Πέμπτη 2 Απριλίου 2015

The Future of Cyber Crime


Over the past years we have witnessed the illegal uses of the Internet to completely change in form, shape, and objectives. Today's hackers are often members of the organized crime who hack computers for profit or even for political power. Motivated by radical new goals and armed with exceptional programming skills they pose a major challenge to cybercrime researchers and law enforcement investigators alike. The field of cybercrime is a multidisciplinary area that includes law, computer science, finance, telecommunications, and data analysis.

Online security companies have made their predictions for 2015, from the malware that will be trying to weasel its way onto our computers and smartphones to the prospect of cyberwar involving state-sponsored hackers. WebSense suggests, “Cybercriminals upping their game are perfecting their campaign abilities previously associated only with advanced, targeted attacks. These advanced tactics designed to evade most modern email security solutions are quickly becoming the new norm as more sophisticated email threats increase...”

A parallel trend cited by several information security companies is the prospect of attacks on bigger companies in the private and public sector, with cybercriminals having specific goals in mind. Executives at some of the world’s largest banks are pressing government officials to pursue cyber criminals more aggressively or let the industry off the leash to fight them directly. The topic has shot up the agenda at the World Economic Forum in Davos this year, partly because of a series of high-profile incidents in the past 12 months, including the theft from JPMorgan Chase of data belonging to 75 million US households. Cybercriminals go after bigger targets rather than home users as this can generate more profits for them. We will see more data breach incidents with banks, financial institutions, and customer data holders remaining to be attractive targets.

One of the most common forms of malware in 2014 was “ransomware” – cybercriminals trying to extort money from victims either by locking their devices and demanding a fee to release them, or by accusing them of various unpleasant crimes. Ransomware will be a key strategy for malware developers and it will be a more relevant threat in coming years. During 2014, we have seen big companies hit by ransomware (like Yahoo, Match and AOL). In December 2014, in a panel discussion called “Cybercrime 2020: The Future of Online Crime and Investigations” it was said that "...ransomware is the future of consumer cybercrime".

As more of our devices talk to one another – the “Internet of Things” – there may be a range of new cybersecurity headaches to think about,  from domestic appliances to home security and climate control. It has to be said that some reporting on IoT hacking has exaggerated the scale of the problem. While it probably won’t be a massive problem next year, it is an emerging space for cyber crime.

As 2014 ended with the now-infamous hack of Sony Pictures – with intense debate about whether North Korea was involved – security firms see 2015 bringing a greater prospect of cyberattacks on behalf of nation states, even if they don’t run them themselves. Cyber warfare is very attractive to small nations. The development of a government-built malware is cheaper than any other conventional weapon and far more accessible to any nation-state. Cyber warfare represents for every government an efficient alternative to conventional weapons. The boundaries between cybercriminal gangs and governments may also blur. “Criminal groups will increasingly adopt nation-state tactics,” predicts Kaspersky.

One suggested solution is cyber security awareness and advice – where the public and businesses can go to get the information they need to protect themselves, how to implement basic controls to protect their data and privacy, and finally who to trust online and who to avoid.

Σάββατο 21 Φεβρουαρίου 2015

Desert Falcons


The action group Desert Falcons, a digital espionage network that targeted many organizations and high-profile individuals from the Middle East, was revealed during the Kaspersky Lab Security Analyst Summit in Mexico. Analysts consider this unit as the first known Arab group of "digital mercenaries" who have developed and executed integrated digital espionage operations against companies.

The list of victims includes military and governmental organizations, in particular, officers responsible for tackling money laundering. Also, the attack targeted executives from the fields of health and economy, leading media, research and educational institutions, energy providers and utilities, activists and political leaders, private security companies and other individuals that hold considerable geopolitical information.

The group is active for at least two years. Team Desert Falcons began to develop and consolidate the operation in 2011. However, the start of the key action of the group and infections through malware mounted in 2013. The peak of activity recorded in early 2015.

The vast majority of targets located in Egypt, Palestine, Israel and Jordan.

Apart from the Middle East, which were the original objectives, the team Desert Falcons operates outside this range. Overall, its members have been able to attack more than 3000 victims in more than 50 countries worldwide, having stolen more than one million records.

Attackers use malicious tools they have developed themselves, to launch attacks on Windows computers and Android devices. The Kaspersky Lab specialists have many reasons to believe that the mother tongue of the Desert Falcons is Arabic.

While the attack vector appears to act in countries such as Egypt, Palestine, Israel and Jordan, many victims were also found in Qatar, Saudi Arabia, the United Arab Emirates, Algeria, Lebanon, Norway, Turkey, Sweden, France, the United States, Russia and other countries.

The main method used by the group Desert Falcons for transferring malicious payload was spearphishing via email, messaging and social media messages in chat. The phishing messages contained malicious files (or link leading to malware), which imitated legal documents or applications.

