Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Sunday, 25 August 2013

Middle Eastern 'Molerats' hackers step up attacks


A wave of cyberattacks against Israeli and Middle Eastern targets this summer was the work of a highly active but shadowy hacktivist group that has started using Remote Access Trojans (RATs) previously favored by Chinese cyber-actors, security firm FireEye has warned.

Dubbed "Molerats" by FireEye, the politically-motivated group launched its latest attacks in June and July using the Poison Ivy (PIVY) RAT, analyzed earlier this week in a separate piece of research by the firm that studied its extensive use over many years by Chinese groups.

The campaign was originally believed to have focused on Israeli and Palestinian organizations but now appears to have had a wider target list, including other Arabic countries and the U.S.

Significantly, the latest wave of attacks were almost certainly linked to a wave of cyber-attacks last October and November on Middle Eastern targets using the XtremeRAT backdoor, including one on the Israeli Police, FireEye said.

The Molerats group's signatures included spearphishing attacks using malicious RAR archives, and a command and control infrastructure using and reusing known domains. The targeting also showed a consistent theme.

FireEye's conclusions are twofold; the sudden popularity of Poison Ivy suggests that this particular RAT is now being used beyond China and defenders should be more wary about attribution. Second, the Middle East has another hacktivist group—that might or might not have a connection with the better known "Gaza Hackers Team"—a development that needs to be watched.

"We do not know whether using PIVY is an attempt by those behind the Molerats campaign to frame China-based threat actors for their attacks or simply evidence that they have added another effective, publicly-available RAT to its arsenal," said FireEye's researchers in a blog note. "But this development should raise a warning flag for anyone tempted to automatically attribute all PIVY attacks to threat actors based in China. The ubiquity of off-the-shelf RATs makes determining those responsible an increasing challenge."

The Middle East now has a clutch of little-understood "nuisance" hacking groups, the best known of which is the Syrian Electronic Army (SEA), a group notable for focusing on Western targets such as U.S. media and dissidents opposing the country's Assad regime.

SpeedyPC ProA second group is the Iranian Izz ad-Din al-Qassam Cyber Fighters, blamed for a series of huge DDoS attacks on U.S. banks in the last year. What distinguishes all of these groups from Western anti-establishment organisations such as the apparently extinct Anonymous Group is the level of resources, state backing and staffing they must have to sustain such large campaigns.

Although Molerats appears small by comparison with the other groups, the fact it wields RAT-based tools is significant. Such malware requires manual control, something that is anathema to conventional crime groups interested in profit at the minimum outlay. Its appearance is just another symptom of the gradual spread of cyberwar tactics to every corner of the globe. 

Sunday, 28 July 2013

Hackers use Android 'master key'


 Chinese app Symantec said the exploit has been added to two Chinese health apps A security firm says it has identified the first known malicious use of Android's "master key" vulnerability.

The bug - which was first publicised earlier this month - allows attackers to install code on to phones running Google's mobile operating system and then take control of them.

Symantec said its researchers had found two apps distributed in China that had been infected using the exploit.

Google has already taken moves to tackle the problem.

A fortnight ago it released a patch to manufacturers, but it will not have been sent to all handset owners yet.

Google also scans its own Play marketplace for the exploit, but this will not protect consumers who download software from other stores.

Premium texts
The vulnerability was first reported by security research firm BlueBox on 3 July.

All Android apps contain an encrypted signature that the operating system uses to check the program is legitimate and has not been tampered with.

But BlueBox said it had found a way to make changes to an app's code without affecting the signature.

It warned the technique could be used to install a Trojan to read any data on a device, harvest passwords, record phone calls, take photos and carry out other functions.

According to Symantec, hackers have now exploited the flaw to install malware called Android.Skullkey, which steals data from compromised phones, monitors texts received and written on the handset, and also sends its own SMS messages to premium numbers.

It said the Trojan had been added to two legitimate apps used in China to find and make appointments with a doctor.



Android phones The fragmented nature of the Android market means updates take time before they become available
"We expect attackers to continue to leverage this vulnerability to infect unsuspecting user devices," its report warned.

"Symantec recommends users only download applications from reputable Android application marketplaces."

The firm added that affected users could manually remove the software by going into their settings menu.

One telecoms consultant said the news highlighted the difficulty Google had in distributing changes to Android.

"When Google releases its updates, manufacturers want to check them and then network operators also want to certify the code as well," said Ben Wood, director of research at CCS Insight.

