Showing posts with label Cyberattack. Show all posts
Showing posts with label Cyberattack. Show all posts

Sunday, March 31, 2013

After Cyberattack, Sven Olaf Kamphuis Is at Heart of Investigation

Mr. Kamphuis, who is actually Dutch, is at the heart of an international investigation into one of the biggest cyberattacks identified by authorities. He has not been charged with any crime and he denies direct involvement. But because of his outspoken position in a loose federation of hackers, authorities in the Netherlands and several other countries are examining what role he or the Internet companies he runs played in snarling traffic on the Web this week.

He describes himself in his own Web postings as an Internet freedom fighter, along the lines of Julian Assange of WikiLeaks, with political views that range from eccentric to offensive. His likes: German heavy metal music, “Beavis and Butt-head” and the campaign to legalize medicinal marijuana. His dislikes: Jews, Luddites and authority.

Dutch computer security experts and former associates describe Mr. Kamphuis as a loner with brilliant programming skills. He did not respond to various requests for interviews, but he has communicated with the public through his Facebook page, which includes photos of himself, a thin, angular man with close-cropped hair and dark, bushy eyebrows, often wearing a hoodie sweatshirt.

“He’s like a loose cannon,” said Erik Bais, the owner of A2B-Internet, an Internet service provider that used to work with Mr. Kamphuis’s company, but severed ties two years ago. “He has no regard for repercussions or collateral damage.”

Mr. Kamphuis’s current nemesis is Spamhaus, a group based in Geneva that fights Internet spam by publishing blacklists of alleged offenders. Clients of Spamhaus use the information to block annoying e-mails offering discount Viagra or financial windfalls. But Mr. Kamphuis and other critics call Spamhaus a censor that judges what is or isn’t spam. Spamhaus acted, he wrote, “without any court verdict, just by blackmail of suppliers and Jew lies.”

The spat that rocked the Internet escalated in mid-March when Spamhaus blacklisted two companies that Mr. Kamphuis runs, CB3ROB, an Internet service provider, and CyberBunker, a Web hosting service. Spamhaus contended that CyberBunker was a conduit for vast amounts of spam. CyberBunker says it accepts business from any site as long as it does not deal in “child porn nor anything related to terrorism.”

Mr. Kamphuis responded by soliciting support for a hackers’ campaign to snarl Spamhaus’s Internet operations. “Yo anons, we could use a little help in shutting down illegal slander and blackmail censorship project ‘spamhaus.org,’ which thinks it can dictate its views on what should and should not be on the Internet,” he wrote on Facebook on March 23.

Mr. Kamphuis later disavowed any direct role in the so-called distributed denial of service, or DDoS, attack, which spilled over from Spamhaus to affect other sites. He took to Facebook to inform the world that the flood of Internet traffic that threatened to cripple parts of the Web emanated from Stophaus, an ad-hoc, amorphous group set up in January with the aim to thwart Spamhaus, a company it claims uses its “tiny business to attempt to control the Internet through underhanded extortion tactics.” Stophaus, which lists no contact or location for the group, claims to have members in the United States, Canada, Russia, Ukraine, China and Western Europe.

Mr. Kamphuis said Stophaus was not a front for him; he is merely acting as a spokesman.

Nonetheless, the authorities are curious. The Dutch national prosecutor’s office said on Thursday that it had opened an investigation. Wim de Bruin, a spokesman for the agency, which is based in Rotterdam, said prosecutors were first trying to determine whether the DDoS attacks had originated in the Netherlands. Authorities in Britain and several other European countries are also looking into the matter.

Mr. Kamphuis, who is believed to be about 35, is singled out because of his vocal role. “For the Dutch Internet community, it’s very clear that he has a big role in this, even if there isn’t 100 percent airtight proof that he is behind it,” said J. P. Velders, a security specialist at the University of Amsterdam. “He could not be not involved. How much is he involved — that is for law enforcement to figure out and to act upon.”

