Showing posts with label using. Show all posts
Showing posts with label using. Show all posts

Thursday, September 26, 2013

Chinese 'Icefog' gang attacks Asian countries using 'hit and run' APTs

Kaspersky Lab has identified another Chinese APT campaign. Dubbed ‘Icefog’, the largely Japanese, Taiwanese and South Korean targets included a well-publicised attack on Japan’s House of Representatives in 2011.

Kaspersky Lab and others have released a steady stream of research on what is starting to look like a thriving mostly Chinese industry selling hacking expertise and espionage to governments.

In recent weeks, Symantec published a paper on a major hacking-for-hire group it called ‘Hidden Lynx’ responsible for a large number of attacks while Kaspersky itself has uncovered evidence that North Korea was trying its hand at the same chicanery with its ‘Kimsuky’ Trojan.

Related Articles on Techworld

Judging from Kaspersky’s latest research, Icefog looks like a smaller player than Hidden Lynx or the notorious Comment Crew/APT1 convincingly blamed for a hugely successful raid on defence contractor QinetiQ.

At first Icefog doesn’t look particularly innovative, pivoting on the same collection of tried and trusted spear-phishing and software exploit via email attacks techniques as every other APT campaign yet discovered.  The aim is to gather address books, user credentials, and documents, including those created by Office and the South Korean Hangul word processor.

One interesting variation is a ‘Macfog’ beta variant targeting 64-bit OS X users. Seeded through Chinese bulletin boards to several hundred victims and masquerading as a graphics application, Kaspersky speculates that this might be a test run for a more featured version designed to attack the platform in a future version.

The campaign’s defining characteristic is probably its command and control network, which uses a ‘hit and run’ model to set up an attack before disappearing in a month or two. This is an unusual tactic. Commercial criminals invest a lot of time and effort trying to protect their C&C; Icefog deliberately builds and dismantles it once the attack is over, a technique of obscuring its activities from security researchers.

This also makes it very hard to estimate the extent of Icefog’s activity, Kaspersky said. Dating back to 2011 at least, it had a slower year in 2012 before an uptick in 2013, but this could just be another consequence of its temporary C&C design.

“For the past few years, we’ve seen a number of APTs hitting pretty much all kinds of victims and sectors. In most cases, attackers maintain a foothold in corporate and governmental networks for years, exfiltrating terabytes of sensitive information”, said Kaspersky Lab’s director of global research, Costin Raiu.

“The 'hit and run' nature of the Icefog attacks demonstrate a new emerging trend: smaller hit-and-run gangs that are going after information with surgical precision. The attack usually lasts for a few days or weeks and after obtaining what they were looking for, the attackers clean up and leave,” he said.

“In the future, we predict the number of small, focused ‘APT-to-hire’ groups to grow, specialising in hit-and-run operations; sort of ‘cyber mercenaries’ of the modern world.”

Sectors targeted included the military, shipbuilding, maritime, computing, research, telcos, satellite firms and the media.  A range of Japanese and South Korean firms had been on the list including Lig Nex1, Selectron Industrial Company, Hanjin Heavy Industries, Korea Telecom, Fuji TV, and the the Japan-China Economic Association.

After sinkholing 14 of 70 detected C&C domains, the firm had discovered that 4,000 IP addresses had been infected, including 200 Windows PCs and 350 Macs. This was only a fraction of the true number of victims, Kaspersky said.

The motivation of the Icefog group was almost certainly commercial rather than ideological.

“In the future, we predict the number of small, focused APT-to-hire groups to grow, specializing in hit-and-run operations, a kind of 'cyber mercenaries' of the modern world,” Kaspersky’s report concludes.

Stanford researchers develop first computer using only carbon nanotube transistors

Researchers at Stanford University have demonstrated the first functional computer built using only carbon nanotube transistors, according to an article published Wednesday on the cover of scientific journal Nature.

Scientists have been experimenting with transistors based on carbon nanotubes or CNTs as successors to silicon transistors, as silicon is expected to meet its physical limits in delivering the increasingly smaller transistors required for higher performance in smaller and cheaper computing devices that are less power-consuming. Digital circuits based on the long chains of carbon atoms are expected to be more energy-efficient than silicon transistors.

The rudimentary CNT computer, developed by the researchers at Stanford, is said to run a simple operating system that is capable of multitasking, according to a synopsis of the article.

