NSA Broke the Encryption on File-Sharing Apps Kazaa and eDonkey
An NSA program called GRIMPLATE was developed to study how Department of Defense employees used BitTorrent, discover if this use was malicious, and potentially build a case for ending such use. According to a classified presentation from the 2012 iteration of the NSA’s annual SIGDEV conference, which aims to develop new sources of signals intelligence, “BitTorrent sessions are seen on a daily basis between NIPRnet hosts,” referring to computers on the DOD network for sensitive but unclassified information, “and [in] adversary space,” that is, outside networks run by U.S. targets like Russia and China. By 2010, the British electronic eavesdropping agency Government Communications Headquarters was also interested in “active P2P exploitation research,” according to a page on an internal GCHQ wiki. The page describes DIRTY RAT, a GCHQ web application used by analysts that at the time had “the capability to identify users sharing/downloading files of interest on the eMule (Kademlia) and BitTorrent networks. The wiki article also hints at information sharing with law enforcement. “DIRTY RAT will soon be delivered to the [London] Metropolitan Police and we are in the early stages of relationships with [U.K. child protection agency] CEOP and the FBI,” it stated. GCHQ also developed the technology to leverage its peer-to-peer monitoring for active attacks against users of file-sharing networks. A tool called PLAGUE RAT “has the capability to alter the search results of eMule and deliver tailored content to a target,” the wiki article states. “This capability has been tested successfully on the Internet against ourselves and testing against a real target is being pursued.”
intercept, 13.09.2017
NSA officials worried about the day its potent hacking tool would get loose. Then it did.
When the National Security Agency began using a new hacking tool called EternalBlue, those entrusted with deploying it marveled at both its uncommon power and the widespread havoc it could wreak if it ever got loose. Some officials even discussed whether the flaw was so dangerous they should reveal it to Microsoft, the company whose software the government was exploiting, according to former NSA employees who spoke on the condition of anonymity given the sensitivity of the issue. But for more than five years, the NSA kept using it — through a time period that has seen several serious security breaches — and now the officials’ worst fears have been realized. The malicious code at the heart of the WannaCry virus that hit computer systems globally late last week was apparently stolen from the NSA, repackaged by cybercriminals and unleashed on the world for a cyberattack that now ranks as among the most disruptive in history. The failure to keep EternalBlue out of the hands of criminals and other adversaries casts the NSA’s decisions in a harsh new light, prompting critics to question anew whether the agency can be trusted to develop and protect such potent hacking tools.
wp, 16.05.2017
WannaCry: Was wir bisher über die Ransomware-Attacke wissen
Seit Freitagabend breitet sich die Ransomware WannaCry (WanaDecrypt0r 2.0) im weltweiten Internet aus. Es handelt sich um einen Kryptotrojaner, der Daten auf den betroffenen Computern verschlüsselt. Weltweit sollen zur Stunde über 220.000 Systeme betroffen sein. Anders als Locky & Co springt der Schädling von einem infizierten Rechner auf andere, übers Netz erreichbare Windows-Systeme über. Nach bisherigen Erkenntnissen nutzt WannaCry zwei Angriffsvektoren: Einmal verbreitet er sich – wie bei Kryptotrojanern üblich – per E-Mail. Doch wenn der Schädling ein Sytem infiziert hat, versucht er auch, wie ein Wurm andere Rechner im gleichen Netz zu kompromittieren. Dafür nutzt WannaCry offenbar eine Lücke in Windows Dateifreigaben (SMB). Diese Lücke war bekannt geworden, nachdem eine Hackergruppe namens Shadow Brokers einige Exploits der NSA-nahen Equation Group veröffentlicht hatte. Der Exploit, der die von WannaCry genutzte Lücke ausnutzt, ist unter dem Namen EternalBlue bekannt.
heise, 13.05.2017
Shadow Brokers Leak Shows NSA Hacked Middle East Banking System and Had Major Windows Exploits
Friday morning, the Shadow Brokers published documents that—if legitimate—show just how thoroughly US intelligence has compromised elements of the global banking system. The new leak includes evidence that the NSA hacked into EastNets, a Dubai-based firm that oversees payments in the global SWIFT transaction system for dozens of client banks and other firms, particularly in the Middle East. The leak includes detailed lists of hacked or potentially targeted computers, including those belonging to firms in Qatar, Dubai, Abu Dhabi, Syria, Yemen, and the Palestinian territories. Also included in the data dump, as in previous Shadow Brokers releases, are a load of fresh hacking tools, this time targeting a slew of Windows versions.
