{"id":238749,"date":"2017-08-25T01:31:18","date_gmt":"2017-08-25T05:31:18","guid":{"rendered":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/major-leak-suggests-nsa-was-deep-in-middle-east-wired-3.php"},"modified":"2017-08-25T01:31:18","modified_gmt":"2017-08-25T05:31:18","slug":"major-leak-suggests-nsa-was-deep-in-middle-east-wired-3","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/nsa-2\/major-leak-suggests-nsa-was-deep-in-middle-east-wired-3.php","title":{"rendered":"Major Leak Suggests NSA Was Deep in Middle East &#8230; &#8211; WIRED"},"content":{"rendered":"<p><p>    A woman walks past a branch of Noor Islamic Bank along Khalid    Bin Al-Waleed Road in Dubai.  <\/p>\n<p>    Reuters  <\/p>\n<p>        For eight months,     the hacker    group known as Shadow Brokers has trickled out an intermittent    drip of highly classified NSA data. Now, just when it seemed    like that trove of secrets might be exhausted, the group has    spilled a new batch. The latest dump appears to show that the    NSA has penetrated deep into the finance infrastructure of the    Middle Easta revelation that could create new scandals for the    worlds most well-resourced spy agency.  <\/p>\n<p>    Friday morning, the Shadow Brokers    published documents thatif legitimateshow just how thoroughly    US intelligence has compromised elements of the global banking    system. The new leak includes evidence that the NSA hacked into    EastNets, a Dubai-based firm that oversees payments in the    global SWIFT transaction system for dozens of client banks and    other firms, particularly in the Middle East. The leak includes    detailed lists of hacked or potentially targeted computers,    including those belonging to firms in Qatar, Dubai, Abu Dhabi,    Syria, Yemen, and the Palestinian territories. Also included in    the data dump, as in previous Shadow Brokers releases, are a    load of fresh hacking tools, this time targeting a slew of    Windows versions.  <\/p>\n<p>    \"Oh you thought that was it?\" the    hacker group wrote in a typically grammar-challenged statement    accompanying their leak. There was speculation prior to this    morning's release that the group had finally published its full    set of stolen documents, after a seemingly failed attempt to    auction them for bitcoins. \"Too bad nobody deciding to be    paying theshadowbrokers for just to shutup and going away.\"       <\/p>\n<p>    The transaction protocol SWIFT has been    increasingly targeted by hackers seeking to redirect millions    of dollars from banks around the world, with recent efforts in    India, Ecuador, and Bangladesh. Security researchers have even    pointed to     clues that a $81 million Bangladesh    bank theft via SWIFT may have been the work of the North Korean    government .    But the Shadow Brokers' latest leak offers new evidence that    the NSA has also compromised SWIFT, albeit most likely for    silent espionage rather than wholesale larceny.       <\/p>\n<p>            Andy Greenberg          <\/p>\n<p>            The Shadow Brokers Mess Is What Happens When the NSA            Hoards Zero-Days          <\/p>\n<p>            Lily Hay Newman          <\/p>\n<p>            WikiLeaks Just Dumped a Mega-Trove of CIA Hacking            Secrets          <\/p>\n<p>            Andy Greenberg          <\/p>\n<p>            How the CIA Can Hack Your Phone, PC, and TV (Says            WikiLeaks)          <\/p>\n<p>    EastNets has denied that it was hacked,        writing on its Twitter account        that there's \"no credibility to the online claim of a    compromise of EastNets customer information on its SWIFT    service bureau.\" But the Shadow Brokers' leak seems to suggest    otherwise: One spreadsheet in the release, for instance, lists    computers by IP address, along with corresponding firms in the    finance industry and beyond, including the Qatar First    Investment Bank, Arab Petroleum Investments Corporation    Bahrain, Dubai Gold and Commodities Exchange, Tadhamon    International Islamic Bank, Noor Islamic Bank, Kuwait Petroleum    Company, Qatar Telecom and others. A \"legend\" at the top of the    spreadsheet notes that the 16 highlighted IP addresses mean,    \"box has been implanted and we are collecting.\" That NSA jargon    translates to a computer being successfully infected with its    spyware.    1  <\/p>\n<p>    Those IP addresses don't actually    correspond to the client's computers, says Dubai-based security    researcher Matt Suiche, but rather to computers servicing those    clients at EastNets, which is one of 120 \"service bureaus\" that    form a portion of the SWIFT network and make transactions on    behalf of customers. \"This is the equivalent of hacking all the    banks in the region without having to hack them individually,\"    says Suiche, founder of UAE-based incident response and    forensics startup Comae Technologies. \"You have access to all    their transactions.