Showing posts with label Hacker groups. Show all posts
Showing posts with label Hacker groups. Show all posts

Wednesday, December 20, 2017

North Korea Amassing Bitcoin To Fund Cyberattacks According To Crowdstrike CEO


Content originally published at iBankCoin.com


The CEO of cybersecurity firm Crowdstrike, George Kurtz, says North Korea is "absolutely" accumulating a giant pile of bitcoin to fund cyberattacks.

"They"re building a cache of bitcoin, if you think about it. It"s an anonymous currency, it can easily bypass any sort of sanctions because there are none on bitcoin, and the value has increased dramatically," Kurtz told CNBC"s "Squawk Alley." "It"s the perfect currency for North Korea to be hoarding." -CNBC



Can someone say "prohibited country" regulations?


The opinion comes on the heels of an op-ed in the WSJ by Homeland Security advisor Tom Bossert, who says North Korea was behind the WannaCry ransomware hack earlier this year, which demanded ransom in bitcoin.


The U.S. government has assessed with a "very high level of confidence" that a hacking entity known as Lazarus Group, which works on behalf of the North Korean government, carried out the WannaCry attack, said the official, who spoke on condition of anonymity to discuss details of the government"s investigation. -CNBC



The WannaCry hack is said to have cost billions, crippling hospitals, banks and companies around the world - and "highlights the capabilities that North Korea has in cyber," according to Kurtz.



Crowdstrike CEO on 2018 cyber threat outlook from CNBC.


Crowdstrike is the firm which analyzed the DNC servers and determined that Russia hacked them - however the Irvine, CA company came under fire in late 2016 when they had to retract a botched report on Russian hacking of Ukrainian artillery using the same "fancy bear" malware they also say the Kremlin used on the DNC servers.


The government of Ukraine issued a statement after the artillery report came out, calling it Fake News:


In connection with the emergence in some media reports which stated that the alleged “80% howitzer D-30 Armed Forces of Ukraine removed through scrapping Russian Ukrainian hackers software gunners,” Land Forces Command of the Armed Forces of Ukraine informs that the said information is incorrect.


Ministry of Defence of Ukraine asks journalists to publish only verified information received from the competent official sources. Spreading false information leads to increased social tension in society and undermines public confidence in the Armed Forces of Ukraine. –mil.gov.ua (translated) (1.6.2017)



So DHS"s Tom Bossert drops an op-ed on a North Korean hacking operation which only takes Bitcoin, and the CEO of Crowdstrike follows up with a stark warning on Bitcoin hoarding by Pyongyang. 




Follow on Twitter @ZeroPointNow § Subscribe to our YouTube channel


Saturday, July 15, 2017

Mysterious Hacker Leaks Emails Of Top US State Department Expert On Russia

Coming at a "sensitive" moment for US-Russian hacking diplomatic relations, on Friday Foreign Policy reported that emails belonging to a senior US State Department intelligence official involved in Russian affairs have been leaked by a hacker known as "Johnnie Walker." The official, whose work is focused on Russian domestic affairs and who was described to FT as “probably the top intelligence guy in the entire U.S. government on Russia [who] knows more than anybody about what’s going on there,” is said to have been particularly interested in Russian media and government reshuffling.


The emails which were sourced from a hacked nongovernmental account over a two-year period, were sent to “an unknown number of recipients" and while the leaks were first released on July 10, they did not gain widespread attention until Friday when both FP and Newsweek commented on the hack.


In a letter announcing the alleged hacking, Johnnie Walker said that the leak would provide evidence for establishing what was called “agenda formation in many countries worldwide, especially where the situation is insecure.” The sender also claimed that the US State Department official was in contact with various intelligence agencies, including the CIA, as well as “mainstream media, NGOs, and international funds.”


Although the alleged hacking victim holds “a senior position in the State Department’s Bureau of Intelligence and Research” and while name was disclosed in the leaked emails, Foreign Policy outlet did not disclose the name, citing a request from the state department, which has so far neither confirmed nor denied the hack. The leaked correspondence was released online on Pastebin although its authenticity remains unclear for now. The description to the three archives available for download also adds the name of the alleged agent.


