwiched between regular C++ code, there's a mysterious section written in an unknown programming language. "It's definitely not C++, Objective C, Java, Python, Ada, Lua or many other languages we have checked," says Soumenov. If it is a customised language that might very well need the support and resources of a nation state's security apparatus.

One of the strongest hints in the comments thread suggests that the language may be a variant of the AI programming language LISP, while another says the code looks like it might hail from a version of C++ for old IBM System/38 (from 1978) computers. They suggest the IBM-alike code may give Duqu a robust TCP/IP internet connection for receiving its malicious commands. _NewScientist
Duqu Spread

Here are a few conclusions that experts have arrived at regarding Duqu (excerpted and edited):
  • It is obvious that every single Duqu incident is unique with its own unique files using different names and checksums;
  • Duqu is used for targeted attacks with carefully selected victims (The term APT has been used to describe this, but I don’t like this expression and prefer not to use it);
  • We know that there are at least 13 different driver files (and we have only 6 of them);
    We haven’t found any ‘keylogger’ module usage. Either it has never been used in this particular set of incidents, or it has been encrypted, or it has been deleted from the systems;
  • Analysis of driver igdkmd16b.sys shows that there is a new encryption key, which means that existing detection methods of known PNF files (main DLL) are useless. It is obvious that the DLL is differently encoded in every single attack. Existing detection methods from the majority of AV vendors are able to successfully detect Duqu drivers. But it is almost 100% certain that the main DLL component (PNF) will go undetected.
  • Duqu is a multifunctional framework which is able to work with any number of any modules. Duqu is highly customizable and universal;
  • The main library (PNF) is able (export 5) to fully reconfigure and reinstall the package. It is able to install drivers and create additional components, record everything in the registry, etc. It means that if there is a connection to active the C&C and commands, then Duqu’s infrastructure on a particular system might be changed completely;
_Securenet
The fact that part of Duqu is written in an unknown programming language, suggests that the coders may just bet getting started, and are conducting something of an experiment in advanced remote command and control of computing systems.

Duqu code is being shared among a large number of persons and institutions interested in computer security and hacking. Symantec is among the companies that are tracking Duqu:
Symantec Corp. (SYMC) is among the firms tracking Duqu. Interestingly, they make some statements about the worm's origin which seemingly exonerate the U.S. from Stuxnet suspicions. Symantec states that the Duqu authors must have either been given code by the Stuxnet authors, have stolen the code from the Stuxnet authors, or are themselves the Stuxnet authors.

Symantec's Kevin Haley comments to Reuters, "We believe it is the latter."

The sophistication of this worm suggests that if the U.S. didn't have a hand in crafting it, that China or Russia perhaps did. A command and control server was found to be hosted in Belgium, but it's rather unlikely that the attackers chose their home nation to host the attacking platform.

China -- a cyber-superpower and notorious aggressor -- is thought to maintain a repository of unpublished vulnerabilities on platforms such as Windows, Linux, and OS X, waiting to exploit them when the need arises.

Nine international organizations have found their systems compromised. The compromised nations in these victim organizations are:
Organization A - France, Netherlands, Switzerland, Ukraine
Organization B - India
Organization C - Iran
Organization D - Iran
Organization E - Sudan
Organization F - Vietnam
Other researchers report that systems in the United Kingdom, Austria, Hungary, and Indonesia were infected. _DailyTech
No one is coming forward to admit having composed Duqu or Stuxnet. It is not clear that the two worms were disseminated by the same entities, since Stuxnet appears to have been aimed at Iran's nuclear projects, while Duqu may well be a copycat which is evolving beyond the abilities of its predecessor.

Labels: , ,

Bookmark and Share

21 February 2011

Night Dragon Hack-Attacks Connected to Industrial Accidents?

We hear about industrial accidents and explosions all the time. Here is a recent example from Turkey:
At least seven people were killed and 34 injured Thursday in an apparent accidental explosion at a factory in Turkey's capital Ankara, media reports said.

The death toll was likely to rise because several people were still believed to be buried under the rubble left by the explosion....The powerful explosion is believed to have been caused by a worker's mishandling of oxygen tanks at the factory, which employed at least 80 people in manufacturing hydraulic machinery. _MAC
But such accidents begin to take on new possible meanings as knowledge about the Chinese "Night Dragon" intrusions and the Stuxnet worm become more widely known. The Stuxnet worm took control of target machines in Iranian uranium enrichment facilities, causing them to behave erratically and destroy themselves. The Chinese Night Dragon attacks and intrusions are likewise capable of taking control of target machines:
...a [Chinese] company that, according to the company’s advertisements, provides “Hosted Servers in the U.S. with no records kept” for as little as 68 RMB (US$10) per year for 100 MB of space. The company’s U.S.-based leased servers have been used to host the zwShell C&C application that controlled machines across the victim companies.