wired, 14.04.2017
NSA-Mitarbeiter verlassen angeblich den Geheimdienst in Scharen
Auf einer Veranstaltung der Journalism School an der University of Maryland berichtete der ehemalige NSA-Direktor Keith Alexander am vergangenen Dienstag, dass der berühmt-berüchtigte Geheimdienst angeblich in Schwierigkeiten steckt. Die besten Leute würden scharenweise die NSA verlassen, deren Direktor auch der Kommandeur des Cyberkommandos des Pentagon ist. Schuld sei der schlechte Ruf nach den Leaks von Edward Snowden, aber auch bessere Verdienstmöglichkeiten in der Privatwirtschaft. Man kann durchaus vermuten, dass Alexander damit nicht seinen früheren Arbeitgeber klein reden will, sondern schon einmal vor dem Amtsantritt von Donald Trump die Aufmerksamkeit auf die NSA lenken will, dass hier nicht gespart werden darf, sondern mehr Geld zum Schutz der nationalen Sicherheit erforderlich sei.
telepolis, 09.12.2016
The NSA Leak Is Real, Snowden Documents Confirm
On Monday, a hacking group calling itself the “ShadowBrokers” announced an auction for what it claimed were “cyber weapons” made by the NSA. Based on never-before-published documents provided by the whistleblower Edward Snowden, The Intercept can confirm that the arsenal contains authentic NSA software, part of a powerful constellation of tools used to covertly infect computers worldwide. The evidence that ties the ShadowBrokers dump to the NSA comes in an agency manual for implanting malware, classified top secret, provided by Snowden, and not previously available to the public. The draft manual instructs NSA operators to track their use of one malware program using a specific 16-character string, “ace02468bdf13579.” That exact same string appears throughout the ShadowBrokers leak in code associated with the same program, SECONDDATE. SECONDDATE is a tool designed to intercept web requests and redirect browsers on target computers to an NSA web server. That server, in turn, is designed to infect them with malware. SECONDDATE’s existence was first reported by The Intercept in 2014, as part of a look at a global computer exploitation effort code-named TURBINE. The malware server, known as FOXACID, has also been described in previously released Snowden documents. This overview jibes with previously unpublished classified files provided by Snowden that illustrate how SECONDDATE is a component of BADDECISION, a broader NSA infiltration tool. According to one December 2010 PowerPoint presentation titled “Introduction to BADDECISION,” that tool is also designed to send users of a wireless network, sometimes referred to as an 802.11 network, to FOXACID malware servers. To position themselves within range of a vulnerable wireless network, NSA operators can use a mobile antenna system running software code-named BLINDDATE, depicted in the field in what appears to be Kabul. The software can even be attached to a drone. BLINDDATE in turn can run BADDECISION, which allows for a SECONDDATE attack.
intercept, 19.08.2016
The Shadow Brokers EPICBANANAS and EXTRABACON Exploits
On August 15th, 2016, Cisco was alerted to information posted online by the “Shadow Brokers”, which claimed to possess disclosures from the Equation Group. The files included exploit code that can be used against multi-vendor devices, including the Cisco ASA and legacy Cisco PIX firewalls. There were three references to exploits that affect Cisco ASA, Cisco PIX, and Cisco Firewall Services Module: EXTRABACON, EPICBANANA, and JETPLOW. The EXTRABACON exploit targets a buffer overflow vulnerability in the SNMP code of the Cisco ASA, Cisco PIX, and Cisco Firewall Services Module. An attacker could exploit this vulnerability by sending crafted SNMP packets to an affected Cisco product. The EPICBANANA exploit could allow an authenticated attacker to create a denial of service (DoS) condition or potentially execute arbitrary code. An attacker could exploit this vulnerability by invoking certain invalid commands in an affected device. The attacker must know the telnet or SSH password in order to successfully exploit an affected device. JETPLOW is a persistent implant of EPICBANANA. Digitally signed Cisco software is signed using secure asymmetrical (public-key) cryptography in newer platforms prevents these types of attacks.
