Showing posts with label WikiLeaks. Show all posts
Showing posts with label WikiLeaks. Show all posts

Tuesday, May 2, 2017

Source Code for CIA’s Tool to Track Whistleblowers Leaked by Wikileaks


Friday, April 28, 2017 Swati Khandelwal





Wikileaks has just published a new batch of the Vault 7 leak, exposing the documentation and source code for a CIA project known as "Scribbles."

Scribbles, a.k.a. the "Snowden Stopper," is a piece of software allegedly designed to embed 'web beacon' tags into confidential documents, allowing the spying agency to track whistleblowers and foreign spies.

Since March, as part of its "Vault 7" series, the Whistleblowing website has published thousands of documents and other confidential information that the whistleblower group claims came from the US Central Intelligence Agency (CIA).



The CIA itself described Scribbles as a "batch processing tool for pre-generating watermarks and inserting those watermarks into documents that are apparently being stolen by FIO (foreign intelligence officers) actors."


Here's How Scribbles Tool Works:
Scribbles is coded in C# programming language and generates a random watermark for each document, inserts it into the document, saves all processed documents in an output directory, and creates a log file that identifies the watermarks inserted into every document.

This technique works exactly in the same way as the "tracking pixel" works, where a tiny pixel-sized image is embedded inside an email, allowing marketers and companies to keep track of how many users have seen the advertisement.

Using this tool CIA inserts a tiny uniquely generated file, hosted on a CIA-controlled server, to the classified documents "likely to be stolen."



So, every time the watermarked document is accessed by anyone, including potential whistleblowers, it will secretly load an embedded file in the background, which creates an entry on the CIA's server, containing unique information about the one who accessed it, including the time stamp and his/her IP address.

"It generates a random watermark for each document, inserts that watermark into the document, saves all such processed documents in an output directory, and creates a log file which identifies the watermarks inserted into each document," Scribbles' user guide manual reads.

Scribbles Only Works with Microsoft Office Products
The user manual also specifies that the tool is intended for off-line preprocessing of Microsoft Office documents. So, if the watermarked documents are opened in any other application like OpenOffice or LibreOffice, they may reveal watermarks and URLs to the user.

According to the documentation, "the Scribbles document watermarking tool has been successfully tested on…Microsoft Office 2013 (on Windows 8.1 x64), documents from Office versions 97–2016 (Office 95 documents will not work!) [and]...documents that are not be locked forms, encrypted, or password-protected."However, since the hidden watermarks are loaded from a remote server, this technique should work only when the user accessing the marked documents is connected to the Internet.

WikiLeaks notes that the latest released version of Scribbles (v1.0 RC1) dated March 1, 2016, which indicates it was in use up until at least last year and seemingly meant to remain classified until 2066.

More technical details of Scribble can be found in the User Guide.

So far, Wikileaks has revealed the "Year Zero" batch which uncovered CIA hacking exploits for popular hardware and software, the "Dark Matter" batch which focused on hacking exploits the agency designed to target iPhones and Macs, the "Marble" batch, and the "Grasshopper" batch that reveal a framework, allowing the agency to easily create custom malware for breaking into Microsoft's Windows and bypassing antivirus protection.

Friday, April 14, 2017

Symantec Connects 40 Cyber Attacks to CIA Hacking Tools Exposed by Wikileaks


Monday, April 10, 2017 Swati Khandelwal





Security researchers have confirmed that the alleged CIA hacking tools recently exposed by WikiLeaks have been used against at least 40 governments and private organizations across 16 countries.

Since March, as part of its "Vault 7" series, Wikileaks has published over 8,761 documents and other confidential information that the whistleblower group claims came from the US Central Intelligence Agency (CIA).

Now, researchers at cybersecurity company Symantec reportedly managed to link those CIA hacking tools to numerous real cyber attacks in recent years that have been carried out against the government and private sectors across the world.



Those 40 cyber attacks were conducted by Longhorn — a North American hacking group that has been active since at least 2011 and has used backdoor trojans and zero-day attacks to target government, financial, energy, telecommunications, education, aerospace, and natural resources sectors.