Greenhost, a Dutch Internet hosting service, said in a detailed blog post that it had found the digital fingerprints of CB3ROB when it examined the rogue traffic that had been directed at Spamhaus.

Mr. Kamphuis created CB3ROB in 1996 and helped set up CyberBunker in 1999. From 1999 to 2001, he worked on the help desk at a Dutch Internet service provider, XS4ALL, according to one senior manager at the company who declined to be named, citing company policy. One co-worker said Mr. Kamphuis was constantly being reprimanded for hacking into his employer’s computer system. He was known for eccentric behavior; during a company trip to Berlin, the former co-worker said, Mr. Kamphuis refused to travel with his colleagues and rode alone in a bus.

“Sven absolutely hates authority in any form,” this person said. “He was very smart. Too smart for customers, by the way. Oftentimes they couldn’t understand his technobabble when he tried to help them.”

After leaving XS4ALL, he continued to run his Web hosting business, which was based for a time in a former army bunker in Goes, the Netherlands. Photos on Mr. Kamphuis’s Facebook page show him holding a flag in front of the bunker, like a freedom fighter defending his redoubt.

CyberBunker still lists its address as the bunker. But Joost Verboom, a Dutch businessman, says the address is occupied by his own company, BunkerInfra Datacenters, which is building a subterranean Web hosting center at the site. Mr. Verboom said CyberBunker and Mr. Kamphuis left the site a decade ago. It is not clear where the servers of CyberBunker and CB3ROB are now.

Associates say Mr. Kamphuis moved to Berlin in about 2006, and his Facebook page displays photos indicating his interest in the Pirate Party, a small political movement focusing on Internet issues that holds some opposition seats in Berlin’s city-state government assembly, and in the Chaos Computer Club, a group that discusses computer issues.

For a time, CyberBunker’s clients included WikiLeaks and The Pirate Bay, a Web site whose founders were convicted by a Swedish court in 2009 of abetting movie and music piracy. In May 2010, six American entertainment companies obtained a preliminary injunction in a German court ordering CB3ROB and CyberBunker to stop providing bandwidth to The Pirate Bay.

Since the attacks, Mr. Kamphuis has given television interviews from what appeared to be an empty Internet cafe or office. In a Russian television interview, he suggested that the people responsible for the attacks were in countries where there were no laws against cyberattacks or no serious enforcement.

Mr. Kamphuis also continued to provoke people in Facebook postings. “The Internet is puking out a cancer, please stand by while it is being removed,” he wrote.

Sunday, March 24, 2013

Cyberattack Hits South Korean Banking Networks

The attacks, which left many South Koreans unable to withdraw money from A.T.M.’s and news broadcasting crews staring at blank computer screens, came as the North’s official Korean Central News Agency quoted the country’s leader, Kim Jong-un, as threatening to destroy government installations in the South, along with American bases in the Pacific.

Though American officials dismissed those threats, they also noted that the broadcasters hit by the virus had been cited by the North before as potential targets.

The Korea Communications Commission said Thursday that the disruption originated at an Internet provider address in China but that it was still not known who was responsible.

Many analysts in Seoul suspect that North Korean hackers honed their skills in China and were operating there. At a hacking conference here last year, Michael Sutton, the head of threat research at Zscaler, a security company, said a handful of hackers from China “were clearly very skilled, knowledgeable and were in touch with their counterparts and familiar with the scene in North Korea.”

But there has never been any evidence to back up some analysts’ speculation that they were collaborating with their Chinese counterparts. “I’ve never seen any real evidence that points to any exchanges between China and North Korea, ” said Adam Segal, a senior fellow who specializes in China and cyberconflict at the Council on Foreign Relations,

Wednesday’s attacks, which occurred as American and South Korean military forces were conducting major exercises, were not as sophisticated as some from China that have struck United States computers, and certainly less sophisticated than the American and Israeli cyberattack on Iran’s nuclear facilities. But it was far more complex than a “denial of service” attack that simply overwhelms a computer system with a flood of data.

