Showing posts with label computer crime. Show all posts
Showing posts with label computer crime. Show all posts

Wednesday, November 19, 2008

Israeli "Hackers" Penetrate Gaza Phone Network to Offer Reward

StrategyPage.com reports of an intrusion into the Gaza phone network to offer rewards for the return of an Israeli soldier:
"Israeli Cyber War troops again hacked into the cell phone networks in Gaza, and sent a message offering a $10,000 reward for anyone who could provide information that led to the rescue of kidnapped Israeli soldier Gilad Shalit."



Saturday, November 15, 2008

IMF Systems Compromised

There are several reports of allegations that the International Monetary Fund (IMF) systems were penetrated last month with speculation that the source of the attacks was China. The Dark Visitor, a site that follows the Chinese computer underground, reports on why the Chinese might be interested in IMF communications.

Chinese hackers hit International Monetary Fund

Friday, November 07, 2008

Obama, McCain Systems Compromised?

Newsweek magazine is reporting that the computer systems of both candidates for U.S. president were compromised last summer. However, few details were provided and there seems to be some issues with the story such as why there would be senior level White House involvement in the investigation:
"The following day, Obama campaign chief David Plouffe heard from White House chief of staff Josh Bolten, to the same effect: "You have a real problem ... and you have to deal with it."

The Newsweek article alleges that the source of the intrusions were from outside of the U.S. (again, the article provides no details or supporting evidence):
"Officials at the FBI and the White House told the Obama campaign that they believed a foreign entity or organization sought to gather information on the evolution of both camps' policy positions—information that might be useful in negotiations with a future administration. The Feds assured the Obama team that it had not been hacked by its political opponents."

Hackers and Spending Sprees

Friday, October 10, 2008

Increase in High-Tech Terrorists in India

Indian police are reporting and increase in recruiting of high-tech individuals to assist in terrorist attacks. Most recently was the arrest of three IT professionals that used computer intrusions to send e-mails just before and after bombings in India:
"Evidence is mounting that recruiters for Islamist terror groups have targeted the information technology and engineering sectors, in a successful effort to give India’s jihadist movement a quantum jump in skills and ideological focus.

"Most of the 15 men arrested in Mumbai on Monday, on charges of participating in the hit-teams which planted explosives in Ahmedabad and Surat, are criminals linked to Pakistan-based ganglord Amir Raza Khan.

"But three men in the group were, till their arrest, believed to be model citizens. Key among them is Mohammed Mansoor Asghar Peerbhoy, who worked as a software engineer at multinational Yahoo India."

India - White-collar jihadists,a cause for growing concern

Wednesday, October 01, 2008

South Korean Missile Manufacturer Compromised with Malicious Code

This article provides very little information about an alleged breach of computer systems at South Korean guided missile manufacturer, LIGNex1 Hyundai Heavy Industries.

The report states that malicious code was planted "through which they stolen [sic] information.
"A spokesperson said: “The research institute suspects the culprits are Chinese or North Korean hackers but doesn't know specifically what information they stole. In the worst case, the blueprints of missiles and Aegis ship could have been stolen."


South Korean defence suppliers uncover malicious code

Monday, April 07, 2008

NATO and EU Concern on Cybercrime

In separate meetings last week, both the EU and NATO organizations discussed cyberterror issues and their need to respond.

The Council of Europe will review the new Convention on Cybercrime and discuss how to strengthen online anti-terrorism activities.

Separately, politically motivated computer crime was discussed at the NATO summit held in Romania including how member countries can better coordinate online defense activities.
"World leaders gathered in Bucharest for this week’s NATO summit are debating what role the trans-Atlantic alliance can play in containing “cyberterrorists,” “hacktivists” and other emerging menaces that experts concede are untraditional, but still potentially lethal."

Most of the concern quoted in the press center around the cyber attacks against Estonia.