Although the group's targets were all in the Middle East, Europe, Asia, and Africa, researchers said the group once infected a computer in the United States, but an uninstaller was launched within an hour, which indicates the "victim was infected unintentionally."

What's interesting is that Symantec linked some of CIA hacking tools and malware variants disclosed by Wikileaks in the Vault 7 files to Longhorn cyber espionage operations.


Fluxwire (Created by CIA) ≅ Corentry (Created by Longhorn)
Fluxwire, a cyber espionage malware allegedly created by the CIA and mentioned in the Vault 7 documents, contains a changelog of dates for when new features were added, which according to Symantec, closely resemble with the development cycle of "Corentry," a malware created by Longhorn hacking group.

"Early versions of Corentry seen by Symantec contained a reference to the file path for the Fluxwire program database (PDB) file," Symantec explains. "The Vault 7 document lists removal of the full path for the PDB as one of the changes implemented in Version 3.5.0."
"Up until 2014, versions of Corentry were compiled using GCC [GNU Compiler Collection]. According to the Vault 7 document, Fluxwire switched to an MSVC compiler for version 3.3.0 on February 25, 2015. This was reflected in samples of Corentry, where a version compiled on February 25, 2015, had used MSVC as a compiler."

Similar Malware Modules
Another Vault 7 document details 'Fire and Forget' specification of the payload and a malware module loader called Archangel, which Symantec claims, match almost perfectly with a Longhorn backdoor called Plexor.



"The specification of the payload and the interface used to load it was closely matched in another Longhorn tool called Backdoor.Plexor," says Symantec.


Use of Similar Cryptographic Protocol Practices
Another leaked CIA document outlined cryptographic protocols that should be used within malware tools, such as using AES encryption with a 32-bit key, inner cryptography within SSL to prevent man-in-the-middle attacks, and key exchanges once per connection.

One leaked CIA document also recommends using of in-memory string de-obfuscation and Real-time Transport Protocol (RTP) for communicating with the command and control (C&C) servers.

According to Symantec, these cryptographic protocol and communication practices were also used by Longhorn group in all of its hacking tools.


More About LongHorn Hacking Group
Longhorn has been described as a well-resourced hacking group that works on a standard Monday to Friday working week — likely a behavior of a state-sponsored group — and operates in an American time zone.

Longhorn's advanced malware tools are specially designed for cyber espionage with detailed system fingerprinting, discovery, and exfiltration capabilities. The group uses extremely stealthy capabilities in its malware to avoid detection.

Symantec analysis of the group's activities also shows that Longhorn is from an English speaking North American country with code words used by it referring, the band The Police with code words REDLIGHT and ROXANNE, and colloquial terms like "scoobysnack."

Overall, the functionality described in the CIA documents and its links to the group activities leave "little doubt that Longhorn's activities and the Vault 7 documents are the work of the same group."

Wednesday, April 12, 2017

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks
The US National Security Agency (NSA) has been spying on Pakistan’s mobile networks, whistleblowing organisation WikiLeaks has tweeted. “Hundreds of NSA cyber weapons variants publicly released including code showing hacking of Pakistan mobile system,” @wikileaks tweeted.
According to a report in Express Tribune on Monday, the hacker group “Shadow Brokers” released a new cache of information detailing how the NSA accessed private and public networks in other countries. A researcher on Twitter who identifies himself as ‘x0rz’ decrypted the files and uploaded them on Github, a web-based repository and internet hosting service.
“The researcher confirmed that the archives include evidence of NSA operators’ access inside the GSM network of Mobilink – one of the Pakistan’s most popular mobile services provider,” the report noted. The hacker group had previously released data suggesting the US agency may have been monitoring hundreds of IP addresses in Pakistan. The encrypted files were being decrypted by security researchers around the world.
“Shadow Brokers” had initially wanted to auction its data cache in exchange for Bitcoin but as no buyer turned up, they released the data online. This is not the first time that reports have surfaced claiming that the US NSA is snooping on other countries. According to a Daily Mail report in 2014, WikiLeaks disclosed documents that suggested the Bharatiya Janata Party (BJP) was among six political parties from around the world the NSA was authorised to conduct surveillance on for gathering foreign intelligence. The authorisation was given by a secret American court, it said.
The leak was planned months ahead of Prime Minister Narendra Modi’s visit to the US, the report claimed. Another report in the Washington Post that also came in 2014 said the US has long had broad no-spying arrangements with four countries – Britain, Canada, Australia and New Zealand – in a group known collectively as the “Five Eyes”.
“But a classified 2010 legal certification – approved by the Foreign Intelligence Surveillance Court and included among a set of documents leaked by former NSA contractor Edward Snowden – lists 193 countries [including India], that would be of valid interest for US intelligence,” the Post said.
Publish date: April 12, 2017 11:45 am| Modified date: April 12, 2017 11:41 am