cisco, 17.08.2016
‘Shadow Brokers’ Claim to be Selling NSA Malware, in What Could Be Historic Hack
A mysterious online group calling itself “The Shadow Brokers” is claiming to have penetrated the National Security Agency, stolen some of its malware, and is auctioning off the files to the highest bidder. The files posted over the weekend include two sets of files. The hackers have made one set available for free. The other remains encrypted and is the subject of an online auction, payable in bitcoin, the cryptocurrency. The set of files available for free contains a series of tools for penetrating network gear made by Cisco, Juniper, and other major firms. Targeting such gear, which includes things like routers and firewalls, is a known tactic of Western intelligence agencies like the NSA, and was documented in the Edward Snowden files. Some code words referenced in the material Monday — BANANAGLEE and JETPLOW — match those that have appeared in documents leaked by Snowden. Security researchers analyzing the code posted Monday say it is functional and includes computer codes for carrying out espionage.
foreign policy, 15.08.2016
ProjectSauron: top level cyber-espionage platform covertly extracts encrypted government comms
Over the last few years, the number of “APT-related” incidents described in the media has grown significantly. For many of these, though, the designation “APT”, indicating an “Advanced Persistent Threat”, is usually an exaggeration. With some notable exceptions, few of the threat actors usually described in the media are advanced. These exceptions, which in our opinion represent the pinnacle of cyberespionage tools: the truly “advanced” threat actors out there, are Equation, Regin, Duqu or Careto. Another such an exceptional espionage platform is “ProjectSauron”, also known as “Strider”. Our colleagues from Symantec have also released their analysis on ProjectSauron / Strider. You can read it here:
securelist/kaspersky, 08.08.2016
U.S. Had Cyberattack Plan if Iran Nuclear Dispute Led to Conflict
The plan, code-named Nitro Zeus, was devised to disable Iran’s air defenses, communications systems and crucial parts of its power grid, and was shelved, at least for the foreseeable future, after the nuclear deal struck between Iran and six other nations last summer was fulfilled. At its height, officials say, the planning for Nitro Zeus involved thousands of American military and intelligence personnel, spending tens of millions of dollars and placing electronic implants in Iranian computer networks to “prepare the battlefield,” in the parlance of the Pentagon. The existence of Nitro Zeus was uncovered in the course of reporting for “Zero Days,” a documentary that will be first shown Wednesday at the Berlin Film Festival. Directed by Alex Gibney, who is known for other documentaries including the Oscar-winning “Taxi to the Dark Side” about the use of torture by American interrogators, and “We Steal Secrets: The Story of WikiLeaks.” While Cyber Command would have executed Nitro Zeus, the National Security Agency’s Tailored Access Operations unit was responsible for penetrating adversary networks, which would have required piercing and maintaining a presence in a vast number of Iranian networks, including the country’s air defenses and its transportation and command control centers [NB:].
geheimdienst_us_nsa_tao_cna_cne  geheimdienst_uk_gchq_jtrig_cna_cne  geheimdienst_il_idf_aman_unit8200_isnu  geheimdienst_us_cia  militär_us_cyber_command_nitro_zeus  geheimdienst_allg_sabotage  geheimdienst_allg_verdeckte_operation  itsicherheit_malware_spyware  land_usa  land_uk  land_israel  land_iran  militär_allg_sabotage  militär_allg_kriegsführung_elektro_it  militär_allg_kollateralschaden  militär_us_cyber_command_cna_oceo_oco  geheimdienst_polizei_infiltration_tech 
NSA Helped British Spies Find Security Holes In Juniper Firewalls
A TOP-SECRET document dated February 2011 reveals that British spy agency GCHQ, with the knowledge and apparent cooperation of the NSA, acquired the capability to covertly exploit security vulnerabilities in 13 different models of firewalls made by Juniper Networks, a leading provider of networking and Internet security gear. The six-page document, titled “Assessment of Intelligence Opportunity – Juniper,” raises questions about whether the intelligence agencies were responsible for or culpable in the creation of security holes disclosed by Juniper last week.