"It's a consequence of having so many different firms making Android devices, with most running their own user interfaces on top.

"By contrast, Apple just pushes its updates directly to consumers."

Saturday, 27 July 2013

Car hackers 'drive' car with laptop

Steering a car with a games console The researchers managed to stop, start and steer a car with an old Nintendo handset Next time you have a passenger in the back seat of your car offering infuriatingly "helpful" advice about your driving skills, count yourself lucky that they aren't doing anything more sinister in their attempts to guide your vehicle.

Two security experts in the US have demonstrated taking control of two popular models of car, while someone else was driving them, using a laptop.

Speaking to one news channel ahead of revealing their research at security conference Defcon in Las Vegas in August, Charlie Miller and Chris Valasek said they hoped to raise awareness about the security issues around increasingly computer-dominated car control.

"At the moment there are people who are in the know, there are nay-sayers who don't believe it's important, and there are others saying it's common knowledge but right now there's not much data out there," said Mr Miller, a security engineer at Twitter.

"We would love for everyone to start having a discussion about this, and for manufacturers to listen and improve the security of cars."

Their work, funded by the Pentagon's research facility Darpa, has so far received a mixed reaction from the manufacturers themselves.

How they did it
The researchers used cables to connect the devices to the vehicles' electronic control units (ECUs) via the on-board diagnostics port (also used by mechanics to identify faults) inside a 2010 model Ford Escape and Toyota Prius.

Contained within most modern vehicles, ECUs are part of the computer network that controls most aspects of car functionality including acceleration, braking, steering, monitor displays and the horn.

The pair were able to write software which sent instructions to the car network computer and over-rode the commands from the actual drivers of the cars.

They filmed themselves in the back of one of the vehicles steering it left and right, activating the brakes and showing the fuel gauge drop to zero, all while the vehicle was under driver control and in motion.



cable used in hack The cable used to connect the devices to the ECUs via the diagnostics port.
A spokesman for Toyota told that because the hardware had to be physically connected inside the car, he did not consider it to be "hacking".

"Altered control can only be made when the device is connected. After it is disconnected the car functions normally," he said.

"We don't consider that to be 'hacking' in the sense of creating unexpected behaviour, because the device must be connected - ie the control system of the car physically altered.

"The presence of a laptop or other device connected to the OBD [on board diagnostics] II port would be apparent."

Expensive and difficult
Mr Miller and Mr Valasek say this is not the point.

Their work builds on earlier research carried out by researchers at the University of Washington and the University of San Diego in 2010, who demonstrated that it was possible to control a car remotely and developed a tool, which they called CarShark, for the purpose.

"We're big fans of their work but we figured they already proved you can remotely get into a car's network," Chris Valasek, director of security intelligence at consultancy IOActive.

"We wanted to see how much control would you have once that's happened."

They admitted that they had destroyed a few cars while refining their technique.

"It's very expensive and difficult to do the research to show you can hack into a car. It's not like you can just download something and look at it," said Mr Miller.

"I wouldn't dare do this to my own car," added Mr Valasek.

They said the cars did not appear to acknowledge the address from where a command was being sent, only the instruction itself.

"There's no authentication," said Mr Miller.

"But there are restrictions - the car has to operate very fast. If you run into a wall you need to kill the engine immediately, engage the airbag.

"Car manufacturers don't have the luxury PC software makers have - if something doesn't work in a car that can't happen, it needs to function."

Mr Miller and Mr Valasek intend to make their research openly available following the conference.



car speedometer The hackers set the speedometer to read 199 miles per hour while the car was stationary
"The information will be released to everyone. If you're just relying on the fact people aren't talking about the problem to stay safe, you're not really dealing with the problem," said Mr Miller.

Toyota said it invested heavily in security research.

"Our focus, and that of the entire automotive industry, is to prevent hacking into a vehicle's by-wire control system from a remote/wireless device outside of the vehicle.

"Toyota has developed very strict and effective firewall technology against such remote and wireless services. We continue to try to hack our systems and have a considerable investment in state of the art electro-magnetic R&D facilities.

"We believe our systems are robust and secure."

Ford also told that the company takes electronic security seriously.

"This particular attack was not performed remotely over-the-air, but as a highly aggressive direct physical manipulation of one vehicle over an elongated period of time, which would not be a risk to customers on any mass level," it said in a statement.

"The safety, privacy, and security of our customers is and always will be paramount."

