<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Affairs</title>
	<atom:link href="http://securityaffairs.co/wordpress/feed" rel="self" type="application/rss+xml" />
	<link>http://securityaffairs.co/wordpress</link>
	<description>Read, think, share … Security is everyone&#039;s responsibility</description>
	<lastBuildDate>Fri, 24 May 2013 09:34:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>US critical infrastructure under unceasing cyber attacks</title>
		<link>http://securityaffairs.co/wordpress/14641/cyber-crime/us-critical-infrastructure-under-cyber-attacks.html</link>
		<comments>http://securityaffairs.co/wordpress/14641/cyber-crime/us-critical-infrastructure-under-cyber-attacks.html#comments</comments>
		<pubDate>Fri, 24 May 2013 06:45:26 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cyber attacks]]></category>
		<category><![CDATA[cyber terrorism]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Department of Homeland Security]]></category>
		<category><![CDATA[grid]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[spear-phishing attacks]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[US critical infrastructure]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14641</guid>
		<description><![CDATA[<p>US Congressmen Ed Markey and Henry Waxman issued the report &#8220;Electric grid vulnerability&#8221; on the level of security for US critical infrastructure. Attack on critical infrastructure is the main concern for worldwide security community, every government has become aware of the risks related to a cyber attack against their own country and is investing to improve its cyber capabilities. [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14641/cyber-crime/us-critical-infrastructure-under-cyber-attacks.html">US critical infrastructure under unceasing cyber attacks</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>US Congressmen Ed Markey and Henry Waxman issued the report &#8220;Electric grid vulnerability&#8221; on the level of security for US critical infrastructure.</h2>
<p>Attack on <a title="SCADA and critical infrastructures, in … security" href="http://securityaffairs.co/wordpress/11684/security/scada-and-critical-infrastructures-in-security.html" target="_blank">critical infrastructure</a> is the main concern for worldwide security community, every government has become aware of the risks related to a cyber attack against their own country and is investing to improve its cyber capabilities.</p>
<p>Day after day the number of attacks against critical infrastructure is increasing at an alarming, US is among the most targeted countries, a report issued by U.S. Congressmen Ed Markey and Henry Waxman revealed that  that the quantity of assaults against core infrastructure continues to rise.</p>
<p>The report, titled &#8220;<a href="http://markey.house.gov/sites/markey.house.gov/files/documents/Markey%20Grid%20Report_05.21.13.pdf">Electric grid vulnerability&#8221; report</a>, states that a utility facing roughly 10,000 attacks every month, the study is based on 160 surveyed U.S. <span class="GINGER_SOFATWARE_correct">utilities</span>.</p>
<p>The most concerning aspect is that around 10 % of US critical infrastructure are daily under attack of various types, such as malware based or <a title="APWG Global Phishing Survey report revealed new scaring trends" href="http://securityaffairs.co/wordpress/13991/cyber-crime/apwg-global-phishing-survey-report.html" target="_blank">spear-phishing attacks</a>.</p>
<p>The report highlighted the economic impact of grid vulnerabilities, it is estimated that power outages and related damage cost the U.S. <span class="GINGER_SOFATWARE_correct">economy</span> between $119 to $188 billion per year and a single successful <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cyberattack</span> can cause losses upwards of $10 billion.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/US-Critical-Infrastructures-Electric-Grid-Report-2.jpg"><img class="aligncenter  wp-image-14657" alt="US Critical Infrastructures Electric Grid Report 2" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/US-Critical-Infrastructures-Electric-Grid-Report-2.jpg" width="448" height="252" title="US critical infrastructure under unceasing cyber attacks" /></a></p>
<p>&nbsp;</p>
<p>The <a title="DHS alerted energy companies on ongoing spear-phishing campaign" href="http://securityaffairs.co/wordpress/13608/cyber-crime/dhs-alerted-energy-companies-on-ongoing-spear-phishing-campaign.html" target="_blank">Department of Homeland Security</a> demonstrated that 2012 registered an increase of 68 percent in comparison to 2011 for the number of <span class="GINGER_SOFATWARE_correct">cyberattacks</span> against US critical infrastructure, industrial bodies and Federal offices.</p>
<p>Every day there are numerous attacks conducted to discover vulnerabilities within these critical systems, many of these attacks is perpetrated in an automatic and method manner.</p>
<blockquote><p><i>A Midwestern power provider declared that it was “subject to ongoing malicious cyber and physical activity. For example, we see probes on our network to look for vulnerabilities in our systems and applications on a daily basis. Much of this activity is automated and dynamic in nature – able to adapt to what is discovered during its probing process.”</i></p></blockquote>
<p>To respond the increasing threat of cyber-attack security community has called on Congress to provide a federal authority with the necessary power to ensure the grid protection from potential cyber-attacks, but despite these calls for action since now Congress has not provided any governmental entity with the necessary capabilities.</p>
<p>Today the protection of  the nation’s electricity grid from cyber-attack is referenced “by voluntary actions recommended by the North American Electric Reliability Corporation (NERC), an industry organization, combined with mandatory reliability standards that are developed through NERC’s protracted, consensus-based process. Additionally, an electric utility “</p>
<blockquote><p><i>&#8220;Almost all utilities surveyed are compliant with mandatory NERC standards but totally ignore recommendations by NERC. The report provided disturbing data, for example despite NERC has established both mandatory standards and voluntary measures to protect against Stuxnet warm, the implementation of voluntary countermeasures was overruled.&#8221;</i></p></blockquote>
<p><a title="Stuxnet was dated 2005, Symantec discovered earlier version 0,5" href="http://securityaffairs.co/wordpress/12616/malware/stuxnet-was-dated-2005-symantec-discovered-earlier-version-05.html" target="_blank"><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">Stuxnet</span></a> voluntary measures have been implemented by only 21% of IOUs, 44% of <span class="GINGER_SOFATWARE_correct">municipally</span>- or cooperatively owned utilities, and 62.5% of federal entities reported compliance, an alarming data in my opinion.</p>
<p>The <a title="Cost of cybercrime for UK Small Businesses" href="http://securityaffairs.co/wordpress/14628/cyber-crime/cost-of-cybercrime-for-uk-small-businesses.html" target="_blank">cybercrime</a> is considered the most dangerous threat <span class="GINGER_SOFATWARE_correct">for</span> US critical infrastructure that are under unceasing cyber attacks, its menace is more concerning of terrorism, because the increasing sophistication level of the attacks.</p>
<p>Fortunately despite the delay in the adoption of proper countermeasures for many US critical infrastructures hasn’t yet caused a successful breach of their systems.</p>
<p>As usual there are different opinions, some say the report provides a false overview on real security of national critical infrastructure that are protected from external cyber attacks thanks the <span class="GINGER_SOFATWARE_correct">compliant</span> of mandatory standards set by the NERC.</p>
<blockquote><p>&#8220;The majority of those attacks, while large in number, are the same attacks that every business receives&#8221; through web-connected networks,&#8221; &#8221;Those are very routine kinds of attacks and we know very well how to protect against those&#8230;Our control systems are not vulnerable to attack,&#8221; Arkansas Electric Cooperative Corporation Chief Executive Duane Highley told Reuters.</p></blockquote>
<p>It is my opinion that whatever the actual state of infrastructure is necessary that all measures are taken to ensure  protection from the attacks of increasing complexity.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cyber Security, US critical infrastructure</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14641/cyber-crime/us-critical-infrastructure-under-cyber-attacks.html">US critical infrastructure under unceasing cyber attacks</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14641/cyber-crime/us-critical-infrastructure-under-cyber-attacks.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cost of cybercrime for UK Small Businesses</title>
		<link>http://securityaffairs.co/wordpress/14628/cyber-crime/cost-of-cybercrime-for-uk-small-businesses.html</link>
		<comments>http://securityaffairs.co/wordpress/14628/cyber-crime/cost-of-cybercrime-for-uk-small-businesses.html#comments</comments>
		<pubDate>Thu, 23 May 2013 06:42:27 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[cost of cybercrime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Federation of Small Businesses]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14628</guid>
		<description><![CDATA[<p>The Federation of Small Businesses issued an interesting study on cost of cybercrime suffered by small businesses in the UK. Cost of cybercrime is usually evaluated for large corporate underestimating its dramatic effect on small business, small companies are in fact most vulnerable to the increasing cyber criminals and hacktivists. An interesting study conducted by [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14628/cyber-crime/cost-of-cybercrime-for-uk-small-businesses.html">Cost of cybercrime for UK Small Businesses</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<div>
<h2>The Federation of Small Businesses issued an interesting study on cost of cybercrime suffered by small businesses in the UK.</h2>
<p>Cost of cybercrime is usually evaluated for large corporate underestimating its dramatic effect on small business, small companies are in fact most vulnerable to the increasing cyber criminals and <span class="GINGER_SOFATWARE_spelling"><a title="OpUSA, Anonymous against US Banking and Government offices" href="http://securityaffairs.co/wordpress/14225/cyber-crime/opusa-anonymous-against-us-banking-government.html" target="_blank">hacktivists</a>.</span></p>
</div>
<p>An interesting <a title="http://www.fsb.org.uk/News.aspx?loc=pressroom&amp;rec=8083" href="http://www.fsb.org.uk/News.aspx?loc=pressroom&amp;rec=8083" target="_blank">study</a> conducted by the Federation of Small Businesses on cost of cybercrime in UK revealed the incidence of the phenomena on the small business, worrying losses for billions of pounds every year, the average small firm facing a near £4,000 cost.</p>
<p>The Federation of Small Businesses declared that around 30% of its members had been victims of fraud, majority of crimes is related to <a title="http://securityaffairs.co/wordpress/14252/intelligence/china-us-mutual-accusations-cyber-cold-war.html" href="http://securityaffairs.co/wordpress/14252/intelligence/china-us-mutual-accusations-cyber-cold-war.html" target="_blank">virus</a> infections, more than 50% of small business was hit by a malware, 8% of UK small business had been victims of hacking and around 5% had suffered <a title="Rapid 7, analysis on data breach incidents" href="http://securityaffairs.co/wordpress/8581/security/rapid-7-analysis-on-data-breach-incidents.html" target="_blank">security breaches</a>.<br />
The report of the Federation of Small Businesses revealed that cost of <a title="Cybercriminals sell hacked PayPal credentials in underworld" href="http://securityaffairs.co/wordpress/12550/cyber-crime/cybercriminals-sell-hacked-paypal-credentials-in-underworld.html" target="_blank">cybercrime</a> and fraud for its 200,000 members is around £800m a year, (£3,926 each on average), but according the analysts the total cost is much bigger for total UK small business.<br />
According the FSB estimation, by projecting the data related to the small business on a national scale the cost of cybercrime is greater than  £18.8bn based on the FSB&#8217;s average.</p>