European Union, NATO to tackle cybercrime

NATO grows increasingly concerned about terrorism on world's computer networks

Thursday, March 20, 2008

Review: The National Security Strategy of the United Kingdom

The United Kingdom has released the first ever National Security Strategy "set[ting] out the Government's approach to dealing with threats to national security, ranging from war and terrorism to climate change, disease and poverty."

The report summarizes a wide range of threats and provides a comprehensive prevention and control strategy. Within the report are several references to national threats from computer crime:

Under the heading of "Defending the United Kingdom against state-led threats" the strategy defines the requirements as:
  • "...to defend the territory of the United Kingdom, its sea and air approaches, its information and communications systems, and its other vital interests..."
  • "On intelligence, in addition to the major effort required to tackle the current level of terrorist threat, the security and intelligence agencies will continue to protect the United Kingdom against covert activity by foreign intelligence organisations aimed at political, economic and security targets, including cyber-attack."

Under the heading "Responding to global trends" the report discusses a strategy to handle cyber incidents:
"In response to the technological challenges, we are committed to working with international, public, and private sector partners to ensure that our government systems and critical national infrastructure are adequately protected against cyberattack.

"We are also investing, through the interception modernisation programme, to update our intelligence and law-enforcement capability to meet the challenges of rapidly advancing communications technology. We are committed to maximising the opportunities and benefits of the internet, by protecting the freedom to develop and host new services, while also reducing the scope for terrorists and criminals to exploit those opportunities and freedoms, and ensuring that the internet itself is resilient enough to withstand attacks and accidents.

"Finally, we support international efforts to monitor and protect the safety and security of new technology including the internet and communications networks, and the space assets that are increasingly important for communications. We will continue to explore how new confidence‑building and arms control measures might contribute to international security in this area."

Finally, under the heading "The interdependence of threats, risks and drivers – an integrated response" the report discusses how many of the threats to the United Kingdom are interrelated and discusses how cyber threats will be managed:
"The Centre for the Protection of National Infrastructure (CPNI) was established in 2007 to act as an interdepartmental organisation providing advice on information, physical and personnel security to businesses and organisations across the national infrastructure. CPNI works closely with the private sector, delivering advice to reduce the vulnerability of critical infrastructure to terrorism and other national security threats."
The full report is available at:

The National Security Strategy of the United Kingdom

Thursday, March 13, 2008

Review: 2009 FBI Congressional Budget Submission

The U.S. Department of Justice has submitted its FY 2009 budget for the FBI to Congress. This report provides insight into what the FBI believes are critical threats and the initiatives it would like funded. The 2009 budget reveals cyber crime (including politically motivated crimes) as a major issue and priority of the Bureau.

The Highlights:

  1. Requests over US $54,000,000 in increased budgeting for cyber crime initiatives - more than any other FBI initiative;
  2. Protecting cyber attacks against the U.S. is the third overall priority of the Counterterrorism/Counterintelligence (CT/CI) decision unit after preventing terrorist attacks (first priority) and foreign intelligence operations and espionage (second priority);
  3. Increasing threat from "Islamist extremists who have directly expressed an interest in attacking government and private computer systems";
  4. There has been a major increase in CI/CT computer intrusion cases: from 18 pending CT/CI computer intrusion cases in 2001 to 326 cases in 2007;
  5. More than 20 terabytes of sensitive information has been stolen from military and other sensitive national interest systems; and,
  6. The FBI continues to be challenged by rapid technology changes, shortage of skill sets and limited technical forensic capabilities.