"Scary"
Security expert Prof Alan Woodward, Chief Technology Officer at consultancy Charteris, said that car hacking hasn't been widely discussed because as yet there has been no criminal incident of it.

"I think [car hacking] is one of the most scary things out there - [the hacking of] cars and medical devices are the two things nobody talks about,"

"You've heard of ransomware - imagine that happening inside a car. It won't take criminals that long."

Damian Lewis in Homeland Actor Damian Lewis stars in Homeland, a TV series which featured a car hack storyline



Ransomware is a computer virus that freezes a victim's computer or threatens to release personal files unless a payment is made.

A car crash caused by a hacked car featured as a storyline on the US TV series Homeland but was widely dismissed as fantasy, he added.

"There was loads of talk afterwards saying it was rubbish. I remember saying on Twitter, 'I'm sorry, it's not.'"

However both the researchers and Prof Woodward agree that hacking into a car is not easy.

"This is a very technical attack, it requires a great deal of technical knowledge," Prof Woodward said.

"A lot of manufacturers are doing work on security software but they don't talk about it. It's not about anti-malware software, it's more about penetration testing - finding any holes left in the system.

"When people build things based on software, it is built with Intention A. They never think about intention B - which could be all sorts of nefarious purposes."

Thursday, 25 July 2013

Once more into the breach: How hackers compromise websites like Apple's

Unless you happen to call the proverbial rock home, you’ve probably heard that Apple’s developer websites were recently hit by a hacking attack. Though the developer site has been inaccessible since last week, the company didn’t announce the intrusion until Sunday; as of this writing, the site remains down. That outage has resulted in considerable inconvenience for app developers, not to mention the poor IT people in Cupertino who have been working around the clock to deal with the breach.

According to the company, the attackers didn’t manage to get their hands on any sensitive information, but the fact remains that security hacks like this one happen with alarming frequency all over the Web, and one cannot help but wonder why websites seem to be so easy to break into.

Computers can be hacked using a variety of techniques, which typically fall into three categories: social engineering, software exploits, and hardware cracks.

Social engineering is the least technological member of this trio, although it’s by no means the least sophisticated. It works by extracting access credentials from an unsuspecting user, or acquiring them from an unscrupulous operator, such as a disgruntled employee. If you’ve been on the Internet for more than a day, you’ve probably been on the receiving end of a “phishing” email, which invites you to log on to a site that looks and feels like, say, your bank’s, but is in reality controlled by hackers who capture your username and password and then use it to help themselves to the money in your account.

These types of attacks, while very common against the general public, are hard to pull off against a website owner—particularly one as large and sophisticated as Apple. For one thing, IT personnel tend to be well acquainted with phishing attempts, and are usually on the lookout for them. In addition, the private nature of the internal systems that are used to manage a company’s network makes them hard to spoof, unlike a banking website, which is open to the public and can be easily replicated.

In practical terms, most successful attacks against websites tend to be software-based, and are often caused by the site’s developers making the wrong set of assumptions. For example, a very common class of attacks called code injections is caused by code that “trusts” data coming from the outside world, and thus doesn’t attempt to filter out any potentially malicious commands embedded in that data. Unchecked, this kind of bug can have catastrophic repercussions, allowing a third party to gain access and even delete information stored in the site’s database—such as username, emails, or passwords.

A more sophisticated vulnerability, known as cross-site request forgery, can be used to force a browser to surreptitiously navigate a target website without human intervention. If the user happens to be logged into a password-protected website, an attacker could perform unauthorized operations, including locking the real user out of his or her own account.

These are but two examples of dozens of possible vulnerabilities that can be caused by weak programming. And even when the website’s code itself is perfect—and we know how often software is perfect—there is still plenty that can go wrong: Regardless of the operating system on which a Web server runs, it typically also makes use of hundreds of different software components that take care of everything from delivering documents to keeping the system’s time. Since many of these programs have a network component, any defect in their code has the potential to become a possible entry point for a would-be hacker.

If this appears to paint a bleak picture of Web security, keep in mind that practically every potential attack can be mitigated—and almost always prevented—by using the right security measures.

In many organizations, for example, Web servers are usually kept behind firewalls—systems that are designed to be connected to the open Internet, and whose software is hardened in such a way as to prevent intrusion while simultaneously letting legitimate traffic through. In addition, larger companies employ sophisticated intrusion-detection software that can “sniff” network traffic and detect illicit activity before it becomes a problem; they also implement policies that that promote the development of secure software, for example by placing significant emphasis on data encryption and good programming practices.

