Showing posts with label cyberterrorism. Show all posts
Showing posts with label cyberterrorism. Show all posts

Saturday, May 13, 2017

The NSA’s Virus Can Still Destroy Your Data, Here Are 5 Ways to Make Sure It Won’t




Thanks to the NSA’s apparent lust to know and see everything, agency-designed ransomware virus was unleashed on the planet yesterday, leaving anyone using a Windows system — corporations, governments, and even those who only post cat pictures online — vulnerable to exploitation for a price.


That price — $300 in Bitcoin, increasing after a given time period — would theoretically have to be paid in order to rid the infected computer of the WanaCrypt ransomware, or the victim would lose everything on their system. Ransomware literally holds your data hostage until the fee asked by attackers is paid — but if you don’t pay, you lose everything.


Everything.


WanaCrypt0r, alternately known as WanaCry, WanaCrypt, or WCry, is believed to have infected no less than 126,500 computers in 99 countries prior to the threat being partially abated — but not before it had wrought havoc on the U.K.’s National Health Service, FedEx, Spanish telecommunications company, Telefónica, and other systems around the globe.


“This is one of the largest global ransomware attacks the cyber community has ever seen,” Splunk director of threat research, Rich Barger, told Reuters. Splunk is one of several firms who divined WanaCrypt0r’s origins with the National Security Agency.


Analysts say the particularly infectious worm exploited a Microsoft software flaw, and, although the company issued a patch in March after identifying WCry in February, not all users had updated their systems accordingly.


Cybersecurity experts worked at a fever pitch to stop the malicious worm, but it took what the Guardian termed an “accidental hero” to bring a tentative halt to the pandemonium. Reports the outlet, a Twitter user, “tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and inadvertently activated a ‘kill switch’ in the malicious software.”


He “halted the global spread of an unprecedented ransomware attack by registering a garbled domain name hidden in the malware has warned the attack could be rebooted.”


And payment of the $10.69 registration fee — temporary, though the end to the exploit may be — was all it took.


A significant risk could still be lurking — after all, the attackers used tools designed by the NSA, whose entire collection of older hacking tools were leaked online last month by an entity calling itself the Shadow Brokers, and WCry could yet mutate or be altered — but there are a few ways to stay safe and prevent having precious data and files wrested from you.



1. Update, update, update


As tech outlet, Tom’s Guide, notes, “If you’ve not installed the March, April or May Windows Update bundles, do so immediately. It’s worth shutting down your system for a few minutes if it gives you a chance to avoid this.”


Windows Vista users will be protected through the March or April update bundles, and Microsoft has since issued a patch for Windows XP and its 2003 server — while the company released information to help customers cope with the ransomware virus.


2. Don’t fall hook, line, or sinker


Although WanaCrypt exploits the aforementioned Windows vulnerability, people must be vigilant — as always — not to fall for online phishing schemes, as this malware could also have been spread randomly in hopes people would open email from an unfamiliar source.


Be exceedingly cautious when visiting websites and opening attachments — WanaCry could be ready to pounce. Use common sense — and pepper it with extraordinary discretion.


3. Back it up


Cybersecurity experts constantly harangue the rest of us to backup important data and files, and — while that directive might generate an eyeroll, and grumblings about time and energy — backing up one’s system is an imperative which now cannot be ignored.


Storing vital information in a secondary location, such as a USB storage stick or external hard drive, could save you tears and headaches in the long run — particularly if WCry or another variant takes control of your system. Cloud storage could be an option — depending on which cloud you use, as the original NSA leaker and insider, Edward Snowden, has warned — but would also leave your data vulnerable in other ways.


4. Get your defenses up


Install solid, reputable antivirus software — particularly one targeting ransomware — as a line of defense against the intrusion. Experts now say WanaCrypt appears to be “wormable,” which, Tom’s Guide explains, means it spreads “from system to system by itself as a computer worm, rather than relying on human interaction as a Trojan horse, or infecting desktop applications like a traditional computer virus.”


Since most antivirus software protects and updates in real time, even if the worm breaks through your defenses, RT points out, “chances are good that within a short while an automatic antivirus update will clear the intruder from your system. Most antivirus companies offer trial versions free of charge to test before subscribing for a paid service, which should be enough if one needs to urgently remove a stray malware.”


Forbes reports, “If you have up-to-date malware protection software from a reputable cybersecurity company such as Avast installed on your computer, you are probably protected.  Check your cybersecurity company’s website to make sure you are. WanaCry is a world-wide, runaway threat. If your cybersecurity company’s website has nothing to say about it, don’t assume you are protected. Make sure you are running the current version of Windows.”


5. Keep your money


Perhaps the most basic instruction most analysts and security pros emphasize is also difficult for many to swallow. Don’t shell out the money they’re demanding — be it Bitcoin, dollars, gold, or any other iteration.


