Monthly Archives: January 2015

Source code reveals link between NSA and Regin cyberespionage malware

Posted: January 27, 2015 at 10:52 am

Keylogging malware that may have been used by the NSA shares signficant portions of code with a component of Regin, a sophisticated platform that has been used to spy on businesses, government institutions and private individuals for years.

The keylogger program, likely part of an attack framework used by the U.S. National Security Agency and its intelligence partners, is dubbed QWERTY and was among the files that former NSA contractor Edward Snowden leaked to journalists. It was released by German news magazine Der Spiegel on Jan. 17 along with a larger collection of secret documents about the malware capabilities of the NSA and the other Five Eyes partnersthe intelligence agencies of the U.K., Canada, Australia and New Zealand.

Weve obtained a copy of the malicious files published by Der Spiegel and when we analyzed them, they immediately reminded us of Regin, malware researchers from antivirus firm Kaspersky Lab said Tuesday in a blog post. Looking at the code closely, we conclude that the QWERTY malware is identical in functionality to the Regin 50251 plugin.

Moreover, the Kaspersky researchers found that both QWERTY and the 50251 plug-in depend on a different module of the Regin platform identified as 50225 which handles kernel-mode hooking. This component allows the malware to run in the highest privileged area of the operating systemthe kernel.

This is strong proof that QWERTY can only operate as part of the Regin platform, the Kaspersky researchers said. Considering the extreme complexity of the Regin platform and little chance that it can be duplicated by somebody without having access to its source code, we conclude the QWERTY malware developers and the Regin developers are the same or working together.

Der Spiegel reported that QWERTY is likely a plug-in of a unified malware framework codenamed WARRIORPRIDE that is used by all Five Eye partners. This is based on references in the code to a dependency called WzowskiLib or CNELib.

In a separate leaked document authored by the Communications Security Establishment Canada, the Canadian counterpart of the NSA, WARRIORPRIDE is described as a flexible computer network exploitation (CNE) platform thats an implementation of the WZOWSKI Five Eyes API (application programming interface).

The document also notes that WARRIORPRIDE is known under the code name DAREDEVIL at the UK Government Communications Headquarters (GCHQ) and that the Five Eyes intelligence partners can create and share plug-ins for it.

The newly discovered link between QWERTY and Regin suggests that the cyberespionage malware platform security researchers call Regin is most likely WARRIORPRIDE.

Some experts already suspected this based on other clues. According to Kaspersky Lab, Regin was the malware program that infected the personal computer of Belgian cryptographer Jean-Jacques Quisquater in 2013. That attack was linked to another malware attack against Belgian telecommunications group Belgacom whose customers include the European Commission, the European Parliament and the European Council.

Go here to read the rest:
Source code reveals link between NSA and Regin cyberespionage malware

Posted in NSA | Comments Off on Source code reveals link between NSA and Regin cyberespionage malware

Link between NSA and Regin cyberespionage malware becomes clearer

Posted: at 10:52 am

Security researchers found a strong connection between Regin and a keylogger used by the Five Eyes intelligence alliance

Keylogging malware that may have been used by the NSA shares signficant portions of code with a component of Regin, a sophisticated platform that has been used to spy on businesses, government institutions and private individuals for years.

The keylogger program, likely part of an attack framework used by the U.S. National Security Agency and its intelligence partners, is dubbed QWERTY and was among the files that former NSA contractor Edward Snowden leaked to journalists. It was released by German news magazine Der Spiegel on Jan. 17 along with a larger collection of secret documents about the malware capabilities of the NSA and the other Five Eyes partners -- the intelligence agencies of the U.K., Canada, Australia and New Zealand.

"We've obtained a copy of the malicious files published by Der Spiegel and when we analyzed them, they immediately reminded us of Regin," malware researchers from antivirus firm Kaspersky Lab said Tuesday in a blog post. "Looking at the code closely, we conclude that the 'QWERTY' malware is identical in functionality to the Regin 50251 plugin."

Moreover, the Kaspersky researchers found that both QWERTY and the 50251 plug-in depend on a different module of the Regin platform identified as 50225 which handles kernel-mode hooking. This component allows the malware to run in the highest privileged area of the operating system -- the kernel.

This is strong proof that QWERTY can only operate as part of the Regin platform, the Kaspersky researchers said. "Considering the extreme complexity of the Regin platform and little chance that it can be duplicated by somebody without having access to its source code, we conclude the QWERTY malware developers and the Regin developers are the same or working together."

Der Spiegel reported that QWERTY is likely a plug-in of a unified malware framework codenamed WARRIORPRIDE that is used by all Five Eye partners. This is based on references in the code to a dependency called WzowskiLib or CNELib.

In a separate leaked document authored by the Communications Security Establishment Canada, the Canadian counterpart of the NSA, WARRIORPRIDE is described as a flexible computer network exploitation (CNE) platform that's an implementation of the "WZOWSKI" Five Eyes API (application programming interface).

The document also notes that WARRIORPRIDE is known under the code name DAREDEVIL at the UK Government Communications Headquarters (GCHQ) and that the Five Eyes intelligence partners can create and share plug-ins for it.

The newly discovered link between QWERTY and Regin suggests that the cyberespionage malware platform security researchers call Regin is most likely WARRIORPRIDE.

See the rest here:
Link between NSA and Regin cyberespionage malware becomes clearer

Posted in NSA | Comments Off on Link between NSA and Regin cyberespionage malware becomes clearer

The NSA's infosec tips won't stop you from being hacked

Posted: at 10:52 am

Earlier this month, the NSAs cyber security wing released its best practice guide to defending against destructive malware - presumably with one eye on the beleaguered Sony bosses who continue to deal with the fallout from the companys high profile hack.