Thus, while the occasional slip-up may still occur, it’s a safe bet that, the more important a Web-based system is, the more sophisticated the level of control over its operations. What happened at Apple appears to have been a lapse in network administration that allowed outdated software on a server to leak information about developers. While serious, this bug is unlikely to affect Apple’s consumer-facing services, like iTunes or iCloud, which are probably under much greater scrutiny from the company.

This is not to say that any website is absolutely secure. An old dictum in the security community is that the only computer that cannot be broken into is one that is unplugged from the Internet and turned off.

Indeed, hardware hacks have been used to pull off some rather remarkable stunts against systems that were thought to be hack-proof because they weren’t connected to any network, such as crippling Iran’s nuclear program with a USB key and even reading a computer screen through a wall by detecting its radio emissions.

Spy stories aside, this goes to show that the potential for intrusion is a byproduct of the very functionality that makes running a website possible. While the risk can never be completely eliminated, the right combination of expertise and care, mixed with a hint of paranoia, can greatly reduce its potential impact—and nowhere is this combination of skills more likely to come into play than in a company’s most important properties.

Site break-ins are serious threats that tend to get lots of publicity, but not all breaches are created equal. The kind of issue that afflicted Apple last week only involved a relatively small and obscure section of its operations, and appears to have left everyone’s really important data, like credit card numbers, uncompromised. If anything, in fact, it’s likely that what happened gave Apple’s IT department a reason to tighten its internal policies, which may well result in better security for its end users in the long term.

Monday, 22 July 2013

Ubuntu forum defaced, breached by hackers

A website dedicated to discussion of the Ubuntu Linux distribution was breached on Saturday, with hackers gaining access to encrypted passwords and email addresses.

The site, Ubuntuforums.org, will remain offline until it can be fixed, wrote Jane Silber, CEO of Canonical, a company that develops and provides services for the free, open-source operating system.

"We have begun the process of notifying by email all users whose details have been compromised," Silber wrote. "We are continuing to investigate exactly how the attackers were able to gain access and are working with the software providers to address that issue."

According to a notice on Ubuntuforums.org, the forum was defaced around 8:11 PM UTC Saturday by hackers before it was taken offline about four minutes later. It is believed the attackers gained access to every person's local user name, encrypted passwords and email addresses from the database.

The encrypted passwords were "salted," an additional security measure that makes them more difficult to revert to their original form. Users are encouraged nonetheless to assume their passwords are now insecure, especially if people use the same password for other web services.

Sunday, 21 July 2013

Hackers breach Nasdaq community forum website

Hackers have breached part of Nasdaq's website, with the stock exchange group warning members of its community forum that email and password details have been compromised.

Nasdaq sent an email to users explaining that it had been made aware of the breach following "standard security monitoring", warning that account information could have been stolen following the breach on Tuesday.
However the firm said that its trading and commerce platforms had not been affected.

Security expert Graham Cluley said on his blog that it is likely that hackers had capitalised on a deficiencies in Nasdaq's security infrastructure.

"My guess is that the servers running the NASDAQ community message board software had not been properly configured or not kept updated against vulnerabilities, and this allowed hackers an open window to access sensitive information," he said.

The website is still unavailable, though an onsite message states that the forum is offline due to upgrades being made.

Cluley added that the stock exchange group should be more clear about the security risk posed, and warned over potential phishing attacks as a result of the breach.

"What also irks me is how NASDAQ is describing the issue on the (currently shut-down) community forum itself.

"Any member of the online NASDAQ community who has missed the email advisory, won't be any the wiser from that message that the site has been hacked, and their usernames, email addresses and passwords have been compromised."

It is not the first time that the stock exchange's security has come under the spotlight following a breach. In 2011 an FBI investigation pointed to Nasdaq's ageing software and out of date security patches as part of the reason for servers being hacked.

Investigators found some PCs and servers with out of date software and uninstalled security patches, including Microsoft Windows Server 2003, while some of its firewalls ahd been incorrectly configured.

Monday, 15 July 2013

Chinese hackers hurt business, Congressional committee told

As senior officials from China and the United States wrap up a series of talks in Washington about an array of economic issues, across town members of Congress probed the extent of Chinese efforts to steal intellectual property from tech companies and other U.S. businesses.