...McAfee has determined that all of the identified data exfiltration activity occurred from Beijing-based IP addresses and operated inside the victim companies weekdays from 9:00 a.m. to 5:00 p.m. Beijing time, which also suggests that the involved individuals were “company men” working on a regular job, rather than freelance or unprofessional hackers. In addition, the attackers employed hacking tools of Chinese origin and that are prevalent on Chinese underground hacking forums. These included Hookmsgina and WinlogonHack, tools that intercept Windows logon requests and hijack usernames and passwords. _Forbes
The targets of Night Dragon included oil & gas companies which operate refineries -- refineries that are subject to exploding if their controls malfunction. The same is true for many chemical plants, and other types of industrial plants. Machinery at most modern factories is networked, to allow for highly automated operation. Anyone who can hack into the network and take control of the machines can also take control of the destiny of that plant.

Industrial work is already extremely hazardous, as jobs go. But in the highly-networked age, where sensitive machinery is controlled remotely via the net, there is one more hazard to worry about.

As Obama and his allies press for a highly networked "smart grid" which is meant to grow more reliant on inherently unreliable wind power, the hazards for society at large only grow larger.

Labels: , , ,

Bookmark and Share

17 February 2011

Stuxnet Heralds a Brave New World of Sophisticated Weaponry

Natanz Nuclear Enrichment Defense Iran
Stuxnet appears to have been developed in the US and refined in Israel, before being introduced into Iranian computers by shadowy import-export companies. More from Wired:
Suddenly, over a six-month period beginning late 2009, U.N. officials monitoring the surveillance images “watched in amazement” as Iranian workers “dismantled more than 10 percent of the plant’s 9,000 centrifuge machines used to enrich uranium,” according to the Washington Post. “Then, just as remarkably, hundreds of new machines arrived at the plant to replace the ones that were lost.”

Investigators described the effort as a feverish attempt to contain damage and replace broken parts, suggesting the centrifuges had indeed been operational when they broke....One other piece of information suggests Iran’s nuclear program was the target of Natanz. Last week security firm Symantec released a report revealing that the Stuxnet attack targeted five organizations in Iran that were infected first in an effort to spread the malware to Natanz.

Because Natanz’s PLCs are not connected to the internet, the best hope of attacking them – short of planting a mole inside Natanz – was infecting other computers that could serve as a gateway to the Natanz PLC. For example, infecting computers belonging to a contractor in charge of installing software at Natanz could help get the malware onto the Natanz system.

Symantec said the companies were hit in attacks in June and July 2009 and in March, April and May 2010. Symantec didn’t name the five organizations but said that they all “have a presence in Iran” and are involved in industrial processes._Wired
No one will shed tears for the Iranian nuclear weapons program, nor for the international companies which are illegally aiding the Iranians. But this attack is just the tip of the iceberg, and a mere suggestion of the wave of more sophisticated forms of sabotage, espionage, and covert warfare which is on the way.
Targeted acts of sabotage disrupt, but the real pay-off comes from identifying the human and technical links in the chain of command. Observing who responds – and when – to worm-driven destruction helps illuminate who really runs Iran’s nuclear infrastructures. Real-world Iranian responses offer critical clues as to which scientists, administrators and engineers are trusted and who is suspect. The chance to monitor Iran’s response would be of great interest to Mossad, the International Atomic Energy Agency, America’s CIA and/or Britain’s GCHQ.

Crafting a worm that generates potential insight into all those issues represents an intelligence coup. It is as potentially revelatory as a WikiLeaks data dump. That is why interpreting Stuxnet as desperate stop-gap or one-off intervention almost certainly misunderstands its purpose. Sabotage here is a means to an end; it is a gambit to make Iran’s nuclear processes more transparent.

Iran’s nuclear elite and Ministry of Intelligence know this. It is no secret now to the mullahs that their responses to the Stuxnet breach were closely monitored by external intelligence agencies. Their internal security is furiously trying to assess what information might have inadvertently been revealed. _FT

Stuxnet's sophistication is considered to be unprecedented. But from now on, Stuxnet will be the benchmark against which future spyware and malware will be gauged.
Mr Salem [of Symantec] said new technology and new approaches are needed.