Of course, those holding your files hostage for money hope to exploit you in two insidious ways — first, by locking down your data, but second, through your emotional panic resultant from having your critical files abruptly unavailable. That alarm pumps you full of adrenaline, and could provoke a response which seems the simplest solution in the moment — forking over the funds.


If you do that, cybersecurity analysts say, no guarantee exists you’ll actually get your data back — and your willingness to do so could make you a target for future exploits — which, again, could be coming around anytime.


***


Considering the scope of the documents leaked by the Shadow Brokers, virtually anything could be possible now. This basic list will only help to an extent, and should not be considered comprehensive — nor should it be considered, of course, expert advice.


That said, the precautions offered are a bit better than leaving your system naked to malicious infection.



That “accidental hero” credited with truncating the worm’s virulent proliferation admonished the public to be wary and alert, because — although altered or ‘improved’ iterations of WanaCrypt have yet to appear online — “they will.”


“This is not over,” he told the Guardian. “The attackers will realise how we stopped it, they’ll change the code and then they’ll start again. Enable Windows update, update and then reboot.”

Monday, April 3, 2017

UK Puts Nuclear Power Plants And Airports On Terror Alert Over "Credible" Cyber Threat

The global cyberwarfare scare washed ashore the British isles this weekend after UK nuclear power stations and airports were told to tighten defenses against terrorist attacks in the face of increased threats to electronic security systems, after intelligence agencies concluded terrorists could plant explosives in laptops and mobile phones that won’t be caught by normal security screenings.



The Telegraph reports that British security services issued a series of alerts in the past 24 hours, warning that "terrorists may have developed ways of bypassing safety checks."


To be sure, there was no surprise as to the bogeyman behind the latest terror threat: intel agencies believe that ISIS and other terrorist groups have developed ways to plant explosives in laptops and mobile phones that can evade airport security screening methods.


What is perhaps surprising, is that it is this latest intelligence which is said to be behind the recent bans, in both the US and UK, of travellers from a number of countries carrying laptops and large electronic devices on board. Furthermore, "there are concerns that terrorists will use the techniques to bypass screening devices at European and US airports."


There are also fears that computer hackers were trying to bypass nuclear power station security measures. Government officials have warned that terrorists, foreign spies and “hacktivists” are looking to exploit “vulnerabilities” in the nuclear industry’s internet defences. Energy minister Jesse Norman told The Telegraph that nuclear plants must make sure that they “remain resilient to evolving cyber threats”.





Norman said: “The Government is fully committed to defending the UK against cyber threats, with a £1.9 billion investment designed to transform this country’s cyber security.”



He said the civil nuclear strategy published in February sets out ways to ensure that the civil nuclear sector “can defend against, recover from, and remain resilient to evolving cyber threats”.



Meanwhile, back in the US, intelligence officials have warned that groups including ISIS and al-Qaeda may have developed ways to build bombs in laptops and other electronic devices that can fool airport security. There are fears that terrorists made the breakthrough after obtaining airport screening equipment to allow them to experiment. FBI experts have tested how the explosives can be hidden inside laptop battery compartments in a way that allows a computer still to be turned on.


The US Department of Homeland Security said in a statement: “Evaluated intelligence indicates that terrorist groups continue to target commercial aviation, to include smuggling explosive devices in electronics.


“The US government continually reassesses existing intelligence and collects new intelligence. This allows us to constantly evaluate our aviation security processes and policies and make enhancements when they are deemed necessary to keep passengers safe.”


Manny Gomez, a former FBI special agent, cited by the Telegraph said: “We had the shoe bomber, cartridge attempt, now this is the next level. We need to be several steps ahead of them.”


For now there have been no effected cyber-terrorist attacks, although few things can redirect public attention and send the world to scramble demanding the "safety of the government" quite like a terrorist attack on a nuclear power plant. We can only hope that despite the overt warnings, such an escalation will not take place.

Saturday, November 5, 2016

BREAKING: US Military Just Hacked Into Russia’s Entire Infrastructure Prepping for Massive Cyber Attack

hacked


Russia is demanding answers after a report from an unnamed senior U.S. intelligence official claimed the United States military has successfully hacked into “Russia’s electric grid, telecommunications networks and the Kremlin’s command systems, making them vulnerable to attack by secret American cyber weapons should the U.S. deem it necessary,” according to NBC News.


Speaking to the anonymous intelligence official and after a review of putative top-secret documents, NBC reported it can confirm long-swirling rumors the U.S. has penetrated critical Russian systems and left behind malware operable from afar and on command.


Russia, understandably, has not taken the news with a grain of salt.


“If no official reaction from the American administration follows,” Russian Foreign Ministry spokesperson Maria Zakharova said in a statement, “it would mean state cyberterrorism exists in the US. If the threats of the attack, which were published by the US media, are carried out, Moscow would be justified in charging Washington.”