"From defense contractors to manufacturing, no American company has been immune from the scourge of Chinese intellectual property theft," says Rep. Tim Murphy (R-Pennsylvania), the chairman of the House Energy and Commerce Committee's oversight subcommittee.

Among the witnesses on hand was Slade Gorton, a former senator from Washington who serves on the Commission on the Theft of American Intellectual Property, a group that has been studying the economic impact of the problem, with a particular focus on China.

Gorton cited the commission's estimate that cyber espionage and other forms of IP theft from foreign countries account for annual losses of $300 billion for U.S. companies. The group attributes between 50 percent and 80 percent of those losses to China.

The commission produced a series of short-, medium- and long-term solutions, ranging from the restructuring of U.S. government authorities that deal with intellectual property to encouraging reforms within China to strengthen laws against IP theft and their enforcement. That multifaceted approach comes from a recognition that the war against hackers will not be won simply by playing defense.

"It is clear that we need better defensive measures to deal with cyber theft and other forms of intellectual property theft, but I am convinced that that will never solve the problem on its own," Gorton says.

Last week's hearing comes amid ongoing, if halting, efforts in Congress to craft legislation to shore up the nation's defenses against cyber attacks, a policy debate that has focused on the appropriate mechanisms for businesses and government authorities to share information about threats and the extent to which the federal government should be involved in regulating the cybersecurity operations of the private sector.

"We cannot take these problems lightly," says Rep. Jan Schakowsky (D-Illinois). "They cost our economy billions of dollars and place our national security at risk, and as the number of Internet-connected devices and the use of cloud computing increases the number of entry points for malicious actors to exploit will also rise. With more information and more sensitive information now stored on the Web we must sharpen our focus on cybersecurity."

Issues of cybersecurity were expected to arise at this week's U.S.-China trade talks, though the matter is complicated by the string of revelations about U.S. surveillance programs by former government contractor Edward Snowden. Descriptions of the sweeping data collection involved in the National Security Agency's PRISM program could reinforce the contention of Chinese officials that they have been on the receiving end of cyber intrusions.

Witnesses at the recent hearing contended that the Chinese perspective often does not draw a distinction between the espionage that countries—even allies—routinely conduct on one another and hacking into businesses to steal trade secrets.


James Lewis, a senior fellow at the Center for Strategic and International Studies, where he directs the Technology and Public Policy Program, recalled a meeting with Chinese officials when a senior colonel in the People's Liberation Army told him: "'Look, in the U.S. military espionage is heroic, and economic espionage is a crime, but in China the line is not so clear.' So one of the things we can do is make the line a little clearer to them."

Much of the problem can be traced to a weak legal structure in China, Russia, and other countries that are identified with intellectual property theft, Lewis explains.

"They have no tradition of protecting intellectual property," he says. "One of the differences between the U.S. and countries like China and Russia is that we have laws and we enforce them. They either don't have laws and they certainly don't enforce them."

Apart from the legal factors, Lewis' diagnosis of China's stance on intellectual property notes a fear among party leaders that rapid economic growth is crucial to their ability to hold onto power, and the concern that businesses in the state-controlled economy are unable to innovate to achieve that growth.

Lewis says that the defenses of U.S. companies vary widely by sector—he gives high marks to the banking industry while he says many utilities are soft targets—but sums up the security posture of the private sector as "feeble," and has advocated for strong legislation to prod businesses to "harden their networks."

Hackers use Dropbox, WordPress to spread malware

The Chinese cyberspies behind the widely publicized espionage campaign against The New York Times have added Dropbox and WordPress to their bag of spear-phishing tricks.

The gang, known in security circles as the DNSCalc gang, has been using the Dropbox file-sharing service for roughly the last 12 months as a mechanism for spreading malware, said Rich Barger, chief intelligence officer for Cyber Squared. While the tactic is not unique, it remains under the radar of most companies.

"I wouldn't say it's new," Barger said on Thursday. "It's just something that folks aren't really looking at or paying attention to."

The gang is among 20 Chinese groups identified this year by security firm Mandiant that launch cyberattacks against specific targets to steal information. In this case, the DNSCalc gang was going after intelligence on individuals or governments connected to the Association of Southeast Asian Nations. ASEAN is a non-governmental group that represents the economic interests of ten Southeast Asian countries.

The attackers did not exploit any vulnerabilities in Dropbox or WordPress. Instead, they opened up accounts and used the services as their infrastructure.