The Desert Falcons team uses various techniques to lure victims and forced them to carry out malicious files. One of the most typical techniques used by the group is the so-called «Right-to-Left Override». This technique takes advantage of a special character in Unicode, to reverse the order of characters in the name of a file, hiding a dangerous extension in the middle of the name and putting a false file extension, which looks harmless, near the end of the file name. Using this technique, malicious files (.exe, .scr) look like an innocuous document or file PDF, and even careful users with good technical knowledge can be dragged and "run" these files. For example, a file with extension ".fdp.scr" will be presented as ".rcs.pdf".

After successful "infection" of the victim, team members Desert Falcons use one of two different backdoors, either their main Trojan or DHS Backdoor, which seems to have been developed from the beginning and is in constant development. The Kaspersky Lab experts managed to identify more than 100 samples of malware used for attacks.

Malicious tools used have fully backdoor functionality. So they can take screenshots, steal keystrokes, make upload or download files to collect information about all files on hard disk or USB connected devices of a victim, stealing passwords stored in the system registry (Internet Explorer and Live Messenger) and make recordings. The Kaspersky Lab experts were also able to detect traces of the activity of a malicious software, which seems to be a backdoor for Android, with call interception capabilities and SMS logs.

Δευτέρα 22 Δεκεμβρίου 2014

Bureau-121

Bureau 121 (Unit 121 of the North Korean General Bureau of Reconnaissance) is the name of a secret cyberwarfare agency belonging to the military of North Korea. It is one of two such cyberwarfare units in the General Bureau of Reconnaissance, the other being No. 91 Office.

The activity of the agency came into public limelight in December 2014 when Sony Pictures canceled the opening of its movie The Interview after its computers had been hacked. Bureau 121 has been blamed for the cyber breach. North Korea has rejected this accusation. 

According to a report by Reuters, Bureau 121, also known as the DarkSeoul Gang is staffed by some of North Korea's most talented computer experts and is run by the Korean military.
According to Jang Se-yul, a computer expert who defected in 2007, about 1800 cyber warriors are located throughout the world. Other sources, including Prof. Kim Heung Kwang estimations vary on Unit 121's size. In 2012, South Korea asserted 3000 people belonged to Unit 121 and earlier this year predicted an increase to 5900. Many hackers of the bureau are hand-picked graduates of the University of Automation, Pyongyang. While these specialists are scattered around the world, their families benefit from special privileges at home

Much of the agency’s activity has been directed at South Korea. Prior to the attack at Sony, the agency was said to have attacked more than 30.000 PCs in South Korea affecting banks and broadcasting companies as well as a website of South Korean President Park Geun-Hye. The malicious code used in a 2012 attack on a South Korean media organization appears to be similar to the code used in the Sony hack, according to Choi Sang-myung, a senior online security researcher and adviser to Seoul's cyber warfare command. "I noticed the similarities as soon as I saw it." 

It are also has been thought to have been responsible for infecting thousands of South Korean smartphones in 2013 with a malicious gaming app. 

According to Jang Se-Yul, another North Korean defector, North Korea is very active in cyberwarfare and its capabilities have been underestimated. North Korea has sophisticated cyber warfare capabilities with cells from Bureau 121 operating around the world. One of the suspected locations of a cell is the Chilbosan Hotel in Shenyang, China.

The FBI and Justice Department's National Security Division are still investigating the "sophisticated actor" behind it. When asked how the U.S. planned to respond, White House Press Secretary, said the president's national security team was considering "a range of available responses" but did not elaborate on what that response might be.

Τρίτη 16 Δεκεμβρίου 2014

Cyber Warfare: The Modern Theater of Operations

A great deal of debate circles around the concept of cyberwarfare – and definitions are rarely agreed upon. While some claim that cyberwarfare is the fifth domain of warfare (after land, sea, air and space) others simply claim that the term is an attempt at sensationalism. The increasing importance of cyberspace for military operations has led to the United States Department of Defense classifying it as the Fifth Domain of Warfare. However, cyberspace lacks the explicit physical properties of land, sea, air and space, and as a consequence its classification as a warfighting domain is controversial. The cyber debate is replete with hyperbole and ambiguous terminology and there are calls to limit the militarization of cyberspace. The critical dependence of Western military forces on microprocessor technology inevitably means that exploiting this domain is viewed from the dual perspectives of opportunity and vulnerability. From a more specific perspective, cyberwarfare refers to any action by a nation-state to penetrate another state’s computer networks for the purpose of causing some sort of damage. However, broader definitions claim that cyberwarfare also includes acts of "cyberhooliganism", "cybervandalism" or "cyberterrorism".

Cyber warfare involves the actions by a nation-state or international organization to attack and attempt to damage another nation's computers or information networks through, for example, computer viruses or denial-of-service attacks.

The Internet security company McAfee stated in their 2007 annual report that approximately 120 countries have been developing ways to use the Internet as a weapon and target financial markets, government computer systems and utilities.