The malware is called “DarkSeoul” in the computer world and was first identified about a year ago. It is intended to evade some of South Korea’s most popular antivirus products and to render computers unusable. In Wednesday’s strikes, the attackers made no effort to disguise the malware, leading some to question whether it came from a state sponsor — which tend to be more stealthy — or whether officials or hackers in North Korea were sending a specific, clear message: that they can reach into Seoul’s economic heart without blowing up South Korean warships or shelling South Korean islands.

North Korea was accused of using both those techniques in attacks over the past three years.

The cyberattacks Wednesday come just days after North Korea blamed South Korea and the United States for attacks on some of its Web sites. The North’s official Korean Central News Agency said last week that North Korea “will never remain a passive onlooker to the enemies’ cyberattacks that have reached a very grave phase as part of their moves to stifle it.”

The South Korean government cautioned that it was still too early to point the finger for Wednesday’s problems at the North, which has been threatening “pre-emptive nuclear attacks” and other, unspecified actions against its southern neighbor for conducting the military exercises with the United States this month and for supporting new American-led United Nations sanctions against the North.

“We cannot rule out the possibility of North Korean involvement, but we don’t want to jump to a conclusion,” said Kim Min-seok, a spokesman for the Defense Ministry.

The military raised its alert against cyberattacks, he added, and the Korea Communications Commission asked government agencies and businesses to triple the number of monitors for possible hacking attacks. South Korea’s new president, Park Geun-hye, instructed a civilian-government task force to investigate the disruptions.

It could take months to determine the true source of the attacks, and sometimes investigators never come to a firm conclusion. In 2009, a similar campaign of coordinated cyberattacks over the Fourth of July holiday hit 27 American and South Korean Web sites, including South Korea’s presidential palace, called the Blue House; its Defense Ministry; and Web sites belonging to the United States Treasury Department, the Secret Service and the Federal Trade Commission.

Nicole Perlroth contributed reporting from San Francisco, and David E. Sanger from Washington.

Thursday, October 25, 2012

Cyberattack on Saudi Oil Firm Disquiets U.S.

On Aug. 15, more than 55,000 Saudi Aramco employees stayed home from work to prepare for one of Islam’s holiest nights of the year — Lailat al Qadr, or the Night of Power — celebrating the revelation of the Koran to Muhammad.

That morning, at 11:08, a person with privileged access to the Saudi state-owned oil company’s computers, unleashed a computer virus to initiate what is regarded as among the most destructive acts of computer sabotage on a company to date. The virus erased data on three-quarters of Aramco’s corporate PCs — documents, spreadsheets, e-mails, files — replacing all of it with an image of a burning American flag.

United States intelligence officials say the attack’s real perpetrator was Iran, although they offered no specific evidence to support that claim. But the secretary of defense, Leon E. Panetta, in a recent speech warning of the dangers of computer attacks, cited the Aramco sabotage as “a significant escalation of the cyber threat.” In the Aramco case, hackers who called themselves the “Cutting Sword of Justice” and claimed to be activists upset about Saudi policies in the Middle East took responsibility.

But their online message and the burning flag were probably red herrings, say independent computer researchers who have looked at the virus’s code.

Immediately after the attack, Aramco was forced to shut down the company’s internal corporate network, disabling employees’ e-mail and Internet access, to stop the virus from spreading.

It could have been much worse. An examination of the sabotage revealed why government officials and computer experts found the attack disturbing. Aramco’s oil production operations are segregated from the company’s internal communications network. Once executives were assured that only the internal communications network had been hit and that not a drop of oil had been spilled, they set to work replacing the hard drives of tens of thousands of its PCs and tracking down the parties responsible, according to two people close to the investigation but who were not authorized to speak publicly about it.

Aramco flew in roughly a dozen American computer security experts. By the time those specialists arrived, they already had a good handle on the virus. Within hours of the attack, researchers at Symantec, a Silicon Valley security company, began analyzing a sample of the virus.

That virus — called Shamoon after a word embedded in its code — was designed to do two things: replace the data on hard drives with an image of a burning American flag and report the addresses of infected computers — a bragging list of sorts — back to a computer inside the company’s network.