<p><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/cost-of-cybercrime2.jpg"><img class="aligncenter size-full wp-image-14630" alt="cost of cybercrime2" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/cost-of-cybercrime2.jpg" width="370" height="229" title="Cost of cybercrime for UK Small Businesses" /></a></p>
<p>In the UK there are around 4.8 million small firms and despite the impact of <a title="The “company” cybercrime seen by Fortinet" href="http://securityaffairs.co/wordpress/11282/cyber-crime/the-company-cybercrime-seen-by-fortinet.html" target="_blank">cybercrime</a> and the high frequency of malicious events almost 20% had taken no countermeasure to mitigate the cyber threats..</p>
<blockquote><p><i>&#8220;Cybercrime poses a real and growing threat for small firms and it isn&#8217;t something that should be ignored,&#8221; </i></p>
<p><i>&#8220;Many businesses will be taking steps to protect themselves but the cost of crime can act as a barrier to growth”.</i><i></i></p>
<p>&#8220;Many businesses will not embrace new technology as they fear the repercussions and do not believe they will get adequate protection from crime.”</p>
<p>&#8220;While we want to see clear action from the government and the wider public sector, there are clear actions that businesses can take to help themselves.&#8221;said Mike Cherry, the FSB&#8217;s national policy chairman, referring the effect of cybercrime on UK businesses.</p></blockquote>
<p><em id="__mceDel"><br />
</em>The scenario is alarming, on one side the activities of cybercrime are becoming even more <a title="FireEye report on advanced cyber attacks landscape" href="http://securityaffairs.co/wordpress/13877/cyber-crime/fireeye-report-advanced-cyber-attacks.html" target="_blank">sophisticated</a> and pounding, on the other side the response of Small business is still inappropriate with obvious repercussion, due this reason the FSB issued new advice to small firms encouraging the implementation of the security mechanisms and the adoption of best practices.</p>
<p>The FSB issued 10 tips to suggest businesses how to protect their assets from cybercrime, including a combination of standard security protection steps (e.g. Define and constantly update security policy, keep systems <a title="5 Reasons Why You Need Good Patch Management" href="http://securityaffairs.co/wordpress/6370/security/5-reasons-why-you-need-good-patch-management.html" target="_blank">updated</a>, protect networks with firewall, use and update antivirus and anti-spam software).</p>
<p>Security is a must for the growth of the entire United Kingdom, security minister James Brokenshire commented the results proposed by the study spurring the action and in the adoption of a proactive approach to cybercrime.</p>
<blockquote><p><i> &#8221;We need to make sure that all businesses, large and small are engaged in implementing appropriate prevention measures in their business”</i><i></i></p>
<p>&#8220;This report will help give a greater understanding of how online security and fraud issues affect small businesses, giving guidance as well as valuable top tips to protect their business.&#8221;</p>
<p><i>&#8220;We know only too well of the importance of securing buy-in from both big and small business in implementing appropriate protection against cyber risks &#8211; business success can depend on it. Increasing security drives growth.&#8221; said </i>Business minister David Willets added.</p></blockquote>
<p>To limit the impact of cybercrime and reduce the <a title="Ponemon statistics 2012 on cost of cybercrime" href="http://securityaffairs.co/wordpress/9319/cyber-crime/ponemon-statistics-2012-on-cost-of-cybercrime.html" target="_blank">cost of cybercrime</a> another fundamental issue is the information sharing on cyber attacks, incidents and data breaches, the Government issued The Data Protection Bill will force companies to denounce every incidents and data breaches. Despite the Act there is still much to do, the strong support of the Government and principal enterprises is an essential factor to support the growth of a security culture that could help to reduce the effect of cybercrime.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cybercrime</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14628/cyber-crime/cost-of-cybercrime-for-uk-small-businesses.html">Cost of cybercrime for UK Small Businesses</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14628/cyber-crime/cost-of-cybercrime-for-uk-small-businesses.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google data breach, Company’s Surveillance Database hacked</title>
		<link>http://securityaffairs.co/wordpress/14586/hacking/google-data-breach-surveillance-database-hacked.html</link>
		<comments>http://securityaffairs.co/wordpress/14586/hacking/google-data-breach-surveillance-database-hacked.html#comments</comments>
		<pubDate>Wed, 22 May 2013 07:04:59 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Chinese intelligence]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google data breach]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Sabotage]]></category>
		<category><![CDATA[zero-Day]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14586</guid>
		<description><![CDATA[<p>Chinese hackers who breached Google in 2010 are responsible for the recent violation to Google Company’s Surveillance Database according officials revelations. Google data breach is reality and Google Company’s Surveillance Database has been violated by the same hackers who breached Google&#8217;network in 2010, the attackers have obtained the access to the company’s tracking system for [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14586/hacking/google-data-breach-surveillance-database-hacked.html">Google data breach, Company’s Surveillance Database hacked</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>Chinese hackers who breached Google in 2010 are responsible for the recent violation to Google Company’s Surveillance Database according officials revelations.</h2>
<p>Google data breach is reality and Google Company’s Surveillance Database has been violated by the same hackers who breached <a title="http://securityaffairs.co/wordpress/8528/hacking/elderwood-project-who-is-behind-op-aurora-and-ongoing-attacks.html" href="http://securityaffairs.co/wordpress/8528/hacking/elderwood-project-who-is-behind-op-aurora-and-ongoing-attacks.html" target="_blank">Google&#8217;network in 2010</a>, the attackers have obtained the access to the company’s tracking system for management of surveillance requests from law enforcement.</p>
<p>The news has been published by the <a title="http://www.washingtonpost.com/world/national-security/chinese-hackers-who-breached-google-gained-access-to-sensitive-data-us-officials-say/2013/05/20/51330428-be34-11e2-89c9-3be8095fe767_story.html" href="http://www.washingtonpost.com/world/national-security/chinese-hackers-who-breached-google-gained-access-to-sensitive-data-us-officials-say/2013/05/20/51330428-be34-11e2-89c9-3be8095fe767_story.html" target="_blank">Washington Post</a> and confirmed the voices on the Google <a title="How to respond to a data breach" href="http://securityaffairs.co/wordpress/13549/security/how-to-respond-to-the-a-data-breach.html" target="_blank">data breach</a>.</p>
<p>The database hacked is used by Google company to archive the court orders submitted by law enforcement who are investigating on a user&#8217;s profile, but the repository also includes classified Foreign Intelligence Surveillance Act<b> (</b>FISA) orders that are used in foreign intelligence surveillance investigations.</p>
<p>FISA is a US law which outlines practices for the physical and electronic surveillance and &#8220;collection of &#8220;foreign intelligence information&#8221; between &#8220;foreign powers&#8221; and &#8220;agents of foreign powers&#8221;, &#8220;the sections of FISA authorizing electronic surveillance and physical searches without a court order specifically exclude their application to groups engaged in international terrorism. <i>&#8220;</i></p>
<p>The Google&#8217;s database contained precious information on surveillance activities conducted during the last years, it&#8217;s clear the purpose of the attack, it was arranged to gather information on law enforcement and intelligence agency&#8217;s investigation on <a title="China vs US mutual accusations, the cyber cold war is begun" href="http://securityaffairs.co/wordpress/14252/intelligence/china-us-mutual-accusations-cyber-cold-war.html" target="_blank">Chinese intelligence</a> operatives in the US, a former US official confirmed to the Washington Post it:</p>
<blockquote><p><em>“Knowing that you were subjects of an investigation allows them to take steps to destroy information, get people out of the country,” </em></p></blockquote>
<p>The Post states:</p>
<blockquote><p><em>&#8220;The breach appears to have been aimed at unearthing the identities of Chinese intelligence operatives in the United States who may have been under surveillance by American law enforcement agencies.&#8221;</em></p></blockquote>
<p>In 2010 numerous companies were hacked by Chinese hackers, including Adobe and many other financial institutions and defense contractors, with a series of sophisticated cyber attacks. The attackers stolen from Google source code and also tried to access to the Gmail accounts of <a title="First APT attack on Android targeted Tibetan &amp; Uyghur activists" href="http://securityaffairs.co/wordpress/13198/intelligence/first-apt-attack-on-android-targeted-tibetan-uyghur-activists.html" target="_blank">Tibetan activists</a>.</p>
<p>The hackers that targeted Google in December also hit 33 other companies using a <a title="Zero-day market, the governments are the main buyers" href="http://securityaffairs.co/wordpress/14561/malware/zero-day-market-governments-main-buyers.html" target="_blank">zero-day vulnerability</a> in Adobe Reader to deliver malware to the victims and steal  source-code management systems to obtain the access to company source code as well as to modify it to make customers who use the application vulnerable to attack.</p>
<p>The Google data breach was originated in China, Secretary of State Hillary Clinton publicly condemned the intrusion requesting for the Chinese Government to give information on the attack.</p>
<p>Google hasn&#8217;t confirmed the impairment of its systems for processing law enforcement surveillance requests, but announced to stop collaborating with Chinese authorities for <a title="The strategic importance of censorship in search engines" href="http://securityaffairs.co/wordpress/1273/intelligence/the-strategic-importance-of-censorship-in-search-engines.html" target="_blank">censoring</a> Google search results in that country.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/google-hacked-china-intelligence.jpg"><img class="aligncenter  wp-image-14596" alt="google hacked china intelligence" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/google-hacked-china-intelligence.jpg" width="512" height="342" title="Google data breach, Company’s Surveillance Database hacked" /></a></p>
<p>Google isn&#8217;t unique victims of this new wave of attacks, last month, a senior Microsoft official denounced that Chinese hackers had targeted the company’s systems having the same function of Google Surveillance DB about the same time that Google’s was breached.</p>
<blockquote><p><em>“What we found was the attackers were actually looking for the accounts that we had lawful wiretap orders on,” David W. <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">Aucsmith</span>, senior director of Microsoft’s Institute for Advanced Technology in Governments, said at a conference near Washington, according to a recording of his remarks. “If you think about this, this is brilliant counterintelligence,” he said in the address, which was <a href="http://www.cio.com/article/732122/_Aurora_Cyber_Attackers_Were_Really_Running_Counter_Intelligence" data-xslt="_http">first reported</a> by the online magazine CIO.com. “You have two choices: If you want to find out if your agents, if you will, have been discovered, you can try to break into the FBI to find out that way. Presumably that’s difficult. Or you can break into the people that the courts have served <span class="GINGER_SOFATWARE_correct">paper</span> on and see if you can find it that way. That’s essentially what we think they were trolling for, at least in our case.”</em></p></blockquote>
