you advocate interfering with their political and economic processes and then demonize their advances? fear and aggression noted.
On Wednesday, December 3, 2014 2:28:39 PM UTC-6, Travis wrote: > > > > > > > > > http://arstechnica.com/security/2014/12/critical-networks-in-us-15-nations-completely-owned-by-iran-backed-hackers/ > > > Critical networks in US, 15 other nations, completely owned, possibly by > Iran > Operation Cleaver gets near-complete control of airlines, gas producers, > defense. > > by Dan Goodin <http://arstechnica.com/author/dan-goodin/> - Dec 2 2014, > 5:30pm EST > > [image: > http://cdn.arstechnica.net/wp-content/uploads/2014/12/operation-cleaver-targets-640x353.jpg] > > <http://cdn.arstechnica.net/wp-content/uploads/2014/12/operation-cleaver-targets.jpg> > > Enlarge > <http://cdn.arstechnica.net/wp-content/uploads/2014/12/operation-cleaver-targets.jpg> > > / Geographic distribution of victims, as determined by the global > headquarters of the parent company or organization breached > > Cylance > > For more than two years, pro-Iranian hackers have penetrated some of the > world's most sensitive computer networks, including those operated by a > US-based airline, auto maker, natural gas producer, defense contractor, and > military installation, security researchers said. > > In many cases, "Operation Cleaver," as the sustained hacking campaign is > being dubbed, has attained the highest levels of system access of targets > located in 16 countries total, according to a report published Tuesday > <http://www.cylance.com/operation-cleaver/> by security firm Cylance. > Compromised systems in the ongoing attacks include Active Directory domain > controllers that store employee login credentials, servers running > Microsoft Windows and Linux, routers, switches, and virtual private > networks. With more than 50 victims that include airports, hospitals, > telecommunications providers, chemical companies, and governments, the > Iranian-backed hackers are reported to have extraordinary control over much > of the world's critical infrastructure. Cylance researchers wrote: > > Perhaps the most bone-chilling evidence we collected in this campaign was > the targeting and compromise of transportation networks and systems such as > airlines and airports in South Korea, Saudi Arabia and Pakistan. The level > of access seemed ubiquitous: Active Directory domains were fully > compromised, along with entire Cisco Edge switches, routers, and internal > networking infrastructure. Fully compromised VPN credentials meant their > entire remote access infrastructure and supply chain was under the control > of the Cleaver team, allowing permanent persistence under compromised > credentials. They achieved complete access to airport gates and their > security control systems, potentially allowing them to spoof gate > credentials. They gained access to PayPal and Go Daddy credentials allowing > them to make fraudulent purchases and allow[ing] unfettered access to the > victim’s domains. We were witnessed [sic] a shocking amount of access into > the deepest parts of these companies and the airports in which they operate. > > Tuesday's 86-page report relies on circumstantial evidence to arrive at > the conclusion that the 20 or more hackers participating in Operation > Cleaver are backed by Iran's government. Members take Persian handles such > as Salman Ghazikhani and Bahman Mohebbi; they work from numerous Internet > domains, IP addresses, and autonomous system numbers > <https://en.wikipedia.org/wiki/Autonomous_System_%28Internet%29> > registered in Iran; and many of the custom-configured hacking tools they > use issue warnings when their external IP addresses trace back to the > Middle Eastern country. The infrastructure supporting the vast campaign is > too sprawling to be the work of a lone individual or small group; it could > only have been sponsored by a nation state. > Avenging StuxnetFurther Reading > > [image: > http://cdn.arstechnica.net/wp-content/uploads/2012/08/oil-eqipment-300x150.png] > > <http://arstechnica.com/security/2012/08/shamoon-malware-attack/> > Mystery malware wreaks havoc on energy sector computers > <http://arstechnica.com/security/2012/08/shamoon-malware-attack/> > > Like malware that attacked Iran, Shamoon permanently destroys hard disk > data. > > The disclosure of Operation Cleaver comes 28 months after highly > destructive malware known as Shamoon > <http://arstechnica.com/security/2012/08/shamoon-malware-attack/> > permanently destroyed data on more than 30,000 computers belonging to Saudi > Aramco and RasGas, two large natural gas producers located in Saudi Arabia > and Qatar respectively. Around that same time, a series of extremely > disruptive denial-of-service attacks knocked out access to major US banks > <http://arstechnica.com/security/2012/10/ddos-attacks-against-major-us-banks-no-stuxnet/>. > > A year earlier, in August 2011, hackers penetrated the Dutch certificate > authority DigiNotar and made off with digital certificates for Gmail and > other high-profile sites > <http://www.theregister.co.uk/2011/08/29/fraudulent_google_ssl_certificate/>. > Some security researchers have said that Iran was behind all three hacks as > part of an effort to retaliate for Stuxnet > <http://arstechnica.com/security/2013/02/new-version-of-stuxnet-sheds-light-on-iran-targeting-cyberweapon/>, > > Duqu <http://www.theregister.co.uk/2011/10/18/son_of_stuxnet_disclovered/>, > and Flame <http://arstechnica.com/series/flame-malware-eruption/>, > malware campaigns widely believed to have been orchestrated by the US and > Israel to monitor and disrupt Iran's nuclear programs. > > "Iran's cyber sophistication has grown rapidly since the dawn of Stuxnet > and they have used hard dollars combined with national pride to help build > their cyber army," the Cylance report stated. "Few doubt their commitment > as a government and nation state to funding and recruiting cyber warriors > to infiltrate and damage their enemies. And it has been commonly postulated > that almost all activity since 2010 coming out of Iran is associated with > retaliation for Stuxnet/Duqu/Flame, which seems natural given the severity > of the impact." > > Most of the Operation Cleaver attacks detected by Cylance began with small > incursions into a target system, using techniques such as SQL injection > exploits to pipe commands into the back-end server of a website. From > there, the hackers elevated their access by targeting unpatched > vulnerabilities such as MS08-067 > <https://technet.microsoft.com/en-us/library/security/ms08-067.aspx>. The > attackers would then install a battery of customized tools on the servers > that gave the attackers a variety of capabilities. In at least one case, a > target's private signing certificates were captured, allowing the team to > compromise the rest of the target's infrastructure. Unlike Stuxnet, there's > no evidence any zero-day vulnerabilities were exploited. > > Over the past two years, Cylance has collected more than eight gigabytes > of data connected to the campaign, including 80,000 files of captured data, > hacker tools, victim logs, and highly sensitive reconnaissance data. The > researchers retrieved the data by using the Internet's domain name system > to divert traffic traveling between compromised systems and the attackers' > command and control servers, a process known as "sink holing." > Only a fraction detected > > In all, 50 targets in 16 countries are known to have been compromised. The > tally includes 10 victims in the US, four in Israel, and five in Pakistan. > Groups in the UK, France, Germany, and numerous Middle Eastern countries > were also hit. The Cylance report includes in-depth technical details to > help system administrators determine if their systems were compromised. > > Cylance researchers said they believe they detected only a fraction of the > targets penetrated by Operation Cleaver. With more than two years it has > been active, they warned time may be running out. > > "We believe that if the operation is left to continue unabated, it is only > a matter of time before the world’s physical safety is impacted by it," > they wrote. "While the disclosure of this information will be a detriment > to our ability to track the activity of this group, it will allow the > security industry as a whole to defend against this threat. As such, we are > exposing this cyber campaign early in an attempt to minimize additional > real-world impact and prevent further victimization." > > > > > __._,_.___ > ------------------------------ > Posted by: "beowulf" <[email protected] <javascript:>> > ------------------------------ > > > Visit Your Group > <https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmNnE5dWgwBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MTc2MjgzMDg-> > > > > [image: Yahoo! Groups] > <https://groups.yahoo.com/neo;_ylc=X3oDMTJlNDZjZXQ0BF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQxNzYyODMwOA--> > > • Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> • > Unsubscribe <javascript:> • Terms of Use > <https://info.yahoo.com/legal/us/yahoo/utos/terms/> > > __,_._,___ > > > -- -- Thanks for being part of "PoliticalForum" at Google Groups. For options & help see http://groups.google.com/group/PoliticalForum * Visit our other community at http://www.PoliticalForum.com/ * It's active and moderated. Register and vote in our polls. * Read the latest breaking news, and more. --- You received this message because you are subscribed to the Google Groups "PoliticalForum" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