Shamoon’s code included a so-called kill switch, a timer set to attack at 11:08 a.m., the exact time that Aramco’s computers were wiped of memory. Shamoon’s creators even gave the erasing mechanism a name: Wiper.

Computer security researchers noted that the same name, Wiper, had been given to an erasing component of Flame, a computer virus that attacked Iranian oil companies and came to light in May. Iranian oil ministry officials have claimed that the Wiper software code forced them to cut Internet connections to their oil ministry, oil rigs and the Kharg Island oil terminal, a conduit for 80 percent of Iran’s oil exports.

It raised suspicions that the Aramco hacking was retaliation. The United States fired one of the first shots in the computer war and has long maintained the upper hand. The New York Times reported in June that the United States, together with Israel, was responsible for Stuxnet, the computer virus used to destroy centrifuges in an Iranian nuclear facility in 2010.

Last May, researchers discovered that Flame had been siphoning data from computers, mainly in Iran, for several years. Security researchers believe Flame and Stuxnet were written by different programmers, but commissioned by the same two nations.

If American officials are correct that Shamoon was designed by Iran, then clues in its code may have been intended to misdirect blame. Shamoon’s programmers inserted the word “Arabian Gulf” into its code. But Iranians refer to that body of water as the Persian Gulf and are very protective of the name. (This year, Iran threatened to sue Google for removing the name Persian Gulf from its online maps.)

Saturday, October 13, 2012

Panetta Warns of Dire Threat of Cyberattack on U.S.

In a speech at the Intrepid Sea, Air and Space Museum in New York, Mr. Panetta painted a dire picture of how such an attack on the United States might unfold. He said he was reacting to increasing aggressiveness and technological advances by the nation’s adversaries, which officials identified as China, Russia, Iran and militant groups.

“An aggressor nation or extremist group could use these kinds of cyber tools to gain control of critical switches,” Mr. Panetta said. “They could derail passenger trains, or even more dangerous, derail passenger trains loaded with lethal chemicals. They could contaminate the water supply in major cities, or shut down the power grid across large parts of the country.”

Defense officials insisted that Mr. Panetta’s words were not hyperbole, and that he was responding to a recent wave of cyberattacks on large American financial institutions. He also cited an attack in August on the state oil company Saudi Aramco, which infected and made useless more than 30,000 computers.

But Pentagon officials acknowledged that Mr. Panetta was also pushing for legislation on Capitol Hill. It would require new standards at critical private-sector infrastructure facilities — like power plants, water treatment facilities and gas pipelines — where a computer breach could cause significant casualties or economic damage.

In August, a cybersecurity bill that had been one of the administration’s national security priorities was blocked by a group of Republicans, led by Senator John McCain of Arizona, who took the side of the U.S. Chamber of Commerce and said it would be too burdensome for corporations.

The most destructive possibilities, Mr. Panetta said, involve “cyber-actors launching several attacks on our critical infrastructure at one time, in combination with a physical attack.” He described the collective result as a “cyber-Pearl Harbor that would cause physical destruction and the loss of life, an attack that would paralyze and shock the nation and create a profound new sense of vulnerability.”

Mr. Panetta also argued against the idea that new legislation would be costly for business. “The fact is that to fully provide the necessary protection in our democracy, cybersecurity must be passed by the Congress,” he told his audience, Business Executives for National Security. “Without it, we are and we will be vulnerable.”

With the legislation stalled, Mr. Panetta said President Obama was weighing the option of issuing an executive order that would promote information sharing on cybersecurity between government and private industry. But Mr. Panetta made clear that he saw it as a stopgap measure and that private companies, which are typically reluctant to share internal information with the government, would cooperate fully only if required to by law.

“We’re not interested in looking at e-mail, we’re not interested in looking at information in computers, I’m not interested in violating rights or liberties of people,” Mr. Panetta told editors and reporters at The New York Times earlier on Thursday. “But if there is a code, if there’s a worm that’s being inserted, we need to know when that’s happening.”

