Google Search

Showing posts with label targeted. Show all posts
Showing posts with label targeted. Show all posts

Sunday, February 10, 2013

Zero day vulnerability in Internet Explorer being used in targeted attacks, FixIt now available

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft releases fix for Internet Explorer security hole, full patch coming FridayInternet Explorer users beware, there is a new zero day (previously unknown, unpatched vulnerability) attack targeting your browser.

Microsoft has issued an advisory about the flaw and it is being referred to as CVE-2012-4792. Microsoft has also made a temporary FixIt available until it can deliver a formal patch.

The flaw affects users of Internet Explorer 6, 7 and 8, but not 9 or 10 and allows for remote code execution with the privileges of the logged in user.

Another poignant reminder that running your computer as a non-administrative user pays off when new flaws are uncovered.

Non-privileged users will severely limit the damage that can be done using a vulnerability like this one.

The vulnerability was initially
" href="http://blog.fireeye.com/research/2012/12/council-foreign-relations-water-hole-attack-details.html" rel="nofollow">discovered by FireEye on the Council on Foreign Relations website on December 27th, 2012.

SophosLabs has records showing the Council's website infected as far back as December 7th.

We have seen the exploit used on at least five additional websites suggesting the attack is more widespread than originally thought.

The attack appears to be closely related to attacks we reported on last June that were targeting visitors to a major hotel chain.

While the vulnerability being exploited is entirely different, the payload is nearly identical to the hotel attack and others we have associated with the Elderwood Project.

shutterstock-Wateringhole200While the attacks appeared to be targeted to a small number of sites, there is no obvious link between the victims.

Some are referring to this as a "watering hole" attack, but the evidence we have doesn't necessarily support that conclusion.

If you use Internet Explorer, be sure you are using at least version 9 to avoid being a victim of these attacks. If you can't upgrade, consider using an alternative browser until an official fix is available.

Microsoft's FixIt is intended as a temporary workaround that could also be considered, but until an official fix is available I recommend avoiding IE 8 and lower.

If further information becomes available, we will publish the latest here on Naked Security.

Sophos Anti-Virus on all platforms blocks this malware as follows:

Sus/20124792-B: Misc. files specifically associated with this attack
Sus/Yoldep-A: Encoded payload also seen in other Elderwood Project attacks
Troj/SWFExp-BF: Adobe Flash component
Sus/DeplyJv-A: JavaScript components evolved from earlier Elderwood Project attacks

Follow @chetwisniewski

Watering hole photo courtesy of Shutterstock.


View the original article here

Wednesday, February 6, 2013

Iran claims discovery of new targeted malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Target: IranOn Sunday, December 16th the Iranian CERT issued an advisory warning of a new "targeted data wiping malware."

SophosLabs analyzed these new samples and can confirm that they do in fact attempt to erase the contents of any files on the D:, E:, F:, G:, H: and I: drives.

What is less apparent is why Iran considers this malware to be targeted and, if this malware is indicative of the sophistication of their adversaries, why they are concerned at all.

The Trojan is distributed as a self-extracting WinRAR archive called GrooveMonitor.exe. Once executed it drops juboot.exe, jucheck.exe and SLEEP.EXE.

Juboot.exe and jucheck.exe appear to mask themselves as a Java autoupdate program, whereas SLEEP.EXE is not malware, but a freeware tool to delay application startup.

Juboot.exe is actually a simple DOS BAT file that has been converted to a Windows PE (Portable Executable) file using a Batch to Exe Converter. It uses SLEEP.EXE to wait for two seconds, then sets a registry key to start jucheck.exe on system boot.

Upon execution jucheck.exe waits two seconds, erases GrooveMonitor.exe and juboot.exe, then checks to see if the date matches any of the following:

10-December-2012 to 12-December-2012
21-January-2013 to 23-January-2013
06-May-2013 to 08-May-2013
22-July-2013 to 24-July-2013
11-November-2013 to 13-November-2013
3-February-2014 to 5-February-2014
5-May-2014 to 7-May-2014
11-August-2014 to 13-August-2014
2-February-2015 to 4-February-2015.

If the date matches, it waits for 50 minutes, then performs a recursive delete on the aforementioned drive letters and deletes everything from the user's desktop.

It also attempts to start calc.exe, but fails due to a typo.

The circumstances that have led to Iran's decision that this is a targeted attack are unknown. This is one of the most rudimentary malware samples seen in years.