<p>According the Washington Post<em>,  </em>Justice Department faced with Google resistance to show evidence of the attacks providing full access to internal logs and to authorize a further forensic investigation of the breach &#8230; It is still unclear what Google provided to the investigators.</p>
<p>Michael M. DuBose, former chief of the Justice Department’s Computer Crime and Intellectual Property Section, commented the attacks defining them a wake-up call for the government that the overall security and effectiveness of lawful interception and undercover operations is dependent in large part on security standards in the private sector.</p>
<blockquote><p><em>“Those,”  “clearly need strengthening.” DuBose said,</em></p></blockquote>
<p>The incidents raise once again the need to share information on cyber attacks and data breaches, incidents like these are clear indications of ongoing sophisticated intelligence operations.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cyber espionage</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14586/hacking/google-data-breach-surveillance-database-hacked.html">Google data breach, Company’s Surveillance Database hacked</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14586/hacking/google-data-breach-surveillance-database-hacked.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zero-day market, the governments are the main buyers</title>
		<link>http://securityaffairs.co/wordpress/14561/malware/zero-day-market-governments-main-buyers.html</link>
		<comments>http://securityaffairs.co/wordpress/14561/malware/zero-day-market-governments-main-buyers.html#comments</comments>
		<pubDate>Tue, 21 May 2013 06:46:28 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber warfare]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cyber weapon]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Exploit kits]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[offensive approach]]></category>
		<category><![CDATA[Reuters]]></category>
		<category><![CDATA[US]]></category>
		<category><![CDATA[zero-Day]]></category>
		<category><![CDATA[zero-day vulnerabilities]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14561</guid>
		<description><![CDATA[<p>Governments, and in particular US one, are principal buyers of zero-day vulnerabilities according a report published by Reuters. Zero-days exploits are considered a primary ingredient for success of a cyber attack, the knowledge of zero-day flaw gives to the attacker guarantee of success, state-sponsored hackers and cyber criminals consider zero-day exploits a precious resources around [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14561/malware/zero-day-market-governments-main-buyers.html">Zero-day market, the governments are the main buyers</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>Governments, and in particular US one, are principal buyers of zero-day vulnerabilities according a report published by Reuters.</h2>
<p>Zero-days exploits are considered a primary ingredient for success of a cyber attack, the knowledge of zero-day flaw gives to the attacker guarantee of success, state-sponsored hackers and cyber criminals consider zero-day exploits a precious <span class="GINGER_SOFATWARE_correct">resources</span> around which is grown a booming market.</p>
<p>Zero-day exploits could be used to as an essential component for the design of a <a title="“Olyimpic Games” and boomerang effect, it isn’t sport but cyber war" href="http://securityaffairs.co/wordpress/6048/intelligence/olyimpic-games-and-boomerang-effect-it-isnt-sport-but-cyber-war.html" target="_blank">cyber weapon</a> or could be exploited for <a title="Mandiant report on APT1 &amp; China’s cyber espionage units" href="http://securityaffairs.co/wordpress/12452/intelligence/mandiant-report-on-apt1-chinas-cyber-espionage-units.html" target="_blank">cyber espionage</a> purposes, in both cases governments appear the most interested entities for the use of these malicious code.</p>
<p>Recent cyber attacks conducted by Chinese hackers might lead us to think Chinese Government is <span class="GINGER_SOFATWARE_correct">primary buyer/developer</span> for zero-day vulnerabilities, but a <a href="http://in.reuters.com/article/2013/05/10/usa-cyberweapons-idINDEE9490AX20130510?type=economicNews">report</a> recently published by Reuters claimed the US government is the &#8220;biggest buyer in a burgeoning gray market where hackers and security firms sell tools for breaking into computers.&#8221;</p>
<p>Reuters revealed that the US Government, in particular its intelligence agency and the DoD are &#8220;spending so heavily for information on holes in commercial computer systems, and on exploits taking advantage of them, that they are turning the world of security research on its head.&#8221;, it’s a <span class="GINGER_SOFATWARE_correct">news</span> way to compete with adversary in cyberspace.</p>
<p>Recent <a title="China vs US mutual accusations, the cyber cold war is begun" href="http://securityaffairs.co/wordpress/14252/intelligence/china-us-mutual-accusations-cyber-cold-war.html" target="_blank">tension</a> between China and US gave security experts the opportunity to discuss about the development of the two countries of efficient cyber strategy that improve both offensive and defensive <a title="US nation’s military considered unprepared for a cyber-conflict" href="http://securityaffairs.co/wordpress/12727/intelligence/us-nations-military-considered-unprepared-for-a-cyber-conflict.html" target="_blank">cyber capabilities</a>.</p>
<p>Both countries <span class="GINGER_SOFATWARE_correct">are largely invested</span> in the creation of new cyber units, but according intelligence sources, <a title="The offensive approach to cybersecurity, motivations and risks" href="http://securityaffairs.co/wordpress/14330/security/offensive-approach-cybersecurity-risks.html" target="_blank">offensive approach</a> seems to be most stimulated by the need to preserve the security in the cyberspace.</p>
<p>NSA chief General Keith Alexander <a href="http://www.nytimes.com/2013/05/07/world/asia/us-accuses-chinas-military-in-cyberattacks.html?pagewanted=1&amp;_r=1&amp;" target="_blank">told Congress</a> that the US Government  <span class="GINGER_SOFATWARE_correct">is spending</span> billions of dollars every year on &#8220;<span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cyberdefense</span> and constructing increasingly sophisticated <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cyberweapons</span>&#8221; this led to the birth  of &#8220;more than a dozen offensive cyber units, designed to mount attacks, when necessary, at foreign computer networks.&#8221;</p>
<p>Popular hacker Charlie Miller, security researcher at Twitter, with a past collaboration with NSA confirmed the offensive approach to cyber security:</p>
<blockquote><p><em> &#8221;The only people paying are on the offensive side,&#8221;</em></p></blockquote>
<p>The emerging zero-day market is fueled by intense activities of talented <a title="http://securityaffairs.co/wordpress/11478/hacking/hackers-a-need-for-cyber-security.html" href="http://securityaffairs.co/wordpress/11478/hacking/hackers-a-need-for-cyber-security.html" target="_blank">hackers</a> who sell information on flaws in large use products. According Reuters defense contractors and intelligence agencies “spend at least tens of millions of dollars a year just on exploits”.</p>
<p>The zero-day market is very complex due high &#8220;<span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">perishability</span>&#8221; of the goods, following some key figures of a so complex business</p>
<p><em><strong>Difﬁculty ﬁnding buyers and sellers</strong></em> – It&#8217;s a closed market not openly accessible. Find a buyer or identify a possible seller is a critical phase.</p>
<p><em><strong>Checking the buyer reliability</strong></em> – The reduced number of reliable brokers able to locate a buyer pushes the researcher to try to tell many individuals about the discovery in an attempt to ﬁnd a buyer with obvious risks.</p>
<p><strong>Value cannot be demonstrated without loss</strong> – <em>One of the most fascinating problems a researcher attempting to sell vulnerability information or a 0-day exploit may face is proving the validity of the information without disclosing the information itself. The only way to prove the validity of the information is </em><em>to either reveal it or demonstrate it in some fashion. Obviously, revealing the information before the sale is undesirable as it leaves the researcher exposed to losing the intellectual property of the information without compensation.</em></p>
<p><strong>Exclusivity of rights - </strong><em>The ﬁnal hurdle involves the idea of the exclusive rights of the information. In order to receive the largest payoffs, the researcher must be willing to sell all rights to the information to the buyer. However, the buyer has no way to protect themselves from the researcher selling the information to numerous parties, or even disclosing the information </em><em>publicly, after the sale.</em></p>
<p>Current approaches to <a title="http://securityaffairs.co/wordpress/9566/hacking/wrong-response-to-zero-day-attacks-exposes-to-serious-risks.html" href="http://securityaffairs.co/wordpress/9566/hacking/wrong-response-to-zero-day-attacks-exposes-to-serious-risks.html" target="_blank">zero-day</a> vulnerabilities are to be bought up exploits avoiding that they could be acquired by government’s opponents such as dictators or organized criminals, many security firms sell subscriptions for exploits, guaranteeing a certain number per year.</p>
<p>The trend to exploit zero-day for offensive purposes has been followed by intelligence agencies and also private companies, both actors have started to code their own zero-day exploits.</p>
<blockquote><p><i>&#8220;Private companies have also sprung up that hire programmers to do the grunt work of identifying vulnerabilities and then writing exploit code. The starting rate for a zero-day is around $50,000, some buyers said, with the price depending on such factors as how widely installed the targeted software is and how long the zero-day is expected to remain exclusive.&#8221;</i></p></blockquote>
<p>The Reuters report also revealed the participation of government representatives to the Secret Snoop <a href="https://www.networkworld.com/community/blog/secret-snoop-conference-govt-spying-go-stealt">Conference</a> for Government and law enforcement spying, clearly with the intent to acquire new technologies to conduct cyber espionage through malware based attacks able to compromise target  networks.</p>
<p>The choice of a government to acquire a zero-day exploit to use it against a foreign governments hide serious risks for its country, cyber terrorist, cyber criminals or state-sponsored hackers could  reverse engineer the source code to compose new malicious agent to use against the same authors.</p>
<p>The most popular example is the case of <a title="Stuxnet &amp; Duqu, update on cyber weapons usage" href="http://securityaffairs.co/wordpress/4544/hacking/stuxnet-duqu-update-on-cyber-weapons-usage.html" target="_blank">Duqu</a> malware, a powerful spyware designed “to steal industrial-facility designs from Iran.&#8221;  which code was adopted by cybercrime industry to be the active components in popular Blackhole and Cool <a title="The rise of exploit kits according to Solutionary SERT" href="http://securityaffairs.co/wordpress/11957/cyber-crime/the-raise-of-exploit-kits-according-solutionary-sert.html" target="_blank">exploit kits</a>.</p>
<p>In many cases the efficiency of these zero-day exploits <span class="GINGER_SOFATWARE_correct">has</span> a long life due the presence of not updated target systems, typical zero-day attack has an average duration of 312 days and once publicly disclosed it is <span class="GINGER_SOFATWARE_correct">observable</span> an <span class="GINGER_SOFATWARE_correct">increases</span> of 5 orders of magnitude of the volume of attacks.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Zero-day-Analysis.jpg"><img class="aligncenter  wp-image-14572" alt="Zero day Analysis" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Zero-day-Analysis.jpg" width="449" height="356" title="Zero day market, the governments are the main buyers" /></a></p>
