30 August 2012

Cyber War Envelops Middle East

Iran has already been hit by Flame, Duqu, and Stuxnet. Now we are learning of a more mysterious attack against Iran's oil infrastructure by malware called "Wiper:"
Wiper was an aggressive piece of malware that targeted machines belonging to the Iranian Oil Ministry and the National Iranian Oil Company in April.

...No one has ever found a sample of Wiper in order to study its code and determine exactly what it did to machines in Iran, but Kaspersky did obtain mirror images of “dozens” of hard drives that had been hit by the malware.

Although the disks were thoroughly wiped in most cases, leaving no malware behind – or much of anything else – the researchers did find evidence of its previous existence on some of the systems that weren’t completely wiped. The evidence came in the form of a registry key that pointed to files that had been on the machines before being erased.

According to Kaspersky, the wiping activity occurred between April 21 and April 30. Wiper’s erase operation focused initially on destroying data on the first half of a disk, then systematically erasing system files, causing the systems to crash and preventing them from rebooting... _Wired
Spread of Duqu

But Iran has not been entirely passive in this cyber-war. A recent cyber attack against Saudi Aramco -- Saudi Arabia's state energy company -- is thought to have originated with groups allied with Iran.
Saudi Aramco, Saudi Arabia's national energy company, said on Sunday it had repaired 30,000 workstations infected with a malicious virus earlier this month....

...A group calling itself the "Cutting Sword of Justice" claimed responsibility for the attacks. The group accused the Saudi Arabian government of supporting "crimes and atrocities" in countries such as Syria and Egypt, according to a post on Pastebin.

Saudi Aramco said it expected further intrusions. "Saudi Aramco is not the only company that became a target for such attempts, and this was not the first nor will it be the last illegal attempt to intrude into our systems, and we will ensure that we will further reinforce our systems with all available means to protect against a recurrence of this type of cyber-attack." _CW

Saudi Aramco is right to expect further attacks, just as the Iranian Oil Ministry should expect further attacks. In fact, all middle eastern oil production in and around the Persian Gulf is vulnerable to one type of malware or another. Whoever controls the flow of oil will be able to hold global oil markets hostage to potentially devastating price swings.
Earlier this year, a group of international experts at the Herzliya Conference imagined a very different scenario — a far more drastic one — in which a sophisticated attack on Abqaiq was directed by Iran and carried out from within. In the simulation, a series of explosions, along with a cyber-weapon, crippled the facility...

...The results of this simulated attack, detailed here in full for the first time, were profoundly disturbing. The price of oil skyrocketed to over $200 per barrel. The House of Saud, and the territorial integrity of the kingdom, were existentially threatened. Saudi Arabia’s neighbors — Jordan, Iraq, the UAE, Bahrain, Qatar, Kuwait and Oman — were destabilized. Developing countries that use oil for electricity were propelled into war, both civil and external.

And Iran, the world’s third-largest producer of oil, authoritatively recognized as the perpetrator of the attack, reaped the rewards, its influence growing throughout the Middle East as the demand for oil outpaced the supply, and the Shiite populations in the Gulf — increasingly unrestful throughout the Arab Spring revolutions — rose up in arms.

“The simulation showed that global over-reliance on Saudi oil and our over-reliance on Saudi stability, would give Iran, in the case of such an attack, carte blanche in the Middle East — and that’s without a nuclear weapon,” said Tommy Steiner, the author of the report... _How Iran Might Triumph Even Without Nukes

The evolution of increasingly sophisticated cyber attacks has just begun, and every industrial facility and information network is clearly at risk.

There is a limit to how well protected large networks can be and still function. In this situation, resilient backups will be increasingly important.

Labels: , , ,

Bookmark and Share

12 March 2012

Et Tu, Duqu?

Duqu, a trojan of unknown purpose spread by tainted Microsoft Word files, is supposedly the follow up to the Stuxnet worm, the self-replicating USB-stick-distributed malware that wrecked 400 uranium centrifuges with overspeed commands at Iran's Natanz nuclear fuel enrichment facility in 2010. Duqu is a remote access trojan (a RAT) and is waiting on instructions from a remote commander to activate it and tell it which files to steal, corrupt or run.

Stuxnet and Duqu are thought to have come from the same programming teams because they share whole chunks of code.... In a section of the malware called 'payload dll', and sandwiched between regular C++ code, there's a mysterious section written in an unknown programming language. "It's definitely not C++, Objective C, Java, Python, Ada, Lua or many other languages we have checked," says Soumenov. If it is a customised language that might very well need the support and resources of a nation state's security apparatus.

