<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/css" media="screen" href="http://s2.wp.com/wp-content/themes/vip/newyorkobserver/stylesheets/rss.css"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Betabeat &#187; cyber warfare</title>
	<atom:link href="http://betabeat.com/tag/cyber-warfare/feed/" rel="self" type="application/rss+xml" />
	<link>http://betabeat.com</link>
	<description>Just another WordPress.com site</description>
	<lastBuildDate>Thu, 23 May 2013 21:03:21 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='betabeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Betabeat &#187; cyber warfare</title>
		<link>http://betabeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://betabeat.com/osd.xml" title="Betabeat" />
	<atom:link rel='hub' href='http://betabeat.com/?pushpress=hub'/>
		<item>
				
		<title>Meet MiniFlame, The Ninja Assassin of Cyber Warfare Tools</title>

		<comments>http://betabeat.com/2012/10/meet-miniflame-the-ninja-assassin-of-cyber-warfare-tools/#comments</comments>
		<pubDate>Mon, 15 Oct 2012 18:18:02 -0400</pubDate>
					<link>http://betabeat.com/2012/10/meet-miniflame-the-ninja-assassin-of-cyber-warfare-tools/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=66453</guid>
		<description><![CDATA[<p><div id="attachment_66486" class="wp-caption aligncenter" style="width: 610px"><a href="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png"><img class="size-full wp-image-66486" title="kasperskyminiflamedistrib" alt="" src="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png" height="352" width="600" /></a><p class="wp-caption-text">Countries where MiniFlame and Flame have been found. (Kaspersky Lab)</p></div></p>
<p>Researchers at Kaspersky Lab have been patiently picking apart the ingenious malware packages that romped through computer networks in the Middle East, sucking up data and destroying Iranian nuclear centrifuges and it seems Kaspersky finds a new addition to the allegedly U.S. and Israeli-sponsored family of cyber-weapons every other month. Monday they <a href="http://www.securelist.com/en/analysis/204792247/miniFlame_aka_SPE_Elvis_and_his_friends#5" target="_blank">announced</a> the discovery of the <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame</a> malware's baby cousin, <a href="http://www.wired.com/threatlevel/2012/10/miniflame-espionage-tool/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Top+Stories%29">MiniFlame</a>.</p>
<p>Kaspersky's bug hunters <a href="http://www.securelist.com/en/analysis/204792247/miniFlame_aka_SPE_Elvis_and_his_friends#5" target="_blank">found that MiniFlame's association with Flame and related infections</a> was Transformers-like in nature:<!--more--></p>
<blockquote><p>In early July 2012, we discovered a smaller Flame module, which appeared to be able to work by itself. The module had many similarities with Flame, so we thought it might simply be an earlier version. In the months that followed, we not only studied the connection of this malware with Flame, but also came across examples of this module being used concurrently with Gauss and being controlled by the Gauss main module.</p></blockquote>
<p>Researchers found that MiniFlame was something of a ninja assassin compared to the other programs. Whereas Flame, Duqu and Gauss had large missions to infiltrate multiple computers in countries like Iran, Syria and Lebanon, MiniFlame targeted just a few select victims in what Kaspersky calls "highly targeted attacks." Kaspersky reported that MiniFlame, while rare compared to the more well-known malware packages, was more likely to show up in a variety of countries, including a computer located at the Francois Rabelais University in Tours, France.</p>
<p><em>Wired</em> also <a href="http://www.wired.com/threatlevel/2012/10/miniflame-espionage-tool/all/" target="_blank">noted</a> that Kaspersky determined that one machine in Lebanon is the lucky recipient of every nasty cyber weapon in the family:</p>
<blockquote><p>[There] is one machine in Lebanon – what [senior Kaspersky researcher Roel] Schouwenberg calls "the mother of all infections" – which has Flame, Gauss, and miniFlame/SPE on it. "It is like everybody wanted to infect that specific victim in Lebanon for some reason," he says.</p></blockquote>
<p>Kaspersky knows there are two more malware packages still in the wild, currently code-named only SP and IP. They may function much like the previously known malicious programs, churning through the guts of target computers for sensitive data to send home to their controllers before they execute the final trick in their arsenal, deleting themselves and vanishing from the infected system as if they'd never been there at all, like ghosts. Or ninjas.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_66486" class="wp-caption aligncenter" style="width: 610px"><a href="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png"><img class="size-full wp-image-66486" title="kasperskyminiflamedistrib" alt="" src="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png" height="352" width="600" /></a><p class="wp-caption-text">Countries where MiniFlame and Flame have been found. (Kaspersky Lab)</p></div></p>
<p>Researchers at Kaspersky Lab have been patiently picking apart the ingenious malware packages that romped through computer networks in the Middle East, sucking up data and destroying Iranian nuclear centrifuges and it seems Kaspersky finds a new addition to the allegedly U.S. and Israeli-sponsored family of cyber-weapons every other month. Monday they <a href="http://www.securelist.com/en/analysis/204792247/miniFlame_aka_SPE_Elvis_and_his_friends#5" target="_blank">announced</a> the discovery of the <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame</a> malware's baby cousin, <a href="http://www.wired.com/threatlevel/2012/10/miniflame-espionage-tool/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Top+Stories%29">MiniFlame</a>.</p>
<p>Kaspersky's bug hunters <a href="http://www.securelist.com/en/analysis/204792247/miniFlame_aka_SPE_Elvis_and_his_friends#5" target="_blank">found that MiniFlame's association with Flame and related infections</a> was Transformers-like in nature:<!--more--></p>
<blockquote><p>In early July 2012, we discovered a smaller Flame module, which appeared to be able to work by itself. The module had many similarities with Flame, so we thought it might simply be an earlier version. In the months that followed, we not only studied the connection of this malware with Flame, but also came across examples of this module being used concurrently with Gauss and being controlled by the Gauss main module.</p></blockquote>
<p>Researchers found that MiniFlame was something of a ninja assassin compared to the other programs. Whereas Flame, Duqu and Gauss had large missions to infiltrate multiple computers in countries like Iran, Syria and Lebanon, MiniFlame targeted just a few select victims in what Kaspersky calls "highly targeted attacks." Kaspersky reported that MiniFlame, while rare compared to the more well-known malware packages, was more likely to show up in a variety of countries, including a computer located at the Francois Rabelais University in Tours, France.</p>
