Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Saturday, March 19, 2011

fukushima daiichi nuclear plant damaged by stuxnet?

fukushima daiichi nuclear plant damaged by stuxnet?Did Stuxnet infiltrate Fukushima Daiichi plant? The question is getting asked--and rightfully so! Fukushima plant uses Siemens Supervisory Control And Data Acquistion Software (SCADA), which Stuxnet is designed specifically to target. Is Stuxnet implicated in rendering, say, water pumps inoperable, a question asked recently on The Ugly Truth podcast? A Stuxnet link is also examined at whatREALLYhappened.com, "So now the difficulty the Fukushima nuclear plant operators faced in recovering control over their runaway reactors takes on a darker significance. Remember that the first problem following the quake was that the automated shutdown systems failed to operate at some of the reactors, because pumps failed and valves would not open even while running on batteries; the very sorts of mischief Stuxnet supposedly was designed to cause at Iran's power station." Multiple failures experienced at the Fukushima Daiichi nuclear plant begs the question whether Stuxnet malware involved? Webster Tarpley's call for action seems truer than ever at the moment: get active--or get radioactive!

update: attack code for scada vulnerabilities released online

Saturday, March 5, 2011

latest salvo in korean cyberwar

latest salvo in korean cyberwarCybersecurity firm Ahnlab, in a guardian.co.uk article, reported a denial of service attack (DoS) that targeted "... websites belonging to South Korea's presidential office, the foreign ministry, the national intelligence service, US Forces Korea and major financial institutions." Park Kun-woo, Ahnlab spokesman, advised attacks were similar to past ones - a DoS type of attack, and largely, same websites involved. Ahnlab reported a computer user found a bug, and after analysis, discovered malware designed to attack websites. The targets were warned in advance, as a result, experienced only brief slow downs. South Korean officials, in the past, have traced cyberattacks back to China. The current article is only reporting, "it was not immediately clear from where Friday's attack originated." Does this represent new posturing - a reversal - in messages sent in a spirit of keeping peace?

Tuesday, December 28, 2010

2010: the year the internet went to war

2010: the year the internet went to warfrom threat level: It was a year without parallel. Threat Level’s bread-and-butter themes of censorship, hacking, security, privacy, copyright and cyberwar were all represented in tug-of-war struggles with unprecedented outcomes.

Google defeated China’s censors, but caved to corporate censorship in the United States. The largest computer-crime case ever prosecuted ended in the nation’s longest prison term. A small-time Xbox modder who advertised his services online beat the federal rap. And a mysterious computer virus called Stuxnet finally put proof to decades of warnings that malware will eventually be used to kinetic effect in the real world.

A myriad of court decisions seemed to be a boon for online rights, while others clearly were a step backward. The year 2010 saw the rise of the newspaper copyright troll, and judges pushed back on absurd jury verdicts for music file sharing and outdated electronic spying rules.

And a secret-spilling website flirting with insolvency and dissolution suddenly burst onto the world stage. WikiLeaks was without a doubt the biggest 2010 development in Threat Level’s world.


related: cyber-warfare centre coming, germany says

Tuesday, October 5, 2010

virtual flag terrorism: new clues point to israel as author of stuxnet

stuxnet virus contains biblical references to esther & persia
virtual flag terrorism: new clues point to israel as author of stuxnetfrom threat level: New clues released this week show a possible link between Israel and sophisticated malware targeting industrial control systems in critical infrastructure systems, such as nuclear plants and oil pipelines.

Late Thursday, security firm Symantec released a detailed paper with analysis of the headline-making code (.pdf), which reveals two clues in the Stuxnet malware that adds to speculation that Israel may have authored the code to target Iran.

Or, they could simply be red herrings planted in the code by programmers to point suspicion at Israel and away from other possible suspects.

The malware, called Stuxnet, appears to be the first to effectively attack critical infrastructure and in a manner that produces physical results, although there’s no proof yet any real-world damage has been done by it. The malware’s sophistication and infection of thousands of machines in Iran has led some to speculate that the U.S. or Israeli government built the code to take out Iran’s nuclear program.