Made of 178 transistors, each containing between 10 and 200 carbon nanotubes, the computer can do four tasks summarized as instruction fetch, data fetch, arithmetic operation and write-back, and run two different programs concurrently.

As a demonstration, the researchers performed counting and integer-sorting simultaneously, according to the synopsis, besides implementing 20 different instructions from the MIPS instruction set "to demonstrate the generality of our CNT computer," according to the article by Max Shulaker and other doctoral students in electrical engineering. The research was led by Stanford professors Subhasish Mitra and H.S. Philip Wong.

"People have been talking about a new era of carbon nanotube electronics moving beyond silicon," said Mitra, an electrical engineer and computer scientist in a press release issued by Stanford University. "But there have been few demonstrations of complete digital systems using this exciting technology. Here is the proof."

Carbon nanotubes still have imperfections. They do not, for example, always grow in parallel lines, which has led researchers to devise techniques to grow 99.5 percent of CNTs in straight lines, according to the press release. But at billions of nanotubes on a chip, even a small misalignment of the tubes can cause errors. A fraction of the CNTs also behave like metallic wires that always conduct electricity, instead of acting like semiconductors that can be switched off.

The researchers describe a two-pronged approach called an "imperfection-immune design". They passed electricity through the circuits, after switching off the good CNTs, to burn up the metallic nanotubes, and also developed an algorithm to work around the misaligned nanotubes in a circuit.

The basic computer was limited to 178 transistors, which was the result of the researchers using the university's chip-making facilities rather than an industrial fabrication process, according to the press release.

Other researchers are also working on CNTs as they worry about silicon hitting its physical limits. IBM said last October its scientists had developed a way to place over 10,000 transistors made from the nano-sized tubes of carbon on a single chip, up from a few hundred carbon nanotube devices at a time previously possible. This density was, however, far below the density of commercial silicon-based chips, but the company said the breakthrough opened up the path for commercial fabrication of "dramatically smaller, faster and more powerful computer chips."

Tuesday, September 24, 2013

Ransomare criminals attack SMEs using strong file encryption, ESET warns

‘Filecoder’ ransomware that uses strong encryption to lock files and extort money from victims has spiked over the summer months, security firm ESET has reported. The reasons for the surge are not yet clear but probably include attacks on small businesses.

Using its LiveGrid cloud system, the firm recorded a 200 percent rise in the volume of incidents since July compared to the first six months of 2013, with a marked rising trend running from roughly mid-June to the most recent measurement in the first week of September.

ESET was unable to confirm the absolute numbers for these infections but it is clear that a particularly nasty type of ransomware has become more prevalent. What might be going on?

Related Articles on Techworld

The overwhelming majority of today’s ransomware – popularly called ‘police Trojans’ after the official-looking warning screens they use – simply locks files or interferes with the victim’s PC in the hope that the ransom will be paid to avoid further hassle. The techniques are unpleasant usually relatively trivial to block and clean up.

File encryption ransomware is a completely different order of threat because it wields industry-standard forms of encryption to scramble data. As long as it’s been competently implemented, the victim can’t recover the files unless they have the key used to encrypt them and that is only known to the criminals behind the attack.

Curiously, file encryption Trojans are where the whole software extortion or ransomware industry started in 2005 with a Russian example called Gpcode based on RSA encryption. This approach has persisted at low levels ever since but has never gained much popularity.

The assumption has always been that while it's basically impossible to defeat encryption, ransom malware is simply overkill. Much easier simply to trick users into paying up using threats or social engineering than deploy more complicated and sometimes computationally slower methods.

Among the clutch of Trojan variants doing the round in the latest campaigns, ESET has noticed Win32/Filecoder.Q which goes back to 2010, and Win32/Filecoder.AA and Win32/Filecoder.W, which date from 2011. Another, Win32/Filecoder.BQ, even ramps up the pressure on its victims by “displaying a countdown timer showing how long it will be before the encryption key is permanently deleted.”

Some appear to be spread using the popular Poison Ivy Remote Access Trojan (RAT), which offers a clue that the targets might be small businesses whose systems are being targeted by criminals. Payment methods include the established channels of MoneyPak or Ukash but also now Bitcoins.