Monday, April 10, 2017

WikiLeaks Reveals CIA's Grasshopper Windows Hacking Framework

Friday, April 07, 2017 Swati Khandelwal


As part of its Vault 7 series of leaked documents, whistleblowing website WikiLeaks today released a new cache of 27 documents allegedly belonged to the US Central Intelligence Agency (CIA).

Named Grasshopper, the latest batch reveals a CLI-based framework developed by the CIA to build "customised malware" payloads for breaking into Microsoft's Windows operating systems and bypassing antivirus protection.

All the leaked documents are basically a user manual that the agency flagged as "secret" and that are supposed to be only accessed by the members of the agency, WikiLeaks claims.




Grasshopper: Customized Malware Builder Framework
According to the leaked documents, Grasshopper framework allows the agency members to easily create custom malware, depending upon the technical details, such as what operating system and antivirus the targets are using.

The Grasshopper framework then automatically puts together several components sufficient for attacking the target, and finally, delivers a Windows installer that the agency members can run on a target's computer and install their custom malware payloads.

"A Grasshopper executable contains one or more installers. An installer is a stack of one or more installer components," the documentation reads. "Grasshopper invokes each component of the stack in series to operate on a payload. The ultimate purpose of an installer is to persist a payload."The whistleblowing website claimed the Grasshopper toolset was allegedly designed to go undetected even from the anti-virus products from the world's leading vendors including Kaspersky Lab, Symantec, and Microsoft.




CIA's Grasshopper Uses 'Stolen' Russian Malware
According to WikiLeaks, the CIA created the Grasshopper framework as a modern cyber-espionage solution not only to be as easy to use as possible but also "to maintain persistence over infected Microsoft Windows computers."

"Grasshopper allows tools to be installed using a variety of persistence mechanisms and modified using a variety of extensions (like encryption)," Wikileaks said in the press release.One of the so-called persistence mechanisms linked to Grasshopper is called Stolen Goods (Version 2), which shows how the CIA adapted known malware developed by cyber criminals across the world and modified it for its own uses.

One such malware is "Carberp," which is a malware rootkit developed by Russian hackers.

"The persistence method and parts of the installer were taken and modified to fit our needs," the leaked document noted. "A vast majority of the original Carberp code that was used has been heavily modified. Very few pieces of the original code exist unmodified."It is not yet clear how recently the CIA has used the hacking tools mentioned in the documentation, but WikiLeaks says the tools were used between 2012 and 2015.

So far, Wikileaks has revealed the "Year Zero" batch which uncovered CIA hacking exploits for popular hardware and software, the "Dark Matter" batch which focused on exploits and hacking techniques the agency designed to target iPhones and Macs, and the third batch called "Marble."

Marble revealed the source code of a secret anti-forensic framework, basically an obfuscator or a packer used by the CIA to hide the actual source of its malware.

