you advocate interfering with their political and economic processes and 
then demonize their advances?
fear and aggression noted.

On Wednesday, December 3, 2014 2:28:39 PM UTC-6, Travis wrote:
>
>
>
>
>
>  
>
>
> http://arstechnica.com/security/2014/12/critical-networks-in-us-15-nations-completely-owned-by-iran-backed-hackers/
>
>  
> Critical networks in US, 15 other nations, completely owned, possibly by 
> Iran
> Operation Cleaver gets near-complete control of airlines, gas producers, 
> defense.
>
> by Dan Goodin <http://arstechnica.com/author/dan-goodin/> - Dec 2 2014, 
> 5:30pm EST 
>
> [image: 
> http://cdn.arstechnica.net/wp-content/uploads/2014/12/operation-cleaver-targets-640x353.jpg]
>  
> <http://cdn.arstechnica.net/wp-content/uploads/2014/12/operation-cleaver-targets.jpg>
>
> Enlarge 
> <http://cdn.arstechnica.net/wp-content/uploads/2014/12/operation-cleaver-targets.jpg>
>  
> / Geographic distribution of victims, as determined by the global 
> headquarters of the parent company or organization breached
>
> Cylance 
>
> For more than two years, pro-Iranian hackers have penetrated some of the 
> world's most sensitive computer networks, including those operated by a 
> US-based airline, auto maker, natural gas producer, defense contractor, and 
> military installation, security researchers said.
>
> In many cases, "Operation Cleaver," as the sustained hacking campaign is 
> being dubbed, has attained the highest levels of system access of targets 
> located in 16 countries total, according to a report published Tuesday 
> <http://www.cylance.com/operation-cleaver/> by security firm Cylance. 
> Compromised systems in the ongoing attacks include Active Directory domain 
> controllers that store employee login credentials, servers running 
> Microsoft Windows and Linux, routers, switches, and virtual private 
> networks. With more than 50 victims that include airports, hospitals, 
> telecommunications providers, chemical companies, and governments, the 
> Iranian-backed hackers are reported to have extraordinary control over much 
> of the world's critical infrastructure. Cylance researchers wrote:
>
> Perhaps the most bone-chilling evidence we collected in this campaign was 
> the targeting and compromise of transportation networks and systems such as 
> airlines and airports in South Korea, Saudi Arabia and Pakistan. The level 
> of access seemed ubiquitous: Active Directory domains were fully 
> compromised, along with entire Cisco Edge switches, routers, and internal 
> networking infrastructure. Fully compromised VPN credentials meant their 
> entire remote access infrastructure and supply chain was under the control 
> of the Cleaver team, allowing permanent persistence under compromised 
> credentials. They achieved complete access to airport gates and their 
> security control systems, potentially allowing them to spoof gate 
> credentials. They gained access to PayPal and Go Daddy credentials allowing 
> them to make fraudulent purchases and allow[ing] unfettered access to the 
> victim’s domains. We were witnessed [sic] a shocking amount of access into 
> the deepest parts of these companies and the airports in which they operate.
>
> Tuesday's 86-page report relies on circumstantial evidence to arrive at 
> the conclusion that the 20 or more hackers participating in Operation 
> Cleaver are backed by Iran's government. Members take Persian handles such 
> as Salman Ghazikhani and Bahman Mohebbi; they work from numerous Internet 
> domains, IP addresses, and autonomous system numbers 
> <https://en.wikipedia.org/wiki/Autonomous_System_%28Internet%29> 
> registered in Iran; and many of the custom-configured hacking tools they 
> use issue warnings when their external IP addresses trace back to the 
> Middle Eastern country. The infrastructure supporting the vast campaign is 
> too sprawling to be the work of a lone individual or small group; it could 
> only have been sponsored by a nation state.
> Avenging StuxnetFurther Reading
>
> [image: 
> http://cdn.arstechnica.net/wp-content/uploads/2012/08/oil-eqipment-300x150.png]
>  
> <http://arstechnica.com/security/2012/08/shamoon-malware-attack/>
> Mystery malware wreaks havoc on energy sector computers 
> <http://arstechnica.com/security/2012/08/shamoon-malware-attack/>
>
> Like malware that attacked Iran, Shamoon permanently destroys hard disk 
> data.