Indeed in recent months, hotly escalating tensions between the two Cold War foes has reached a fever pitch — with both the United States and Russia having established albeit thin justifications to strike the other first under the ironic premise of offensive self-defense.


Hillary Clinton’s campaign and the Obama administration continue to tout evidence of Russian interference, both in voluminous hacked leaks of damning documents and in the ongoing military conflict in Syria.


In the last few weeks, anti-Russian rhetoric has centered around the wholly unbased prediction Russia is preparing to actively interfere in the U.S. presidential election on Tuesday — even expanding to include altogether laughable accusations Donald Trump has direct and covert dealings with Moscow.



In fact, the latter point comprised the unnamed intelligence official’s rationalization for the military’s alleged malware implantation in Russian infrastructure.


However, none of these assertions from seemingly paranoid American officials have proven unassailably true — and despite hyperbolic claims that, in essence, Russia has in mind to destroy the U.S., no evidence of a legitimate threat, much less outright aggression, has been uncovered.


Asked repeatedly to produce proof to justify allegations Russian state actors were responsible for hacked documents released to Wikileaks and other organizations, U.S. officials have only managed to counter with further bombast.


Although NBC reports such cyber measures penetrating, testing, and gaining an understanding of foreign nations’ electronic infrastructures is considered nearly de rigueur in the modern context, the bold move of publicizing such an exploit constitutes a bit of a veiled threat.


In 2014, according to NBC, National Security Agency Chief Mike Rogers warned Congress adversarial nations had been performing such exploits to assess chemical treatment plants, the electric grid, and other crucial mechanisms in preparation to strike should the need present itself.


“All of that leads me to believe it is only a matter of when, not if, we are going to see something dramatic,” Rogers said at the time.


On a superficial level, by design, the U.S. government could claim such acts of cyber cold-warfare amount to a defensive move — but in light of deteriorating Russian-American relations in recent months, delving into Russia’s infrastructure could be akin, as the Foreign Ministry suggests, to an act of cyberterrorism.


Positioning malware is not the same as simple cyber reconnaissance and intelligence gathering — and publicizing the act implies not only confidence in its success, but, alarmingly, willingness to trigger it as a weapon.


“You’d gain access to a network, you’d establish your presence on the network and then you’re poised to do what you would like to do with the network,” Retired colonel and legal advisor to U.S. Cyber Command, Gary Brown, told NBC News. “Most of the time you might use that to collect information, but that same access could be used for more aggressive activities too.”


In short, the United States military has now readied itself to act to take down parts of Russia’s critical infrastructure if it so chooses — and with politicians and administration officials continuing to claim without evidence Russian agents hacked government and non-government files, justification could come from thin air.


Think about that.


Without proof, state actors have positioned, at least ostensibly, malware that could leave Russian citizens vulnerable if U.S. officials see any intimation of interference in the coming election — and, based on the U.S. history of failing to provide evidence of Russian aggression, the decision could be made on a dime.


Thus far Russian officials have maintained startling cooler heads than their counterparts, and in response to the NBC report, Kremlin spokesman Dmitry Peskov said in a statement Russia had “cybersecurity measures taken at the level proper for the current situation, and the threats voiced against us by officials of other nations.”


Indeed Russian President Vladimir Putin has even dismissed U.S. claims of interference countless times, including during the 13th annual meeting of the Valdai Club in late October, during which he stated,



Another mythical and imaginary problem is what I can only call the hysteria the USA has whipped up over supposed Russian meddling in the American presidential election. The United States has plenty of genuinely urgent problems, it would seem, from the colossal public debt to the increase in firearms violence and cases of arbitrary action by the police.



You would think that the election debates would concentrate on these and other unresolved problems, but the elite has nothing with which to reassure society, it seems, and therefore attempt to distract public attention by pointing instead to supposed Russian hackers, spies, agents of influence and so forth.


I have to ask myself and ask you too: Does anyone seriously imagine that Russia can somehow influence the American people’s choice? America is not some kind of ‘banana republic’, after all, but is a great power. Do correct me if I am wrong.



Early last month, the United States set the stage for electronic warfare in a formal accusation by the Director of National Intelligence and the Department of Homeland Security that held Russia solely responsible for hacking the Democratic National Committee, and subsequent damaging leaks of thousands of documents.


Now, through briskly sharpened posturing, the U.S. has again declared itself ready to commit an act of what it would consider, were the situation reversed, cyberterrorism and electronic warfare.


Whether or not the Obama administration, the U.S. military and intelligence officials, and the Clinton campaign will rein in this precipitous and arrogant scaremongering is yet to be seen — but the consequences of this dangerous game could affect us all.


“Cyber war is undefined,” Brown cautioned about how to consider the muddled gray-area concerning the putative U.S. hack. “There are norms of behavior that we try to encourage, but people violate those.”