As part of his introduction to the leaked emails, the mysterious hacker says that “perhaps you know that the U.S. State Department has a direct bearing on the agenda formation not only at home but throughout the world. Now you can make sure it’s true." Below is the preface that "Johnnie Walker" posted on the pastebin:





Perhaps you know that the U.S. State Department has a direct bearing on the agenda formation not only at home but throughout the world.



Now you can make sure it"s true. Let me show you the correspondence between the Deputy Chief of Staff for Intelligence, Surveillance and Reconnaissance Agency Robert P. Otto and his colleagues, CIA officers and other intelligence agencies, as well as representatives of mainstream media, NGOs, international funds and think tanks.



With the respect for privacy I"ve deleted his correspondence with his wife and relatives. The rest of emails will give evidence of who is responsible for different information campaigns, the so-called mythmaking and essentially engaged in the promotion of "American values" throughout the world.



As a reminder, two days before the find round of the French election, a dump of internal documents of then-French presidential hopeful Emmanuel Macron was also released on Pastebin, although it is unclear if the two releases are related. Apart from the name of the hacker’s target, the content of the letters has not been published in the Western media, although Russia"s Kommersant claims it has access to the files.


The Russian newspaper says that the intel official sent his colleagues links to articles from different Russian news outlets, including Novaya Gazeta, The New Times, Vedomosti, and RBK, among others. Among the topic of particular interest for the State Department official were social media accounts of Russian officials, staff re-shuffling in governmental bodies, and the influence of some state officials. According to the report, it is also unclear if it was a single leak or only one in a series of hacking attacks.


As Redditor NathanOhio summarized overnight, the facts so far appear to be as follows:


  1. A hacker going by the name "Johnnie Walker" has hacked a senior state department official"s personal Gmail account.

  2. The official has not been publicly named, but is claimed to be the foremost expert on Russia.

  3. Two years worth of emails were stolen and include exchanges between the victim and "CIA officers and other intelligence agencies, mainstream media, NGOs and international funds” that would “give you evidence of who is responsible for agenda formation in many countries worldwide, especially where the situation is insecure.”

  4. A link to the email cache has been published by "an obscure website in Crimea" that the MSM claims is "financed by the Russian secret service, and its topics assigned by top political leadership in Moscow."

In retrospect, it appears that the email contents are relatively innocuous: as the Redditor notes:





Reading through some of the messages, it seems they are mostly discussions between various neocon academics and forwarding of articles. Most of these people rather than experts seem to be groupthinkers endlessly building up the walls of their own echo chamber.



Found a couple of things that are interesting. A Russian scholar "Valery Solovei" is sending Robert Otto a monthly report on Russia. Also, Otto and his buddies HATE John Kerry and continually refer to him as an idiot!



With the Trump administration neck-deep in Russia-hacking drama, we expect that this story, which somehow failed to make last week"s news cycle will be among the main topics in the days ahead, with questions (and predetermined answers) over the identity (and nationality) of Johnnie Walker among the most discussed items.

Thursday, June 29, 2017

NSA-Linked Hackers Raise Price Of Monthly Subscription to $61,000 After Tuesday's Cyberattack

In the wake of Tuesday’s massive global ransomware attack, the hacker group called the Shadow Brokers is again trying to capitalize on its reputation as a source of leaked NSA hacking exploits, saying it will up the price of a subscription service launched earlier this month, while also introducing a new “premium” feature.


The group introduced a monthly subscription service following last month’s WannaCry attack, after initially trying to sell its entire cache of NSA-funded cyberweapons for a staggering one million bitcoin (worth $2.5 billion at current prices). Both WannaCry and Tuesday’s attack, which has been blamed on the “Goldeneye” strain of the “Petya” ransomware, were aided by exploits that the Shadowbrokers allegedly stole from an NSA special-ops crew called “the Equation Group.”





Now, the Shadowbrokers are marketing their wares not only at hackers, but at corporations who’d like to buy insurance against being hacked.


Here’s the Shadowbrokers, in their characteristic broken English, as reported by The Hill.





"Another global cyber attack is fitting end for first month of theshadowbrokers dump service. There is much theshadowbrokers can be saying about this but what is point and having not already being said? So to business! Time is still being left to make subscribe and getting June dump. Don’t be let company fall victim to next cyber attack, maybe losing big bonus or maybe price on stock options be going down after attack. June dump service is being great success for theshadowbrokers, many many subscribers, so in July theshadowbrokers is raising price," the ShadowBrokers wrote in an online message released early Wednesday.”



