U.S. Hunts Chinese Malware That Could Disrupt American Military Operations

… The malware, one congressional official said, was essentially “a ticking time bomb” that could give China the power to interrupt or slow American military deployments or resupply operations by cutting off power, water and communications to U.S. military bases. But its impact could be far broader, because that same infrastructure often supplies the houses and businesses of ordinary Americans, according to U.S. officials.

Share

Why is it so rare to hear about Western cyber-attacks?

A cyber-attack that took over iPhones at a Russian technology company is being blamed on US government hackers. Could the attack, and the response from the Russian government, be rewriting the narrative of who the good guys and bad guys are in cyber-space?

Camaro Dragon, Fancy Bear, Static Kitten and Stardust Chollima – these aren’t the latest Marvel film superheroes but the names given to some of the most feared hacking groups in the world.

For years, these elite cyber teams have been tracked from hack to hack, stealing secrets and causing disruption allegedly under orders from their governments.

Share

Chinese spies breached hundreds of public, private networks, security firm says

Suspected state-backed Chinese hackers used a security hole in a popular email security appliance to break into the networks of hundreds of public and private sector organizations globally, nearly a third of them government agencies including foreign ministries, the cybersecurity firm Mandiant said Thursday.

“This is the broadest cyber espionage campaign known to be conducted by a China-nexus threat actor since the mass exploitation of Microsoft Exchange in early 2021,” Charles Carmakal, Mandiant’s chief technical officer, said in a emailed statement. That hack compromised tens of thousands of computers globally.

Share

New Russian malware could bring down the US power grid

As if you didn’t have enough to worry about. Who will bring down America’s power grid first? Joe Biden or Vladimir Putin? Biden has a head start, to be sure. But some Russian hackers have reportedly cooked up some new malware designed specifically to target electrical grids and cause disruptions. The new threat was discovered by Mandiant, a cyber threat intelligence specialist firm. They believe that this new malware system “poses a plausible threat” to the operational technology behind various electrical grid assets. (Security Week)

Share

The Snake, The FBI, And Center 16: Why The Takedown Of A ‘Most Sophisticated Cyber-Espionage Tool’ Is Important

For more than a decade, a unique bit of malicious computer code was burrowed in the deepest corners of Internet servers in more than 50 countries, secretly gathering data and even records of what a person might be typing on a keyboard. Important information was extracted and covertly sent via a network of other infected computers, hiding its tracks from easy detection, back to the code’s creators.

Called various names — Snake, Uroburos, Venomous Bear — the malware was suspected in a damaging hack of Germany’s Foreign Ministry in 2017. NATO computers were reportedly compromised. The personal computer of a journalist who worked for a U.S. news organization and reported on the Russian government was reportedly targeted.

Share

A pro-Russian hacking group may have targeted Canada’s energy infrastructure.

A hacking group, under the guidance of Russia’s Federal Security Service, may have compromised the I.P. address of a Canadian gas pipeline company in February and caused damage to its infrastructure, according to leaked Pentagon documents.

If the attack by the cybercriminal group, Zarya, succeeded, the intelligence report said, “it would mark the first time” the United States intelligence community “has observed a pro-Russia-hacking group execute a disruptive attack against Western industrial control systems.”

(more…)

Share

Revealed: the hacking and disinformation team meddling in elections

A team of Israeli contractors who claim to have manipulated more than 30 elections around the world using hacking, sabotage and automated disinformation on social media has been exposed in a new investigation.

The unit is run by Tal Hanan, a 50-year-old former Israeli special forces operative who now works privately using the pseudonym “Jorge”, and appears to have been working under the radar in elections in various countries for more than two decades.

He is being unmasked by an international consortium of journalists. Hanan and his unit, which uses the codename “Team Jorge”, have been exposed by undercover footage and documents leaked to the Guardian.

Share

Russian cyber threat worse than previously reported: CSE

Russia’s cyber operations following its invasion of Ukraine have “almost certainly” been more extensive than what has been publicly reported, and Canada is among the targets, the Communications Security Establishment said.

The CSE’s Canadian Centre for Cybersecurity said in a threat bulletin issued Thursday “the scope and severity of cyber operations related to the Russian invasion of Ukraine has almost certainly been more sophisticated and widespread than has been reported in open sources.”

Share

Cyber spy agency targeted foreign extremists trying to recruit Canadians: report

 

Canada’s electronic spy agency says it’s used its arsenal to try and stop foreign extremists from recruiting Canadians and sharing violent material online.

The acknowledgement is nestled in the Communications Security Establishment’s annual report made public Tuesday, which points to recent cases where it flexed its cyber muscles.

While the details are largely sanitized in the report, the examples shed some light on how the foreign signals intelligence agency has been using the “active” cyber capabilities granted to it by the Liberal government in 2019.

Share

Canada on ‘high alert’ for cyberattacks from Russia, others: minister

The Canadian government is on “high alert” for cyberattacks by Russia and others amid a global threat environment that continues to shake the foundations of the post-second World War international order.

Public Safety Minister Marco Mendicino issued the warning during an appearance at the House of Commons public safety committee on Thursday morning. He told members of the committee that the threat is not just to the federal government but also to provinces and critical infrastructure.

Share

Canada directs military to take more ‘assertive’ stance in cyberspace

The Canadian government has directed its military to take a more “assertive” stance in cyberspace in anticipation of electronic warfare becoming a more central component in conflict, documents obtained by Global News suggest.

A “cyber playbook” prepared by the Canadian Armed Forces and the Department of National Defence comes as Ottawa pushes for international rules and norms around cyber espionage and warfare.

Share

Canada, allies warn of Russian cyberattacks on critical infrastructure due to Ukraine war

Western governments jointly warned on Wednesday about a potential threat of increased malicious cyber activity by Russia against critical infrastructure as a response to sanctions imposed as punishment for its invasion of Ukraine.

The cybersecurity agencies of the United States, Britain, Australia, Canada and New Zealand that together form the Five Eyes intelligence-sharing alliance said the war could expose organizations everywhere to cyber crime.

Share

Companies were slow to remove Russian spies’ malware, so FBI did it for them

How the FBI took down “Cyclops Blink,” a Russia state botnet infecting network firewalls.

The FBI remotely accessed and disinfected US-located devices running a powerful new strain of Russian state botnet malware, federal authorities said Wednesday. Those authorities added that the Kremlin was using the malware to wage stealthy hacks of its adversaries.

The infected devices were primarily made up of firewall appliances from WatchGuard and, to a lesser extent, network devices from Asus. Both manufacturers recently issued advisories providing recommendations for hardening or disinfecting devices infected by the botnet, known as Cyclops Blink. It is the latest botnet malware from Russia’s Sandworm, which is among the world’s most elite and destructive state-sponsored hacking outfits.

Share

Kaspersky antivirus software added to US national security risk list

Antivirus software maker Kaspersky Labs has been added to a federal list of companies that pose “an unacceptable risk to the national security of the United States.”

The Moscow-based cybersecurity firm, which says it has more than 400 million users worldwide, was added to the Federal Communications Commission’s list of restricted entities on Friday alongside two Chinese companies.

Share