<p><em>Wired</em> also <a href="http://www.wired.com/threatlevel/2012/10/miniflame-espionage-tool/all/" target="_blank">noted</a> that Kaspersky determined that one machine in Lebanon is the lucky recipient of every nasty cyber weapon in the family:</p>
<blockquote><p>[There] is one machine in Lebanon – what [senior Kaspersky researcher Roel] Schouwenberg calls "the mother of all infections" – which has Flame, Gauss, and miniFlame/SPE on it. "It is like everybody wanted to infect that specific victim in Lebanon for some reason," he says.</p></blockquote>
<p>Kaspersky knows there are two more malware packages still in the wild, currently code-named only SP and IP. They may function much like the previously known malicious programs, churning through the guts of target computers for sensitive data to send home to their controllers before they execute the final trick in their arsenal, deleting themselves and vanishing from the infected system as if they'd never been there at all, like ghosts. Or ninjas.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/10/meet-miniflame-the-ninja-assassin-of-cyber-warfare-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png?w=150" medium="image">
			<media:title type="html">kasperskyminiflamedistrib</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/10/kasperskyminiflamedistrib.png" medium="image">
			<media:title type="html">kasperskyminiflamedistrib</media:title>
		</media:content>
	</item>
		<item>
				
		<title>The Pakistan Cyber Army May Be Coming For Your Small Business Website</title>

		<comments>http://betabeat.com/2012/09/the-pakistan-cyber-army-may-be-coming-for-your-small-business-website/#comments</comments>
		<pubDate>Mon, 24 Sep 2012 12:42:20 -0400</pubDate>
					<link>http://betabeat.com/2012/09/the-pakistan-cyber-army-may-be-coming-for-your-small-business-website/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=63658</guid>
		<description><![CDATA[<p><div id="attachment_63669" class="wp-caption alignleft" style="width: 241px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png"><img class="size-medium wp-image-63669" title="pakcyberarmy" src="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png?w=231" alt="" width="231" height="300" /></a><p class="wp-caption-text">Screengrab from a site defaced by Sizzling Soul.</p></div></p>
<p>Protests against anti-Muslim "film" <em>Innocence of Muslims</em> have been violent and continue in several countries, but they have not yet exploded into sustained military conflict. However, religiously motivated hackers are waging active war online. While DDoS (Directed Denial of Service) hits against large, well-known sites owned by financial instutions <a href="http://betabeat.com/2012/09/iran-possibly-behind-operation-ababil-cyber-attacks-against-financial-institutions/" target="_blank">may have been sponsored by Iran</a>, independent Muslim hackers appear to be targeting a slew of small websites with wickedly effective full-blown hacks and defacements.</p>
<p>A hacker calling himself Sizzling Soul and claiming membership in a hacker collective dubbed the Pakistan Cyber Army has <a href="http://www.hackread.com/more-80-websites-hacked-by-sizzling-soul-against-anti-islamic-movie/">taken down more than 80 sites in the name of the Prophet</a>. Many of of those sites remain under his control and are displaying his message:<!--more--></p>
<blockquote><p>100 %<br />
Attempting Bypass…<br />
Code broken!<br />
A message for Boobish People:<br />
Dont Try To Insult Our PROPHET (P.B.U.H)<br />
Why You People Always Try To Attack Our Religion?<br />
You Made An Insulting Movie Of PROPHET(P.B.U.H)”<br />
Damn<br />
This Is Totally Insane,.<br />
You Are Provoking The Anger Of PeaceFull Muslims!<br />
Stop This<br />
Otherwise You WOn’t Be Able To Stop Us<br />
This Is Just A Warning For You….<br />
If You Don’t Stop,Next Attack Will Destroy Yours Whole Cyber Space<br />
If You Want Some Then Come And Get Some…</p></blockquote>
<p>As <a href="http://www.hackread.com/more-80-websites-hacked-by-sizzling-soul-against-anti-islamic-movie/" target="_blank">HackRead notes</a>, most of Sizzling Soul's victims are "small and local businesses, such as banks, chemical factories" as well as pages related to gaming and the auto industry.</p>
<p>Sizzling Soul has listed his <a href="http://pastebin.com/k3Zy62nZ" target="_blank">hits on Pastebin</a>. We could joke about the hacker choosing easy targets, but going after so many small establishments could add up to a minor but noticeable hit on multiple local economies.</p>
<p>Sizzling Soul isn't the only cyber attacker working this angle. A hacker with the handle Rude_Thunder has slammed over 100 sites and <a href="http://pastebin.com/fwRHgDvZ" target="_blank">posted his own list on Pastebin</a>, stating the web pages were "defaced for insulting the holy Prophet."</p>
<p>Since Google will not completely remove <em>Innocence of Muslims </em>from the web, we suspect you should just change your passwords now and hang on for more bumpy rides to come, Boobish People.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_63669" class="wp-caption alignleft" style="width: 241px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png"><img class="size-medium wp-image-63669" title="pakcyberarmy" src="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png?w=231" alt="" width="231" height="300" /></a><p class="wp-caption-text">Screengrab from a site defaced by Sizzling Soul.</p></div></p>
<p>Protests against anti-Muslim "film" <em>Innocence of Muslims</em> have been violent and continue in several countries, but they have not yet exploded into sustained military conflict. However, religiously motivated hackers are waging active war online. While DDoS (Directed Denial of Service) hits against large, well-known sites owned by financial instutions <a href="http://betabeat.com/2012/09/iran-possibly-behind-operation-ababil-cyber-attacks-against-financial-institutions/" target="_blank">may have been sponsored by Iran</a>, independent Muslim hackers appear to be targeting a slew of small websites with wickedly effective full-blown hacks and defacements.</p>
<p>A hacker calling himself Sizzling Soul and claiming membership in a hacker collective dubbed the Pakistan Cyber Army has <a href="http://www.hackread.com/more-80-websites-hacked-by-sizzling-soul-against-anti-islamic-movie/">taken down more than 80 sites in the name of the Prophet</a>. Many of of those sites remain under his control and are displaying his message:<!--more--></p>
<blockquote><p>100 %<br />
Attempting Bypass…<br />
Code broken!<br />
A message for Boobish People:<br />
Dont Try To Insult Our PROPHET (P.B.U.H)<br />
Why You People Always Try To Attack Our Religion?<br />
You Made An Insulting Movie Of PROPHET(P.B.U.H)”<br />
Damn<br />
This Is Totally Insane,.<br />
You Are Provoking The Anger Of PeaceFull Muslims!<br />
Stop This<br />
Otherwise You WOn’t Be Able To Stop Us<br />
This Is Just A Warning For You….<br />
If You Don’t Stop,Next Attack Will Destroy Yours Whole Cyber Space<br />