The Details:

The report provides several 'external drivers and influences' related to cyber crime:
  • Communications revolution – advances in communications technology outpace the ability of the FBI to perform court-authorized intercepts; use of encryption and other communications technologies requires closer access to end-nodes; identity theft will make perpetrator identification more difficult;
  • Technological and scientific revolutions – reduced ability for threat groups or governments to hide undercover identity of agents; increase in espionage and cyber crime against U.S. corporations... inexpensive computing technology outpaces forensic science capacities
The report also notes an important attribute of nationalist-based politically motived computer crime:
"Sub-national and non-governmental entities are expected to play an increasing role in world affairs in the coming years, presenting new “asymmetric” and non-traditional threats to the U.S. Although the U.S. will continue to occupy a position of economic and political leadership — and although other governments will also continue to be important actors on the world stage — terrorist groups, criminal enterprises, and other non-state actors will assume an increasing role in international affairs. Nation states and their governments will exercise decreasing control over the flow of information, resources, technology, services, and people."
To meet the challenge of increasing computer intrusions, the budget requests 70 new Special Agents:
"The most significant challenge facing the Cyber program in FY 2009 is improving the FBI’s capacity for addressing more sophisticated and more frequent computer intrusion events. Acquiring this capability will necessitate the addition of 70 new Special Agent positions in FY 2009."
Interestingly, the FBI's cyber initiatives receive the greatest increases of any program in FY 2009 including:
  • Computer Intrusion Program - To conduct CT, CI, and criminal computer intrusion investigations where the Internet, computers, or networks are the primary tools or targets of the activity: US $10,231,000
  • Comprehensive National Cybersecurity Initiative - To allow the FBI to combat computer intrusions that hinder U.S. national security interests: US $38,648,000
  • Cyber Training - To provide additional specialized cyber training courses: US $5,389,000
These sums are for budget line items specifically related to cyber threats and do not include amounts incorporated in other line items. These amounts are larger than the proposed investment increase for such initiatives as 'Response to a WMD Incident' with a requested funding increase of US $30,055,000.

A detailed breakdown and justification for the Computer Intrusion Program includes:
"The FBI requests 57 positions (35 agents) and $10,231,000 ($655,000 non-personnel) for its Computer Intrusion Program (CIP). The request consists of 39 field personnel (25 agents, 6 investigative support, 7 clerical and 1 Information Technology Specialist) and 18 Headquarters (HQ) personnel (10 agents and 8 Management and Program Analysts) to conduct counterterrorism (CT), counterintelligence (CI), and criminal computer intrusion-related investigations where the Internet, computers, or networks are the primary tools or targets of the activity.

Justification

"The emerging threat to the U.S. of foreign information operations is expanding rapidly. The number of actors with the ability to utilize computers for illegal, harmful, and possibly devastating purposes continues to rise; most significant is the immediate threat posed by hostile nation states to our government, military, defense industrial base, and critical infrastructure networks. More than 20 terabytes of sensitive information has been stolen to date, disrupting military operations and significantly impacting the confidence in the integrity of our national information infrastructure. There is a growing threat of Islamist extremists who have directly expressed an interest in attacking government and private computer systems. As they develop more advanced skills, Islamist extremist hackers will pose an increasing threat, especially as they are not deterred by geopolitical realities that restrain the behavior of nation-states. As the only federal agency that has the statutory authority, expertise, and ability to combine the CT, CI, and criminal resources needed to effectively address illegal computer-supported operations, the FBI is in a unique position to counter cyber threats. As attacks increase in frequency, number, and sophistication, the FBI’s workload subsequently increases. Since FY 2001, there has been a 78 percent increase in the total number of computer intrusion investigations..."

"Of particular note is the increase in CT and CI computer intrusions. In FY 2001, there were 18 pending CT/CI computer intrusion cases, and as of December 2007, there were 316 cases."

The Cyber Program is described as:
"The FBI’s Cyber Program consolidates Headquarters and field resources dedicated to combating cyber-crime under a single entity. This allows the to Cyber Program coordinate, supervise, and facilitate the FBI's investigation of those federal violations in which the Internet, computer systems, or networks are exploited as the principal instruments or targets of terrorist organizations, foreign government-sponsored intelligence operations, or criminal activity.

"Included under the purview of the Cyber Program are counterterrorism, counterintelligence and criminal computer intrusion investigations; intellectual property rights-related investigations involving theft of trade secrets and signals; copyright infringement investigations involving computer software; credit/debit card fraud where there is substantial Internet and online involvement; online fraud and related identity theft investigations; and the Innocent Images National Initiative."