Saturday, April 1, 2017

WikiLeaks Vault 7 documents about vulnerable Cisco products exposes US govt’s stance on cyber security

WikiLeaks Vault 7 documents about vulnerable Cisco products exposes US govt’s stance on cyber security

Image Credit: REUTERS
When WikiLeaks founder Julian Assange disclosed earlier this month that his anti-secrecy group had obtained CIA tools for hacking into technology products made by U.S. companies, security engineers at Cisco Systems swung into action.
The Wikileaks documents described how the Central Intelligence Agency had learned more than a year ago how to exploit flaws in Cisco’s widely used Internet switches, which direct electronic traffic, to enable eavesdropping.
Senior Cisco managers immediately reassigned staff from other projects to figure out how the CIA hacking tricks worked, so they could help customers patch their systems and prevent criminal hackers or spies from using the same methods, three employees told Reuters on condition of anonymity.
The Cisco engineers worked around the clock for days to analyze the means of attack, create fixes, and craft a stopgap warning about a security risk affecting more than 300 different products, said the employees, who had direct knowledge of the effort.
That a major U.S. company had to rely on WikiLeaks to learn about security problems well-known to U.S. intelligence agencies underscores concerns expressed by dozens of current and former U.S. intelligence and security officials about the government’s approach to cybersecurity. That policy overwhelmingly emphasizes offensive cyber-security capabilities over defensive measures, these people told Reuters, even as an increasing number of U.S. organizations have been hit by hacks attributed to foreign governments.
Larry Pfeiffer, a former senior director of the White House Situation Room in the Obama administration, said now that others were catching up to the United States in their cyber capabilities, “maybe it is time to take a pause and fully consider the ramifications of what we’re doing.” U.S. intelligence agencies blamed Russia for the hack of the Democratic National Committee during the 2016 election. Nation-states are also believed to be behind the 2014 hack of Sony Pictures Entertainment and the 2015 breach of the U.S. Government’s Office of Personnel Management.
CIA spokeswoman Heather Fritz Horniak declined to comment on the Cisco case, but said it was the agency’s “job to be innovative, cutting-edge, and the first line of defense in protecting this country from enemies abroad.” The Office of the Director of National Intelligence, which oversees the CIA and NSA, referred questions to the White House, which declined to comment.
Across the federal government, about 90 percent of all spending on cyber programs is dedicated to offensive efforts, including penetrating the computer systems of adversaries, listening to communications and developing the means to disable or degrade infrastructure, senior intelligence officials told Reuters.
President Donald Trump’s budget proposal would put about $1.5 billion into cyber-security defense at the Department of Homeland Security (DHS). Private industry and the military also spend money to protect themselves.
But the secret part of the U.S. intelligence budget alone totaled about $50 billion annually as of 2013, documents leaked by NSA contractor Edward Snowden show. Just 8 percent of that figure went toward “enhanced cyber security,” while 72 percent was dedicated to collecting strategic intelligence and fighting violent extremism.
Departing NSA Deputy Director Rick Ledgett confirmed in an interview that 90 percent of government cyber spending was on offensive efforts and agreed it was lopsided. “It’s actually something we’re trying to address” with more appropriations in the military budget, Ledgett said. “As the cyber threat rises, the need for more and better cyber defense and information assurance is increasing as well.”
The long-standing emphasis on offense stems in part from the mission of the NSA, which has the most advanced cyber capabilities of any U.S. agency. It is responsible for the collection of intelligence overseas and also for helping defend government systems. It mainly aids U.S. companies indirectly, by assisting other agencies.
“I absolutely think we should be placing significantly more effort on the defense, particularly in light of where we are with exponential growth in threats and capabilities and intentions,” said Debora Plunkett, who headed the NSA’s defensive mission from 2010 to 2014.
Government Role
How big a role the government should play in defending the private sector remains a matter of debate. Former military and intelligence leaders such as ex-NSA Director Keith Alexander and former Secretary of Defense Ashton Carter say that U.S. companies and other institutions cannot be solely responsible for defending themselves against the likes of Russia, China, North Korea and Iran.
For tech companies, the government’s approach is frustrating, executives and engineers say. Sophisticated hacking campaigns typically rely on flaws in computer products. When the NSA or CIA find such flaws, under current policies they often choose to keep them for offensive attacks, rather than tell the companies.
In the case of Cisco, the company said the CIA did not inform the company after the agency learned late last year that information about the hacking tools had been leaked. “Cisco remains steadfast in the position that we should be notified of all vulnerabilities if they are found, so we can fix them and notify customers,” said company spokeswoman Yvonne Malmgren.
Side by Side
A recent reorganization at the NSA, known as NSA21, eliminated the branch that was explicitly responsible for defense, the Information Assurance Directorate (IAD), the largest cyber-defense workforce in the government. Its mission has now been combined with the dominant force in the agency, signals intelligence, in a broad operations division.
Top NSA officials, including director Mike Rogers, argue that it is better to have offensive and defensive specialists working side by side. Other NSA and White House veterans contend that perfect defense is impossible and therefore more resources should be poured into penetrating enemy networks – both to head off attacks and to determine their origin.
Curtis Dukes, the last head of IAD, said in an interview after retiring last month that he feared defense would get even less attention in a structure where it does not have a leader with a direct line to the NSA director. “It’s incumbent on the NSA to say, ‘This is an important mission’,” Dukes said. “That has not occurred.”
Reuters
Publish date: March 30, 2017 7:14 pm| Modified date: March 30, 2017 7:14 pm
×