The gang uploaded on Dropbox a .ZIP file disguised as belonging to the U.S.-ASEAN Business Council. Messages were then sent to people or agencies that would be interested in the draft of a Council policy paper. The paper, contained in the file, was legitimate, Barger said.

When a recipient unzipped the file, they saw another one that read, "2013 US-ASEAN Business Council Statement of Priorities in the US-ASEAN Commercial Relationship Policy Paper.scr." Clicking on the file would launch a PDF of the document, while the malware opened a backdoor to the host computer in the background.

Once the door was open, the malware would reach out to a WordPress blog created by the attackers. The blog contained the IP address and port number of a command and control server that the malware would contact to download additional software.

Dropbox is a desirable launchpad for attacks because employees of many companies use the service. "People trust Dropbox," Barger said.

For companies that have the service on its whitelist, malware moving from Dropbox won't be detected by a company's intrusion prevention systems. Also, communications to a WordPress blog would likely go undetected, since it would not be unusual behavior for any employee with access to the Internet.

In general, no single technology can prevent such an attack. "There's no silver bullet here," Barger said.

The best prevention is for security pros to share information when their companies are targeted, so others can draw up their own defense, he said.

In The New York Times attack, the hackers penetrated the newspaper's systems in September 2012 and worked undercover for four months before they were detected.

The attack coincided with an investigative piece the newspaper published on business dealings that reaped several billion dollars for the relatives of Wen Jiabao, China's prime minister.

Saturday, 13 July 2013

Nations Buying as Hackers Sell Computer Flaws

The hackers, Luigi Auriemma, 32, and Donato Ferrante, 28, sell technical details of such vulnerabilities to countries that want to break into the computer systems of foreign adversaries. The two will not reveal the clients of their company, ReVuln, but big buyers of services like theirs include the National Security Agency — which seeks the flaws for America’s growing arsenal of cyberweapons — and American adversaries like the Revolutionary Guards of Iran.

All over the world, from South Africa to South Korea, business is booming in what hackers call “zero days,” the coding flaws in software like Microsoft Windows that can give a buyer unfettered access to a computer and any business, agency or individual dependent on one.

Just a few years ago, hackers like Mr. Auriemma and Mr. Ferrante would have sold the knowledge of coding flaws to companies like Microsoft and Apple, which would fix them. Last month, Microsoft sharply increased the amount it was willing to pay for such flaws, raising its top offer to $150,000.

But increasingly the businesses are being outbid by countries with the goal of exploiting the flaws in pursuit of the kind of success, albeit temporary, that the United States and Israel achieved three summers ago when they attacked Iran’s nuclear enrichment program with a computer worm that became known as “Stuxnet.”

The flaws get their name from the fact that once discovered, “zero days” exist for the user of the computer system to fix them before hackers can take advantage of the vulnerability. A “zero-day exploit” occurs when hackers or governments strike by using the flaw before anyone else knows it exists, like a burglar who finds, after months of probing, that there is a previously undiscovered way to break into a house without sounding an alarm.

“Governments are starting to say, ‘In order to best protect my country, I need to find vulnerabilities in other countries,’ ” said Howard Schmidt, a former White House cybersecurity coordinator. “The problem is that we all fundamentally become less secure.”

A zero-day bug could be as simple as a hacker’s discovering an online account that asks for a password but does not actually require typing one to get in. Bypassing the system by hitting the “Enter” key becomes a zero-day exploit. The average attack persists for almost a year — 312 days — before it is detected, according to Symantec, the maker of antivirus software. Until then it can be exploited or “weaponized” by both criminals and governments to spy on, steal from or attack their target.

Ten years ago, hackers would hand knowledge of such flaws to Microsoft and Google free, in exchange for a T-shirt or perhaps for an honorable mention on a company’s Web site. Even today, so-called patriotic hackers in China regularly hand over the information to the government.

Now, the market for information about computer vulnerabilities has turned into a gold rush. Disclosures by Edward J. Snowden, the former N.S.A. consultant who leaked classified documents, made it clear that the United States is among the buyers of programming flaws. But it is hardly alone.

Israel, Britain, Russia, India and Brazil are some of the biggest spenders. North Korea is in the market, as are some Middle Eastern intelligence services. Countries in the Asian Pacific, including Malaysia and Singapore, are buying, too, according to the Center for Strategic and International Studies in Washington.