The Shadowbrokers launched its monthly subscription document leaks service this month at a price of $27,000 a month in digital currency. Their new release more than doubles the price to $61,000.  The group also announced a new premium service allowing customers to make requests for assistance or specific document releases.


The group has been active since August 2016, when it began leaking hacking tools that were allegedly developed by the NSA. It has also leaked documents appearing to show the NSA hacked a Middle Eastern banking services company to try and get at the company’s clients, according to the Hill.


One of the exploits released by the group back in April, known as EternalBlue, was instrumental in aiding last month’s WannaCry cyberattack. Both WannaCry and another NSA exploit were allegedly intrumental in Tuesday"s attack.


The group also publicly released a password to what Edward Snowden called the NSA’s “top-secret arsenal of digital weapons.” Back in April, the group released passwords to hacking tool binaries developed by the NSA in 2013 as a “protest” against President Donald Trump, whom they accused of betraying his base by launching a missile strike against a Syrian government airfield and for backing away from his commitment to combating globalism.  


The first reports of organizations being hit by Tuesday’s attack were from Russia and Ukraine, but the impact quickly spread westwards to computers in Romania, the Netherlands, Norway, and Britain. Companies affected included German pharmaceutical company Merck, Russia"s Rosneft and metals giant Evraz, Danish shipper Maersk, UK ad company WPP, and both the Ukrainian and Russian central banks.


Already, Ukrainian government officials are blaming the attack on a Russian entity – likely government-sponsored – claiming that the virus’s code was written in Russian, ignoring the fact that Russian firms were also attacked, and mirroring the laughable conclusion that the North Korean government was somehow responsible for the original WannaCry attack.


With two global attacks unfolding in the span of two months, it’s incredible that the public – not to mention investors – aren’t more worried. How long until these attacks become a weekly, or even daily, occurrence. And more importantly, how long until they begin to seriously disrupt the functioning of private infrastructure.


At least one former NSA employee chimed in with his two cents about the agency’s role in making these attacks possible.






Nobody has been able to say for certain who or what the Shadowbrokers are. But at least one famed NSA whistleblower has a theory:


William Binney - who exposed the NSA"s pervasive surveillance of Americans long before Snowden confirmed it - said he and his colleagues are fairly certain the Shadowbrokers aren"t really a group of rogue actors, but rather an insider employee at NSA.

Wednesday, May 24, 2017

WannaCry Attackers Have Links To North Korea's Lazarus Group

Cybersecurity researchers at Symantec say they"ve found linkes between the WannaCry Ransomware attackers was likely carried out by a hacking group with ties to North Korea.


In a blog post, Symantec said the “Tools and infrastructure used in the WannaCry ransomware attacks have strong links to Lazarus, the group that was responsible for the destructive attacks on Sony Pictures and the theft of $81 million from the Bangladesh Central Bank.”


Here"s a summary of links provided by Symantec:


  • Following the first WannaCry attack in February, three pieces of malware linked to Lazarus were discovered on the victim’s network: Trojan.Volgmer and two variants of Backdoor.Destover, the disk-wiping tool used in the Sony Pictures attacks.

  • Trojan.Alphanc, which was used to spread WannaCry in the March and April attacks, is a modified version of Backdoor.Duuzer, which has previously been linked to Lazarus.

  • Trojan.Bravonc used the same IP addresses for command and control as Backdoor.Duuzer and Backdoor.Destover, both of which have been linked to Lazarus.

  • Backdoor.Bravonc has similar code obfuscation as WannaCry and Infostealer.Fakepude (which has been linked to Lazarus).

  • There is shared code between WannaCry and Backdoor.Contopee, which has previously been linked to Lazarus.

Symantec discovered that the WannaCry attackers used some of the same hacking tools that were previousky used in other Lazarus Group attacks. There are also, the group reported, “a number of links between WannaCry itself and Lazarus.”


The WannaCry ransomware, for example, shares some code with a piece of malware that has previously been linked to Lazarus.




Symantec also found that the WannaCry attackers used some of the same network infrastructure as the Lazarus Group. “There are a number of crossovers seen in the C&C servers used in the WannaCry campaigns and by other known Lazarus tools.”