Tuesday, September 28, 2010

'cyber storm iii' tests US on cyber attack

stuxnet & cyberstorm3 are unrelated, nothing to see here...
'cyber storm iii' tests US on cyber attackfrom defencetalk: US keyboard warriors were doing battle Tuesday with a simulated cyberattack on government and private computer networks that undermines basic trust in the Internet. The "Cyber Storm III" exercise involves participants from seven US government departments, including the Pentagon, 11 US states, 60 private companies and 12 international partners.

The biennial exercise is being staged by the Department of Homeland Security and is the first test of the new National Cybersecurity and Communications Integration Center based in an office building in this Washington suburb. The NCCIC booted up in October 2009 to serve as the coordinating center for US cybersecurity operations and houses US government computer experts and their private sector counterparts under one roof.

Briefing reporters ahead of "Cyber Storm III," Brett Lambo, the director of DHS's Cyber Exercise Program, stressed that the exercise, which is expected to last three days, is "completely simulated... We're not attacking any real networks," Lambo said. "We're not taking down a network. We're not injecting any real malware."

The thousands of participants in the exercise will receive more than 1,500 "injects" of simulated events that they will have to react to as unknown adversaries seek to exploit known vulnerabilities in cyber infrastructure...

The international partners taking part in the exercise are from Australia, Britain, Canada, France, Germany, Hungary, Japan, Italy, the Netherlands, New Zealand, Sweden and Switzerland.


update: millions of comps hit by virus across china*
'cyber storm iii' simulates large-scale cyberattack*
dhs tests cyber response plan in global drill*
cyber attack on iranian industry appears well-funded*
iran says no virus hit nuclear systems*
in a computer worm, a possible biblical clue*

Wednesday, August 25, 2010

defense official discloses cyberattack

or: dod & cfr vs usb
defense official discloses cyberattackfrom washington post: Now it is official: The most significant breach of U.S. military computers was caused by a flash drive inserted into a U.S. military laptop on a post in the Middle East in 2008. In an article to be published Wednesday discussing the Pentagon's cyberstrategy, Deputy Defense Secretary William J. Lynn III says malicious code placed on the drive by a foreign intelligence agency uploaded itself onto a network run by the U.S. military's Central Command. "That code spread undetected on both classified and unclassified systems, establishing what amounted to a digital beachhead, from which data could be transferred to servers under foreign control," he says in the Foreign Affairs article.

update: insiders doubt hack was foreign spy attack

Thursday, May 6, 2010

hacked US treasury websites serve visitors malware

hacked US treasury websites serve visitors malwarefrom the register: Websites operated by the US Treasury Department are redirecting visitors to websites that attempt to install malware on their PCs, a security researcher warned on Monday. The infection buries an invisible iframe in bep.treas.gov, moneyfactory.gov, and bep.gov that invokes malicious scripts from grepad.com, Roger Thompson, chief research officer of AVG Technologies, told The Register. The code was discovered late Sunday night and was active at time of writing, about 12 hours later.

To cover their tracks, the miscreants behind the compromise tailored it so it attacks only IP addresses that haven't already visited the Treasury websites. That makes it harder for white hat-hackers and law enforcement agents to track the exploit. Indeed, Thompson initially reported that the problem had been fixed until he discovered the sites were merely skipping over laboratory PCs that had already encountered the attack.

The attack is most likely related to mass infections that two weeks ago hit hundreds of sites hosted by Network Solutions and GoDaddy, said Dean De Beer, founder and CTO of security consultancy zero(day)solutions. He made that assessment based on the observation that the compromised Treasury websites are hosted at Network Solutions and the owner of grepad.com is also the owner of record for most of the websites used in the earlier attacks. "There's a very high probability that it's the same person," De Beer said. "The only things that are changing are the domains."

Earlier, Thompson speculated the attack might be the result of someone exploiting a SQL injection vulnerability on the Treasury websites. After investigating that possibility, De Beer said it was unlikely because the hacked Treasury sites contained static HTML pages that aren't susceptible to such exploits. Media representatives at the Treasury Department didn't return a phone call seeking comment.