"I run the largest security company in the world. I get up and people say I have a vested interest (in pushing this line). But my job is to protect and provide security and when we say critical infrastructure is under attack, it is real."

Mr Salem mapped out a number of strategic steps that need to be taken to guard against the next major cyber attack. They include an early warning system, better intelligence on what attacks could happen, better protection, the ability to anticipate what any threat could look like and the ability to clean up after an attack.

He also pointed to a role for government that might involve a counter attack or strike.

The idea of a kill switch to allow the government to switch off the internet if it is under attack is one he did not seem overly enthusiastic about.

"The ability for us to turn something off like that and not cause other massive disruption would be very hard. We are becoming more and more dependent on the internet. There are better approaches than trying to shut off the internet.
_BBC
This growing dependency on the internet can be seen at all levels of every society in the advanced world. It represents a growing vulnerability -- given the revelation of what malware like Stuxnet can do -- and needs to be addressed now, before societies move to depend upon an even more vulnerable "smart grid" power system. We should not make it easy for malicious outsiders to turn out our lights.

The threat is real, and the threat is now. The US government is one salient target, with large corporations and city/state governments also being notable targets.
More than 100 foreign intelligence agencies have tried to breach United States defence networks, largely to steal military plans and weapons systems designs, a top Pentagon official said. _NZHerald
Consequently, the US Pentagon is seeking half a billion US dollars to develop new cyber technologies -- including powerful new defenses to guard agains the powerful new cyber-attack threats.
The $500 million is part of the Pentagon’s 2012 budget request of $2.3 billion to improve the Defense Department’s cyber capabilities. At a Pentagon news conference yesterday, Defense Secretary Robert Gates called the research money, to be spent through the Defense Advanced Research Projects Agency, or Darpa, “big investment dollars, looking to the future.”

The military is reaching out to commercial companies for the latest technologies and technical experts to safeguard the Pentagon’s computer networks from attacks and espionage, Lynn said. The effort is part of a “comprehensive cyber strategy called Cyber 3.0,” he said. _Bloomberg

The djinn is long out of the bottle, wreaking havoc on uranium enrichment centrifuge cyber systems. Similar djinns will soon fly out, based upon similar advanced cyber technology, with wider mission profiles and less selective targeting.

But regular readers of Al Fin blogs will understand that this cyber threat -- for all its potential for disruption and destruction -- is only the visible and more imaginable problem. More creative and malicious destructors are on the way, as advanced sciences and technology merge with unimaginably sophisticated hardware and software.

This is the start of the long war, which may either result in humans sinking to a pre-technological level for hundreds or thousands of years, or in humans transcending their monkey natures on the way to the wide-open next level. Watch and see.

Excerpted from an article at abu al-fin

Stay up to date on the hidden war of cyber attack at Infowar.com

For the military side of things, stay current with StrategyPage.com

One of the deepest threats will come from "nano guns, nano germs, and nano steel".

It is not unreasonable to assume that a computer virus sent from across the world could program the assembly of a deadly human virus inside an unsecured university research lab located inside a friendly country. Tight connections to the internet by conventional research DNA and RNA (and protein) assembling equipment, will allow such stealth long-range hybrid cyber/bio warfare.

The same approach could lead to the programming of deadly stealth nanoweapons, and even macro-weapons, utilising 3-D printing devices connected to the net.

If you can imagine it, so can someone else with more malignant intent. Hope for the best. Prepare for the worst.

Labels: , , , ,

Bookmark and Share

28 November 2010

"Stuxnet Can't Hurt Us," Says Iranian Government

According to a report by the International Atomic Energy Agency, Iran has been forced to suspend activity on enriching uranium because of “technical problems” that are bedeviling thousands of centrifuges at its Natanz nuclear reactor. _TNA

Fueling of the reactor was delayed in recent months by what Iran called a small leak in a storage pool and not by the Stuxnet computer worm, allegedly designed to sabatoge Iran's nuclear power program, as is widely believed. _jta
Iran has adamantly stated that its nuclear program has not been hit by the bug. But in doing so it has backhandedly confirmed that its nuclear facilities were compromised. _FoxNews


Map: Ebequity
The sophisticated Stuxnet computer worm has the uncanny ability to "worm" its way into sensitive computer systems, then interferes with commands to motor controllers for centrifuges involved in uranium enrichment. Iran denies that its nuclear enrichment operations were negatively impacted by Stuxnet, but:
Experts dissecting the computer worm suspected of being aimed at Iran’s nuclear program have determined that it was precisely calibrated in a way that could send nuclear centrifuges wildly out of control.