One of the strongest hints in the comments thread suggests that the language may be a variant of the AI programming language LISP, while another says the code looks like it might hail from a version of C++ for old IBM System/38 (from 1978) computers. They suggest the IBM-alike code may give Duqu a robust TCP/IP internet connection for receiving its malicious commands. _NewScientist
Duqu Spread

Here are a few conclusions that experts have arrived at regarding Duqu (excerpted and edited):
  • It is obvious that every single Duqu incident is unique with its own unique files using different names and checksums;
  • Duqu is used for targeted attacks with carefully selected victims (The term APT has been used to describe this, but I don’t like this expression and prefer not to use it);
  • We know that there are at least 13 different driver files (and we have only 6 of them);
    We haven’t found any ‘keylogger’ module usage. Either it has never been used in this particular set of incidents, or it has been encrypted, or it has been deleted from the systems;
  • Analysis of driver igdkmd16b.sys shows that there is a new encryption key, which means that existing detection methods of known PNF files (main DLL) are useless. It is obvious that the DLL is differently encoded in every single attack. Existing detection methods from the majority of AV vendors are able to successfully detect Duqu drivers. But it is almost 100% certain that the main DLL component (PNF) will go undetected.
  • Duqu is a multifunctional framework which is able to work with any number of any modules. Duqu is highly customizable and universal;
  • The main library (PNF) is able (export 5) to fully reconfigure and reinstall the package. It is able to install drivers and create additional components, record everything in the registry, etc. It means that if there is a connection to active the C&C and commands, then Duqu’s infrastructure on a particular system might be changed completely;
_Securenet
The fact that part of Duqu is written in an unknown programming language, suggests that the coders may just bet getting started, and are conducting something of an experiment in advanced remote command and control of computing systems.

Duqu code is being shared among a large number of persons and institutions interested in computer security and hacking. Symantec is among the companies that are tracking Duqu:
Symantec Corp. (SYMC) is among the firms tracking Duqu. Interestingly, they make some statements about the worm's origin which seemingly exonerate the U.S. from Stuxnet suspicions. Symantec states that the Duqu authors must have either been given code by the Stuxnet authors, have stolen the code from the Stuxnet authors, or are themselves the Stuxnet authors.

Symantec's Kevin Haley comments to Reuters, "We believe it is the latter."

The sophistication of this worm suggests that if the U.S. didn't have a hand in crafting it, that China or Russia perhaps did. A command and control server was found to be hosted in Belgium, but it's rather unlikely that the attackers chose their home nation to host the attacking platform.

China -- a cyber-superpower and notorious aggressor -- is thought to maintain a repository of unpublished vulnerabilities on platforms such as Windows, Linux, and OS X, waiting to exploit them when the need arises.

Nine international organizations have found their systems compromised. The compromised nations in these victim organizations are:
Organization A - France, Netherlands, Switzerland, Ukraine
Organization B - India
Organization C - Iran
Organization D - Iran
Organization E - Sudan
Organization F - Vietnam
Other researchers report that systems in the United Kingdom, Austria, Hungary, and Indonesia were infected. _DailyTech
No one is coming forward to admit having composed Duqu or Stuxnet. It is not clear that the two worms were disseminated by the same entities, since Stuxnet appears to have been aimed at Iran's nuclear projects, while Duqu may well be a copycat which is evolving beyond the abilities of its predecessor.

Labels: , ,

Bookmark and Share

17 February 2011

Stuxnet Heralds a Brave New World of Sophisticated Weaponry

Natanz Nuclear Enrichment Defense Iran
Stuxnet appears to have been developed in the US and refined in Israel, before being introduced into Iranian computers by shadowy import-export companies. More from Wired:
Suddenly, over a six-month period beginning late 2009, U.N. officials monitoring the surveillance images “watched in amazement” as Iranian workers “dismantled more than 10 percent of the plant’s 9,000 centrifuge machines used to enrich uranium,” according to the Washington Post. “Then, just as remarkably, hundreds of new machines arrived at the plant to replace the ones that were lost.”

Investigators described the effort as a feverish attempt to contain damage and replace broken parts, suggesting the centrifuges had indeed been operational when they broke....One other piece of information suggests Iran’s nuclear program was the target of Natanz. Last week security firm Symantec released a report revealing that the Stuxnet attack targeted five organizations in Iran that were infected first in an effort to spread the malware to Natanz.

Because Natanz’s PLCs are not connected to the internet, the best hope of attacking them – short of planting a mole inside Natanz – was infecting other computers that could serve as a gateway to the Natanz PLC. For example, infecting computers belonging to a contractor in charge of installing software at Natanz could help get the malware onto the Natanz system.

Symantec said the companies were hit in attacks in June and July 2009 and in March, April and May 2010. Symantec didn’t name the five organizations but said that they all “have a presence in Iran” and are involved in industrial processes._Wired
No one will shed tears for the Iranian nuclear weapons program, nor for the international companies which are illegally aiding the Iranians. But this attack is just the tip of the iceberg, and a mere suggestion of the wave of more sophisticated forms of sabotage, espionage, and covert warfare which is on the way.
Targeted acts of sabotage disrupt, but the real pay-off comes from identifying the human and technical links in the chain of command. Observing who responds – and when – to worm-driven destruction helps illuminate who really runs Iran’s nuclear infrastructures. Real-world Iranian responses offer critical clues as to which scientists, administrators and engineers are trusted and who is suspect. The chance to monitor Iran’s response would be of great interest to Mossad, the International Atomic Energy Agency, America’s CIA and/or Britain’s GCHQ.