\"  <\/p>\n<p>    While the Shadow Brokers' releases have    already included NSA exploits, today's leak is the first    indication of targets of that sophisticated hacking in the    global banking system. Unlike previous known hacks of the SWIFT    financial network, nothing in the leaked documents suggests    that the NSA used its access to EastNets' SWIFT systems to    actual alter transactions or steal funds. Instead, stealthily    tracking the transactions within that network may have given    the agency visibility into money flows in the regionincluding    to potential terrorist, extremist, or insurgent groups.      <\/p>\n<p>    If that sort of finance-focused    espionage was in fact the NSA's goal, it would hardly deviate    from the agency's core mission. But Suiche points out that    confirmation of the operation would nonetheless lead to    blowback for the NSA and the US governmentparticularly given    that many of the listed targets are in US-friendly countries    like Dubai and Qatar. \"A big shitstorm is to come,\" says    Suiche. \"You can expect the leadership of key organizations    like banks and governments are going to be quite irritated, and    theyre going to react.\"  <\/p>\n<p>    Beyond EastNets alone, Suiche points to    references in the files to targeting the Panama-based firm    Business Computer Group or BCG, although it's not clear if the    firm was actually compromised. Beyond its Twitter statement,    EastNets didn't respond to WIRED's request for comment. WIRED    also reached out to BCG and the NSA, but didn't get a response.      <\/p>\n<p>    SWIFT aside, the leak also contains a    cornucopia of NSA hacking tools or \"exploits,\" including what    appear to be previously secret techniques for hacking PCs and    servers running Windows. Matthew Hickey, the founder of the    security firm Hacker House, analyzed the collection and    believes there are more than 20 distinct exploits in the leak,    about 15 of which are included in an automated hacking    \"framework\" tool called FuzzBunch.  <\/p>\n<p>        This is as big as it gets.              <\/p>\n<p>      Matthew Hickey, Hacker House           <\/p>\n<p>    The attacks seem to target every recent    version of Windows other than Windows 10, and several allow a    remote hacker to gain the full ability to run their own code on    a target machine. \"There are exploits here that are quite    likely zero days that will let you hack into any number of    servers on the internet,\" says Hickey. \"This is as big as it    gets. Its internet God mode.\"  <\/p>\n<p>    In a statement to WIRED, however, a    Microsoft spokesperson wrote that the company had previously    patched all the vulnerabilities in Windows that the hacking    tools exploited. \"We've investigated and confirmed that the    exploits disclosed by the Shadow Brokers have already been    addressed by previous updates to our supported products,\" the    statement reads. In a blog post, the company clarified that    several of the exploits do still work, but only on versions of    Windows prior to Windows 7.        2  <\/p>\n<p>    But the Shadow Brokers hinted in their    release that they're not done creating trouble for the NSA yet.    \"Maybe if all suviving [sic] WWIII theshadowbrokers be seeing    you next week,\" the group's message concludes. \"Who knows what    we having next time?\"   <\/p>\n<p>    1         Updated 4\/14\/2017 12:15 EST to include    comments from EastNets.  <\/p>\n<p>    2         Updated 4\/15\/2017 3:50 EST to include a    response from Microsoft.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Continued here:<\/p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.wired.com\/2017\/04\/major-leak-suggests-nsa-deep-middle-east-banking-system\/\" title=\"Major Leak Suggests NSA Was Deep in Middle East ... - WIRED\">Major Leak Suggests NSA Was Deep in Middle East ... - WIRED<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A woman walks past a branch of Noor Islamic Bank along Khalid Bin Al-Waleed Road in Dubai. Reuters For eight months, the hacker group known as Shadow Brokers has trickled out an intermittent drip of highly classified NSA data <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/nsa-2\/major-leak-suggests-nsa-was-deep-in-middle-east-wired-3.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[261463],"tags":[],"class_list":["post-238749","post","type-post","status-publish","format-standard","hentry","category-nsa-2"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/238749"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=238749"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/238749\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=238749"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=238749"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=238749"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}