Compared to other alleged state-sponsored attacks like Stuxnet, Duqu, Flame and Shamoon, this malware bears no resemblance.

We were able to discover a further variant that looks to replace jucheck.exe and is called Wmiprv.exe.

This version tries to delete GrooveMonitor.exe from C:\Documents and settings\All Users\Start Menu\Programs\Startup\ and runs in an endless loop every 50 minutes to erase the drives.

This is likely indicative of a more advanced dropper file and a way to be sure to harm machines that are not rebooted during the specified time windows.

Why Iran is drawing attention to this is anybody's guess. It does go to show that malware doesn't need to be sophisticated to cause trouble though. If you can execute arbitrary files, all it takes is a few lines in a batch file and some wrappers to cause serious damage.

Sophos Anti-Virus on all platforms detects and blocks this malware as follows:

* Troj/BatDel-B: Detects all known components and variants of this malware including:

GrooveMonitor.exe (MD5 f3dd76477e16e26571f8c64a7fd4a97b)
juboot.exe (MD5 fa0b300e671f73b3b0f7f415ccbe9d41)
jucheck.exe (MD5 c4cd216112cbc5b8c046934843c579f6)
Wmiprv.exe (MD5 b7117b5d8281acd56648c9d08fadf630)

Thank you to Gabor Szappanos and Boris Lau from SophosLabs for providing the detailed analysis of this malware.

Follow @chetwisniewski
Follow @SophosLabs

Image of weapon pointed at Iranian flag courtesy of Shutterstock.


View the original article here

Wednesday, October 24, 2012

Leading US banks targeted in DDoS attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Bank. Image from ShutterstockAttacks against the websites of leading banks in the United States have the banking and financial services industry on edge.

The Financial Services ISAC (Information Sharing and Analysis Center) set its Threat Level to “High” on Wednesday, September 19, indicating a high risk of cyber attacks.

That proved prophetic, as websites for banks including Bank of America, JP Morgan Chase and Wells Fargo suffered outages in recent days that some are attributing to politically motivated hacktivist groups.

A string of statements posted online in the last week has claimed responsibility for the attacks in the name of a Muslim hacking group calling itself Izz ad-Din al Qassam Cyber Fighters.

The group has claimed responsibility for attacks on the New York Stock Exchange, Bank of America and Chase last week. This week brought attacks against Wells Fargo, US Bank and PNC.

Wells FargoWells Fargo used its Twitter account to apologize for service interruptions on Wednesday and said it was working to "quickly resolve this issue." Most of the targeted banks were back online and operational Thursday.

The events prompted U.S. Senator Joe Lieberman (I-CT) to use an interview on C-SPAN to point the finger of blame at the Iranian government and its elite Quds Force.

Lieberman said he believed the attacks were in retaliation for attacks on that country’s nuclear program, though he didn’t offer any evidence to support his claim. Gholam Reza Jalali, the head of Iran’s Civil Defense Organization, denied that the country was behind the attacks in a statement to Iran’s Fars News Agency.

Public statements on Pastebin taking credit for the attacks don’t mention Iran’s nuclear program as a motivation.

However, they do mention the roiling controversy about the anti-Islamic film "Innocence of Muslims" that has provoked riots and civil unrest throughout the Muslim world.

"These series of attacks will continue until the Erasing of that nasty movie from the Internet," one statement reads.

Of course, as is always the case, it was impossible to verify the authenticity of any of the statements posted online or their connection to whomever is responsible for the attacks against the banking websites.

Politically motivated hacks – or hacktivism – have been on the rise in recent years, with the activities of Western-based groups like Anonymous and Lulzsec drawing attention to the doings of ideologically motivated hacking crews.

But the phenomenon isn’t limited to Europe and the United States.

Politically aligned hacking groups are also common in Asia and the Middle East. Notably: a group called Electr0n defaced Libya’s top level domain with messages opposed to then-dictator Muammar Gaddafi.

Follow @paulfroberts
Follow @NakedSecurity

Bank image from Shutterstock.

Tags: Bank of America, Banking, BoA, Chase, DDoS, denial of service, hacking, hacktivism, Iran, Izz ad-Din al Qassam Cyber Fighters, US Bank, Wells Fargo


View the original article here

Thursday, August 30, 2012

Targeted destructive malware explained: Troj/Mdrop-ELD

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I work in SophosLabs, and one of my jobs is to write detections for new malware. What makes this piece of malware stand apart is that it is targeted.