>
> The disclosure of Operation Cleaver comes 28 months after highly 
> destructive malware known as Shamoon 
> <http://arstechnica.com/security/2012/08/shamoon-malware-attack/> 
> permanently destroyed data on more than 30,000 computers belonging to Saudi 
> Aramco and RasGas, two large natural gas producers located in Saudi Arabia 
> and Qatar respectively. Around that same time, a series of extremely 
> disruptive denial-of-service attacks knocked out access to major US banks 
> <http://arstechnica.com/security/2012/10/ddos-attacks-against-major-us-banks-no-stuxnet/>.
>  
> A year earlier, in August 2011, hackers penetrated the Dutch certificate 
> authority DigiNotar and made off with digital certificates for Gmail and 
> other high-profile sites 
> <http://www.theregister.co.uk/2011/08/29/fraudulent_google_ssl_certificate/>. 
> Some security researchers have said that Iran was behind all three hacks as 
> part of an effort to retaliate for Stuxnet 
> <http://arstechnica.com/security/2013/02/new-version-of-stuxnet-sheds-light-on-iran-targeting-cyberweapon/>,
>  
> Duqu <http://www.theregister.co.uk/2011/10/18/son_of_stuxnet_disclovered/>, 
> and Flame <http://arstechnica.com/series/flame-malware-eruption/>, 
> malware campaigns widely believed to have been orchestrated by the US and 
> Israel to monitor and disrupt Iran's nuclear programs.
>
> "Iran's cyber sophistication has grown rapidly since the dawn of Stuxnet 
> and they have used hard dollars combined with national pride to help build 
> their cyber army," the Cylance report stated. "Few doubt their commitment 
> as a government and nation state to funding and recruiting cyber warriors 
> to infiltrate and damage their enemies. And it has been commonly postulated 
> that almost all activity since 2010 coming out of Iran is associated with 
> retaliation for Stuxnet/Duqu/Flame, which seems natural given the severity 
> of the impact."
>
> Most of the Operation Cleaver attacks detected by Cylance began with small 
> incursions into a target system, using techniques such as SQL injection 
> exploits to pipe commands into the back-end server of a website. From 
> there, the hackers elevated their access by targeting unpatched 
> vulnerabilities such as MS08-067 
> <https://technet.microsoft.com/en-us/library/security/ms08-067.aspx>. The 
> attackers would then install a battery of customized tools on the servers 
> that gave the attackers a variety of capabilities. In at least one case, a 
> target's private signing certificates were captured, allowing the team to 
> compromise the rest of the target's infrastructure. Unlike Stuxnet, there's 
> no evidence any zero-day vulnerabilities were exploited.
>
> Over the past two years, Cylance has collected more than eight gigabytes 
> of data connected to the campaign, including 80,000 files of captured data, 
> hacker tools, victim logs, and highly sensitive reconnaissance data. The 
> researchers retrieved the data by using the Internet's domain name system 
> to divert traffic traveling between compromised systems and the attackers' 
> command and control servers, a process known as "sink holing."
> Only a fraction detected
>
> In all, 50 targets in 16 countries are known to have been compromised. The 
> tally includes 10 victims in the US, four in Israel, and five in Pakistan. 
> Groups in the UK, France, Germany, and numerous Middle Eastern countries 
> were also hit. The Cylance report includes in-depth technical details to 
> help system administrators determine if their systems were compromised.
>
> Cylance researchers said they believe they detected only a fraction of the 
> targets penetrated by Operation Cleaver. With more than two years it has 
> been active, they warned time may be running out.
>
> "We believe that if the operation is left to continue unabated, it is only 
> a matter of time before the world’s physical safety is impacted by it," 
> they wrote. "While the disclosure of this information will be a detriment 
> to our ability to track the activity of this group, it will allow the 
> security industry as a whole to defend against this threat. As such, we are 
> exposing this cyber campaign early in an attempt to minimize additional 
> real-world impact and prevent further victimization."
>
>  
>
>
> __._,_.___
>  ------------------------------
> Posted by: "beowulf" <[email protected] <javascript:>> 
> ------------------------------
>  
>
>  Visit Your Group 
> <https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmNnE5dWgwBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MTc2MjgzMDg->
>  
>    
>    
>  [image: Yahoo! Groups] 
> <https://groups.yahoo.com/neo;_ylc=X3oDMTJlNDZjZXQ0BF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQxNzYyODMwOA-->
>  
> • Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> • 
> Unsubscribe <javascript:> • Terms of Use 
> <https://info.yahoo.com/legal/us/yahoo/utos/terms/> 
>  
> __,_._,___
>
>
>

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to