intercept, 23.12.2015
Schnüffelcode in Juniper-Netzgeräten: Weitere Erkenntnisse und Spekulationen
Bei Analysen zum Juniper-Skandal fanden Experten des niederländischen Unternehmens FoxIT das von Hackern in den NetScreen-Code eingebaute SSH-Master-Passwort. Krypto-Fachleute stellten parallel dazu fest, dass die zugleich von Juniper offengelegte Kompromittierung von VPN-Verkehr sich wohl den löchrigen Zufallszahlengenerators für elliptische Kurven (Dual_EC_DRBG) zu Nutze machte. Zusammen gefasst: Juniper hatte die NSA-Hintertür verbaut – zur Sicherheit aber dann das Schloss ausgewechselt. Dann hat wie es aussieht jemand – vielleicht die NSA oder auch ein anderer Geheimdienst – sein Schloss eingebaut. So viel zu "sicheren Hintertüren". Wer das dritte Schloss verbaut hat, ist immer noch unklar. Einen Fingerzeig in Richtung des britischen Geheimdienstes GCHQ lieferte Federic Jacobs, im Hauptberuf Entwicker bei OpenWhisper. Der Belgacom-Einbruch, hinter dem GCHQ vermutet wird, so sein Twitter-Verweis, beruhe auf einem Einbruch ins Belgacom-VPN auf Basis von Juniper-Geräten.
heise, 21.12.2015
Kampagne gegen Verschlüsselung bricht zusammen
Zuletzt hatte nur noch FBI-Direktor James Comey allein auf weiter Flur behördliche Hintertüren für Sicherheitssoftware gefordert, am Donnerstag bekam er sie. Allerdings anders herum als gefordert, denn das FBI ermittelt seitdem gegen Unbekannte, die Firewalls des großen US-Herstellers Juniper systematisch mit solchen Hintertüren versehen hatten. Juniper hatte am Donnerstag eine Eil-Update für seine Firewallsysteme bekanntgegeben, da diese mit "unautorisiertem Code" verseucht seien, der Angreifer zu Administratorenrechten verhelfen würde. Die nun identifizierte und am Donnerstag angeblich geschlossene Sicherheitslücke, die es Angreifern ermöglicht, das gesamte, verschlüsselte "Virtual Private Network" (VPN) von Behörden wie von großen Firmen auszuhebeln, datiert zumindest bis in das Jahr 2012 zurück. Noch ist völlig unklar, ob das FBI hier womöglich gegen die NSA ermittelt, Hinweise auf einen solchen Angriff finden sich nämlich im Snowden-Fundus interner NSA-Dokumente zuhauf. Dort wird ein Mechanismus namens FEEDTROUGH beschreiben, eine Art elektronischer Durchreiche, die es ermögliche, dass "Implants" auch nach dem Neustart oder dem Update der Firewallsysteme weiter zur Verfügung stünden. Die entsprechenden Folien der NSA zum sogenannten ANT-Katalog beschränken sich nicht auf diese eine Angriffsweise auf die Produkte von Juniper. Mit SOUFFLETHROUGH, GOURMETTHROUGH, SIERRAMONTANA, SCHOOLMONTANA und STUCCOMONTANA standen bereits 2008 fünf weitere solcher Updatemachanismen alleine für Firewalls oder Router von Juniper zur Verfügung., 20.12.2015
XKEYSCORE: NSA's Google for the World's Private Communications
Today, The Intercept is publishing 48 top-secret and other classified documents about XKEYSCORE dated up to 2013, which shed new light on the breadth, depth and functionality of this critical spy system — one of the largest releases yet of documents provided by NSA whistleblower Edward Snowden. These newly published documents demonstrate that collected communications not only include emails, chats and web-browsing traffic, but also pictures, documents, voice calls, webcam photos, web searches, advertising analytics traffic, social media traffic, botnet traffic, logged keystrokes, computer network exploitation (CNE) targeting, intercepted username and password pairs, file uploads to online services, Skype sessions and more.
intercept, 01.07.2015
Popular Security Software Came Under Relentless NSA and GCHQ Attacks
The National Security Agency and its British counterpart, Government Communications Headquarters, have worked to subvert anti-virus and other security software in order to track users and infiltrate networks, according to documents from NSA whistleblower Edward Snowden. The spy agencies have reverse engineered software products, sometimes under questionable legal authority, and monitored web and email traffic in order to discreetly thwart anti-virus software and obtain intelligence from companies about security software and users of such software. One security software maker repeatedly singled out in the documents is Moscow-based Kaspersky Lab, which has a holding registered in the U.K., claims more than 270,000 corporate clients, and says it protects more than 400 million people with its products.
