Showing posts with label Shadow Brokers. Show all posts
Showing posts with label Shadow Brokers. Show all posts

Wednesday, April 12, 2017

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks
The US National Security Agency (NSA) has been spying on Pakistan’s mobile networks, whistleblowing organisation WikiLeaks has tweeted. “Hundreds of NSA cyber weapons variants publicly released including code showing hacking of Pakistan mobile system,” @wikileaks tweeted.
According to a report in Express Tribune on Monday, the hacker group “Shadow Brokers” released a new cache of information detailing how the NSA accessed private and public networks in other countries. A researcher on Twitter who identifies himself as ‘x0rz’ decrypted the files and uploaded them on Github, a web-based repository and internet hosting service.
“The researcher confirmed that the archives include evidence of NSA operators’ access inside the GSM network of Mobilink – one of the Pakistan’s most popular mobile services provider,” the report noted. The hacker group had previously released data suggesting the US agency may have been monitoring hundreds of IP addresses in Pakistan. The encrypted files were being decrypted by security researchers around the world.
“Shadow Brokers” had initially wanted to auction its data cache in exchange for Bitcoin but as no buyer turned up, they released the data online. This is not the first time that reports have surfaced claiming that the US NSA is snooping on other countries. According to a Daily Mail report in 2014, WikiLeaks disclosed documents that suggested the Bharatiya Janata Party (BJP) was among six political parties from around the world the NSA was authorised to conduct surveillance on for gathering foreign intelligence. The authorisation was given by a secret American court, it said.
The leak was planned months ahead of Prime Minister Narendra Modi’s visit to the US, the report claimed. Another report in the Washington Post that also came in 2014 said the US has long had broad no-spying arrangements with four countries – Britain, Canada, Australia and New Zealand – in a group known collectively as the “Five Eyes”.
“But a classified 2010 legal certification – approved by the Foreign Intelligence Surveillance Court and included among a set of documents leaked by former NSA contractor Edward Snowden – lists 193 countries [including India], that would be of valid interest for US intelligence,” the Post said.
Publish date: April 12, 2017 11:45 am| Modified date: April 12, 2017 11:41 am

Tuesday, November 1, 2016

Shadow Brokers reveal more tools from NSA trove

Shadow Brokers reveal more tools from NSA trove

Image Credit: Venture Beat
A group calling itself “Shadow Brokers” says it has released another gem from its trove of high-level hacking tools stolen from the U.S.’s National Security Agency, potentially offering added insight into how America’s spies operate online. The leak discloses NSA-style codenames — including “Jackladder” and “Dewdrop”— and carries internet protocol information about scores of organizations, many based in Japan, China and South Korea, according to severalexperts who have examined the data.
Matthew Hickey, co-founder of U.K.-based cybersecurity consultancy Hacker House, said it was plausible that the servers would have seen use as staging posts to help obfuscate the origin of electronic eavesdropping operations. More worrying for the NSA, the leak backs Shadow Brokers’ claims to have stolen an as-yet undisclosed set of electronic lock picks from the agency.
“Those can be hard to generate,” Hickey said in a telephone interview, calling it “quite expensive to replicate all those tools.” Shadow Brokers has been closely followed by intelligence watchers and cybersecurity specialists since the group released an initial set of NSA hacking tools back in August. The seriousness of the leak was confirmed when security companies rushed to patch holes in their software revealed by the disclosure.
The Intercept, an investigative publication with access to NSA material leaked by former intelligence contractor Edward Snowden, later confirmed Shadow Brokers’ tools were really from the NSA by cross-referencing the leaked data with information held in a previously unpublished top secret manual. The authenticity of the latest batch of material could not immediately be established, although Hickey said any hoax would have to have been unusually elaborate.
Shadow Brokers did not return messages seeking comment Monday. The NSA declined to comment.
AP

Monday, October 31, 2016

Shadow Brokers reveals list of Servers Hacked by the NSA

nsa-shadow-brokers








The hacker group calling itself the Shadow Brokers, who previously claimed to have 
leaked a portion of the NSA’s hacking tools and exploits, is back with a Bang!


The Shadow Brokers published more files today, and this time the group dumped a list of foreign servers allegedly compromised by the NSA-linked hacking unit, Equation Group, in various countries to expand its espionage operations.

Top 3 Targeted Countries — China, Japan, and Korea


The data dump [Download / File Password: payus] that experts believe contains 306 domain names, and 352 IP addresses belong to at least 49 countries. As many as 32 domains of the total were run by educational institutes in China and Taiwan.

A few target domains were based in Russia, and at least nine domains include .gov websites.

The top 10 targeted countries include China, Japan, Korea, Spain, Germany, India, Taiwan, Mexico, Italy, and Russia.

The latest dump has been signed by the same key as the first Shadow Brokers’ dump of NSA exploits, though there is a lot to be done to validate the contents of the leaked data dump fully.

Targeted Systems — Solaris, Unix, Linux and FreeBSD


Most of the affected servers were running Solaris, Oracle-owned Unix-based operating system, while some were running FreeBSD or Linux.

Each compromised servers were reportedly targets of INTONATION and PITCHIMPAIR, code-names given for cyber-spy hacking programs.

The data dump also contains references to a list of previously undisclosed Equation Group tools, including Dewdrop, Incision, Orangutan, Jackladder, Reticulum, Patchicillin, Sidetrack and Stoicsurgeon.

The tools as mentioned above could be hacking implants, tools or exploits used by the NSA's notorious group.

Security researcher Mustafa Al-Bassam, an ex-member of Lulzsec and the Anonymous hacking collective, said the NSA likely compromised all the servers between 2000 and 2010.
"So even the NSA hacks machines from compromised servers in China and Russia. This is why attribution is hard," Al-Bassam added. 

Are Hackers trying to influence U.S. Presidential elections?


A message accompanying the leaked data dump calls for attempts to disrupt the forthcoming United States presidential election. The portion of message from the Shadow Brokers reads:
"TheShadowBrokers is having suggestion. On November 8th, instead of not voting, maybe be stopping the vote all together? Maybe being grinch who stopped the election from coming? Maybe hacking election is being the best idea? #hackelection2016."
Targeted victims can use the leaked files in an effort to determine if they were the potential target of the NSA-linked hacking unit.

Since the records are old, many servers should now be clean of infection. However, a brief Shodan scan of these domains indicates that some of the affected servers are still active and still running old, possibly-vulnerable systems.

The latest release comes after the FBI arrested Harold Thomas Martin, an NSA contractor, who was reportedly a prime suspect in The Shadow Brokers case.
Related Posts Plugin for WordPress, Blogger...