Saturday, October 22, 2016

Ecuador cuts off Assange’s internet access over fears of interference in US elections

Ecuador cuts off Assange’s internet access over fears of interference in US elections

Image Credit: WikiLeaks.org
Ecuador says it has temporarily cut off internet access to WikiLeaks founder Julian Assange over fears he was using it to interfere in the US presidential election. The move comes in the wake of the publication of leaked emails by WikiLeaks, including emails from the account of Democratic candidate Hillary Clinton’s campaign adviser John Podesta.
The Ecuadorean Foreign Ministry on Tuesday said WikiLeaks’ documents could interfere in the electoral process. It said Ecuador “respects the principle of non-intervention in the internal affairs of other states” and had cut off the internet access available to Assange because “in recent weeks WikiLeaks has published a wealth of documents, impacting on the US election campaign.
“In that respect, Ecuador, exercising its sovereign right, has temporarily restricted access to part of its communications systems in its UK Embassy,” the statement said. Ecuador clarified the move was not a result of pressure from Washington. The US denied WikiLeaks’ accusations on Sunday that it had asked Ecuador to stop the site publishing documents about Hillary Clinton.
The Ecuador statement also reaffirmed the asylum granted to Assange and reiterated its intention “to safeguard his life and physical integrity until he reaches a safe place”. Assange’s internet access was cut off on Monday morning. Assange has sought asylum at London’s Ecuadorean embassy since 2012 to avoid extradition to Sweden over sex assault allegation.
According to the latest leaked emails, Clinton told a Goldman Sachs conference she would like to intervene secretly in Syria. She made the remark in answer to a question from Lloyd Blankfein, the bank’s chief executive, in 2013 — months after she left office as the Secretary of State. “My view was you intervene as covertly as is possible for Americans to intervene,” she told employees of the bank in South Carolina, which had paid her about $225,000 to give a speech.
IANS

Tuesday, October 11, 2016

WikiLeaks releases emails that detail the effort to make PM Modi’s Silicon Valley visit a success

WikiLeaks releases emails that detail the effort to make PM Modi’s Silicon Valley visit a success

Image Credits: Wikipedi
The latest batch of emails released by WikiLeaks from Clinton campaign chairman John Podesta gives an insight into the planning done by the Obama administration to ensure a successful visit by Prime Minister Narendra Modi to the Silicon Valley in 2015. More than a month and half before Modi was to visit Silicon Valley in the last week of September, US Assistant Secretary of State for South and Central Asia Nisha Desai Biswal wrote an email to John Podesta, who had by then joined the Clinton campaign, seeking his advice and input on making the trip successful.
She also sought to know if former US president Bill Clinton could co-host a clean energy event with Modi at Stanford. In an email to Podesta dated 12 August, Biswal said there is a lot of interest in the Indian government to focus on two themes for the Silicon Valley visit.  First is the digital economy, she wrote, and added that the focus will be a visit to Google and some announcements on Google’s massive investments in India, she said.
“The other focus is on clean energy. Here, the Indians want to visit Tesla and hopefully announce a Tesla partnership/venture with India focusing on