intercept, 22.06.2015
NSA Planned to Hijack Google App Store to Hack Smartphones
The National Security Agency and its closest allies planned to hijack data links to Google and Samsung app stores to infect smartphones with spyware, a top-secret document reveals. The surveillance project was launched by a joint electronic eavesdropping unit called the Network Tradecraft Advancement Team, which includes spies from each of the countries in the “Five Eyes” alliance. The agencies used the Internet spying system XKEYSCORE to identify smartphone traffic flowing across Internet cables and then to track down smartphone connections to app marketplace servers operated by Samsung and Google. As part of a pilot project codenamed IRRITANT HORN, the agencies were developing a method to hack and hijack phone users’ connections to app stores so that they would be able to send malicious “implants” to targeted devices. They were also keen to find ways to hijack them as a way of sending “selective misinformation to the targets’ handsets” as part of so-called “effects” operations that are used to spread propaganda or confuse adversaries. Moreover, the agencies wanted to gain access to companies’ app store servers so they could secretly use them for “harvesting” information about phone users. Another major outcome of the secret workshops was the agencies’ discovery of privacy vulnerabilities in UC Browser, a popular app used to browse the Internet across Asia, particularly in China and India.
intercept, 20.05.2015
US Used Zero-Day Exploits Before It Had Policies for Them
Around the same time the US and Israel were already developing and unleashing Stuxnet on computers in Iran, using five zero-day exploits to get the digital weapon onto machines there, the government realized it needed a policy for how it should handle zero-day vulnerabilities, according to a new document obtained by the Electronic Frontier Foundation. The document, found among a handful of heavily redacted pages released after the civil liberties group sued the Office of the Director of National Intelligence to obtain them, sheds light on the backstory behind the development of the government’s zero-day policy and offers some insight into the motivations for establishing it. What the documents don’t do, however, is provide support for the government’s assertions that it discloses the “vast majority” of zero-day vulnerabilities it discovers instead of keeping them secret and exploiting them.
wired, 30.03.2015
Equation APT Group Attack Platform A Study in Stealth
Today, researchers at Kaspersky Lab released a deeper analysis of the older attack platform used by the Equation group [NB:]. EquationDrug is a complete platform that is selectively installed on targets’ computers. It is used to deploy any of 116 modules (Kaspersky says it has found only 30 so far); the modules support a variety of cyberespionage functions ranging from data exfiltration to monitoring a target’s activities local activities and on the Web. “The architecture of the whole framework resembles a mini-operating system with kernel-mode and user-mode components carefully interacting with each other via a custom message-passing interface. The platform includes a set of drivers, a platform core (orchestrator) and a number of plugins,” Kaspersky researchers wrote in a report. Kaspersky researchers said they also studied code artifacts and analyzed timestamps inside EquationDrug, concluding from a limited number of text strings they were able to deobfuscate that the attackers are native English speakers. The link timestamps also demonstrate its developers generally worked a Monday through Friday 9-5 work week in the UTC-3 or UTC-4 time zone.
threatpost, 11.03.2015
iSpy: The CIA Campaign to Steal Apple's Secrets
Researchers working with the Central Intelligence Agency have conducted a multi-year, sustained effort to break the security of Apple’s iPhones and iPads, according to top-secret documents obtained by The Intercept. The security researchers presented their latest tactics and achievements at a secret annual gathering, called the “Jamboree,” where attendees discussed strategies for exploiting security flaws in household and commercial electronics. The conferences have spanned nearly a decade, with the first CIA-sponsored meeting taking place a year before the first iPhone was released. Researchers also claimed they had successfully modified the OS X updater, a program used to deliver updates to laptop and desktop computers, to install a “keylogger.” Other presentations at the CIA conference have focused on the products of Apple’s competitors, including Microsoft’s BitLocker encryption system, which is used widely on laptop and desktop computers running premium editions of Windows.
intercept, 10.03.2015
Massive, Decades-Long Cyberespionage Framework Uncovered
The Equation Group has a massive, flexible and intimidating arsenal at its disposal. Along with using several zero days in its operations, the attack crew also employs two discrete modules that enable them to reprogram the hard drive firmware on infected machines. This gives the attackers the ability to stay persistent on compromised computers indefinitely and create a hidden storage partition on the hard drive that is used to store stolen data. At the Security Analyst Summit here Monday, researchers at Kaspersky presented on the Equation Group’s operations while publishing a new report that lays out the inner workings of the crew’s tools, tactics and target list. The group’s toolkit includes components for infection, a self-propagating worm that gathers data from air-gapped targets, a full-featured bootkit that maintains control of a compromised machine and a “validator” module that determines whether infected PCs are interesting enough to install the full attack platform on.
threatpost, 16.02.2015