Beginning a week ago Friday, the WannaCry virus infected thousands of computers around the world, threatening to destroy users" data unless a ransom was paid in bitcoin. Ultimately, the group received less than $100,000, and most of the data were destroyed.

Saturday, May 20, 2017

"ShadowBrokers" Hacking Group Launches Subscription Service Selling Nuclear Secrets

The hacking group known as "The Shadow Brokers" is pushing a monthly subscription service offering members top secret information including "compromised network data" from the nuclear and ballistic missile programs of Russia, China, North Korea and Iran.



As a reminder, we have noted in the past, many security experts believe the Equation Group is the National Security Agency, and that the Shadow Brokers may be part of a psychological operations campaign run by Russian intelligence.





Shadow Brokers first emerged last August, offering to auction hacking exploits it said were used by the NSA’s elite hacking team known as Equation Group (officially named Tailored Access Operations). NSA whistleblower Edward Snowden and others confirmed the leak was authentic.



In December, Shadow Brokers cancelled its auction and offered to sell the exploits.



In April, the group released passwords to the rest of the hacking exploits in a move described as a protest against President Donald Trump for abandoning his base.



The release included a Windows SMB [Server Message Block] exploit, EternalBlue, which was leveraged in the recent WannaCry global ransomware attack.



In its Tuesday blog post, the group expressed its surprise that governments or tech companies didn’t bid in its past auctions.



It said is has always been about “the shadowbrokers vs theequation group,” and implied the NSA is a cohort of tech companies like Microsoft.


And now, as RT reports, the group’s monthly data dump could also include hacking exploits for web browsers, routers, and operating systems including Windows 10.





"TheShadowBrokers Data Dump of the Month" is a new monthly subscription model, the group said.



Payment will likely be made in the cryptocurrency Bitcoin given the group’s ransom demands in previous cyber attacks.



The group also promised to include compromised financial data from the SWIFT international payment order system, used by banks to transfer trillions of dollars each day, as well as confidential data from several central banks.



In a blog post published Tuesday, titled, ‘Oh Lordy! Comey Wanna Cry Edition’ the group accused the NSA of paying Microsoft to keep vulnerabilities in its software (and did not hold back in its accusations)





If theshadowbrokers is telling the peoples theequationgroup is paying U.S technology companies NOT TO PATCH vulnerabilities until public discovery, is this being Fake News or Conspiracy Theory?



Why Microsoft patching SMB vulnerabilities in secret? Microsoft is being embarrassed because theequationgroup is lying to Microsoft. TheEquationGroup is not telling Microsoft about SMB vulnerabilities, so Microsoft not preparing with quick fix patch. More important theequationgroup not paying Microsoft for holding vulnerability. Microsoft is thinking it knowing all the vulnerabilities theEquationGroup is using and paying for holding patch.



Douche bag, dumbass, libtard, rich prick Head Microsoft Lawyer is running his cock holster because he is having ruff weekend doing real work. Head Microsoft Lawyer being angry because he is missing leisurely weekend playing the skin flute behind the country club.



Real work is not being for executives. Real work is being for dirty foreign H1B workforce, happily working for less than stupid lazy American workers.



Shadow Brokers finished its post saying if a responsible party were to buy “all lost data before it is being sold to the peoples” then the group would have no more financial incentives and would “go dark permanently.”

Saturday, May 6, 2017

France Warns Media Not To Publish Hacked Macron Emails, Threatens With Criminal Charges

After 9 gigabytes of Macron-linked documents and emails were released on an anonymous pastebin website on Friday afternoon in what Macron"s campaign said was a "massive and coordinated" hacking attack, France - fearing a similar response to what happened with Hillary Clinton after 35,000 John Podesta emails were released one month before the US presidential election - cracked down on the distribution of the files, warning on Saturday it would be a "criminal offense" to republish the data, and warning the French media not to publish content from any of the hacked emails "to prevent the outcome of the vote being influenced."



Quoted by Reuters, the French election commission said in a statement that "on the eve of the most important election for our institutions, the commission calls on everyone present on internet sites and social networks, primarily the media, but also all citizens, to show responsibility and not to pass on this content, so as not to distort the sincerity of the ballot." Following a rushed meeting on Saturday morning, the commission which supervises the electoral process, said that the data been "fraudulently obtained and could be mixed with false information." It is unclear, however, how it hopes to enforce any punitive claims, especially when much of the initial document distribution appears to have taken place offshore.