Criminals were also installing the crypto Trojans directly using compromised RDP credentials, ESET said. Some instances it had researched pointed to the manual setting of an encryption key after infection, a further hint that these are not attacks on low-value targets.

The sums being demanded ranged up to 3,000 euros ($4,000), with most of the victims in Russia with smaller volumes in Italy, Spain, the US, Germany, and other Eastern European countries. It’s not clear how much of this global picture can be explained by ESET’s customer base (the firm is based in Slovakia).

The security firm offers no clear  explanation for the sudden increase in crypto ransomware but one can infer from the inherent complexity of the attacks that suspicion should fall on criminals targeting vulnerable business rated as likely to pay up.

There has been a slowly increasing frequency of targeted attacks using encryption going back a couple of years, with a particularly good example the sustained campaign on Australian businesses in 2012. Victims reported paying up to $3,000 AUD to retrieve the key for encrypted database files they could not function without.

It is likely that many businesses have simply not been reporting incidents for fear of the reputational damage. Some will have paid up. But as with every extortion racket, the criminals don’t let up because a victim pays up. There is always another target to hunt down.

Ransomware criminals attack SMEs using strong file encryption, ESET warns

‘Filecoder’ ransomware that uses strong encryption to lock files and extort money from victims has spiked over the summer months, security firm ESET has reported. The reasons for the surge are not yet clear but probably include attacks on small businesses.

Using its LiveGrid cloud system, the firm recorded a 200 percent rise in the volume of incidents since July compared to the first six months of 2013, with a marked rising trend running from roughly mid-June to the most recent measurement in the first week of September.

ESET was unable to confirm the absolute numbers for these infections but it is clear that a particularly nasty type of ransomware has become more prevalent. What might be going on?

Related Articles on Techworld

The overwhelming majority of today’s ransomware – popularly called ‘police Trojans’ after the official-looking warning screens they use – simply locks files or interferes with the victim’s PC in the hope that the ransom will be paid to avoid further hassle. The techniques are unpleasant usually relatively trivial to block and clean up.

File encryption ransomware is a completely different order of threat because it wields industry-standard forms of encryption to scramble data. As long as it’s been competently implemented, the victim can’t recover the files unless they have the key used to encrypt them and that is only known to the criminals behind the attack.

Curiously, file encryption Trojans are where the whole software extortion or ransomware industry started in 2005 with a Russian example called Gpcode based on RSA encryption. This approach has persisted at low levels ever since but has never gained much popularity.

The assumption has always been that while it's basically impossible to defeat encryption, ransom malware is simply overkill. Much easier simply to trick users into paying up using threats or social engineering than deploy more complicated and sometimes computationally slower methods.

Among the clutch of Trojan variants doing the round in the latest campaigns, ESET has noticed Win32/Filecoder.Q which goes back to 2010, and Win32/Filecoder.AA and Win32/Filecoder.W, which date from 2011. Another, Win32/Filecoder.BQ, even ramps up the pressure on its victims by “displaying a countdown timer showing how long it will be before the encryption key is permanently deleted.”

Some appear to be spread using the popular Poison Ivy Remote Access Trojan (RAT), which offers a clue that the targets might be small businesses whose systems are being targeted by criminals. Payment methods include the established channels of MoneyPak or Ukash but also now Bitcoins.

Criminals were also installing the crypto Trojans directly using compromised RDP credentials, ESET said. Some instances it had researched pointed to the manual setting of an encryption key after infection, a further hint that these are not attacks on low-value targets.

The sums being demanded ranged up to 3,000 euros ($4,000), with most of the victims in Russia with smaller volumes in Italy, Spain, the US, Germany, and other Eastern European countries. It’s not clear how much of this global picture can be explained by ESET’s customer base (the firm is based in Slovakia).

The security firm offers no clear  explanation for the sudden increase in crypto ransomware but one can infer from the inherent complexity of the attacks that suspicion should fall on criminals targeting vulnerable business rated as likely to pay up.

There has been a slowly increasing frequency of targeted attacks using encryption going back a couple of years, with a particularly good example the sustained campaign on Australian businesses in 2012. Victims reported paying up to $3,000 AUD to retrieve the key for encrypted database files they could not function without.

It is likely that many businesses have simply not been reporting incidents for fear of the reputational damage. Some will have paid up. But as with every extortion racket, the criminals don’t let up because a victim pays up. There is always another target to hunt down.