If You Want Some Then Come And Get Some…</p></blockquote>
<p>As <a href="http://www.hackread.com/more-80-websites-hacked-by-sizzling-soul-against-anti-islamic-movie/" target="_blank">HackRead notes</a>, most of Sizzling Soul's victims are "small and local businesses, such as banks, chemical factories" as well as pages related to gaming and the auto industry.</p>
<p>Sizzling Soul has listed his <a href="http://pastebin.com/k3Zy62nZ" target="_blank">hits on Pastebin</a>. We could joke about the hacker choosing easy targets, but going after so many small establishments could add up to a minor but noticeable hit on multiple local economies.</p>
<p>Sizzling Soul isn't the only cyber attacker working this angle. A hacker with the handle Rude_Thunder has slammed over 100 sites and <a href="http://pastebin.com/fwRHgDvZ" target="_blank">posted his own list on Pastebin</a>, stating the web pages were "defaced for insulting the holy Prophet."</p>
<p>Since Google will not completely remove <em>Innocence of Muslims </em>from the web, we suspect you should just change your passwords now and hang on for more bumpy rides to come, Boobish People.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/the-pakistan-cyber-army-may-be-coming-for-your-small-business-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png?w=115" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png?w=115" medium="image">
			<media:title type="html">pakcyberarmy</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/pakcyberarmy.png?w=231" medium="image">
			<media:title type="html">pakcyberarmy</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Iran Possibly Behind &#8216;Operation Ababil&#8217; Cyber Attacks Against Financial Institutions</title>

		<comments>http://betabeat.com/2012/09/iran-possibly-behind-operation-ababil-cyber-attacks-against-financial-institutions/#comments</comments>
		<pubDate>Sat, 22 Sep 2012 19:06:50 -0400</pubDate>
					<link>http://betabeat.com/2012/09/iran-possibly-behind-operation-ababil-cyber-attacks-against-financial-institutions/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=63565</guid>
		<description><![CDATA[<p><div id="attachment_63567" class="wp-caption alignleft" style="width: 310px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg"><img class="size-medium wp-image-63567" title="stuxnet" src="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg?w=300" alt="" width="300" height="262" /></a><p class="wp-caption-text">Stuxnet, the first shot across the bow. (<a href="http://krebsonsecurity.com/tag/stuxnet/">Krebs On Security</a>)</p></div></p>
<p><a href="http://betabeat.com/2012/09/muslim-cyber-fighters-attack-chase-bank-in-operation-ababil/" target="_blank">Cyber attackers</a> who went after Chase and Bank of America with Directed Denial of Service (DDoS) attacks on the banks' websites may have been working for Iran.</p>
<p>A report from the <em>Washington Post</em> cites several officials who have made this claim, including Senator Joseph Lieberman, the chair of the Homeland Security and Governmental Affairs Committee.</p>
<p><a href="http://www.washingtonpost.com/world/national-security/iran-blamed-for-cyberattacks/2012/09/21/afbe2be4-0412-11e2-9b24-ff730c7f6312_print.html">The <em>Post</em> reports</a> that in an interview with C-SPAN, Sen. Lieberman disputed the idea the attackers were independent hacktivists outraged by a controversial anti-Muslim film:<!--more--></p>
<blockquote><p>"I don’t believe these were just hackers who were skilled enough to cause disruption of the Web sites," said Lieberman in an interview taped for C-SPAN's "Newsmakers" program. "I think this was done by Iran and the Quds Force, which has its own developing cyberattack capability." The Quds Force is a special unit of Iran's Revolutionary Guard Corps, a branch of the military.</p></blockquote>
<blockquote><p>Lieberman said he believed the efforts were in response to "the increasingly strong economic sanctions that the United States and our European allies have put on Iranian financial institutions."</p></blockquote>
<p>The <em>Post</em> also reported that there have been similar attacks against American telecoms such as AT&amp;T and Level 3.</p>
<p>What wasn't clear from Sen. Lieberman's remarks or the <em>Post</em>'s report was whether the "<a href="http://pastebin.com/u/QassamCyberFighters" target="_blank">Cyber fighters of Izz ad-din Al qassam</a>," who claimed credit for the attacks and dubbed them "Operation Ababil" were opportunistic trolls or misdirection by Iranian cyber forces.</p>
<p>If officials and cyber-security experts quoted by the <em>Post</em> are correct, it is likely Iran intended the bank attacks as a response to U.S. actions such as the infiltration of the <a href="http://krebsonsecurity.com/tag/stuxnet/" target="_blank">Stuxnet worm</a>, which disrupted Iranian nuclear operations in 2010. Stuxnet targeted uranium enrichment centrifuges and caused them to spin wildly out of control.</p>
<p>The most <a href="http://pastebin.com/ncarq2UK" target="_blank">recent Pastebin post</a> from the Cyber fighters of Izz ad-din Al qassam claimed the attack on Chase's web properties was step two. They seemed to imply there were several more steps to go.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_63567" class="wp-caption alignleft" style="width: 310px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg"><img class="size-medium wp-image-63567" title="stuxnet" src="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg?w=300" alt="" width="300" height="262" /></a><p class="wp-caption-text">Stuxnet, the first shot across the bow. (<a href="http://krebsonsecurity.com/tag/stuxnet/">Krebs On Security</a>)</p></div></p>
<p><a href="http://betabeat.com/2012/09/muslim-cyber-fighters-attack-chase-bank-in-operation-ababil/" target="_blank">Cyber attackers</a> who went after Chase and Bank of America with Directed Denial of Service (DDoS) attacks on the banks' websites may have been working for Iran.</p>
<p>A report from the <em>Washington Post</em> cites several officials who have made this claim, including Senator Joseph Lieberman, the chair of the Homeland Security and Governmental Affairs Committee.</p>
<p><a href="http://www.washingtonpost.com/world/national-security/iran-blamed-for-cyberattacks/2012/09/21/afbe2be4-0412-11e2-9b24-ff730c7f6312_print.html">The <em>Post</em> reports</a> that in an interview with C-SPAN, Sen. Lieberman disputed the idea the attackers were independent hacktivists outraged by a controversial anti-Muslim film:<!--more--></p>
<blockquote><p>"I don’t believe these were just hackers who were skilled enough to cause disruption of the Web sites," said Lieberman in an interview taped for C-SPAN's "Newsmakers" program. "I think this was done by Iran and the Quds Force, which has its own developing cyberattack capability." The Quds Force is a special unit of Iran's Revolutionary Guard Corps, a branch of the military.</p></blockquote>
<blockquote><p>Lieberman said he believed the efforts were in response to "the increasingly strong economic sanctions that the United States and our European allies have put on Iranian financial institutions."</p></blockquote>