The budget documents the FBI's strategies to manage the case load of cyber crimes:
"Strategies to Accomplish Outcomes - With the current FY 2009 budget enhancement, the FBI anticipates addressing an ever-increasing caseload and hence changes in the amount of subsequent convictions/pre-trial diversions. The strategies to accomplish these outcomes includes; continuing and enhancing the alliances with the Intelligence Community (IC), the coordination of intelligence across the IC, and the most critical - the chairmanship of the Strategic Alliance Cyber Crime Working Group. This strategic alliance is a key initiative that addresses the increasing need for defending national security through joint cyber training, curriculum exchanges and joint investigative initiatives among five countries. This high-profile initiative has vast potential, with the ability to identify and exploit the Counterterrorism and Counterintelligence efforts within each of the participating countries. The Working Group has put forth a set of initiatives to develop cyber crime law enforcement strategy, leverage international cooperation between governments, law enforcement, and private industry, share information and training, share and develop new tools, and educate the public. Given the transnational nature of cyber crime, it is imperative to establish effective international cooperation and develop appropriate and consistent legislation. As cyber crimes cross national boundaries, international law enforcement cooperation is crucial. Because most laws and agencies operate within national borders, gaps exist in international legal coverage and harmonization of offences [sic], and agencies seek (or provide) international assistance only when a crime impacts their interests. A lack of staff with sufficient technical skills to effectively assist in investigating cyber crimes compounds this situation."
The report also contains background information and initiatives for other cyber threats such as child pornography, identity theft and online fraud.

FY2009 DoJ Congressional Budget Submission - Federal Bureau of Investigation

Tuesday, March 11, 2008

CNN Reports Allegations that Chinese 'Hackers' Were Payed by the Chinese Government

In the ongoing guessing game of the motives behind alleged cyber attacks from China targeting U.S., British and German government systems, CNN is reporting on an interview with a Chinese 'hacker' (calling himself 'Xiao Chen') who stated off the air that the Chinese government had paid 'hackers' for the information they obtained from compromised systems. These allegations have been strongly denied by China:

"Beijing hit back at that, denying such an allegation and calling on the United States to provide proof. "If they have any evidence, I hope they would provide it. Then, we can cooperate on this issue," Qin Gang, a spokesman for the Chinese Foreign Ministry, said during a regular press briefing this week.

"But again off-camera, Xiao Chen says after the alleged Pentagon attack, his colleagues were paid by the Chinese government. CNN has no way to independently confirm if that is true.

"His allegations brought strenuous denials from Beijing. "I am telling you honestly, the Chinese government does not do such a thing," Qin said.

"But if Xiao Chen is telling the truth, it appears his colleagues launched a freelance attack -- not initiated by Beijing, but paid for after the fact."


The veracity of these claims are also questioned by the website 'The Dark Visitor' that reports on the Chinese computer underground. The blog also provides an analysis of the underground website featured in the CNN report.

Chinese hackers: No site is safe


Chinese hacker Xiao Chen’s Organization Revealed!


Chinese hacker Xiao Chen denies he hacked into Pentagon

Thursday, February 28, 2008

Terrorist Fundraising Via Credit Card Theft

Credit card theft (both from manual swiping and network intrusions) has been identified in several major terrorist funding investigations. Dennis Lormel looks at three cases and the lack of a coherent strategy to investigate or prevent these types of crime:
"The above cases [Ali Al Marri, Imam Samudra author of "Hacking, Why Not" and Younes Tsouli, aka Terrorist 007] are particularly troubling because of the upward trend of terrorists communicating on and using the internet as a learning tool. In both the Samudra and Terrorist 007 cases, they left their successful tradecraft on web pages and in chat rooms for aspiring terrorists to learn and grow from."