<p>Reuters reported to have reviewed a product catalogue from one large contractor, it contained various applications for cyber espionage purposes. The article <span class="GINGER_SOFATWARE_correct">refer</span> of a product “to turn any iPhone into a room-wide eavesdropping device” and another one “was a system for installing spyware on a printer or other device and moving that malware to a nearby computer via radio waves, even when the machines aren&#8217;t connected to anything.</p>
<p>The product portfolio is very wide including tools for getting access to computers or phones and tools for grabbing different categories of data, it’s clear that <span class="GINGER_SOFATWARE_correct">majority</span> of these products exploits zero-day vulnerabilities <span class="GINGER_SOFATWARE_correct">on</span> various <span class="GINGER_SOFATWARE_correct">application</span> and OSs …. <span class="GINGER_SOFATWARE_correct">most</span> of the programs cost more than $100,000.</p>
<p>Based from my experience the cost of a zero day-day depends on a multitude of factors such as the product target, its diffusion level and of course the scope of use, a zero-day sold to a government could have a price up to 100 times an exploit kit sold to private industry.</p>
<blockquote><p><em>Which are the principal mediators for zero-day sale?</em></p></blockquote>
<p>The <span class="GINGER_SOFATWARE_correct">Grugq</span> is the famous one but also small firms like Vupen and Netragard and other defense contractors such as Northrop Grumman operate this growing market.</p>
<p><em><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">Netragard’s</span> founder Adriel Desautels says he’s been in the exploit-selling game for a decade, and describes how the market has “exploded” in just the last year.  He says there are now “more buyers, deeper pockets,” that the time for a purchase has accelerated from months to weeks, and he’s <span class="GINGER_SOFATWARE_correct">being</span> approached by sellers with around 12 to 14 zero-day exploits every month compared to just four to six a few years ago.</em></p>
<p>Prepare for the worst, the explosion in demand for zero-day leaves little doubt about the true intentions of governments and the impact is certainly not confined to just cyberspace.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cyber security, Zero-day vulnerabilities</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14561/malware/zero-day-market-governments-main-buyers.html">Zero-day market, the governments are the main buyers</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14561/malware/zero-day-market-governments-main-buyers.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Operation Hangover, the Indian Cyberattack Infrastructure</title>
		<link>http://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html</link>
		<comments>http://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html#comments</comments>
		<pubDate>Mon, 20 May 2013 18:41:56 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[Norman Shark]]></category>
		<category><![CDATA[Operation Hangover]]></category>
		<category><![CDATA[spear phishing]]></category>
		<category><![CDATA[state sponsored hackers]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14550</guid>
		<description><![CDATA[<p>Operation Hangover is the title of a report published by Norman Shark that details a sophisticated cyberattack infrastructure that appears to originate from India, conducted by private threat actors with no evidence of state-sponsorship. Operation Hangover, this is the name assigned by Norman Shark&#8217;s security analyst team to an interesting report revealing a large and sophisticated cyber-attack [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html">Operation Hangover, the Indian Cyberattack Infrastructure</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>Operation Hangover is the title of a report published by Norman Shark that details a sophisticated <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cyberattack</span> infrastructure that appears to originate from India, conducted by private threat actors with no evidence of state-<span class="GINGER_SOFATWARE_correct">sponsorship</span>.</h2>
<p>Operation Hangover, this is the name assigned by Norman Shark&#8217;s security analyst team to an interesting <a href="http://enterprise.norman.com/resource_center/unveiling_an_indian_cyberattack_infrastructure-a_special_report">report</a> revealing a large and sophisticated cyber-attack infrastructures that appears to have originated from India.<br />
The cyber attacks have primary purpose of cyber espionage, they seem to be conducted by private entities over a period of three years. The attacks are still ongoing and there is no evidence of <a title="Nation state sponsored attacks: the offensive of Governments in cyberspace" href="http://securityaffairs.co/wordpress/10203/security/nation-state-sponsored-attacks-the-offensive-of-governments-in-cyberspace.html" target="_blank">state-sponsored commitment</a>, even if principal security experts are convinced that we are facing with a a government intelligence operation.</p>
<p>The concerning news is that the cyber espionage campaign Operation Hangover is still ongoing gathering information from national security targets and private sector companies mostly based in Pakistan and in the United States.</p>
<p style="text-align: center;" align="center"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Operation-Hangover-Targets.jpg"><img class="aligncenter  wp-image-14551" alt="Operation Hangover Targets" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Operation-Hangover-Targets.jpg" width="485" height="335" title="Operation Hangover, the Indian Cyberattack Infrastructure" /></a><br />
<!--[endif]--></p>
<p>The story begun on March 17th, when a Norwegian newspaper revealed that Telenor, Norway’s major telecommunications company,  denounced to the authorities an unlawful computer intrusion, the attack was malware based and Norman Shark analyst team revealed that many other similar intrusions hit the company.</p>
<p>The Norman Shark&#8217;s team discovered that hackers of Operation Hangover used spear phishing emails targeting senior management of corporate and government institutions.</p>
<blockquote><p><i>“<a title="APWG Global Phishing Survey report revealed new scaring trends" href="http://securityaffairs.co/wordpress/13991/cyber-crime/apwg-global-phishing-survey-report.html" target="_blank">Spear phishing</a> to carefully-selected target individuals <span class="GINGER_SOFATWARE_correct">was</span> the primary attack vector identified in the investigation. The attackers went to great lengths to make the social engineering aspects of the attack appear as credible and applicable as possible. In many cases, decoy files and websites were used, specifically geared to the particular sensibilities of regional targets including cultural and religious subject matter. Victims would click on what appeared to be an interesting document, and begin the long-running infection cycle.” Report states.</i></p></blockquote>
<p>Analyzing IP addresses used by cyber criminals it appears that <span class="GINGER_SOFATWARE_correct">victims</span> are located in more than a dozen countries, the claim that they <span class="GINGER_SOFATWARE_correct">are originate</span> from India is based on analysis of IP addresses, website domain registrations and text-based identifiers contained within the malware used for attacks.</p>
<p>The malicious code used in the <a title="http://enterprise.norman.com/resources/files/Unveiling_an_Indian_Cyberattack_Infrastructure.pdf" href="http://enterprise.norman.com/resources/files/Unveiling_an_Indian_Cyberattack_Infrastructure.pdf" target="_blank">Operation Hangover</a> campaign relied on various well-known previously identified <a title="http://securityaffairs.co/wordpress/3913/cyber-crime/1-day-exploitsbinary-diffing-patch-management-the-side-threats.html" href="http://securityaffairs.co/wordpress/3913/cyber-crime/1-day-exploitsbinary-diffing-patch-management-the-side-threats.html" target="_blank">vulnerabilities</a> in popular software applications and browsers, such as Java and Word documents.</p>
<p>But how is it possible that well know vulnerabilities are exploited for a massive cyber espionage campaign?</p>
<p>The fact that the Operation Hangover was successful suggests that government organizations, defense and private businesses do not properly manage the <a title="5 Reasons Why You Need Good Patch Management" href="http://securityaffairs.co/wordpress/6370/security/5-reasons-why-you-need-good-patch-management.html" target="_blank">update</a> of their systems exposing them to serious risks. Snorre Fagerland, head of research for Norman Shark labs in Oslo, Norway declared:</p>
<blockquote><p><i>“The data we have appears to indicate that a group of attackers based in India may have employed multiple developers tasked with delivering specific malware,” “The organization appears to have the resources and the relationships in India to make surveillance attacks possible anywhere in the world. What is surprising is the extreme diversity of the sectors targeted, including natural resources, telecommunications, law, food and restaurants, and manufacturing. It is highly unlikely that this organization of hackers would be conducting industrial espionage for just its own purposes—which makes this of considerable concern.”</i></p></blockquote>
<p>The words of Fagerland leave no doubt, a group of hackers is targeting with sophisticated techniques an extreme diversity of the sectors, the investigation is still ongoing by international authorities.</p>
<p style="text-align: center;" align="center"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Operation-Hangover.png"><img class="aligncenter  wp-image-14552" alt="Operation Hangover" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Operation-Hangover.png" width="447" height="293" title="Operation Hangover, the Indian Cyberattack Infrastructure" /></a><br />
<!--[endif]--></p>
<p>The security analysts at Norman Shark evidenced a professional project management approach used for the campaign and the outsourcing of key tasks.</p>
<blockquote><p><i> “Something like this has never been documented before,” “This type of activity has been associated primarily with China over the past several years but to our knowledge, this is the first time that evidence of cyber espionage has shown to be originating from India,” </i>commented Fagerland on code outsourcing and on the fact that hackers exploited well known flaws in popular applications.</p></blockquote>
<p><a title="FireEye report on advanced cyber attacks landscape" href="http://securityaffairs.co/wordpress/13877/cyber-crime/fireeye-report-advanced-cyber-attacks.html" target="_blank">Cyber ​​espionage</a> is becoming one of the most frequent activities in cyberspace, its actions can cause devastating effects on entire economies and identify campaigns is becoming more and more complicated, but in cases like this the failure to update the target system has certainly contributed to the success of operations.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cyber espionage</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html">Operation Hangover, the Indian Cyberattack Infrastructure</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14550/cyber-crime/operation-hangover-indian-cyberattack-infrastructure.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WSIS Forum 2013 &#8211; Securing Cyberspace in a borderless world</title>
		<link>http://securityaffairs.co/wordpress/14525/cyber-crime/wsis-forum-2013-securing-cyberspace.html</link>
		<comments>http://securityaffairs.co/wordpress/14525/cyber-crime/wsis-forum-2013-securing-cyberspace.html#comments</comments>
		<pubDate>Mon, 20 May 2013 09:01:42 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Critical infrastructures]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[Group-IB]]></category>
		<category><![CDATA[ITU]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14525</guid>
		<description><![CDATA[<p>“Securing Cyberspace in a borderless world: Vision 2015 and Beyond” is the title of a High Level Dialogue that was held during The World Summit on the Information Society Forum (WSIS) 2013. The World Summit on the Information Society Forum (WSIS) represents the world’s largest annual gathering of the ICT for development  community, the event is organized [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14525/cyber-crime/wsis-forum-2013-securing-cyberspace.html">WSIS Forum 2013 &#8211; Securing Cyberspace in a borderless world</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>“<em>Securing Cyberspace in a borderless world: Vision 2015 and Beyond</em>” is the title of a High Level Dialogue that was held during The World Summit on the Information Society Forum (WSIS) 2013.</h2>