The report (PDF) focuses on cost-effective countermeasures that can be easily established in your organisation to make life more difficult for the average attacker.

Starting with controls such as segregation of networks, protection and restriction of the use of administrative privileges, and whitelisting authorised application execution on your systems, the tips aim to circumvent the damage cyber bad guys can do.

But is the NSA's new fact sheet just wishful thinking from the US spy agency? Would any of this information have stopped something like the Sony attack from happening?

I have scoured the content of the document in search of anything new. I didn't find it.

None of this is groundbreaking advice (and none of it should be new to the security team at Sony).

The NSA best practice controls will already be familiar to anyone following our own Australian Signals Directorate (ASD) guidelines on attack mitigation strategies, including its highly regarded Top 4 Strategies to Mitigate Targeted Cyber Intrusions-a mandatory requirement for government departments adhering to the Protective Security Policy Framework (PSPF).

Whitelisting, reduction of administrative privileges and a comprehensive approach to patching feature heavily in the ASDs top four. Its top 35 adds even more defensive measures that can be implemented to protect your organisation.

Nearly all of the mitigations listed in the NSA document - such as the use of Microsofts Enhanced Mitigation Experience Toolkit (EMET) and subscribing to cloud-based reputation services - are also covered in the ASD documentation.

As a result I was rather disappointed with this latest effort from the NSA. Realistically, the only valuable advice in this document is a warning for organisations to prepare for the worst.

Read more here:
The NSA's infosec tips won't stop you from being hacked

Posted in NSA | Comments Off on The NSA's infosec tips won't stop you from being hacked

The First Amendment…(Historically Speaking) – Episode #13 – Video

Posted: at 10:51 am


The First Amendment...(Historically Speaking) - Episode #13
A weekly program on UPTV hosted by Frederick Douglass Dixon.

By: UPTV6

Read the rest here:
The First Amendment...(Historically Speaking) - Episode #13 - Video

Posted in First Amendment | Comments Off on The First Amendment…(Historically Speaking) – Episode #13 – Video

Why Bitcoin is one of the easiest markets to trade | Chris Dunn – Video

Posted: at 10:50 am


Why Bitcoin is one of the easiest markets to trade | Chris Dunn
How to catch the BIGGEST moves in Bitcoin for gains of 16%-32%. Why Bitcoin is FAR easier to trade than stocks, forex, options. My 3 ""underground secrets"" ...

By: Investor Inspiration

Read the original here:
Why Bitcoin is one of the easiest markets to trade | Chris Dunn - Video

Posted in Bitcoin | Comments Off on Why Bitcoin is one of the easiest markets to trade | Chris Dunn – Video

What’s up with bitcoin and the euro – Video

Posted: at 10:50 am


What #39;s up with bitcoin and the euro
join the Syndicate: http://www.tradeempowered.com/syndicate.

By: Jason Stapleton

More here:
What's up with bitcoin and the euro - Video

Posted in Bitcoin | Comments Off on What’s up with bitcoin and the euro – Video

Transmission 23 – Bitcoin Mining, Cloud Mining w/ Knights of the Satoshi – Video

Posted: at 10:50 am


Transmission 23 - Bitcoin Mining, Cloud Mining w/ Knights of the Satoshi
Make sure to thumbs up and subscribe http://worldcryptonetwork.com http://knightsofthesatoshi.com http://libertehosting.com http://transmission.rocks http://soundwallet.net Twitter: https://twitte...

By: World Crypto Network

Read the rest here:
Transmission 23 - Bitcoin Mining, Cloud Mining w/ Knights of the Satoshi - Video

Posted in Bitcoin | Comments Off on Transmission 23 – Bitcoin Mining, Cloud Mining w/ Knights of the Satoshi – Video

Bitcoin Prices Spike After News of First Regulated U.S. Bitcoin Exchange – Video

Posted: at 10:50 am


Bitcoin Prices Spike After News of First Regulated U.S. Bitcoin Exchange
Bitcoin may be getting a boost. Coinbase, a startup that develops a mobile wallet to buy and store the digital currency, announced Monday that it is launching the first licensed Bitcoin exchange...

By: WochitGeneralNews

See the original post:
Bitcoin Prices Spike After News of First Regulated U.S. Bitcoin Exchange - Video

Posted in Bitcoin | Comments Off on Bitcoin Prices Spike After News of First Regulated U.S. Bitcoin Exchange – Video

U.S. Bitcoin Exchange Makes Debut – Video

Posted: at 10:50 am


U.S. Bitcoin Exchange Makes Debut
Bitcoin payments processor Coinbase on Monday opened a regulated exchange in the United States for trading the virtual currency. Launched just days after Coinbase raised $75 million from blue-chip ...

By: WochitBusiness

Read the rest here:
U.S. Bitcoin Exchange Makes Debut - Video

Posted in Bitcoin | Comments Off on U.S. Bitcoin Exchange Makes Debut – Video

Trading on Kraken Bitcoin Exchange with LUXSTACK – Video

Posted: at 10:50 am


Trading on Kraken Bitcoin Exchange with LUXSTACK
Link an exchange to LUXSTACK #39;s mobile app and trade in and out of bitcoin with ease, right from the palm of your hand.

By: LUXSTACK

Go here to read the rest:
Trading on Kraken Bitcoin Exchange with LUXSTACK - Video

Posted in Bitcoin | Comments Off on Trading on Kraken Bitcoin Exchange with LUXSTACK – Video