<p>The <em>Post</em> also reported that there have been similar attacks against American telecoms such as AT&amp;T and Level 3.</p>
<p>What wasn't clear from Sen. Lieberman's remarks or the <em>Post</em>'s report was whether the "<a href="http://pastebin.com/u/QassamCyberFighters" target="_blank">Cyber fighters of Izz ad-din Al qassam</a>," who claimed credit for the attacks and dubbed them "Operation Ababil" were opportunistic trolls or misdirection by Iranian cyber forces.</p>
<p>If officials and cyber-security experts quoted by the <em>Post</em> are correct, it is likely Iran intended the bank attacks as a response to U.S. actions such as the infiltration of the <a href="http://krebsonsecurity.com/tag/stuxnet/" target="_blank">Stuxnet worm</a>, which disrupted Iranian nuclear operations in 2010. Stuxnet targeted uranium enrichment centrifuges and caused them to spin wildly out of control.</p>
<p>The most <a href="http://pastebin.com/ncarq2UK" target="_blank">recent Pastebin post</a> from the Cyber fighters of Izz ad-din Al qassam claimed the attack on Chase's web properties was step two. They seemed to imply there were several more steps to go.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/iran-possibly-behind-operation-ababil-cyber-attacks-against-financial-institutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg?w=150" medium="image">
			<media:title type="html">stuxnet</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/stuxnet.jpg?w=300" medium="image">
			<media:title type="html">stuxnet</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Muslim Cyber Fighters Attack Chase Bank in &#8216;Operation Ababil&#8217;</title>

		<comments>http://betabeat.com/2012/09/muslim-cyber-fighters-attack-chase-bank-in-operation-ababil/#comments</comments>
		<pubDate>Wed, 19 Sep 2012 18:05:24 -0400</pubDate>
					<link>http://betabeat.com/2012/09/muslim-cyber-fighters-attack-chase-bank-in-operation-ababil/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=63104</guid>
		<description><![CDATA[<p><div id="attachment_63121" class="wp-caption alignleft" style="width: 190px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg"><img class="size-full wp-image-63121" title="EzeldinQassam" src="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg" alt="" width="180" height="240" /></a><p class="wp-caption-text">Izz ad-Din al-Qassam (Wikimedia)</p></div></p>
<p>The <a href="http://betabeat.com/2012/09/cyber-fighters-of-izz-ad-din-al-qassam-claim-they-are-behind-online-attacks-against-bank-of-america-and-the-new-york-stock-exchange/" target="_blank">Cyber fighters of Izz ad-din Al qassam</a>, a group of cyber-attackers who have targeted Bank of America and the New York Stock Exchange, allegedly struck J.P. Morgan Chase today. <a href="http://www.foxbusiness.com/industries/2012/09/19/chase-website-experiences-intermittent-troubles/?cmpid=cmty_twitter_fb" target="_blank">Fox Business reported</a> on the site outage at Chase.com and consulted with Flashpoint Partners about the problems. Flashpoint told Fox that Chase's problems were probably due to a "sustained denial of service attack."</p>
<p>The religiously-motivated hackers, who claim they are responding to the anti-Muslim video, <a href="http://betabeat.com/2012/09/google-refuses-white-house-plea-to-remove-controversial-anti-muslim-video/" target="_blank"><em>Innocence of Muslims</em></a>, have published a <a href="http://pastebin.com/izrLhERu">new Pastebin page claiming credit for the Chase attack</a>:<!--more--></p>
<blockquote><p>In the name of Allah the companionate the merciful</p>
<p>My soul is devoted to you Dear Prophet of Allah</p>
<p>"Operation Ababil" started over BoA :</p>
<p>http://pastebin.com/mCHia4W5<br />
http://pastebin.com/wMma9zyG</p>
<p>In the second step we attacked the largest bank of the united states, the "chase" bank. These series of attacks will continue untill the Erasing of that nasty movie from the Internet.</p>
<p>The site "www.chase.com" is down and also Online banking at "chaseonline.chase.com" is being decided to be Offline !</p>
<p>Down with modern infidels.</p>
<p>### Cyber fighters of Izz ad-din Al qassam ###</p></blockquote>
<p>"Operation Ababil" was also the name of a failed Pakistani military operation that occurred in April, 1984.</p>
<p>Pakistan planned the maneuver (sometimes spelled "Operation Ababeel") as an effort to capture a glacier in the long-disputed region of Kashmir. India learned of the plan and managed to seize the area two days before Pakistan pulled the trigger on the mission.</p>
<p>Are the Cyber fighters of Izz ad-din Al qassam hinting that they might be based in Pakistan? Not necessarily--the name of the operation could be a red herring.</p>
<p>The group's moniker may mean more than whatever they call their efforts against financial institutions; Izz ad-din Al qassam, <a href="http://en.wikipedia.org/wiki/Izz_ad-Din_al-Qassam" target="_blank">according to Wikipedia</a>, was the name of a Syrian-born "Muslim preacher who was a leader in the fight against British, French, and Zionist organizations in the Levant in the 1920s and 1930s."</p>
<p><em>Innocence of Muslims </em>has been blocked in Pakistan and several other heavily Muslim countries but Google has refused to completely remove the film from the web.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_63121" class="wp-caption alignleft" style="width: 190px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg"><img class="size-full wp-image-63121" title="EzeldinQassam" src="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg" alt="" width="180" height="240" /></a><p class="wp-caption-text">Izz ad-Din al-Qassam (Wikimedia)</p></div></p>
<p>The <a href="http://betabeat.com/2012/09/cyber-fighters-of-izz-ad-din-al-qassam-claim-they-are-behind-online-attacks-against-bank-of-america-and-the-new-york-stock-exchange/" target="_blank">Cyber fighters of Izz ad-din Al qassam</a>, a group of cyber-attackers who have targeted Bank of America and the New York Stock Exchange, allegedly struck J.P. Morgan Chase today. <a href="http://www.foxbusiness.com/industries/2012/09/19/chase-website-experiences-intermittent-troubles/?cmpid=cmty_twitter_fb" target="_blank">Fox Business reported</a> on the site outage at Chase.com and consulted with Flashpoint Partners about the problems. Flashpoint told Fox that Chase's problems were probably due to a "sustained denial of service attack."</p>
<p>The religiously-motivated hackers, who claim they are responding to the anti-Muslim video, <a href="http://betabeat.com/2012/09/google-refuses-white-house-plea-to-remove-controversial-anti-muslim-video/" target="_blank"><em>Innocence of Muslims</em></a>, have published a <a href="http://pastebin.com/izrLhERu">new Pastebin page claiming credit for the Chase attack</a>:<!--more--></p>
<blockquote><p>In the name of Allah the companionate the merciful</p>
<p>My soul is devoted to you Dear Prophet of Allah</p>
<p>"Operation Ababil" started over BoA :</p>
<p>http://pastebin.com/mCHia4W5<br />
http://pastebin.com/wMma9zyG</p>