Cyberwarfare can consist of many threats, namely:

Online acts of espionage and security breaches – done to obtain national material and information of a sensitive or classified nature through the exploitation of the internet (e.g. exploitation of network flaws through malicious software).

Sabotage – the use of the internet by one nation state to disrupt online communications systems of another nation state (e.g. military communication networks) with the intent to cause damage and disadvantage.

Attacks on SCADA networks and Nuclear Control Institutes (NCIs).
SCADA networks are national industrial control systems – computer systems (consisting of hardware, software and communication components) designed to monitor and control various critical infrastructures or facility-based processes. They include the computer-based systems that run such critical infrastructure as power generation plants and transmission networks, refinery plants, oil and gas pipelines, and transport and communication systems.

In the past, such SCADA networks operated in isolated environments – with different points communicating to each other within segregated networks, and rarely sharing information with any system outside a specific network. With the advent of internet-based systems however, these SCADA networks have gradually become more and more interconnected with the outside world and integrated into larger global networks. Consequently, their vulnerability to cyber attacks has increased drastically. SCADA networks perform centralized monitoring for wide-ranging networks, which can be spread over long distances. The systems send supervisory commands to field devices based on information they receive from the remote field sites in which these devices are located. For instance, a central SCADA system can control the opening and closing of valves in power plants located hundreds of kilometers away. Consequently, if such a centralized system is compromised by a cyber attack, the attacker could potentially have control over the valve systems of those particular power plants – and may choose to use that control to cause widespread damage. Alternatively, the networks may be infected unintentionally by viruses or worms causing massive and widespread damage.

An example of an intentional cyber attack on a SCADA system was in January 2000 in Queensland Australia, when a disgruntled ex-employee of a sewerage plant covertly took control of the plant’s operating systems – opening and closing valves and disrupting communications systems. The attack resulted in 264,000 gallons of raw sewerage flooding a nearby river. Another more recent example is the 2010 Stuxnet virus, which was allegedly designed to specifically infect the SCADA networks of Iran’s nuclear infrastructures.
SCADA networks are the vital underpinnings of our society and lifestyle; yet, they are notoriously difficult to secure due to the increasing complexity of their system architectures. There is a general lack of discussion on issues related to SCADA vulnerabilities, and it is important that effective strategies and measures are developed to greatly improve the resilience of these vital assets before they become victim to either intentional or unintentional cyber attacks.

In 2011, The White House published an "International Strategy for Cyberspace" that reserved the right to use military force in response to a cyber attack:

When warranted, the United States will respond to hostile acts in cyberspace as we would to any other threat to our country. We reserve the right to use all necessary means — diplomatic, informational, military, and economic — as appropriate and consistent with applicable international law, in order to defend our Nation, our allies, our partners, and our interests. In so doing, we will exhaust all options before military force whenever we can; will carefully weigh the costs and risks of action against the costs of inaction; and will act in a way that reflects our values and strengthens our legitimacy, seeking broad international support whenever possible.
-- International Strategy for Cyberspace, The White House, 2011

In 2013, the Defense Science Board, went further, stating that "The cyber threat is serious, with potential consequences similar in some ways to the nuclear threat of the Cold War," and recommending, in response to the "most extreme case" (described as a "catastrophic full spectrum cyber attack"), that "Nuclear weapons would remain the ultimate response and anchor the deterrence ladder." In a full-scale attack, the report warns of the following scenario:

Should the United States find itself in a full-scale conflict with a peer adversary, attacks would be expected to include denial of service, data corruption, supply chain corruption, traitorous insiders, kinetic and related non-kinetic attacks at all altitudes from underwater to space. U.S. guns, missiles, and bombs may not fire, or may be directed against our own troops. Resupply, including food, water, ammunition, and fuel may not arrive when or where needed. Military Commanders may rapidly lose trust in the information and ability to control U.S. systems and forces. Once lost, that trust is very difficult to regain.
The impact of a destructive cyber attack on the civilian population would be even greater with no electricity, money, communications, TV, radio, or fuel (electrically pumped). In a short time, food and medicine distribution systems would be ineffective; transportation would fail or become so chaotic as to be useless. Law enforcement, medical staff, and emergency personnel capabilities could be expected to be barely functional in the short term and dysfunctional over sustained periods. If the attack's effects were reversible, damage could be limited to an impact equivalent to a power outage lasting a few days. If an attack’s effects cause physical damage to control systems, pumps, engines, generators, controllers, etc., the unavailability of parts and manufacturing capacity could mean months to years are required to rebuild and reestablish basic infrastructure operation.
-- Resilient Military Systems and the Advanced Cyber Threat, Defense Science Board, 2013
Although the risk of a debilitating cyber attack is real, the perception of that risk is far greater than it actually is. No person has ever died from a cyber attack, and only one alleged cyber attack has ever crippled a piece of critical infrastructure, causing a series of local power outages in Brazil. In fact, a major cyber attack of the kind intelligence officials fear has not taken place in the 21 years since the Internet became accessible to the public.