Showing posts with label CYBINT. Show all posts
Showing posts with label CYBINT. Show all posts

Tuesday, November 24, 2009

Espionage by malware

During this month remember having breakfast with a piece of news for many media seem to be new or exclusively connected with some Hollywood films, giving it a connotation of "amazing." I refer to espionage through computerized means.

Then leave a screenshot of the news, in which it's evident that the malicious code are also part of the operations of intelligence in different contexts, both from a viewpoint clearly fraudulent (in the case of computer criminals) as which shields under the "flag" to protect and safeguard the interests of a State (for many intelligence services), which seek to take advantage and/or neutralize the potential actions framed within the context of hostility.

Indeed, in many cases, touching the legality of actions.

According to the information that appears in the article, the most important intelligence service of Israel (Mossad) has used a type of malicious code trojan to obtain confidential information and critiques on nuclear facilities in Syria.

The fact that Mossad used a program to spy isn't a novelty because, like its American counterpart (CIA) and many other formerly used Promis as a resource for spying.

(Someday maybe encourage me to write something about the programs used by intelligence services around the world ;P)

The point is that regardless of the impact of the news, malicious code are without doubt one of the most used for obtaining information, including at government and military, even among companies seeking to obtain confidential data that enable disclose their activities and win competition advantages.

Now, any organization or government entity may be a victim of espionage, and these activities must also be addressed by Information Security. So what can be done to counteract or neutralize these activities, which in most cases are handled on the edge of illegality, the truth isn't easy. However, implementing a strategy of misinformation can be a good practice of counterintelligence.

Ultimately it's easy to deduce that such maneuvers aren't only stock listed as "ghosts" or within the genre "science fiction" films themselves, but every day we are potential victims of the persistent attempts of malware writers seeking to break our security frameworks to obtain secret information.

Related information
Computer Intelligence, Information Security and Cyber-War
CYBINT in the business of Russian cyber-crooks

Jorge Mieres
Pistus Malware Intelligence

Monday, September 28, 2009

CYBINT in the business of Russian cybercriminals

Those who follow this blog sporadically have noticed that most of this year I spent most of the post to bring out many of the applications from a black market flooded Russia where all types of crimeware is available to professional cyber-criminals (botmasters , spammers, phishers, "¿cyber-terrorists?", etc.) but without neglecting the candidates seeking to become high-ranking offenders.

In this sense, time allows us to witness how they allowed this illegal industry fueled heavily by Eastern European countries (particularly Russia), China and some Latin American countries led by Brazil. However, the flow and focus attention in Russia, and as I said at some point, I reminded the world that Gibson describes in Neuromancer, where the illegal marketing of malware is developed in the dark streets of the suburb.

Perhaps, like I did at some point, many will wonder, whatever type of crimeware that could be opened or motivations (the main one has an acronym: USD) of cyber-criminals, who are behind this?

If we consider that the sale of programs is done around a dark business that is part of an industry that operates from the underground (RBN - Russian Business Network), which are cells that lead to well organized fraud conducted via the Internet (eg Russian scammers) corporate espionage (hiring pirates), among other things, it's easy to see that everything has a mafia connotation. And if we go deeper into the origin of the Russian mafia, easily conclude that was conceived by former KGB agents (Intelligence of the former Soviet Union).

In fact, it's estimated that this criminal network with former agents of what became the KGB and now in more than one occasion, has worked in conjunction with the FSB (Federal Security Service of the Russian Federation), the successor to the KGB.

What I mean by this? Although perhaps what I write may seem extreme, we find ourselves in times in which we witness the virtual conflicts involving certain countries. Such computer attacks that we see in Hollywood movies, a little exaggerated, in recent years have made fiction to enter the real world scene, and in this sense, CYBINT (Cyber Intelligence) plays a fundamental role.

For example, more and more cases of defacement that although is not new, made news when it affects the availability of government web sites that form the heart of cyber-warfare on duty . The DDoS (Distributed Denial of Service), carried out through botnets, such as that suffered the site of President of Georgia during the conflict with Russia, the Russians actually loaded a couple more (Estonia and Lithuania), are clear examples of actions that seek to complement the operations at the military level.

What is striking about cases like those mentioned in the preceding paragraph, left in full evidence there is advance planning, in coordination, it is not nothing but an intelligence plan. In the case of defacement, it may seem trivial, we could say that within the conflict, is part of psychological operations that seek to weaken the morale of the opposing side.