<p>In the second step we attacked the largest bank of the united states, the "chase" bank. These series of attacks will continue untill the Erasing of that nasty movie from the Internet.</p>
<p>The site "www.chase.com" is down and also Online banking at "chaseonline.chase.com" is being decided to be Offline !</p>
<p>Down with modern infidels.</p>
<p>### Cyber fighters of Izz ad-din Al qassam ###</p></blockquote>
<p>"Operation Ababil" was also the name of a failed Pakistani military operation that occurred in April, 1984.</p>
<p>Pakistan planned the maneuver (sometimes spelled "Operation Ababeel") as an effort to capture a glacier in the long-disputed region of Kashmir. India learned of the plan and managed to seize the area two days before Pakistan pulled the trigger on the mission.</p>
<p>Are the Cyber fighters of Izz ad-din Al qassam hinting that they might be based in Pakistan? Not necessarily--the name of the operation could be a red herring.</p>
<p>The group's moniker may mean more than whatever they call their efforts against financial institutions; Izz ad-din Al qassam, <a href="http://en.wikipedia.org/wiki/Izz_ad-Din_al-Qassam" target="_blank">according to Wikipedia</a>, was the name of a Syrian-born "Muslim preacher who was a leader in the fight against British, French, and Zionist organizations in the Levant in the 1920s and 1930s."</p>
<p><em>Innocence of Muslims </em>has been blocked in Pakistan and several other heavily Muslim countries but Google has refused to completely remove the film from the web.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/muslim-cyber-fighters-attack-chase-bank-in-operation-ababil/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg?w=112" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg?w=112" medium="image">
			<media:title type="html">EzeldinQassam</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/ezeldinqassam.jpg" medium="image">
			<media:title type="html">EzeldinQassam</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Russia&#8217;s Kaspersky Lab Cracks Password Attached to Alleged U.S. Cyber Weapon</title>

		<comments>http://betabeat.com/2012/09/russias-kaspersky-lab-cracks-password-attached-to-alleged-u-s-cyber-weapon/#comments</comments>
		<pubDate>Wed, 19 Sep 2012 13:24:18 -0400</pubDate>
					<link>http://betabeat.com/2012/09/russias-kaspersky-lab-cracks-password-attached-to-alleged-u-s-cyber-weapon/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=63027</guid>
		<description><![CDATA[<p><div id="attachment_63042" class="wp-caption alignleft" style="width: 178px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg"><img class="size-full wp-image-63042" title="flamegonnalive" src="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg" alt="" width="168" height="240" /></a><p class="wp-caption-text">What Flame did to Iranian computers. (Image: <a href="http://www.flickr.com/photos/wwarby/">William Warby</a>, Flickr)</p></div></p>
<p>The Cold War is over and Russia and America are getting along. So surely the Men in Black behind the United States' cyber weapons program based at Area 51 or wherever will not be too concerned that a Russian researcher cracked an encoded password associated with the now infamous, allegedly American-made <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame malware</a>.</p>
<p><a href="http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/" target="_blank">Symantec and Kaspersky recently teamed to pick apart Flame's command and control systems</a>, discovering at least three previously unknown infectious scripts in the process. The researchers also discovered a great deal about how the weapons were assembled and launched against enemy targets, but were left with a hashed passcode they couldn't break. They put out a call for help but <a href="http://www.networkworld.com/news/2012/091812-kaspersky-flame-262531.html">didn't need the assistance of anyone outside either outfit</a>, after all:<!--more--></p>
<blockquote><p>Kaspersky analyst Dmitry Bestuzhev cracked the hash for the password Sept. 17 just hours after Symantec put out a public request for help getting into the control panel for Flame, which infected thousands of computers in the Mideast. [...]</p></blockquote>
<blockquote><p>The hash - 27934e96d90d06818674b98bec7230fa - was resolved to the plain text password 900gage!@# by Bestuzhev.</p></blockquote>
<p>So now the whole world knows the password that once protected the servers behind Flame, a complex and sophisticated cyber weapon that was a major blow to Iran's nuclear program.</p>
<p>Which is a little scary, because if someone can crack the password that once protected such a covert weapon created by a nation state, the average Internet user's method of password protecting their GMail with a pet's name plus grandma's birthday doesn't seem too safe anymore.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_63042" class="wp-caption alignleft" style="width: 178px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg"><img class="size-full wp-image-63042" title="flamegonnalive" src="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg" alt="" width="168" height="240" /></a><p class="wp-caption-text">What Flame did to Iranian computers. (Image: <a href="http://www.flickr.com/photos/wwarby/">William Warby</a>, Flickr)</p></div></p>
<p>The Cold War is over and Russia and America are getting along. So surely the Men in Black behind the United States' cyber weapons program based at Area 51 or wherever will not be too concerned that a Russian researcher cracked an encoded password associated with the now infamous, allegedly American-made <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame malware</a>.</p>
<p><a href="http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/" target="_blank">Symantec and Kaspersky recently teamed to pick apart Flame's command and control systems</a>, discovering at least three previously unknown infectious scripts in the process. The researchers also discovered a great deal about how the weapons were assembled and launched against enemy targets, but were left with a hashed passcode they couldn't break. They put out a call for help but <a href="http://www.networkworld.com/news/2012/091812-kaspersky-flame-262531.html">didn't need the assistance of anyone outside either outfit</a>, after all:<!--more--></p>
<blockquote><p>Kaspersky analyst Dmitry Bestuzhev cracked the hash for the password Sept. 17 just hours after Symantec put out a public request for help getting into the control panel for Flame, which infected thousands of computers in the Mideast. [...]</p></blockquote>
<blockquote><p>The hash - 27934e96d90d06818674b98bec7230fa - was resolved to the plain text password 900gage!@# by Bestuzhev.</p></blockquote>
<p>So now the whole world knows the password that once protected the servers behind Flame, a complex and sophisticated cyber weapon that was a major blow to Iran's nuclear program.</p>