Their conclusion, while not definitive, begins to clear some of the fog around the Stuxnet worm, a malicious program detected earlier this year on computers, primarily in Iran but also India, Indonesia and other countries. _NYT

Experts have examined the worm's code and come to some interesting conclusions about how the intruder works:
Here's how it worked, according to experts who have examined the worm:

--The nuclear facility in Iran runs an “air gap” security system, meaning it has no connections to the Web, making it secure from outside penetration. Stuxnet was designed and sent into the area around Iran's Natanz nuclear power plant -- just how may never be known -- to infect a number of computers on the assumption that someone working in the plant would take work home on a flash drive, acquire the worm and then bring it back to the plant.

--Once the worm was inside the plant, the next step was to get the computer system there to trust it and allow it into the system. That was accomplished because the worm contained a “digital certificate” stolen from JMicron, a large company in an industrial park in Taiwan. (When the worm was later discovered it quickly replaced the original digital certificate with another certificate, also stolen from another company, Realtek, a few doors down in the same industrial park in Taiwan.)

--Once allowed entry, the worm contained four “Zero Day” elements in its first target, the Windows 7 operating system that controlled the overall operation of the plant. Zero Day elements are rare and extremely valuable vulnerabilities in a computer system that can be exploited only once. Two of the vulnerabilities were known, but the other two had never been discovered. Experts say no hacker would waste Zero Days in that manner.

--After penetrating the Windows 7 operating system, the code then targeted the “frequency converters” that ran the centrifuges. To do that it used specifications from the manufacturers of the converters. One was Vacon, a Finnish Company, and the other Fararo Paya, an Iranian company. What surprises experts at this step is that the Iranian company was so secret that not even the IAEA knew about it.

--The worm also knew that the complex control system that ran the centrifuges was built by Siemens, the German manufacturer, and -- remarkably -- how that system worked as well and how to mask its activities from it.

--Masking itself from the plant's security and other systems, the worm then ordered the centrifuges to rotate extremely fast, and then to slow down precipitously. This damaged the converter, the centrifuges and the bearings, and it corrupted the uranium in the tubes. It also left Iranian nuclear engineers wondering what was wrong, as computer checks showed no malfunctions in the operating system.

Estimates are that this went on for more than a year, leaving the Iranian program in chaos. And as it did, the worm grew and adapted throughout the system. As new worms entered the system, they would meet and adapt and become increasingly sophisticated.

During this time the worms reported back to two servers that had to be run by intelligence agencies, one in Denmark and one in Malaysia. The servers monitored the worms and were shut down once the worm had infiltrated Natanz. Efforts to find those servers since then have yielded no results.

This went on until June of last year, when a Belarusan company working on the Iranian power plant in Beshehr discovered it in one of its machines. It quickly put out a notice on a Web network monitored by computer security experts around the world. _FoxNews
It is apparent to Al Fin security analysts, that Stuxnet is the work of agencies within the Israeli government. It is extremely likely that the Iranians are lying through their teeth in regard to the damage that the worm did to their nuclear enrichment programs.

Imagine that instead of computer worms, the Stuxnet ensemble had been a set of nanotechnological infiltrators, capable of imitating desert dust, bunker concrete, or pipeline insulation. Propelled by blowing winds, flowing water, on the soles of shoes, or inside the lungs of workers -- essentially unstoppable by most modern security systems. Such a suite of nanotech infiltrators could not only install computer worms into virtually any system, they could insert targeted explosive devices to disrupt communications, convey poisonous substances into ventilation or water systems, or travel in a target's circulatory system to cerebral arterioles, where they do whatever damage they are programmed to do.

We see that deep underground bunkers are essentially naked to the newer and more clever tools of saboutage. How much more exposed are government and industrial centers on the surface.

The world is entering a new age of advanced espionage and covert destruction. Stuxnet can be seen as an early warning of the type of destructive tools which are coming soon, out of the djinn's bottle. Once released from their container, they cannot be returned safely.

Update 29 Nov 2010: Someone was unwilling to wait for advances in nanotechnological espionage and saboutage. Bombers-on-motorcycles used magnetic-attachable bombs on automobiles to attack two Iranian nuclear scientists (killing one and injuring the other) in Tehran. One of the scientists, at least may have been involved in trying to counter the effects of the Stuxnet worm on Iran's nuclear facilities (see comments).

Labels: , ,

Bookmark and Share
Older Posts
Al Fin Main Page
Enter your Email


Powered by FeedBlitz
Google
WWW AL FIN

Powered by
Blogger

``