Terrorists and Credit Card Fraud…a Quiet Epidemic

Thursday, January 31, 2008

Russian Duma Considers Legislation to Curb Nationalist Hate Speech

Last week, the Russian Duma heard a first reading of proposed legislation that would increase government monitoring and control over the Internet. The new law is in "...response to the rising number of cyber crimes and, in particular, to curb increasing nationalist hate speech that is resounding across the Russian internet."

Of course, any control over one type of speech has the potential to be used in other areas:
"However, as some critics have pointed out, the text of the law seems to be wider than this: the center is charged with regulate the "development and use of the internet [sic]."

Anton Nosik, a Russian internet expert, argues that this law raises dozens of questions. First, he thinks the creation of a watchdog might lead to the Chinese approach to internet use, in which users are limited access to certain sites."


New Russian Internet Watchdog Proposed

Wednesday, January 16, 2008

Relation between Terrorist Activity, Credit Card Theft and Computer Crime

Credit card fraud is an important tool for many criminal organizations - for both funding and operational support. The Counterterrorism Blog has published an article on the acquisition and use of stolen credit cards by terrorists and the relation to computer crimes.
"The internet not only serves as a learning tool for terrorists but also functions as a mechanism to steal credit card information through hacking, phishing and other means."
The article provides two case studies: Imam SAMUDRA, convicted for the Bali bombings, and Younes TSOULI (see Insight into Al-Qaeda Use of the Internet).
"[Imam] Samudra is technologically savvy and a computer expert. While in prison in 2004, he wrote a jailhouse manifesto. It was an autobiography of his jihadist life. The book contained a chapter, entitled “Hacking, Why Not.” In it, he urged fellow Muslim radicals to take holy war into cyberspace by attacking U.S. computers. Samudra described America’s computer network as being vulnerable to hacking, credit card fraud and money laundering. The chapter did not focus on specific techniques. It focused on how to find techniques on the internet and how to connect with people in chat rooms to perfect hacking and carding skills. It was a course of study for aspiring hackers and carders. Samudra discussed the process of scanning for websites vulnerable to hacking and then went on to discuss the basics of online credit card fraud and money laundering."

Credit Cards and Terrorists

Tuesday, January 01, 2008

A Fine Line between Cybercrime and War? Not Really.

StrategyPage.com ran an article on the blurring line between criminal attacks and acts of war in cyberspace.

"In the computer age -- and 2008 is definitely in the computer age -- the difference between an act of war and crime is often a matter of interpretation as well as degree.

Attack a nation's highways and railroads, and you've attacked transportation infrastructure. You've also committed an obvious, recognized act of war.

An electronic attack doesn't leave craters or bleeding human casualties, at least not in the same overt sense of an assault with artillery and bombs. However, the economic costs can be much larger than a classic barrage or bombing campaign."

This article, like others, points out the problems and appears to want to label many attacks as acts of war or terrorism. The problem is real but answers are not simple. Cyber attacks are no different from physical attacks - what separates crime from terrorism or acts of war is not the medium or even the impact but the motivation, resources and organization behind the attack.

If a seventeen year old in China vandalizes a website because he disagrees with its content, it is a criminal act. If a nation state (whether directly or indirectly) orchestrates an online denial of service attack against another nation state, it's probably an act of war. The problem is the victim rarely knows who or why they have been attacked.

The difference in cyberspace is that it is very difficult to understand the adversary's motive. Corporations and other organizations rarely investigate the actual source of or reason behind the attack. Law enforcement and intelligence agencies are usually ill-equipped and underfunded or staffed.

These types of investigations are not impossible, but they are both costly and time consuming. Yet, as society's dependence on information infrastructures grows, so does the impact of attacks. Understanding the nature of the threat is vital to proper response. Simply labeling every attack as 'cyberwar' or 'cyber terrorism' is counter productive. Society - corporations, governments, academia and security vendors - need to invest in new and better methods and technologies to investigate cyber attacks.

Unfortunately, it will probably take a serious attack before this happens.


War -- or Crime -- in Cyberspace