<p>Which is a little scary, because if someone can crack the password that once protected such a covert weapon created by a nation state, the average Internet user's method of password protecting their GMail with a pet's name plus grandma's birthday doesn't seem too safe anymore.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/russias-kaspersky-lab-cracks-password-attached-to-alleged-u-s-cyber-weapon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg?w=105" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg?w=105" medium="image">
			<media:title type="html">flamegonnalive</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/flamegonnalive.jpg" medium="image">
			<media:title type="html">flamegonnalive</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Muslim Cyberfighters Claim Responsibility for Bank of America and NYSE Hack in Retaliation for Movie</title>

		<comments>http://betabeat.com/2012/09/cyber-fighters-of-izz-ad-din-al-qassam-claim-they-are-behind-online-attacks-against-bank-of-america-and-the-new-york-stock-exchange/#comments</comments>
		<pubDate>Tue, 18 Sep 2012 16:19:46 -0400</pubDate>
					<link>http://betabeat.com/2012/09/cyber-fighters-of-izz-ad-din-al-qassam-claim-they-are-behind-online-attacks-against-bank-of-america-and-the-new-york-stock-exchange/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=62900</guid>
		<description><![CDATA[<p><div id="attachment_62907" class="wp-caption alignleft" style="width: 304px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png"><img class="size-full wp-image-62907" title="bofa" src="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png" alt="" width="294" height="160" /></a><p class="wp-caption-text">Screengrab</p></div></p>
<p>Bank of America customers have had <a href="http://www.reuters.com/article/2012/09/18/us-bankofamerica-website-idUSBRE88H15E20120918" target="_blank">a hard time</a> accessing the bank's website today--and <a href="http://pastebin.com/mCHia4W5">a claim posted by a Muslim hacker group on Pastebin.com</a> may have something to do with that. Reuters has reported that the "scope of the problem could not immediately be learned" but BoA customers across the country were having similar problems.</p>
<p>In a Pastebin post made sometime Tuesday, a group claiming to speak "In the name of Allah the companionate (sic) the merciful" wrote the following:<!--more--></p>
<blockquote><p>My soul is devoted to you Dear Prophet of Allah<br />
Dear Muslim youths, Muslims Nations and are noblemen<br />
When Arab nations rose against their corrupt regimes (those who support Zionist regime) at the other hand when, Crucify infidels are terrified and they are no more supporting human rights. United States of America with the help of Zionist Regime made a Sacrilegious movie insulting all the religions not only Islam.</p>
<p>All the Muslims worldwide must unify and Stand against the action, Muslims must do whatever is necessary to stop spreading this movie. We will attack them for this insult with all we have.</p>
<p>All the Muslim youths who are active in the Cyber world will attack to American and Zionist Web bases as much as needed such that they say that they are sorry about that insult.</p>
<p>We, Cyber fighters of Izz ad-din Al qassam will attack the Bank of America and New York Stock Exchange for the first step. These Targets are properties of American-Zionist Capitalists. This attack will be started today at 2 pm. GMT. This attack will continue till the Erasing of that nasty movie. Beware this attack can vary in type.</p>
<p>Down with modern infidels.<br />
Allah is the Greatest. Allah is the Greatest.</p></blockquote>
<p>The movie referred to in the message is likely the <a href="http://betabeat.com/2012/09/google-refuses-white-house-plea-to-remove-controversial-anti-muslim-video/" target="_blank">infamous <em>Innocence of Muslims</em></a>, a garish amateur propaganda piece that has been roiling Muslim communities around the world for more than a week now.</p>
<p>There aren't any reports yet of similar problems with the <a href="http://www.nyse.com/" target="_blank">New York Stock Exchange's site</a> or systems, but two out of four attempts to reach Bank of America's website were unsuccessful as of 4 p.m. Eastern Time on Tuesday.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_62907" class="wp-caption alignleft" style="width: 304px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png"><img class="size-full wp-image-62907" title="bofa" src="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png" alt="" width="294" height="160" /></a><p class="wp-caption-text">Screengrab</p></div></p>
<p>Bank of America customers have had <a href="http://www.reuters.com/article/2012/09/18/us-bankofamerica-website-idUSBRE88H15E20120918" target="_blank">a hard time</a> accessing the bank's website today--and <a href="http://pastebin.com/mCHia4W5">a claim posted by a Muslim hacker group on Pastebin.com</a> may have something to do with that. Reuters has reported that the "scope of the problem could not immediately be learned" but BoA customers across the country were having similar problems.</p>
<p>In a Pastebin post made sometime Tuesday, a group claiming to speak "In the name of Allah the companionate (sic) the merciful" wrote the following:<!--more--></p>
<blockquote><p>My soul is devoted to you Dear Prophet of Allah<br />
Dear Muslim youths, Muslims Nations and are noblemen<br />
When Arab nations rose against their corrupt regimes (those who support Zionist regime) at the other hand when, Crucify infidels are terrified and they are no more supporting human rights. United States of America with the help of Zionist Regime made a Sacrilegious movie insulting all the religions not only Islam.</p>
<p>All the Muslims worldwide must unify and Stand against the action, Muslims must do whatever is necessary to stop spreading this movie. We will attack them for this insult with all we have.</p>
<p>All the Muslim youths who are active in the Cyber world will attack to American and Zionist Web bases as much as needed such that they say that they are sorry about that insult.</p>
<p>We, Cyber fighters of Izz ad-din Al qassam will attack the Bank of America and New York Stock Exchange for the first step. These Targets are properties of American-Zionist Capitalists. This attack will be started today at 2 pm. GMT. This attack will continue till the Erasing of that nasty movie. Beware this attack can vary in type.</p>
<p>Down with modern infidels.<br />
Allah is the Greatest. Allah is the Greatest.</p></blockquote>
<p>The movie referred to in the message is likely the <a href="http://betabeat.com/2012/09/google-refuses-white-house-plea-to-remove-controversial-anti-muslim-video/" target="_blank">infamous <em>Innocence of Muslims</em></a>, a garish amateur propaganda piece that has been roiling Muslim communities around the world for more than a week now.</p>
<p>There aren't any reports yet of similar problems with the <a href="http://www.nyse.com/" target="_blank">New York Stock Exchange's site</a> or systems, but two out of four attempts to reach Bank of America's website were unsuccessful as of 4 p.m. Eastern Time on Tuesday.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/cyber-fighters-of-izz-ad-din-al-qassam-claim-they-are-behind-online-attacks-against-bank-of-america-and-the-new-york-stock-exchange/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png?w=150" medium="image">
