<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/css" media="screen" href="http://s2.wp.com/wp-content/themes/vip/newyorkobserver/stylesheets/rss.css"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Betabeat &#187; Researchers Uncover U.S. Footprints in Mysterious Cyber Warfare Tools</title>
	<atom:link href="http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://betabeat.com</link>
	<description>Just another WordPress.com site</description>
	<lastBuildDate>Tue, 18 Jun 2013 22:03:24 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='betabeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Betabeat &#187; Researchers Uncover U.S. Footprints in Mysterious Cyber Warfare Tools</title>
		<link>http://betabeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://betabeat.com/osd.xml" title="Betabeat" />
	<atom:link rel='hub' href='http://betabeat.com/?pushpress=hub'/>
		<item>
				
		<title>Researchers Uncover U.S. Footprints in Mysterious Cyber Warfare Tools</title>

		<comments>http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/#comments</comments>
		<pubDate>Mon, 17 Sep 2012 11:50:31 -0400</pubDate>
					<link>http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=62662</guid>
		<description><![CDATA[<p><div id="attachment_62676" class="wp-caption alignleft" style="width: 244px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/flame.png"><img class="size-medium wp-image-62676" title="flame" src="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=234" alt="" width="234" height="300" /></a><p class="wp-caption-text">Attack workflow for Flame controllers (Symantec)</p></div></p>
<p>Kaspersky Lab and Symantec have <a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_flamer_newsforyou.pdf" target="_blank">teamed up</a> to peel apart the United States' cyber warfare efforts. So far, they have uncovered the command and control systems behind the sophisticated malware as well as three previously unknown chunks of malicious code possibly related to alleged American cyber superbugs <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame and Duqu</a>.</p>
<p><a href="http://www.reuters.com/article/2012/09/17/us-usa-security-viruses-idUSBRE88G0QF20120917">Reuters reports</a> that researchers from the security firms discovered how the malware was disseminated--through an outwardly innocent-seeming content management system (CMS) named Newsforyou:<!--more--></p>
<blockquote><p>It was designed to look like a common program for managing content on websites, which was likely done in a bid to disguise its real purpose from hosting providers or investigators so that the operation would not be compromised, Kaspersky said in its report.</p></blockquote>
<blockquote><p>Newsforyou handled four types of malicious software: Flame and programs code-named SP, SPE and IP, according to both firms. Neither firm has obtained samples of the other three pieces of malware.</p></blockquote>
<p>According to <a href="http://www.symantec.com/connect/blogs/have-i-got-newsforyou-analysis-flamer-cc-servers" target="_blank">Symantec</a>, Newsforyou allowed attackers to "upload packages of code, to deliver to compromised computers, and to download packages containing stolen client data." Symantec writes that the mystery chunks of code were "likely unknown variants" on Flame but could have been "totally distinct malware."</p>
<p>More intriguing, researchers uncovered nicknames for a handful of programmers who worked on the malware over the course of the last six years or so:</p>
<blockquote><p>The attackers were not thorough enough, however, as a file revealing the entire history of the server‘s setup was available. In addition, a limited set of encrypted records in the database revealed that compromised computers had been connecting from the Middle East. We were also able to recover the nicknames of four authors—D***, H*****, O******, and R***—who had worked on the code at various stages and on differing aspects of the project, which appear to have been written as far back as 2006.</p></blockquote>
<p>Symantec and Kaspersky have an additional mystery for which they seek the public's help--this mysterious encoded password: 27934e96d90d06818674b98bec7230fa.</p>
<p>Researchers say they have attempted "brute-force" cracks of the hashed code, to no avail. If you're up for a juicy password cracking challenge that may also put you on a government watchlist, <a href="https://twitter.com/threatintel" target="_blank">hit them up on Twitter</a>.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_62676" class="wp-caption alignleft" style="width: 244px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/flame.png"><img class="size-medium wp-image-62676" title="flame" src="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=234" alt="" width="234" height="300" /></a><p class="wp-caption-text">Attack workflow for Flame controllers (Symantec)</p></div></p>
<p>Kaspersky Lab and Symantec have <a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_flamer_newsforyou.pdf" target="_blank">teamed up</a> to peel apart the United States' cyber warfare efforts. So far, they have uncovered the command and control systems behind the sophisticated malware as well as three previously unknown chunks of malicious code possibly related to alleged American cyber superbugs <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame and Duqu</a>.</p>
<p><a href="http://www.reuters.com/article/2012/09/17/us-usa-security-viruses-idUSBRE88G0QF20120917">Reuters reports</a> that researchers from the security firms discovered how the malware was disseminated--through an outwardly innocent-seeming content management system (CMS) named Newsforyou:<!--more--></p>
<blockquote><p>It was designed to look like a common program for managing content on websites, which was likely done in a bid to disguise its real purpose from hosting providers or investigators so that the operation would not be compromised, Kaspersky said in its report.</p></blockquote>
<blockquote><p>Newsforyou handled four types of malicious software: Flame and programs code-named SP, SPE and IP, according to both firms. Neither firm has obtained samples of the other three pieces of malware.</p></blockquote>
<p>According to <a href="http://www.symantec.com/connect/blogs/have-i-got-newsforyou-analysis-flamer-cc-servers" target="_blank">Symantec</a>, Newsforyou allowed attackers to "upload packages of code, to deliver to compromised computers, and to download packages containing stolen client data." Symantec writes that the mystery chunks of code were "likely unknown variants" on Flame but could have been "totally distinct malware."</p>
<p>More intriguing, researchers uncovered nicknames for a handful of programmers who worked on the malware over the course of the last six years or so:</p>
<blockquote><p>The attackers were not thorough enough, however, as a file revealing the entire history of the server‘s setup was available. In addition, a limited set of encrypted records in the database revealed that compromised computers had been connecting from the Middle East. We were also able to recover the nicknames of four authors—D***, H*****, O******, and R***—who had worked on the code at various stages and on differing aspects of the project, which appear to have been written as far back as 2006.</p></blockquote>
<p>Symantec and Kaspersky have an additional mystery for which they seek the public's help--this mysterious encoded password: 27934e96d90d06818674b98bec7230fa.</p>
<p>Researchers say they have attempted "brute-force" cracks of the hashed code, to no avail. If you're up for a juicy password cracking challenge that may also put you on a government watchlist, <a href="https://twitter.com/threatintel" target="_blank">hit them up on Twitter</a>.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=117" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=117" medium="image">
			<media:title type="html">flame</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=234" medium="image">
			<media:title type="html">flame</media:title>
		</media:content>
	</item>
	</channel>
</rss>