On the afternoon of 15 August, SophosLabs received a file called str.exe that claimed to be a Microsoft file:

screenshot of the properties of str.exe

At first glance, the file didn't look to be legitimate, so I launched the program. It copied itself to:

c:\windows\system32\trksvr.exe

The file contained some interesting strings:

trksvr.exe
trksrv.exe
testdomain.com
\System32\cmd.exe /c "ping -n 30 127.0.0.1 >;nul && sc config TrkSvr binpath= system32\trksrv.exe && ping -n 10 127.0.0.1 >;nul && sc start TrkSvr"

Immediately, I became suspicious. There is the apparent misspelling of trksvr (it is also called trksrv in the file - spot the difference?), the use of testdomain.com, and the hackerish way that the code started itself as a service.

The more technical of you might have noticed that the code is interspersed by the command ping -n 30 127.0.0.1, which pauses between actions (about 30 seconds each time on my test machine).

I was confident it was malicious. And, because no other security lab seemed to detect the file, I picked a name, Troj/MDrop-ELD, wrote a quick detection, and went home.

The next day, we saw a flurry of queries about a "new" piece of malware called Disttrack or Shamoon. It turned out that it was the same piece of malware that I had detected the previous night. So one of my colleagues did some more detailed analysis.

Thanks to Darrel for the following information:

Troj/MDrop-ELD is a targeted attack; due to some quirks of the malware, there's currently no chance of data exfiltration (unless you happen to be the company targeted by this attack).

Troj/MDrop-ELD attempts to contact IP address 10.1.252.19 - this is probably the internal IP address of the first owned machine in the target's network - on ports 1103 (xrl) and 1104 (adobeserver).

Troj/MDrop-ELD attempts to gather information about the target's machines:

dir "C:\Documents and Settings\" /s /b /a:-D 2>;nul | findstr -i download
2>;nul >;f1.inf
dir "C:\Documents and Settings\" /s /b /a:-D 2>;nul | findstr -i document
2>;nul >;>;f1.inf
dir C:\Users\ /s /b /a:-D 2>;nul | findstr -i download 2>;nul >;>;f1.inf dir C:\Users\ /s /b /a:-D 2>;nul | findstr -i document 2>;nul >;>;f1.inf dir C:\Users\ /s /b /a:-D 2>;nul | findstr -i picture 2>;nul >;>;f1.inf dir C:\Users\ /s /b /a:-D 2>;nul | findstr -i video 2>;nul >;>;f1.inf dir C:\Users\ /s /b /a:-D 2>;nul | findstr -i music 2>;nul >;>;f1.inf dir "C:\Documents and Settings\" /s /b /a:-D 2>;nul | findstr -i desktop
2>;nul >;f2.inf
dir C:\Users\ /s /b /a:-D 2>;nul | findstr -i desktop 2>;nul >;>;f2.inf dir C:\Windows\System32\Drivers /s /b /a:-D 2>;nul >;>;f2.inf dir C:\Windows\System32\Config /s /b /a:-D 2>;nul | findstr -v -i systemprofile 2>;nul >;>;f2.inf dir f1.inf /s /b 2>;nul >;>;f1.inf dir f2.inf /s /b 2>;nul >;>;f1.inf

This Trojan then attempts to overwrite a number of files in the *userprofile areas of the disk, killing various .lnk, .bmp, .ini, .cab etc file types with a broken JPG (JFIF) file. It also attempts to overwrite the MBR, rendering the machine unbootable. This is most likely being used to obfuscate the source of the user's infection and prevent Data Recovery on the system.

While this is going to be quite frustrating and annoying for users, the good news is that this piece of malware doesn't do anything unrecoverable. The various overwritten files are non-critical ones, so infected machines can be fixed with a fixmbr command from some boot media.

Sophos customers have been protected against this attack since Wednesday 15 August. As always, we are reminded that it is important to back up systems regularly. This particular piece of malware didn't destroy important files permanently, but the next one might.

Follow @sophoslabs

Trojan image from Shutterstock.


View the original article here

Monday, August 13, 2012

Poisoned DOC file used in targeted malware attack against military contractor

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Gas mask. Image from ShutterstockExperts at SophosLabs are recommending that businesses and organisations check that they are keeping up-to-date with their security patches, in the light of a malware attack that was seen today - targeting a defence contractor.