			<media:title type="html">bofa</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/bofa.png" medium="image">
			<media:title type="html">bofa</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Researchers Uncover U.S. Footprints in Mysterious Cyber Warfare Tools</title>

		<comments>http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/#comments</comments>
		<pubDate>Mon, 17 Sep 2012 11:50:31 -0400</pubDate>
					<link>http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=62662</guid>
		<description><![CDATA[<p><div id="attachment_62676" class="wp-caption alignleft" style="width: 244px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/flame.png"><img class="size-medium wp-image-62676" title="flame" src="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=234" alt="" width="234" height="300" /></a><p class="wp-caption-text">Attack workflow for Flame controllers (Symantec)</p></div></p>
<p>Kaspersky Lab and Symantec have <a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_flamer_newsforyou.pdf" target="_blank">teamed up</a> to peel apart the United States' cyber warfare efforts. So far, they have uncovered the command and control systems behind the sophisticated malware as well as three previously unknown chunks of malicious code possibly related to alleged American cyber superbugs <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame and Duqu</a>.</p>
<p><a href="http://www.reuters.com/article/2012/09/17/us-usa-security-viruses-idUSBRE88G0QF20120917">Reuters reports</a> that researchers from the security firms discovered how the malware was disseminated--through an outwardly innocent-seeming content management system (CMS) named Newsforyou:<!--more--></p>
<blockquote><p>It was designed to look like a common program for managing content on websites, which was likely done in a bid to disguise its real purpose from hosting providers or investigators so that the operation would not be compromised, Kaspersky said in its report.</p></blockquote>
<blockquote><p>Newsforyou handled four types of malicious software: Flame and programs code-named SP, SPE and IP, according to both firms. Neither firm has obtained samples of the other three pieces of malware.</p></blockquote>
<p>According to <a href="http://www.symantec.com/connect/blogs/have-i-got-newsforyou-analysis-flamer-cc-servers" target="_blank">Symantec</a>, Newsforyou allowed attackers to "upload packages of code, to deliver to compromised computers, and to download packages containing stolen client data." Symantec writes that the mystery chunks of code were "likely unknown variants" on Flame but could have been "totally distinct malware."</p>
<p>More intriguing, researchers uncovered nicknames for a handful of programmers who worked on the malware over the course of the last six years or so:</p>
<blockquote><p>The attackers were not thorough enough, however, as a file revealing the entire history of the server‘s setup was available. In addition, a limited set of encrypted records in the database revealed that compromised computers had been connecting from the Middle East. We were also able to recover the nicknames of four authors—D***, H*****, O******, and R***—who had worked on the code at various stages and on differing aspects of the project, which appear to have been written as far back as 2006.</p></blockquote>
<p>Symantec and Kaspersky have an additional mystery for which they seek the public's help--this mysterious encoded password: 27934e96d90d06818674b98bec7230fa.</p>
<p>Researchers say they have attempted "brute-force" cracks of the hashed code, to no avail. If you're up for a juicy password cracking challenge that may also put you on a government watchlist, <a href="https://twitter.com/threatintel" target="_blank">hit them up on Twitter</a>.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_62676" class="wp-caption alignleft" style="width: 244px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/flame.png"><img class="size-medium wp-image-62676" title="flame" src="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=234" alt="" width="234" height="300" /></a><p class="wp-caption-text">Attack workflow for Flame controllers (Symantec)</p></div></p>
<p>Kaspersky Lab and Symantec have <a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_flamer_newsforyou.pdf" target="_blank">teamed up</a> to peel apart the United States' cyber warfare efforts. So far, they have uncovered the command and control systems behind the sophisticated malware as well as three previously unknown chunks of malicious code possibly related to alleged American cyber superbugs <a href="http://betabeat.com/topics/flame-im-gonna-live-forever/" target="_blank">Flame and Duqu</a>.</p>
<p><a href="http://www.reuters.com/article/2012/09/17/us-usa-security-viruses-idUSBRE88G0QF20120917">Reuters reports</a> that researchers from the security firms discovered how the malware was disseminated--through an outwardly innocent-seeming content management system (CMS) named Newsforyou:<!--more--></p>
<blockquote><p>It was designed to look like a common program for managing content on websites, which was likely done in a bid to disguise its real purpose from hosting providers or investigators so that the operation would not be compromised, Kaspersky said in its report.</p></blockquote>
<blockquote><p>Newsforyou handled four types of malicious software: Flame and programs code-named SP, SPE and IP, according to both firms. Neither firm has obtained samples of the other three pieces of malware.</p></blockquote>
<p>According to <a href="http://www.symantec.com/connect/blogs/have-i-got-newsforyou-analysis-flamer-cc-servers" target="_blank">Symantec</a>, Newsforyou allowed attackers to "upload packages of code, to deliver to compromised computers, and to download packages containing stolen client data." Symantec writes that the mystery chunks of code were "likely unknown variants" on Flame but could have been "totally distinct malware."</p>
<p>More intriguing, researchers uncovered nicknames for a handful of programmers who worked on the malware over the course of the last six years or so:</p>
<blockquote><p>The attackers were not thorough enough, however, as a file revealing the entire history of the server‘s setup was available. In addition, a limited set of encrypted records in the database revealed that compromised computers had been connecting from the Middle East. We were also able to recover the nicknames of four authors—D***, H*****, O******, and R***—who had worked on the code at various stages and on differing aspects of the project, which appear to have been written as far back as 2006.</p></blockquote>
<p>Symantec and Kaspersky have an additional mystery for which they seek the public's help--this mysterious encoded password: 27934e96d90d06818674b98bec7230fa.</p>