<p>The World Summit on the Information Society Forum (<a title="http://www.itu.int/wsis/implementation/2013/forum/" href="http://www.itu.int/wsis/implementation/2013/forum/" target="_blank">WSIS</a>) represents the world’s largest annual gathering of the ICT for development  community, the event is organized by ITU (INTERNATIONAL TELECOMMUNICATION UNION) and during the last edition it was <span class="GINGER_SOFATWARE_correct">held</span> a high level session dedicated to the topic “<em>Securing Cyberspace in a borderless world: Vision 2015 and Beyond</em>”.</p>
<p>I find the topic very interesting for all cyber security professionals, the dialogue at WSIS was moderated by Mr Kim Andreasson, Managing Director of DAKA advisory AB and editor, Cybersecurity: Public Sector Threats and Response.</p>
<p>The WSIS Forum 2013 was held from the 13-17 May 2013 at the ITU Headquarters in Geneva. This year the Forum attracted more than 1800 WSIS Stakeholders from more than 140 countries. Several high-level representatives of the wider WSIS Stakeholder community graced the Forum with more than 60 ministers and deputies, several ambassadors, CEOs and Civil Society leaders contributing passionately towards the <span class="GINGER_SOFATWARE_correct">programme</span> of the Forum.</p>
<p>Several key panelists from different expert fields have taken part in the WSIS meeting:</p>
<ul>
<li>Dr Hamadoun Touré, Secretary-General, ITU</li>
<li>H.E. Mr Diego Molano Vega, Minister, Ministry of ICT, Colombia</li>
<li>H.E. <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">Amb</span>. Dr. Theodor H. Winkler, Director, DCAF, Switzerland</li>
<li>Ms Ingrid Deltenre, Director General, EBU, Switzerland</li>
<li>Mr Chris Painter, Cybersecurity Coordinator, Department of States, USA (<a href="http://www.state.gov/r/pa/ei/biog/161848.htm" target="_blank">http://www.state.gov/r/pa/ei/biog/161848.htm</a>)</li>
<li>Mr Stuart Carlaw, Chief Research Officer,  ABI Research, United States</li>
<li>Mr Ilya Sachkov, CEO, Group IB, Russian Federation (<a href="http://group-ib.com/" target="_blank">http://group-ib.com</a>)</li>
<li>Mr John Carr, Secretary, Children&#8217;s Charities&#8217; Coalition on Internet Safety, United Kingdom</li>
</ul>
<p>I suggest to read the <a href="http://www.itu.int/wsis/implementation/2013/forum/agenda/session_docs/81/81-ITUSGWSIS130515-1400Cyberv5.pdf">paper</a> prepared by Dr Hamadoun Touré, Secretary General ITU which covers different problems, trends and views on the <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybersecurity</span> situation in the world, as well as key principles of ITU for making trust and peace in the modern world.</p>
<p>Dr<span class="GINGER_SOFATWARE_correct">.</span>Hamadoun I. Toure also mentioned that according to the most recent statistics annual losses of over 100 billion dollars are being caused by <a title="The “company” cybercrime seen by Fortinet" href="http://securityaffairs.co/wordpress/11282/cyber-crime/the-company-cybercrime-seen-by-fortinet.html" target="_blank">cybercrime</a>, and that some 550 million people are being targeted by <span class="GINGER_SOFATWARE_correct">cyberattacks</span> every year. In financial terms, this is the equivalent of the entire GDP of a country like Morocco, Slovakia or Bangladesh. In population terms, it is the equivalent of more than all the inhabitants of Europe. Every second, 18 adults become a victim of cybercrime, resulting in more than 1.5 million cybercrime victims each day on a global level.<br />
<a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/WSIS_2013.jpg"><img class="aligncenter" alt="WSIS_2013" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/WSIS_2013.jpg" width="448" height="159" title="WSIS Forum 2013   Securing Cyberspace in a borderless world" /></a></p>
<p>I decided to interview the Group-IB CEO, who was one of the representatives from the private sector during the WSIS meeting. <a title="Group-IB Exclusive details on Kangoo botnet that hit Australian banks" href="http://securityaffairs.co/wordpress/14444/cyber-crime/from-group-ib-kangoo-botnet-against-australian-banks.html" target="_blank">Group-IB</a> is one of the leading companies in fraud prevention, cybercrime and high-tech crime investigations and that often support me in my analysis on security issues.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/WSIS-2013-Sachkov-Group-IB.jpg"><img class="aligncenter  wp-image-14527" alt="WSIS 2013 Sachkov Group-IB" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/WSIS-2013-Sachkov-Group-IB.jpg" width="262" height="393" title="WSIS Forum 2013   Securing Cyberspace in a borderless world" /></a></p>
<p><b>1) Ilya, what were the most interesting topics of discussion during the high-level dialogue organized during WSIS 2013? </b></p>
<p>The panelists shared their opinions on modern <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybersecurity</span> problems, starting from reducing the risks of harmful use of ICT to the child protection in WEB. I can say, that such dialogue on high level can help the governments, private sector of different countries and society to get an actual view on the situation in the field.</p>
<p><b>2) What key problems in modern <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybersecurity</span> can you figure out? </b></p>
<p>One of the most important question is that private sector should collaborate with governments more closely, as the most actual and interesting information for reducing the <span class="GINGER_SOFATWARE_correct">cybersecurity</span> risks is in private sector hands. Some countries have some political barriers of cooperation which makes cooperation absolutely not clear and impossible, as well as the same problems within own country. The role of private and non-commercial expert companies and organizations is increasing each day and one the best way is to link it with government efforts to make the cyber world safer.</p>
<p>Many private companies with cybercrime solutions are cooperating on the back-end by sharing data on cyber threats anonymously via signatures in a so called &#8220;Eco Systems&#8221;. This allows their big data analysis programs to flag malware and threats before damage is done to networks.</p>
<p><b>3) What do you think about the role of governments, along with intergovernmental bodies such <span class="GINGER_SOFATWARE_correct">us</span> UN and the ITU in modern <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybersecurity</span>? </b></p>
<p>I have already mentioned it a bit in the previous point, but it will be important to say that private-public partnership shows good results. In regard of Russia and former USSR countries, CERT-GIB (Group-IB&#8217;s CERT) acts in very close cooperation with international LEA, domain registers, ISPs and hosting provers to reduce cyber security threats .RU, .РФ, .SU and shows efficient results in <a title="Botnet organization, easy and cheap!" href="http://securityaffairs.co/wordpress/12655/cyber-crime/botnet-organization-easy-and-cheap.html" target="_blank"><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnets</span></a> tracking and <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cyberthreat</span> intelligence each day, operating 24x7x365.</p>
<p>Law enforcement agencies, such as <span class="GINGER_SOFATWARE_correct">FBI</span> and Russia&#8217;s FSB, are seeing threats to national <a title="US Army Corps of Engineers National Inventory of Dams hacked" href="http://securityaffairs.co/wordpress/14089/security/us-army-corps-engineers-national-inventory-of-dams-nid-hacked.html" target="_blank">critical infrastructures</a> like power grids and <a title="vSkymmer botnet, a financial malware appears in the underground" href="http://securityaffairs.co/wordpress/13292/malware/vskymmer-botnet-a-financial-malware-appears-in-the-underground.html" target="_blank">banking sectors</a>, and are making overtures about &#8220;Sharing&#8221; data and intelligence with relevant private partners. Even some newly proposed cyber security laws and new agencies are reflecting this change from traditional law enforcement culture.</p>
<p><b>4) As far as I know Group-IB is a member of IMPACT-ITU, what benefits or advantages you have in this plan? Is this structure efficient for reducing the <span class="GINGER_SOFATWARE_correct">cybersecurity</span> risks? What is your role there? </b></p>
<p>Yes, we are very proud and happy, that Group-IB and its CERT are members of IMPACT-ITU. I can say, that it is one of the most powerful and expert organizations in the world, organized with the support of ITU. We share cyber threat intelligence information within IMPACT-ITU member community, targeted for public and critical infrastructure sectors.</p>
<p>&nbsp;</p>
<p>The security in the cyberspace is a global need, the<a title="APWG Global Phishing Survey report revealed new scaring trends" href="http://securityaffairs.co/wordpress/13991/cyber-crime/apwg-global-phishing-survey-report.html" target="_blank"> cyber threats</a> are increasing in recent months, as has happened before, and the trend is to a relentless growth, to mitigate the risks it is necessary an approach on a global scale that request the participation of governments and private companies that must share information of principal cyber menaces and  define a global recognized law framework … only in this way we can reduce risks to an acceptable level.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cyber <span class="GINGER_SOFATWARE_correct">security</span></strong>)</p>
<p>&nbsp;</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14525/cyber-crime/wsis-forum-2013-securing-cyberspace.html">WSIS Forum 2013 &#8211; Securing Cyberspace in a borderless world</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14525/cyber-crime/wsis-forum-2013-securing-cyberspace.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac malware detected by Appelbaum at Oslo Freedom Forum</title>
		<link>http://securityaffairs.co/wordpress/14497/malware/mac-malware-against-oslo-freedom-forum.html</link>
		<comments>http://securityaffairs.co/wordpress/14497/malware/mac-malware-against-oslo-freedom-forum.html#comments</comments>
		<pubDate>Mon, 20 May 2013 06:21:51 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[anonymity]]></category>
		<category><![CDATA[Appelbaum]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[human rights]]></category>
		<category><![CDATA[Mac malware]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[Oslo Freedom Forum]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[Tor Project]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14497</guid>
		<description><![CDATA[<p>NEW MAC MALWARE HAS BEEN DISCOVERED BY JACOB APPELBAUM ON ATTENDEE COMPUTER AT OSLO FREEDOM FORUM WHERE IS DEBATED ALSO GOVERNMENT SURVEILLANCE. A new Mac Malware has been detected at recent Oslo Freedom Forum workshop, the concerning discovery has been made by the popular security expert Jacob Appelbaum. &#8220;Hundreds of the world&#8217;s most influential dissidents, innovators, journalists, philanthropists, and [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14497/malware/mac-malware-against-oslo-freedom-forum.html">Mac malware detected by Appelbaum at Oslo Freedom Forum</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>NEW MAC MALWARE HAS BEEN DISCOVERED BY JACOB APPELBAUM ON ATTENDEE COMPUTER AT OSLO FREEDOM FORUM WHERE IS DEBATED ALSO GOVERNMENT SURVEILLANCE.</h2>
<p>A new Mac Malware has been detected at recent Oslo Freedom Forum workshop, the concerning discovery has been made by the popular security expert Jacob Appelbaum.</p>
<blockquote><p><em>&#8220;Hundreds of the world&#8217;s most influential dissidents, innovators, journalists, philanthropists, and policymakers will unite in the Norwegian capital for a three-day summit exploring how best to challenge authoritarianism and promote free and open societies.&#8221;</em></p></blockquote>