Domestically, in a similar reaction to the US media"s response to the Podesta emails, French TV news channels chose not to mention the hack, although the left-leading Liberation prominently featured the news on its website. Liberation author Cedric Mathiot wrote that the leak, and its timing, "wants to create chaos" adding that the information was distributed in an "unethical method."


On Friday night, as news of what has been hashtagged as @MacronLeaks on twitter spread, Florian Philippot, deputy leader of the National Front, tweeted "Will Macronleaks teach us something that investigative journalism has deliberately kept silent?" In a tweeted response, Macron spokesman Sylvain Fort called Philippot"s tweet "vile".


In another parallel to the Clinton leaks, Macron"s En Marche! party said the leaked documents dealt with "the normal operations of a campaign and included some information on campaign accounts." It said the hackers had mixed false documents with authentic ones to "sow doubt and disinformation."


But in the biggest parallel to the Clinton hacking, few have touched upon the actual contents of the documents, which some say confirm prior allegations of illicit financial dealings and offshore accounts, and instead merely sought to attack the messenger. Indeed, as journalist Kim Zetter noted overnight, "Telling journos to not report on hacked emails misses point that nearly all important leaks occur because someone broke law or a contract" and then followed up with the following rhetorical question, flipping the situation by 180 degrees: "If GRU, intending to assault dem., hacks Trump & publishes emails showing his direct connection to Russia, should journos report on those."




As reported on Friday evening, WikiLeaks tweeted that the leak contained "many tens of thousands" of emails, photos and attachments dated up to April 24, but it noted that it had come "too late" to affect the election results. In a follow up tweet, the controversial whistleblowing organization posted a tweet sharing the location of all #MacronLeaks archives which are "now available as uncensorable magnet links http://archive.is/aULcm"



Since there has been no suggestion WikiLeaks is responsible for this hack, speculation about the source of the hack has grown, with Russia once again emerging as the "usual suspect."


Cited by Reuters, Vitali Kremez, director of research with New York-based cyber intelligence firm Flashpoint, said his review indicates that APT 28, a group tied to the GRU, the Russian military intelligence directorate, was behind the leak. He cited similarities with U.S. election hacks that have been previously attributed to that group. Kremez also said that APT28 last month registered decoy internet addresses to mimic the name of En Marche, which it likely used send tainted emails to hack into the campaign’s computers. Those domains include onedrive-en-marche.fr and mail-en-marche.fr.





"If indeed driven by Moscow, this leak appears to be a significant escalation over the previous Russian operations aimed at the U.S. presidential election, expanding the approach and scope of effort from simple espionage efforts towards more direct attempts to sway the outcome," Kremez said.



We expect the Kremlin to deny all allegations shortly.


To cover all bases, others have also accused the "Alt Right" of being responsible for the leak:





Ben Nimmo, a UK-based security researcher with the Digital Forensic Research Lab of the Atlantic Council think tank, said initial analysis indicated that a group of U.S. far-right online activists were behind early efforts to spread the documents via social media. They were later picked up and promoted by core social media supporters of Le Pen in France, Nimmo said.



The leaks emerged on 4chan, a discussion forum popular with far right activists in the United States. An anonymous poster provided links to the documents on Pastebin, saying, "This was passed on to me today so now I am giving it to you, the people."



The hashtag #MacronLeaks was then spread by Jack Posobiec, a pro-Trump activist whose Twitter profile identifies him as Washington D.C. bureau chief of the far-right activist site Rebel TV, according to Nimmo and other analysts tracking the election. Contacted by Reuters, Posobiec said he had simply reposted what he saw on 4chan.



“You have a hashtag drive that started with the alt-right in the United States that has been picked up by some of Le Pen’s most dedicated and aggressive followers online,” Nimmo told Reuters.



Sunday"s election, whose result is expected in just over 24 hours, is seen as "the most important in France for decades, with two diametrically opposed views of Europe and the country"s place in the world at stake." Tune in then to find out if Wikileaks is correct, and the #MacronLeaks is nothing more than a tempest in a teapot, unable to chisel away at Macron"s lead over Le Pen which the latest polls calculate to be as much as 25 points.