However, other less trivial aspects are also part of the intelligence plans, and generally are operated through technological resources, eg attacking the availability of telephone networks (COMINT), interruption of satellite signals and attacking other networks (SIGINT), including the public nature, affecting the confidentiality of people using malware.

Under all this scenery, the RBN, one of the organizations biggest cyber-criminals operating under the infrastructure of the Internet, is the basis on which to commit, from Russia (though there is a strong rumor about the RBN are migrating their operations to China), many malicious actions channeled into pedophilia, pornography, commercialization of crimeware, malware, phishing, botnets and more.

This really shows that aspect involving the cyber-crime are controlled and operated by a mob in which Russian cybercriminals up one of the most important pieces for the development of crimeware industry globally, and as we see ... Anything goes and everything merges into everything ...

Related information
Inteligencia informática, Seguridad de la Información y Ciber-Guerra
Los precios del crimeware ruso. Parte 2

Jorge Mieres

Sunday, September 20, 2009

Computer Intelligence, Information Security and Cyber-Warfare

Undoubtedly, we are increasingly dependent on technology and computer networks, not only at home but also at much higher levels as are business and government where the need to obtain and preserve information become relevant actions.

Under this scenario, create new challenges and new strategies to address these challenges at the same time, make the rules of a game where technological resources, information and intelligence processes are the key pieces to ensure business continuity (in trade) and the operation of government projects/military at any level.

First, because business environments are pouring money into new and better technologies to ensure the survival of their business and keep your information reaches the hands of competitors, jealously guarded by security schemes that seek to curb the actions of hired computer is often hired to perform espionage.

On the other hand, states also invest in technologies through its intelligence services (government and military) giving rise to new ways of getting information in a timely manner under the use of technical resources and different sources of information and intense competition channeling constantly trying to advance on their enemies to steal information that would betray the plans (geopolitical, military and economic) of other nations.

This inevitably means that, from a particular point of view, who we are devoted to information security we should funnel some of the efforts to add state of the art methodologies in certain activities that formerly were awarded only to the intelligence.

In this regard, government initiatives to protect their technological perimeters receive special attention from various States who are involved in a war that is happening in a scene that many may consider again, but nevertheless it isn't: the virtual and whose strategies the "battle" was conducted behind closed doors by using something as common as today's Internet.

These matches aren't based on mass murder as in a conventional war, but are based on computer and technological aspects. Consequently, those who develop better technologies and better implement it, enjoy the ability to obtain higher and better level of information. This form of struggle and large-scale unconventional called Cyber-Warfare.

What are we talking about? It's the use of computerized systems for carrying out a war over the Internet. From this perspective, it becomes necessary to resort to Computer Intelligence (CYBINT - Cyber Intelligence).

From a broad perspective, the Cyber-Warfare is no different to what specialists make Information Security in trying to devise defensive strategies, and offensive, to the safeguarding and protection of information, whether at government or private .

Can we say then that those who dedicate ourselves to this we are soldiers in a war that develops virtual world? I would say it indirectly. We are part of a virtual war that feeds on other smaller and private.

From the very existence of intelligence, information became the spoils of war and at the same time, the food with which daily feed regardless of the methods and mechanisms used for their production. So it's obviously the reason for designing mechanisms to obtain in a timely manner.

Gestate strategies and tactics to virtual combat and conflict scenarios carefully planned by intelligence analysts and other characters from the secret that is entertaining environment from a desktop designing action plans to enable implant rumors, shares of diversion and propaganda campaigns to cover up questions "good" (in the broad sense of the word) without attracting the attention of others, even through malware.

It's then that one of the most important parts of the Cyber-Warfare is Information Warfare, but through information technology and where the soldiers are people with extensive computer skills that are risking their lives the battlefield, their weapons are computers and their ammunition are the bits.

The intelligence services know this very well and were always involved in computations maneuvers designed to "learn more from others" (individuals, governments, companies ...), resorting to espionage through actions that involve technological resources as COMINT (Communications Intelligence) and other not so much as HUMINT (Human Intelligence) but directly related to Information Security, among other activities of military intelligence.

All these issues we directly applied the relevant conflicts that were generated in recent years with cases such as USA and Israel, Russia and Estonia, among others where hacktivism, computer vandalism, campaigns propagandists and psychological action strategies flood Internet for the sole fact weaken the opponent.

The first question that might be created in the mind is why use technology in this way? Well ... Sun Tzu I make it quite excellent when still no one spoke of it: "The enemy that operates in isolation, lacking a strategy and taking their opponents lightly will inevitably end up being defeated."

Jorge Mieres