<p>Appelbaum is best known for his work in the fight of online <a title="The right to anonymity on Internet and legal implications" href="http://securityaffairs.co/wordpress/6452/intelligence/the-right-to-anonymity-on-internet-and-legal-implications.html" target="_blank">anonymity</a> (e.g. <a title="What is the Deep Web? A first trip into the abyss" href="http://securityaffairs.co/wordpress/5650/cyber-crime/what-is-the-deep-web-a-first-trip-into-the-abyss.html" target="_blank">Tor Project</a>) and for his participation in numerous activities in the defense of human rights and free access to the Internet.</p>
<p>During  workshop is debated the topic of government <a title="Censorship, governments and corporations enemies of internet" href="http://securityaffairs.co/wordpress/12822/digital-id/censorship-governments-and-corporations-enemies-of-internet.html" target="_blank">surveillance</a>, the experts who participated <span class="GINGER_SOFATWARE_correct">to</span> the event discussed the uncomfortable subject and many other topics such as dictatorship, <a title="Governments are increasing cyber security on social media" href="http://securityaffairs.co/wordpress/7827/intelligence/governments-are-increasing-cyber-security-on-social-media.html" target="_blank">censorship</a> and activism.</p>
<p>During the recent months many <a title="The Flame is “ignited” between the U.S. and France" href="http://securityaffairs.co/wordpress/10525/malware/the-flame-is-ignited-between-the-u-s-and-france.html" target="_blank">cyber espionage</a> campaigns have been uncovered, in majority of the cases governments used malicious codes to track dissident and political opponents, the phenomena have global diffusion and are of great concern to those who are fighting for <span class="GINGER_SOFATWARE_correct">humanitarian</span> rights and freedom of expression.</p>
<p>This edition of the forum,  The fifth, will be reminded also for the discovery of  Appelbaum, a new strain of malware with <span class="GINGER_SOFATWARE_correct">backdoor</span> capabilities on Mac OS has been detected on an Angolan activist’s machine.</p>
<p>Appelbaum sustained that the Angolan activist’s PC was compromised in a spear-phishing attack used to spread the Mac Malware.</p>
<p>F-Secure security firm was one of the first firm that investigated on the Mac Malware, the researcher known as “Brod,” is investigating on the malicious agent. F-Secure security advisor Sean Sullivan published an interesting <a href="http://www.f-secure.com/weblog/archives/00002554.html">post</a> on the case, the Mac Malware code is signed with a legitimate Apple Developer ID and it is able to take screenshots storing them image files in a folder called “MacApp.”.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-Storage.png"><img class="aligncenter  wp-image-14499" alt="Mac Malware Storage" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-Storage.png" width="452" height="222" title="Mac malware detected by Appelbaum at Oslo Freedom Forum" /></a></p>
<p>Appelbaum confirmed via Twitter that Apple has revoked the Developer ID with which the malware is signed</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-Tweet2.jpg"><img class="aligncenter  wp-image-14500" alt="Mac Malware Tweet2" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-Tweet2.jpg" width="458" height="297" title="Mac malware detected by Appelbaum at Oslo Freedom Forum" /></a></p>
<p>The spyware implements simple spying functions, it is able to capture images of the victim’s screen and transfer the data to a Command &amp; Control server, the security researchers found two C&amp;C <span class="GINGER_SOFATWARE_correct">server</span> located in France and in the Netherlands.</p>
<p style="text-align: center;"><b><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-CeC-1.png"><img class="aligncenter  wp-image-14501" alt="Mac Malware CeC 1" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-CeC-1.png" width="450" height="260" title="Mac malware detected by Appelbaum at Oslo Freedom Forum" /></a></b></p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-CeC-2.png"><img class="aligncenter  wp-image-14502" alt="Mac Malware CeC 2" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-CeC-2.png" width="440" height="268" title="Mac malware detected by Appelbaum at Oslo Freedom Forum" /></a></p>
<p>&nbsp;</p>
<p>Sullivan wrote that the French C&amp;C server would not resolve and the Dutch displayed a “Forbidden” access message.</p>
<p>Sullivan and Appelbaum revealed on Twitter that Mac malware detected appeared to be linked to an older Mac malicious code called <span class="GINGER_SOFATWARE_correct">HackBack</span>.</p>
<p style="text-align: center;"><b><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-Tweet.jpg"><img class="aligncenter  wp-image-14503" alt="Mac Malware Tweet" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Mac-Malware-Tweet.jpg" width="456" height="71" title="Mac malware detected by Appelbaum at Oslo Freedom Forum" /></a></b></p>
<p><a href="https://www.virustotal.com/en/file/049db432b05055bdf0152b82cb7939982d38067da364cee2fdbed6ceb5f60cde/analysis/">VirusTotal</a> assigned to the Mac Malware a Detection ratio of 1/46 that means that  only F-Secure antivirus vendors is currently detecting the threat identifying it as as Backdoor: OSX/<span class="GINGER_SOFATWARE_correct">KitM</span><span class="GINGER_SOFATWARE_correct">.</span>A. (SHA1: 4395a2da164e09721700815ea3f816cddb9d676e).</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Cyber espionage</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14497/malware/mac-malware-against-oslo-freedom-forum.html">Mac malware detected by Appelbaum at Oslo Freedom Forum</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14497/malware/mac-malware-against-oslo-freedom-forum.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yahoo Japan suspects 22 million user IDs stolen</title>
		<link>http://securityaffairs.co/wordpress/14512/cyber-crime/yahoo-japan-suspects-22-million-user-ids-stolen.html</link>
		<comments>http://securityaffairs.co/wordpress/14512/cyber-crime/yahoo-japan-suspects-22-million-user-ids-stolen.html#comments</comments>
		<pubDate>Sun, 19 May 2013 09:33:28 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Yahoo! Japan]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14512</guid>
		<description><![CDATA[<p>Yahoo Japan Corp is investigating on a possible data breach that may have exposed 22 million user IDs stolen during an unauthorized access to web portal. Yahoo Japan Corp is investigating on a possible data breach that exposed the user IDs of 22 million accounts, another shocking event that raise the necessity to improve security [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14512/cyber-crime/yahoo-japan-suspects-22-million-user-ids-stolen.html">Yahoo Japan suspects 22 million user IDs stolen</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>Yahoo Japan Corp is investigating on a possible data breach that may have exposed 22 million user IDs stolen during an unauthorized access to <span class="GINGER_SOFATWARE_correct">web portal</span>.</h2>
<p>Yahoo Japan Corp is investigating on a possible <a title="How to respond to a data breach" href="http://securityaffairs.co/wordpress/13549/security/how-to-respond-to-the-a-data-breach.html" target="_blank">data breach</a> that exposed the user IDs of 22 million accounts, another shocking event that raise the necessity to improve security level of customer’s data.</p>
<p>22 million user IDs may have been stolen during an unauthorized access to the administrative system of Yahoo! Japan web portal,  the <a title="http://uk.news.yahoo.com/yahoo-japan-suspects-22-million-user-ids-leaked-194847071.html" href="http://uk.news.yahoo.com/yahoo-japan-suspects-22-million-user-ids-leaked-194847071.html" target="_blank"><span class="GINGER_SOFATWARE_correct">announce</span></a> has been done by the same company:</p>
<blockquote><p><i>&#8220;We don&#8217;t know if the file (of 22 million user IDs) was leaked or not, but we can&#8217;t deny the possibility given the volume of traffic between our server and external terminals,&#8221;</i> the company reported in an official statement.</p></blockquote>
<p><strong><em>Why Yahoo! Japan?</em></strong></p>
<p>Yahoo! Japan is controlled by Japan&#8217;s mobile phone operator SoftBank (35.5%) and  Yahoo! Inc (34.7%), what is interesting is the market share of the portal Yahoo! Japan that holds 50% of the top search engine position in Japan, a figure superior to the Google concurrence at 40%, it&#8217;s clear that the corporation represents a privileged target of cyber criminals and state-sponsored hackers.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/22-million-Yahoo-serch-engine1.jpg"><img class="aligncenter  wp-image-14518" alt="22 million Yahoo serch engine" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/22-million-Yahoo-serch-engine1.jpg" width="450" height="282" title="Yahoo Japan suspects 22 million user IDs stolen" /></a></p>
<p><em><strong>Which information has been stolen exactly?</strong></em></p>
<p>According first investigation it seems that the exposed information doesn’t include any data that could be used to identify the user’s identity or that could be exploited successively to force password reset.</p>
<p>Yahoo! <span class="GINGER_SOFATWARE_correct">has</span> immediately started the incident response procedure adopting any countermeasure to prevent further incidents.</p>
<p>On the case is also working the Japan&#8217;s national police agency that recently announced the  launch an investigation team specialized in <span class="GINGER_SOFATWARE_correct">cybercrimes</span>, let’s <span class="GINGER_SOFATWARE_correct">remind</span> that in the last years the Japan has been hit by a huge quantity of cyber attacks that interested the <a title="Japan Aerospace Exploration Agency hit again by malware" href="http://securityaffairs.co/wordpress/10760/hacking/japan-aerospace-exploration-agency-hit-again-by-malware.html" target="_blank">Japan Aerospace Exploration Agency</a>, Sony and <a title="Japan institutions victim of cyber espionage, is it cyber warfare?" href="http://securityaffairs.co/wordpress/7678/hacking/japan-institutions-victim-of-cyber-espionage-is-it-cyber-warfare.html" target="_blank">Government</a> itself.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Data Breach</strong>)</p>
<p>&nbsp;</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14512/cyber-crime/yahoo-japan-suspects-22-million-user-ids-stolen.html">Yahoo Japan suspects 22 million user IDs stolen</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14512/cyber-crime/yahoo-japan-suspects-22-million-user-ids-stolen.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nir Goldshlager reveals how to hack Facebook Apps</title>
		<link>http://securityaffairs.co/wordpress/14474/hacking/how-to-hack-facebook-apps.html</link>
		<comments>http://securityaffairs.co/wordpress/14474/hacking/how-to-hack-facebook-apps.html#comments</comments>
		<pubDate>Sat, 18 May 2013 07:13:26 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Apps]]></category>
		<category><![CDATA[data spoofing]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Nir Goldshlager]]></category>
		<category><![CDATA[Social Network]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14474</guid>
		<description><![CDATA[<p>The popular security expert Nir Goldshlager found  a serious vulnerability that allows attackers to post spoofed messages from any application on Facebook. Facebook has many vulnerabilities exactly as any other software and daily hackers try to exploit them, the primary concerns of security experts are related to flaws in the popular social network that could all [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14474/hacking/how-to-hack-facebook-apps.html">Nir Goldshlager reveals how to hack Facebook Apps</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>The popular security expert Nir Goldshlager found  a serious vulnerability that allows attackers to post spoofed messages from any application on Facebook.</h2>
<p>Facebook has many <a title="Tens of zero day vulnerabilities, millions of users exposed" href="http://securityaffairs.co/wordpress/9475/hacking/tens-of-zero-day-vulnerabilities-millions-of-users-exposed.html" target="_blank">vulnerabilities</a> exactly as any other software and daily hackers try to exploit them, the primary concerns of security experts are related to flaws in the popular <a title="Facebook compromised by zero-day Java exploit" href="http://securityaffairs.co/wordpress/12400/cyber-crime/facebook-compromised-by-zero-day-java-exploit.html" target="_blank">social network </a>that could all allow attackers to inject external malicious links or images to the Facebook bulletin board.</p>