Crafting a worm that generates potential insight into all those issues represents an intelligence coup. It is as potentially revelatory as a WikiLeaks data dump. That is why interpreting Stuxnet as desperate stop-gap or one-off intervention almost certainly misunderstands its purpose. Sabotage here is a means to an end; it is a gambit to make Iran’s nuclear processes more transparent.

Iran’s nuclear elite and Ministry of Intelligence know this. It is no secret now to the mullahs that their responses to the Stuxnet breach were closely monitored by external intelligence agencies. Their internal security is furiously trying to assess what information might have inadvertently been revealed. _FT

Stuxnet's sophistication is considered to be unprecedented. But from now on, Stuxnet will be the benchmark against which future spyware and malware will be gauged.
Mr Salem [of Symantec] said new technology and new approaches are needed.

"I run the largest security company in the world. I get up and people say I have a vested interest (in pushing this line). But my job is to protect and provide security and when we say critical infrastructure is under attack, it is real."

Mr Salem mapped out a number of strategic steps that need to be taken to guard against the next major cyber attack. They include an early warning system, better intelligence on what attacks could happen, better protection, the ability to anticipate what any threat could look like and the ability to clean up after an attack.

He also pointed to a role for government that might involve a counter attack or strike.

The idea of a kill switch to allow the government to switch off the internet if it is under attack is one he did not seem overly enthusiastic about.

"The ability for us to turn something off like that and not cause other massive disruption would be very hard. We are becoming more and more dependent on the internet. There are better approaches than trying to shut off the internet.
_BBC
This growing dependency on the internet can be seen at all levels of every society in the advanced world. It represents a growing vulnerability -- given the revelation of what malware like Stuxnet can do -- and needs to be addressed now, before societies move to depend upon an even more vulnerable "smart grid" power system. We should not make it easy for malicious outsiders to turn out our lights.

The threat is real, and the threat is now. The US government is one salient target, with large corporations and city/state governments also being notable targets.
More than 100 foreign intelligence agencies have tried to breach United States defence networks, largely to steal military plans and weapons systems designs, a top Pentagon official said. _NZHerald
Consequently, the US Pentagon is seeking half a billion US dollars to develop new cyber technologies -- including powerful new defenses to guard agains the powerful new cyber-attack threats.
The $500 million is part of the Pentagon’s 2012 budget request of $2.3 billion to improve the Defense Department’s cyber capabilities. At a Pentagon news conference yesterday, Defense Secretary Robert Gates called the research money, to be spent through the Defense Advanced Research Projects Agency, or Darpa, “big investment dollars, looking to the future.”

The military is reaching out to commercial companies for the latest technologies and technical experts to safeguard the Pentagon’s computer networks from attacks and espionage, Lynn said. The effort is part of a “comprehensive cyber strategy called Cyber 3.0,” he said. _Bloomberg

The djinn is long out of the bottle, wreaking havoc on uranium enrichment centrifuge cyber systems. Similar djinns will soon fly out, based upon similar advanced cyber technology, with wider mission profiles and less selective targeting.

But regular readers of Al Fin blogs will understand that this cyber threat -- for all its potential for disruption and destruction -- is only the visible and more imaginable problem. More creative and malicious destructors are on the way, as advanced sciences and technology merge with unimaginably sophisticated hardware and software.

This is the start of the long war, which may either result in humans sinking to a pre-technological level for hundreds or thousands of years, or in humans transcending their monkey natures on the way to the wide-open next level. Watch and see.

Excerpted from an article at abu al-fin

Stay up to date on the hidden war of cyber attack at Infowar.com

For the military side of things, stay current with StrategyPage.com

One of the deepest threats will come from "nano guns, nano germs, and nano steel".

It is not unreasonable to assume that a computer virus sent from across the world could program the assembly of a deadly human virus inside an unsecured university research lab located inside a friendly country. Tight connections to the internet by conventional research DNA and RNA (and protein) assembling equipment, will allow such stealth long-range hybrid cyber/bio warfare.

The same approach could lead to the programming of deadly stealth nanoweapons, and even macro-weapons, utilising 3-D printing devices connected to the net.

If you can imagine it, so can someone else with more malignant intent. Hope for the best. Prepare for the worst.

Labels: , , , ,

Bookmark and Share
Older Posts
Al Fin Main Page
Enter your Email


Powered by FeedBlitz
Google
WWW AL FIN

Powered by
Blogger

``