The attack is similar in nature to one which SophosLabs intercepted a couple of years ago, where a malicious PDF file claiming to be about the Trident D-5 missile, launched from nuclear submarines, was sent to a military contractor.

The latest attack was sent to the contractor - whose name is not being made public by Sophos - embedded inside a file called Details.Doc, attached to the following email:

Targeted email attack

Dear Sir,

It is so nice to contact you!

We write to inform you that we are some question for your.
View attached document for the detail.
Looking forward to hearing from you soon!

Many thanks and best regards!

trav.whan

The email pretends to be from a YAHOO.COM.TW address but the headers show that emails did not come from YAHOO.

Part of the email's header

The IP is actually from a personal computer:

Received: from travwhanpc (61-220-44-2xx.HINET-IP.hinet.net [61.220.44.2xx])

The email's attachment - titled Details.doc - exploits the CVE-2012-0158 vulnerability.

Unusually, the file really is an OLE2 format DOC file, despite the majority of files exhibiting this vulnerability being RTF files.

The boobytrapped file tries to drop and execute executable code (in the form of an .EXE file) which will install the 'PittyTiger' backdoor onto the victim's Windows PC.

Malicious code hex dump

SophosLabs has released detection for the DOC file as Troj/DocDrop-AF and the EXE as Troj/BckDrPT-AA.

SophosLabs have seen large number of files exploiting the CVE-2012-0158 vulnerability being emailed to companies in a diverse number of sectors - not just those in defence.

The Microsoft security patch, MS12-027, has been available for 3 months now and there are really no excuses for not having applied it.

Follow @SophosLabs

Gas mask image from Shutterstock.


View the original article here

Monday, June 25, 2012

Gmail accounts targeted by 'state-sponsored attackers' using Internet Explorer zero-day vulnerability

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

IE and GmailBoth Google and Microsoft have put out alerts about an unpatched, zero-day hole in Internet Explorer that didn't get fixed on Patch Tuesday and is actively being exploited in the wild.

According to ZDNet, those attacks are apparently being launched by the "state-sponsored attackers" that Google warned Gmail users about last week.

Neither Google nor Microsoft referred to those state attackers in their respective security warnings. ZDNet attributed that particular detail to a source it said was "close to these investigations".

This source confirmed to ZDNet that the attacks motivated Google to warn Gmail users last week about the attackers.

As ZDNet pointed out, Gmail users have been reporting on Twitter that they've been hit by the Gmail warning.

Google security engineer Andrew Lyons wrote in the company's security blog that Google reported the vulnerability to Microsoft on May 30 and that the two companies have been working on the problem since.

He wrote on Tuesday:

Today Microsoft issued a Security Advisory describing a vulnerability in the Microsoft XML component. We discovered this vulnerability - which is leveraged via an uninitialized variable - being actively exploited in the wild for targeted attacks.

Lyons said that the attacks are spreading both from malicious web pages set up to snare Internet Explorer users and through Office documents.

Users running any flavor of supported Windows are vulnerable, from XP onwards up to and including Windows 7. All supported editions of Microsoft Office 2003 and Microsoft Office 2007 are also vulnerable.

The hole hasn't been stitched up yet, but Microsoft is suggesting a workaround that will help prevent it from being exploited.

Microsoft Fix itMicrosoft's security advisory recommends that IE and Office users immediately install a Fix it solution, downloadable with instructions from Microsoft Knowledge Base Article 2719615, until the company gets the final fix out.

The vulnerability crops up when Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 try to access an object in memory that hasn't been initialized, which can corrupt memory such that an attacker could execute arbitrary code on a hijacked machine.

A victim would have to visit a maliciously crafted site using IE to suffer an attack. An attacker might lure users into visiting a boobytrapped site by enticing them to click on a link in an email or via messaging.

A successful attack grants the intruder the same user rights as the logged-on user. Therefore, a mitigating factor is to configure accounts with fewer rights, as opposed to operating with administrative user rights.

Microsoft noted that by default, IE on Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2 runs in a restricted mode known as Enhanced Security Configuration. That also mitigates the vulnerability.

As far as bolting down Gmail goes, Sophos's Graham Cluley has a collection of tips on how to stop your Gmail account from getting hacked.

Gmail login screenIt's definitely worth a read. Here's a quick cheat-sheet; Graham gives you more detail on these items in his article:

OK, that last one's not a tip, per se, but it's food for thought if you are, in fact, important enough that a state would want to attack your Gmail account.