<p>Using injection techniques the attackers could elude security mechanisms and hijack a Facebook account with serious repercussion on user’s privacy.</p>
<p>The popular security expert Nir Goldshlager,  Founder/CEO of Break Security, found  a serious vulnerability that allows attacker to post spoofed messages from any application on Facebook such as Spotify, Skype and Pinterest.</p>
<p>The vulnerability is still unfixed today and it makes possible <a title="Malware,Botnet &amp; cyber threats,what is happening to the cyberspace?" href="http://securityaffairs.co/wordpress/8926/cyber-crime/malwarebotnet-cyber-threatswhat-is-happening-to-the-cyberspace.html" target="_blank">data spoofing</a> from any Facebook app.</p>
<p>Let&#8217;s step to 2012 analyzing the method used by Facebook to publish content on the wall called <b><i><span class="GINGER_SOFATWARE_correct">stream</span><span class="GINGER_SOFATWARE_correct">.</span><span class="GINGER_SOFATWARE_correct">publish</span>, t</i></b>he Stream Publish Dialog has the following format:</p>
<pre><i>https://www.facebook.com/dialog/stream.publish?app_id=xxxx&amp;redirect_uri=http://www.facebook.com/&amp;action_links=&amp;attachment=%7B%27media%27:%20[%7B%27type%27:%20%27flash%27,%27swfsrc%27:%27http://files.nirgoldshlager.com/goldshlager2.swf%27,%27imgsrc%27:%27http://www.vectorstock.com/i/composite/41,30/hacked-pc-vector-194130.jpg%27,%27width%27:%27130%27,%27height%27:%27%20130%27,%27expanded_width%27:%27500%27,%27expanded_%20height%27:%27500%27%7D],%27name%27:%27xxxx%27,%27caption%27:%27xxxx%20Application%27,%27properties%27:%7B%27xxx%27:%7B%27text%27:%27Download%20xxx%27,%27href%27:%27http://nirgoldshlager.com%27%7D%7D%7D</i></pre>
<p>A hacker could manipulate the  <b><i>app_id</i></b> and <b><i>attachment (<span class="GINGER_SOFATWARE_correct">swfsr</span><span class="GINGER_SOFATWARE_correct">,</span><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">imgsrc</span><span class="GINGER_SOFATWARE_correct">,</span><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">href</span>)</i></b> parameters to conduct an attack. If the &#8220;<b><i>Stream post URL security</i></b>&#8221; option is disabled by the author of that application, a hacker can upload specifically crafted content, like a <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">swf</span> file, as <b><i>attachment </i></b>parameter.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Facebook-unproper-setting.jpg"><img class="aligncenter  wp-image-14477" alt="Facebook - unproper setting" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Facebook-unproper-setting.jpg" width="448" height="280" title="Nir Goldshlager reveals how to hack Facebook Apps" /></a></p>
<p>In the <a title="http://www.breaksec.com/?p=6208" href="http://www.breaksec.com/?p=6208" target="_blank">post</a> on the Break security web site is reported:</p>
<blockquote><p>&#8220;<i><span class="GINGER_SOFATWARE_correct">every</span> time a victim visits my wall post, they will see content spoofing from a Facebook application that they generally trust. Clicking the link on the post makes <span class="GINGER_SOFATWARE_correct">an</span> <span class="GINGER_SOFATWARE_correct">swf</span> file from the external website execute on his client machine.</i>&#8220;</p></blockquote>
<p>In 2013 the situation is changed, Facebook eliminated the stream<span class="GINGER_SOFATWARE_correct">.</span>publish option, instead opting for a <a href="https://developers.facebook.com/docs/reference/dialogs/feed/">Feed Dialog</a> to publish app activity.</p>
<p>Nir Goldshlager has not lost his nerve and analyzed the Feed Dialog and the parameters used to spoof app content.</p>
<p>Following the details of parameters used in Feed Dialog</p>
<ol>
<li><i></i><b><i>Link parameter: </i></b><i>With this parameter, we will include our malicious external link (virus <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">exe</span> file, 0days, Phishing site, or any other malicious link. </i></li>
<li><i></i><b><i>Picture Parameter: </i></b><i>This parameter is only <span class="GINGER_SOFATWARE_correct">usable</span> if we want to spoof the content with an image. The content of the image will only display correctly on our Wall post. It will not display correctly in the <span class="GINGER_SOFATWARE_correct">newsfeed</span>, making it relevant only to wall post app spoofing.</i></li>
<li><i></i><b><i>Caption Parameter: </i></b><i>This parameter will allow <span class="GINGER_SOFATWARE_correct">to</span> an attacker choose from which website the content came from, For Example: Facebook.com Zynga.com Ownerappdomain.com</i></li>
<li><i></i><b><i>Name Parameter: </i></b><i>This parameter produces the title we desire. Whenever the victim clicks on that title, he will be taken to our malicious <span class="GINGER_SOFATWARE_correct">website</span>.</i></li>
</ol>
<p>The post proposes a proof of concept video that present the Facebook hack for some various applications such as Skype and SoundCloud.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Facebook-app-spoofing.jpg"><img class="aligncenter  wp-image-14480" alt="Facebook - app spoofing" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Facebook-app-spoofing.jpg" width="448" height="280" title="Nir Goldshlager reveals how to hack Facebook Apps" /></a></p>
<p style="text-align: center;"><a title="http://vimeo.com/66328805" href="http://vimeo.com/66328805" target="_blank"><img class="aligncenter  wp-image-14481" alt="Facebook - app spoofing Poc video" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Facebook-app-spoofing-Poc-video.jpg" width="461" height="345" title="Nir Goldshlager reveals how to hack Facebook Apps" /></a></p>
<p><b>SoundCloud:</b></p>
<pre><i>https://www.facebook.com/dialog/feed?app_id=19507961798&amp;link=http://nmap.org/dist/nmap-6.20BETA1-setup.exe&amp;picture=http://www.atpfestival.com/assets/img/soundcloud.png&amp;name=Download%20SoundCloud%20For%20Windows&amp;%20caption=http://soundcloud.com&amp;description=&amp;%20redirect_uri=https://facebook.com</i></pre>
<p><b>Skype:</b></p>
<p><i>https://www.facebook.com/dialog/feed?app_id=260273468396&amp;link= https://touch.facebook.com/apps/sdfsdsdsgs &amp;picture=http://he.downloadastro.com/static/files/24/3b/29/243b29a6163cc99e359f4c354422f238.jpg&amp;name=Download%20Skype%20New%20Version&amp;%20caption=http://skype.com&amp;description=&amp;%20redirect_uri=https://facebook.com</i></p>
<p><b> </b>The author suggests the following solutions to solve the problem:</p>
<ul>
<li>Use  Stream post URL security=Enabled in App settings (developers.facebook.com), To prevent  content spoofing on your App.</li>
<li>Use Bonus Video (Advanced Spoofing Apps Links, Fixed By Facebook Security 2012)</li>
<li>Use  Stream post URL security=Enabled</li>
</ul>
<p>The flaw discovered by Goldshlager allow cyber criminals to spoof the content of any Facebook application, they could adopt the technique of attack to install malicious code on the user’s machine or deceive user with social engineering attack.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Hacking</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14474/hacking/how-to-hack-facebook-apps.html">Nir Goldshlager reveals how to hack Facebook Apps</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14474/hacking/how-to-hack-facebook-apps.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Group-IB Exclusive details on Kangoo botnet that hit Australian banks</title>
		<link>http://securityaffairs.co/wordpress/14444/cyber-crime/from-group-ib-kangoo-botnet-against-australian-banks.html</link>
		<comments>http://securityaffairs.co/wordpress/14444/cyber-crime/from-group-ib-kangoo-botnet-against-australian-banks.html#comments</comments>
		<pubDate>Fri, 17 May 2013 06:54:46 +0000</pubDate>
		<dc:creator>paganinip</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Citadel]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[digital certificates]]></category>
		<category><![CDATA[Group-IB]]></category>
		<category><![CDATA[Kangoo]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://securityaffairs.co/wordpress/?p=14444</guid>
		<description><![CDATA[<p>Group-IB researchers have detected a new botnet named Kangoo that infected more than 150 000 machines mainly targeting Australian banks. Group-IB researchers have detected a new botnet named Kangoo that infected more than 150 000 machines, specialists dubbed it «Kangoo» due the presence of  a kangaroo logo on the WEB-interface of the C&#38;C administrative panel. The botnet mainly [...]</p><p>The post <a href="http://securityaffairs.co/wordpress/14444/cyber-crime/from-group-ib-kangoo-botnet-against-australian-banks.html">Group-IB Exclusive details on Kangoo botnet that hit Australian banks</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></description>
				<content:encoded><![CDATA[<h2>Group-IB researchers have detected a new <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnet</span> named Kangoo that infected more than 150 000 machines mainly targeting Australian banks.</h2>
<p>Group-IB researchers have detected a new <a title="Botnet organization, easy and cheap!" href="http://securityaffairs.co/wordpress/12655/cyber-crime/botnet-organization-easy-and-cheap.html" target="_blank"><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnet</span></a> named Kangoo that infected more than 150 000 machines, specialists dubbed it «Kangoo» due the presence of  a kangaroo logo on the WEB-interface of the C&amp;C administrative panel. The <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnet</span> mainly targeted Australian banking with an emphasis on online-banking theft, customers of the leading AUS banks, such as Commonwealth Bank, Bank of Queensland, Bendigo and Adelaide Bank and ANZ, were affected.</p>
<p>According to the information provided by Group-IB, ANZ and Bank of Queensland reacted on the fraud alert immediately and the specialists from Group-IB shared with them information extracted from the <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnet</span> with the details of compromised customers, following some data collected by Group-IB Bot-Trek system.</p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Bot-Trek-Group-IB.png"><img class="aligncenter  wp-image-14449" alt="Kangoo botnet Bot Trek Group-IB" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Bot-Trek-Group-IB.png" width="464" height="250" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a></p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Top-5-Infected-cities.png"><img class="aligncenter  wp-image-14445" alt="Kangoo botnet Top 5 Infected cities" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Top-5-Infected-cities.png" width="490" height="336" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a></p>
<p style="text-align: center;"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Statistics-Group-IB.png"><img class="aligncenter  wp-image-14446" alt="Kangoo botnet Statistics Group-IB" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Statistics-Group-IB.png" width="481" height="212" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a></p>
<p><em><b>Who is responsible for the banking theft? Is it the bank&#8217;s fault?</b></em></p>
<p>One of the most important issues currently facing  the bank is the incident response related to banking trojan infections of its customers, the procedure is still quite complicated, many banks prefer to notify the infected customer  and ask for online-banking credential reset.  Unfortunately this practice is absolutely not efficient because the malware is often still present in the victim&#8217;s PC and could capture a new credential a second time and forward to a controlled server.</p>
<p><em> «The bank can suggest to the customer that their PC may be infected, but it is not their prerogative to insist the customer clean any possible malware” – said Dan Clements, Group-IB US Managing Partner.</em></p>
<p><em><b>What to do if your customers were infected?</b></em></p>
<p><em>«We recommend the banks to create an incident response action plan as well as to develop a customer awareness program with practical recommendations, what they need to do if they were notified by the bank that their banking account was compromised and their computer may be infected by the banking malware» &#8211; said Andrey Komarov, the Head of <span class="GINGER_SOFATWARE_correct">international</span> Project, CERT-GIB CTO.</em></p>