<p>Researchers say they have attempted "brute-force" cracks of the hashed code, to no avail. If you're up for a juicy password cracking challenge that may also put you on a government watchlist, <a href="https://twitter.com/threatintel" target="_blank">hit them up on Twitter</a>.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/researchers-uncover-u-s-footprints-in-mysterious-cyber-warfare-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=117" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=117" medium="image">
			<media:title type="html">flame</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/flame.png?w=234" medium="image">
			<media:title type="html">flame</media:title>
		</media:content>
	</item>
		<item>
				
		<title>Nonstop Cyber Warfare Is Your Scary New Jam</title>

		<comments>http://betabeat.com/2012/08/everyone-always-waging-non-stop-cyber-warfare-is-your-scary-new-jam/#comments</comments>
		<pubDate>Thu, 30 Aug 2012 13:16:53 -0400</pubDate>
					<link>http://betabeat.com/2012/08/everyone-always-waging-non-stop-cyber-warfare-is-your-scary-new-jam/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=60659</guid>
		<description><![CDATA[<p><div id="attachment_59353" class="wp-caption alignleft" style="width: 310px"><a href="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg"><img class="size-medium wp-image-59353" title="hacking" src="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg?w=300" alt="" width="300" height="199" /></a><p class="wp-caption-text">This guy could also be a government agent. (Image <a href="http://www.flickr.com/photos/devdsp/6999839463/sizes/n/in/photostream/">Devdsp</a> on Flickr</p></div></p>
<p>Humanity's fear of "war without end" has yet to be <em>completely</em> fulfilled in the analog world, but <a href="http://www.guardian.co.uk/technology/2012/aug/30/state-sponsored-cyber-espionage-prevalent">state-sponsored cyber warfare</a> has been afoot for years and is only getting worse. That's one takeaway from cyber security expert Pete Warren's report in <em>The Guardian</em> on government-created malware.</p>
<p>Mr. Warren consulted a number of anonymous security experts with military ties to get a sense of how long major governments have been developing nefarious software packages like Flame, Duqu and Stuxnet. Some systems, writes Mr. Warren, "have been under development since at least 1996."  Moreover, the United States and its allies aren't the only nations with skin in the malware game:<!--more--></p>
<blockquote><p>"There are a lot of countries that now have these systems. Every Middle Eastern country and all the states now known as the 'Stans' [Pakistan and the former satellite states of the Soviet Union] have them", said another expert with close links to the UK intelligence agencies and who is actively engaged in combating the software.</p></blockquote>
<p>An unnamed ex-military man in London went further, telling Mr. Warren that "Every nation now has an armory; whether well-stocked or not depends on their resources."</p>
<p>Like guerrilla soldiers adopting military tactics to cause destruction and mayhem, government-made software like the <a href="https://www.securelist.com/en/blog/208193522/" target="_blank">Flame worm</a> has inspired copycats. The mid-August <a href="http://www.informationweek.com/security/attacks/saudi-aramco-restores-network-after-sham/240006278" target="_blank">Shamoon attack</a>, for example, targeted a Saudi-owned oil company and knocked up to 75 percent of that company's workstations offline. Shamoon resembled Flame, but a hacker group calling itself The Cutting Sword of Justice <a href="http://pastebin.com/HqAgaQRj" target="_blank">claimed credit</a> for Shamoon. They say they are an "anti-oppression hacker group" and are "fed up of (sic) crimes and atrocities taking place in various countries around the world."</p>
<p>Ours is a brave new world, with lots of scary new creeping software in it.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_59353" class="wp-caption alignleft" style="width: 310px"><a href="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg"><img class="size-medium wp-image-59353" title="hacking" src="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg?w=300" alt="" width="300" height="199" /></a><p class="wp-caption-text">This guy could also be a government agent. (Image <a href="http://www.flickr.com/photos/devdsp/6999839463/sizes/n/in/photostream/">Devdsp</a> on Flickr</p></div></p>
<p>Humanity's fear of "war without end" has yet to be <em>completely</em> fulfilled in the analog world, but <a href="http://www.guardian.co.uk/technology/2012/aug/30/state-sponsored-cyber-espionage-prevalent">state-sponsored cyber warfare</a> has been afoot for years and is only getting worse. That's one takeaway from cyber security expert Pete Warren's report in <em>The Guardian</em> on government-created malware.</p>
<p>Mr. Warren consulted a number of anonymous security experts with military ties to get a sense of how long major governments have been developing nefarious software packages like Flame, Duqu and Stuxnet. Some systems, writes Mr. Warren, "have been under development since at least 1996."  Moreover, the United States and its allies aren't the only nations with skin in the malware game:<!--more--></p>
<blockquote><p>"There are a lot of countries that now have these systems. Every Middle Eastern country and all the states now known as the 'Stans' [Pakistan and the former satellite states of the Soviet Union] have them", said another expert with close links to the UK intelligence agencies and who is actively engaged in combating the software.</p></blockquote>
<p>An unnamed ex-military man in London went further, telling Mr. Warren that "Every nation now has an armory; whether well-stocked or not depends on their resources."</p>
<p>Like guerrilla soldiers adopting military tactics to cause destruction and mayhem, government-made software like the <a href="https://www.securelist.com/en/blog/208193522/" target="_blank">Flame worm</a> has inspired copycats. The mid-August <a href="http://www.informationweek.com/security/attacks/saudi-aramco-restores-network-after-sham/240006278" target="_blank">Shamoon attack</a>, for example, targeted a Saudi-owned oil company and knocked up to 75 percent of that company's workstations offline. Shamoon resembled Flame, but a hacker group calling itself The Cutting Sword of Justice <a href="http://pastebin.com/HqAgaQRj" target="_blank">claimed credit</a> for Shamoon. They say they are an "anti-oppression hacker group" and are "fed up of (sic) crimes and atrocities taking place in various countries around the world."</p>
<p>Ours is a brave new world, with lots of scary new creeping software in it.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/08/everyone-always-waging-non-stop-cyber-warfare-is-your-scary-new-jam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg?w=150" medium="image">
			<media:title type="html">hacking</media:title>
		</media:content>

		<media:content url="http://0.gravatar.com/avatar/09b55df2047c192d03f25ca0d107f11e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alcranan</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/08/hacking.jpg?w=300" medium="image">
			<media:title type="html">hacking</media:title>
		</media:content>
	</item>
	</channel>
</rss>