If you are, think twice about using a free web email provider for sensitive information. If you're working for the government or the military, like Graham said, put all that sensitive information on secure systems instead.

Follow @LisaVaas
Hairy spider image, courtesy of Shutterstock.

Tags: 2719615, gmail, Google, IE, Internet Explorer, Microsoft, Microsoft XML Core Services, Office, security advisory, state-sponsored attackers, Windows, XML Core Services, Zero Day


View the original article here

Saturday, June 16, 2012

Online romantics targeted by dating site phishing attack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Cursor on heart. Image courtesy of ShutterstockMore and more people are looking for love online.

As a consequence, millions of people have created accounts on online dating websites, which they have filled with personal information and (typically) poorly lit webcam photographs of themselves.

One of the leading dating websites is Match.com, which means that many people might have been tempted to click on the link in this spammed-out email:

Match.com phishing email

Subject: Match.com account verification

Message body:
Our Valued Customer,
You Have 1 New Security Message Alert !
Click here to resolve the problem
Thank you for helping us to protect you.

Yours Sincerely,
Match Online

Fortunately, the bogus website that potential victims are taken to is hardly the most convincing replica of the real Match.com website:

Match.com phishing website

Of course, if you do mistakenly enter your login credentials onto the phishing website, you may not only be handing over control of your dating account to unknown cybercriminals.

They could see if you're one of the many people who use the same password on multiple websites, and explore whether your Match.com password might also unlock - say - your email account.

The bad guys could also line you up for a more convincing targeted attack, using your personal information to lure you into believing you are receiving a legitimate communication from Match.com, perhaps tempting you into clicking a link by showing you possible dates. That link could lead to malware, identity theft or further compromise of your online accounts.

The cybercriminals are not just interested in breaking into your bank accounts. Any information which they can mine from you for monetary purposes, or opportunity to infect your computer, is an attractive goal.

If you're engaged in online dating you're advised to take steps to protect yourself, and are wise to look before you leap. The same should be true if you want to avoid being phished. Always be wary of unsolicited email messages, and think before you click.

Follow @gcluley

Hat tip: Thanks to Naked Security reader Kevin for bringing this phishing campaign to our attention.

Mouse cursor on heart image courtesy of Shutterstock.


View the original article here

Wednesday, June 6, 2012

Flame malware - more details of targeted cyber attack in Middle East

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Filed Under: Featured, Malware

Flame image courtesy of ShutterstockEarlier today, when I first reported on Flame malware that is said to have targeted Iranian computer systems, there was precious little detail.

It seems the reason for the scant information was that an embargo had been put on the media, who were waiting for the magic time of 2pm UK time to publish their stories.

Sure enough, this afternoon much more colour has been brought to the story and high profile news websites such as the BBC and Wired are telling the story of how Flame has been seen on computers in the Middle East, and Iran in particular.

Firstly, The Laboratory of Cryptography and System Security (CrySyS) at the Budapest University of Technology and Economics has published an indepth analysis on the malware, which it has named "Skywiper".

CrySyS's 63-page PDF report says that it began to analyse the malware earlier this month, and hypothesises that it was "developed by a government or nation state with signigficant budget and effort, and may be related to cyber warfare activities."

CrySys report

It is worth noticing that CrySyS received information about computers being infected with Skywiper in various countries, not just the Middle East. In fact, CrySyS noted that it had even received evidence of infections in it home country of Hungary.

One aspect of interest in CrySyS's report is how Skywiper attempts to evade detection by anti-virus products by storing its code in .OCX files (not usually checked by anti-virus products in their default configuration). However, if the malware detects the presence of McAfee's on-access scanner (McShield) it stores its code in .TMP files instead:

CrySys report

Other tricks that Skywiper/Flame might have up its sleeve may take some time to ascertain. It's code more than twenty times larger than Stuxnet, which means it could take substantial effort to analyse it all. Fortunately, complete code analysis is not necessary to add detection.

And now that the cat's out of the bag anyway - you have to ask yourself, who is likely to continue to use Skywiper/Flame now it has received this much attention both from the media and from the computer security industry?

At the same time as CrySyS's Skywiper report was released, anti-virus vendor Kaspersky published a report, claiming that the United Nations' International Telecommunication Union had approached the firm asking it to analyse malware believed to be wiping information from Middle Eastern computers.