<p>Previously, Group-IB has published a recommendation <a title="http://group-ib.ru/images/files/Group-IB_dbo_instruction.pdf" href="http://group-ib.ru/images/files/Group-IB_dbo_instruction.pdf" target="_blank">paper</a> with action plan helping the Russian banks to gather all the most important digital evidences from the compromised PC. Reinstalling of the OS may not help, due the use of so called «bootkits» in modern banking malware which infect the MBR (Master Boot Record), such as <a title="Group-IB: Banking trojan «Carberp» sales were reborn with bootkit module" href="http://securityaffairs.co/wordpress/11113/cyber-crime/group-ib-banking-trojan-carberp-sales-were-reborn-with-bootkit-module.html" target="_blank">Carberp 2</a> and new types of TLD, and affect BIOS. The presence of an antivirus product helps but not represents a complete solution, the majority of new banking trojans can not be detected by AV because the implementation of AV avoidance techniques.</p>
<p>Most common evasion techniques make use of stolen <a title="Bit9 hacked, stolen digital certificates to sign malware" href="http://securityaffairs.co/wordpress/12264/cyber-crime/bit9-hacked-stolen-digital-certificates-to-sign-malware.html" target="_blank">digital certificates</a> from trusted partners, various <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">obfuscators</span>, encryption and new kernel levels of security solutions bypass, and in same rare cases the exploiting of OS vulnerabilities.</p>
<p>Group-IB recommends for the banking fraud and <a title="APWG Global Phishing Survey report revealed new scaring trends" href="http://securityaffairs.co/wordpress/13991/cyber-crime/apwg-global-phishing-survey-report.html" target="_blank">cybercrime</a> analysis departments to proceed with the following steps:</p>
<ol start="1">
<li>To block the compromised customer from online-banking access and to change his credentials. Account block will help to prevent the potential theft during the incident response actions and investigation procedure.</li>
<li>To contact the compromised customer by phone and explain him the reason why his credentials are invalid right now and why they were changed by the bank.  It is important to not use the <span class="GINGER_SOFATWARE_correct">e-mail</span>, because of the <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybercriminals</span> may have the access to it and the banking Trojan can make graphical screenshots from the infected PC to intercept the customer’s actions, which tips off the <span class="GINGER_SOFATWARE_correct">cybercriminals</span> and makes an investigation more difficult.</li>
<li>To use another reserve PC, which is not infected, or to reinstall OS. The infected PC may be provided to the computer forensics laboratory or LEA with the bank’s help for further investigation. Some big banks have own computer forensic laboratories, some use third parties expert companies, which can help to create an image of the infected PC and then to research it in order to create necessary digital evidences for the reporting such as:</li>
</ol>
<ul>
<ul>
<li>Extracted malware sample for further analysis, it’s time of installation on the system, the source of installation;</li>
<li>C&amp;C used to send intercepted data from the infected PC.</li>
</ul>
</ul>
<p>Sometimes, such kinds of reports are widely used by an LEA and courts for successful <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybercriminal</span> prosecution, as today the legislation in cybercrime field is still quite weak, unfortunately, cyber criminals often go unpunished.</p>
<p>In many cases the customer request the support of experts specialized in computer forensics to produce such kind of expertise for the court after online-banking theft, the client requests to recover stolen funds from the bank side but it is a complicated dispute as well. Banks use flexible customer agreements that sometimes clearly declare that the banks have no responsibility for the customer’s safety and security against unauthorized access to his PC, malware and other cyber threat are considered a customer&#8217;s side event and due this reason out of Bank control.</p>
<p>Another possible approach is passive, no response action follows the alert or the incident, the bank can just receive the information about compromised customer and then to monitor it’s activity until suspicious transfer will be created (can be characterized by new transfer destination, suspicious amount and time of the transfer; IP and PC details are useless, as the most part of modern online-banking thefts are going from the same IP of infected customer through remote administration by VNC spawning techniques or patched RDP for multiple remote connections from the hacker’s side). Such approach is very efficient during cybercrime chain investigations, when it is important to get information about all the personalities involved in it such as &#8220;money mules&#8221;, <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botmaster</span> and ISP that is maintaining it, of course the approach takes some efforts from the bank&#8217;s side.</p>
<p><em><b>Are there any «money mules» in Australia? Yes!</b></em></p>
<p>«Money Mule» services have increased during the period 2010-2012,  the following picture shows that the majority of money mules services of AUS work on sharing margin (fifty-fifty).</p>
<p style="text-align: center;"> <a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Money-Mules.png"><img class="aligncenter  wp-image-14453" alt="Kangoo botnet Money Mules" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Money-Mules.png" width="511" height="278" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a></p>
<p> Following the translation:</p>
<p>«Good day. We provide drops in Australia, for 2k and 5k transfers. We make drops by unique methodologies, use only own &#8220;projects&#8221; for it, and don&#8217;t use public solutions. All employees are passing special instruction and control. You will obtain special access to specialized system for controlling them. Work 50/50, costs on cashout are not included. The first contact &#8211; in PM<span class="GINGER_SOFATWARE_correct">.</span>»</p>
<p>Group-IB experts found that <a title="APWG Mobile Financial Fraud report &amp; mobile black market" href="http://securityaffairs.co/wordpress/14158/cyber-crime/apwg-mobile-financial-fraud-report-black-market.html" target="_blank">blackmarket</a> of banking theft for Australian banks is very well developed nowadays and can become one of the key targets for modern <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybercriminals</span> in 2013-2015</p>
<p style="text-align: center;"> <a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Black-Market.png"><img class="aligncenter  wp-image-14455" alt="Kangoo botnet Black Market" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Black-Market.png" width="485" height="225" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a></p>
<p align="center">Рic. 3 –</p>
<p>&nbsp;</p>
<p>Translation:</p>
<p>«Need money mules in AU. Will transfer any amounts. 50% &#8211; my share from the transferred amount. Private message<span class="GINGER_SOFATWARE_correct">.</span>»</p>
<p>One of the reasons Australia is a target is a favorable  time zone for Eastern European cyber criminals to facilitate bank transfers.</p>
<p><em><b>Perspective of customer’s security</b></em></p>
<p>Even though a customer can execute any malicious program, which may compromise their online bank account, the bank is more or less in a partnership with its clients on the financial accounts, sharing some liability. It is in the banks best interest to insure programs and policies that keep the customer happy and retain its loyalty.</p>
<p>“We were really impressed with the time frame of ANZ Bank reaction. A specialized cybercrime analysis representative official responded immediately, and we have provided all the necessary information about the compromised customer credentials with IPs”, said Andrey Komarov of Group-IB.  “It seems the ANZ bank understands the value of getting all of their customers compromised information today, as opposed to moving slowly where more financial losses can affect the bottom line of both the customer and the bank.”</p>
<p>In the specific Kangoo case the investigation suggests that the <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnet</span> owners possibly locate CIS countries (former USSR) and use several WEB-injects methods for hidden automatic hijacking of the transfer’s destination.</p>
<p>WEB-injects is the main weapon of modern cyber criminals, which helps them to make a huge profit without any handy work. The market of WEB-injects nowadays is quite impressive.</p>
<p style="text-align: center;"> <a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Web-Injection1.png"><img class="aligncenter  wp-image-14463" alt="Kangoo botnet Web Injection" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Web-Injection1.png" width="443" height="316" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Web-Injection.png"><br />
</a></p>
<p>In the above picture <a href="http://westpac.com.au/">http://westpac.com.au</a> personal and business online-banking accounts grabber based on <span class="GINGER_SOFATWARE_correct">WEB</span>-inject and virtual keyboard interceptor.</p>
<p>The pricing on it is different and starts from 50$ to 500$, depending on the quality of WEB-inject. Some of it is traded in private communities where the programmer will receive % from all successful thefts. Many of the injects are developed for the well-known banking Trojans such as <a title="Botnets for rent, criminal services sold in the underground market" href="http://securityaffairs.co/wordpress/12339/cyber-crime/botnets-for-rent-criminal-services-sold-in-the-underground-market.html" target="_blank">Citadel</a>, Carberp and <a title="Public offer of Zeus FaaS service on social network" href="http://securityaffairs.co/wordpress/13847/cyber-crime/public-offer-of-zeus-faas-service-on-social-network.html" target="_blank">Zeus</a>, as well as for quite private malware such as Andromeda.</p>
<div id="attachment_14458" class="wp-caption aligncenter" style="width: 522px"><a href="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Web-Injection_2.png.jpg"><img class=" wp-image-14458" alt="Kangoo botnet Web Injection_2.png" src="http://securityaffairs.co/wordpress/wp-content/uploads/2013/05/Kangoo-botnet-Web-Injection_2.png.jpg" width="512" height="202" title="Group IB Exclusive details on Kangoo botnet that hit Australian banks" /></a><p class="wp-caption-text">Commonwealth Bank, Teachers Mutual Bank, DefenceBank, WestPac, Suncorp, BankWest, NAB – <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybercriminals</span> developed WEB-injects for the most famous banks in AUS</p></div>
<p>Group-IB is cooperating with the banks on this issue, as the <span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">cybercriminals</span> are not still arrested, and the investigation is in the progress. The C&amp;C and the personalities involved in the crime were detected and shared with the banks on a confidential basis for collaboration with Australian LEA. All the compromised data and customers IPs for finding <a title="http://resources.infosecinstitute.com/botnets-how-do-they-work-architectures-and-case-studies-part-2/" href="http://resources.infosecinstitute.com/botnets-how-do-they-work-architectures-and-case-studies-part-2/" target="_blank"><span class="GINGER_SOFATWARE_noSuggestion GINGER_SOFATWARE_correct">botnets</span></a> were imported into Group-IB Bot-Trek for further investigation and cyber intelligence sharing.</p>
<p>Pierluigi Paganini</p>
<p><strong>(</strong><a title="http://securityaffairs.co/wordpress/" href="http://securityaffairs.co/wordpress/" target="_blank">Security Affairs</a><strong> – Botnet</strong>)</p>
<p>The post <a href="http://securityaffairs.co/wordpress/14444/cyber-crime/from-group-ib-kangoo-botnet-against-australian-banks.html">Group-IB Exclusive details on Kangoo botnet that hit Australian banks</a> appeared first on <a href="http://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://securityaffairs.co/wordpress/14444/cyber-crime/from-group-ib-kangoo-botnet-against-australian-banks.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 1.208 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2013-05-24 21:45:52 -->