Friday, October 7, 2016

Challenges to tackle Insider threat regains focus after the arrest of former NSA contractor

Challenges to tackle Insider threat regains focus after the arrest of former NSA contractor

The arrest of a former National Security Agency contractor for allegedly stealing classified information represents the second known case since 2013 of a government contractor being publicly accused of removing secret data from the intelligence agency. The latest case comes as the NSA has worked to reform security after the Edward Snowden disclosures, especially with regard to insider threats.
Harold Thomas Martin III, 51, of Glen Burnie, Maryland, was arrested by the FBI in August after federal prosecutors say he illegally removed highly classified information and stored the material in his home and car. A defence attorney said Martin did not intend to betray his country.
The arrest was not made public until Wednesday when the Justice Department unsealed a criminal complaint that accused Martin of having been in possession of top-secret information that could cause “exceptionally grave danger” to national security if disclosed.
It’s not yet clear when the documents were removed. But the fact that Snowden and Martin – both working for Booz Allen Hamilton as contractors for the NSA – were accused of leaving the NSA with highly classified documents raises questions about the effectiveness and adequacy of the intelligence agency’s internal security controls. The NSA, which put security upgrades into place following the Snowden disclosures, has declined to comment.
“One key thing we don’t have visibility into now is how he was caught because that would provide some insight into whether the reforms that were put in post-Snowden were effective or not or their relative efficacy,” said Rajesh De, who was the NSA’s general counsel when the Snowden story broke. Snowden’s 2013 theft of documents that were leaked to journalists revealed the NSA’s bulk collection of millions of Americans’ phone records.
Rep. Adam Schiff of California, the senior Democrat on the House Permanent Select Committee on Intelligence, said in a statement that “it is painfully clear that the intelligence community still has much to do to institutionalise reforms designed to protect (U.S. government secrets) from insider threats.”
White House spokesman Josh Earnest said the federal government has made important changes since Snowden’s disclosures. He said the government has reduced the number of people who need security clearances by 17 percent and has enhanced the quality of background checks. Martin’s arrest appears to illustrate the difficulty of guarding against an insider threat given that employees, by virtue of their clearance level and jobs, must be

Wednesday, October 5, 2016

Julian Assange promises to release new material every week on Wikileaks, for next 10 weeks

Julian Assange promises to release new material every week on Wikileaks, for next 10 weeks

Image Credit: Reuters
WikiLeaks founder Julian Assange announced at a press conference on Tuesday that his platform will release new material in the coming months.
It is planned to publish new material every week in the next ten weeks, Xinhua news agency quoted Assange as saying in a live video broadcast to Berlin on the 10th birthday of WikiLeaks.
The new releases will cover the themes such as oil, weapons and corporations like Google, according to Assange.
Meanwhile, WikiLeaks also wants to publish new details for the US election, but left the exact date open. However, WikiLeaks is working on publishing the material before the election date on 8 November, said Assange.
The upcoming publications were “of significant importance for the elections”, the 45-year-old Australian said in response to a question whether the new information “will destroy the Democratic presidential candidate”.
With a view to the 10th anniversary of the founding of WikiLeaks, Assange emphasised that despite all the hostility of “powerful opponents”, the website is still well positioned.
“We have a strong position, we are debt-free and completely independent,” he said.
“The attacks only make us stronger,” Assange said, “We believe in what we do, and when we are put under pressure, we will fight back.”
WikiLeaks has published hundreds of thousands of secret documents over the past few years, including the US military’s actions in the Iraq and Afghanistan wars.
The Australian, who has taken refuge in the Ecuadorian embassy in London since June 2012, claimed that Sweden intends to hand him over to the United States, where he may face espionage charges for leaking thousands of secret US diplomatic cables and, if convicted, could be given a death penalty.
IANS

Related Posts Plugin for WordPress, Blogger...