To connect sellers and buyers, dozens of well-connected brokers now market information on the flaws in exchange for a 15 percent cut. Some hackers get a deal collecting royalty fees for every month their flaw is not discovered, according to several people involved in the market.

Some individual brokers, like one in Bangkok who goes by “the Grugq” on Twitter, are well known. But after the Grugq spoke to Forbes last year, his business took a hit from the publicity, according to a person familiar with the impact, primarily because buyers demand confidentiality.

A broker’s approach need not be subtle. “Need code execution exploit urgent,” read the subject line of an e-mail sent from one contractor’s intermediary last year to Billy Rios, a former security engineer at Microsoft and Google who is now a director at Cylance, a security start-up.

“Dear Friend,” the e-mail began. “Do you have any code execution exploit for Windows 7, Mac, for applications like Browser, Office, Adobe, SWF any.”

“If yes,” the e-mail continued, “payment is not an issue.”

Friday, 28 June 2013

Opera says hackers pilfered expired code-signing certificate

Opera Software said Wednesday hackers pilfered from its internal systems at least one code-signing certificate that was used to sign malicious software.

 

The Oslo-based company, which makes a mobile and desktop web browser, wrote in a blog post that it believes a few thousand Windows users may have automatically installed malicious software between 01.00 and 01.36 UTC on June 19, the day the attack was detected and halted.

 

Code-signing certificates are used to cryptographically verify that a piece of software comes from its purported publisher. By using the certificate, it would have appeared to users that the malware was legitimate software from Opera, such as the company's browser.

 

In its post, Opera included a link to VirusTotal, a website that tests malware samples against security programs to see if the malware is detected. The VirusTotal page shows the SHA256 hash of what is presumably the malware that used the expired code-signing certificate.

 

At the time of writing, just over half of the 47 security programs listed on VirusTotal that tested the sample detected it. The figure will likely rise as vendors tweak their programs to detect it.

 

Sigbjørn Vik, an Opera developer and quality assurance engineer, wrote that the certificate was expired, but did not reveal further details. The company said it has since cleaned its systems and that it does not believe user data was lost.

 

"We are working with the relevant authorities to investigate its source and any potential further extent," Vik wrote.

 

Opera is planning to release a new version of its browser with a new code-signing certificate, but did not say when it will be available.

 

Follow me on Twitter @sajilpl

Wednesday, 26 June 2013

Suspected China-based hackers 'Comment Crew' rise again

The suspected China-based hackers known as the "Comment Crew" are back at it again, a development likely to contribute to continued tensions between the U.S. and China over cyberattacks.

 

The security community has had the group under its watch for a number of years, but in February, its activity was exhaustively detailed in a report from computer security vendor Mandiant.

 

Mandiant's report said a specific Chinese military unit called "61398" waged a seven-year hacking spree that compromised 141 organizations. The report added to other long-running research from security companies and organizations into suspected state-sponsored hacking.

 

The Comment Crew laid low for a while following the report but is back hacking again, said Alex Lanstein, senior researcher for FireEye.

 

"They took a little breather, and they started back up," Lanstein said.

 

Following the intense attention in February, the group stopped using much of its command-and-control infrastructure. Instead, they started from scratch, directing malware at new targets.

 

"We didn't see them take control of any of the systems they had previously compromised," Lanstein said. "They started fresh with a whole new round of attacks."

 

The group, while skilled, has made mistakes, many of which were picked up by Mandiant. Continuing analysis of the Comment Crew's methods have also revealed another mistake the group made, which conceivably makes it easier to link together attacks to a single source.

 

Lanstein said FireEye found the Comment Crew made an error when compiling their malicious software programs. When an application, including malware, is written in a programming language, it must be compiled, or translated into machine-readable code.

 

In many instances, the Comment Crew forgot to remove the name of their particular coding project, called "Moonclient," evident when a program was decompiled, or reverted back to its original programming language.

 

Lanstein said the error showed that "you are dealing with humans on the other side of the keyboard," who are prone to make mistakes. "This is a mistake made over and over again," he said.

 

FireEye decided to release information on the error since so much had already been released on the Comment Crew, and it would make little difference now for computer security researchers tracking them since their tactics have changed.

 

"It's more difficult to track them now," Lanstein said.

 

FireEye is due to release a report on Wednesday covering how researchers can track malware campaigns by looking for hacking mistakes, including keyboard layouts, embedded fonts and overuse of bogus DNS (domain name system) registration details.