The top 7 countries affected by Flame, according to Kaspersky

Kaspersky's Alexander Gostev wrote that Flame (as he called the malware that the Russian firm analysed) "might be the most sophisticated cyber weapon yet unleashed."

Although Kaspersky was initially hesitant of suggesting that Skywiper and Flame (called "Flamer" by the Iranian authorities) were the same thing, it's now clear that they are.

SophosLabs is in the process of receiving samples of the malware and will add detection as soon as possible.

We will update this article as more information becomes available.

Follow @gcluley

Flames image courtesy of Shutterstock.


View the original article here

Wednesday, November 23, 2011

Foreign hackers targeted US water plant in apparent malicious cyber attack ... - Washington Post (blog)

Foreign hackers caused a pump at an Illinois water plant to fail last week, according to a preliminary state report. Experts said the cyber-attack, if confirmed, would be the first known to have damaged one of the systems that supply Americans with water, electricity and other essentials of modern life.

Companies and government agencies that rely on the Internet have for years been routine targets of hackers, but most incidents have resulted from attempts to steal information or interrupt the functioning of Web sites. The incident in Springfield, Ill., would mark a departure because it apparently caused physical destruction.

Federal officials confirmed that the FBI and the Department of Homeland Security were investigating damage to the water plant but cautioned against concluding that it was necessarily a cyber-attack before all the facts could be learned. “At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety,” said DHS spokesman Peter Boogaard.

News of the incident became public after Joe Weiss, an industry security expert, obtained a report dated Nov. 10 and collected by an Illinois state intelligence center that monitors security threats. The original source of the information was unknown and impossible to immediately verify.

The report, which Weiss read to The Washington Post, describes how a series of minor glitches with a water pump gradually escalated to the point where the pump motor was being turned on and off frequently. It soon burned out, according to the report.

The report blamed the damage on the actions of somebody using a computer registered to an Internet address in Russia. “It is believed that hackers had acquired unauthorized access to the software company’s database” and used this information to penetrate the control system for the water pump.

Experts cautioned that it is difficult to trace the origin of a cyber-attack, and that false addresses often are used to confuse investigations. Yet they also agreed that the incident was a major new development in cyber-security.

“This is a big deal,” said Weiss. “It was tracked to Russia. It has been in the system for at least two to three months. It has caused damage. We don’t know how many other utilities are currently compromised.”

Dave Marcus, director of security research for McAfee Labs, said that the computers that control critical systems in the United States are vulnerable to attacks that come through the Internet, and few operators of these systems know how to detect or defeat these threats. “So many are ill-prepared for cyber-attacks,” Marcus said.

The Illinois report said that hackers broke into a software company’s database and retrieved user names and passwords of control systems that run water plant computer equipment. Using that data, they were able to hack into the plant in Illinois, Weiss said.

Senior U.S. officials have recently raised warnings about the risk of destructive cyber-attacks on critical infrastructure. One of the few documented cases of such an attack resulted from a virus, Stuxnet, that caused centrifuges in an Iranian uranium enrichment facility to spin out of control last year. Many computer security experts have speculated that Stuxnet was created by Israel — perhaps with U.S. help — as a way to check Iran’s nuclear program.

More cybersecurity coverage

- Proactive steps against cyberattacks

- Pentagon: Offensive cyber attacks fair game

- Cyberspying report names China, Russia

- In cyberspace, growing calls for clarity on what U.S. can do to deter against attacks


View the original article here

Tuesday, November 22, 2011

Report: Russian hackers targeted Springfield water pump - WJBC News

SPRINGFIELD – Federal officials are investigating a report that Russian hackers shut down a water pump near Springfield last week.

The Springfield Journal-Register reports the Curran-Gardner Public Water District may have been targeted by the alleged cyberattack. The U.S. Department of Homeland Security is investigating, but no major service disruption was reported.

The Nov. 8 water-pump burnout was first reported by a cybersecurity blog, based on a one-page report from the Illinois Statewide Terrorism and Intelligence Center.

A water district trustee says there’s some indication of an attempt to breach the system’s Supervisory Control and Data Acquisition computer system, but no confirmation yet.

No word on why the tiny water district was targeted.

jQuery.fbInit({fb_options:{appId: '190997570932575',channelUrl: 'http://wjbc.com/wp-content/plugins/facebook/library/channel.html'}});

View the original article here