He said that with an executive order making cooperation by the private sector only voluntary, “I’m not sure they’re going to volunteer if they don’t feel that they’re protected legally in terms of sharing information.”

“So our hope is that ultimately we can get Congress to adopt that kind of legislation,” he added.

Mr. Panetta’s comments, his most extensive to date on cyberwarfare, also sought to increase the level of public debate about the Defense Department’s growing capacity not only to defend but also to carry out attacks over computer networks. Even so, he carefully avoided using the words “offense” or “offensive” in the context of American cyberwarfare, instead defining the Pentagon’s capabilities as “action to defend the nation.”

Elisabeth Bumiller reported from New York, and Thom Shanker from Washington.

Thursday, October 4, 2012

Bits Blog: Google Warns of New State-Sponsored Cyberattack Targets

The warning from Google.

In June, many Google users were surprised to see an unusual greeting at the top of their Gmail inbox, Google home page or Chrome browser. “Warning: We believe state-sponsored attackers may be attempting to compromise your account or computer.”


On Tuesday, tens of thousands more Google users will begin to see that message. The company said that since it started alerting users to malicious — probably state-sponsored — activity on their computers in June, it has picked up thousands more instances of cyberattacks than it anticipated.


Mike Wiacek, a manager on Google’s information security team, said in an interview on Tuesday that since Google started to alert users to state-sponsored attacks three months ago, it had gathered new intelligence about attack methods and the groups deploying them. He said the company was using that information to warn “tens of thousands of new users” that they may have been targets, starting on Tuesday.


By Tuesday afternoon, several people — many of them American journalists and foreign policy experts — had already taken to Twitter to say they had seen the warning. Noah Schactman, the editor of Wired’s national security blog “Danger Room,” tweeted: “Aaaaand I just got Google’s ‘you may be a victim of a state-sponsored attack’ notice. #WhatTookYouSoLong?” Daveed Gartenstein-Ross, a senior fellow at the Foundation for Defense of Democracies, also reported getting the message.  As did Joshua Foust, a fellow at the American Security Project, a nonprofit research organization, who has written extensively about Afghanistan.


Mr. Wiacek noted that Google had seen an increase in state-sponsored activity coming from the Middle East. He declined to call out particular countries, but he said the activity was coming from “a slew of different countries” in the region.


Those findings triangulate with recent discoveries by security researchers that Middle Eastern states, including Iran, Qatar, the United Arab Emirates and Bahrain, have used spyware to monitor citizens and activists overseas.


Last week, several American banks were hit with cyberattacks by hackers claiming Middle Eastern ties. Security researchers have said they have noticed an increase in cyberattacks originating in the region. “We absolutely have seen more activity from the Middle East, and in particular Iran has been increasingly active as they build up their cybercapabilities,” George Kurtz, the president of CrowdStrike, a computer security company, said in a recent interview.


Mr. Wiacek said there were several steps Google users, especially those who get its warning, could take to protect themselves, like changing their e-mail and account passwords, enabling Google’s two-step authentication service and running their computer software updates.

Wednesday, August 1, 2012

The Lede Blog: Iranian Scientist Claims U.S. Cyberattack Was ... Loud

The United States has a rather bizarre history of blasting rock music into the ears of presumed enemies, so it seemed plausible when a prominent security expert reported Monday that a new cyberattack on Iran’s atomic program included workstations erupting in booms of “Thunderstruck” by AC/DC, an Australian rock band.

In a blog post, Mikko Hypponen, the chief research officer of F-Secure, a computer security company based in Finland, cited “a series of e-mails” he had received from “a scientist working at the Atomic Energy Organization of Iran.” He admitted he was unable to confirm any details of the alleged attack but said the sender was using the correct e-mail address, aeoi.org.ir.

Mr. Hypponen quoted the scientist as saying the music hit “in the middle of the night with the volume maxed out.”

His report created a sensation as blogs and news reports around the globe repeated the claim. ForeignPolicy.com went further, noting on its blog that the United States had repeatedly blasted loud music at supposed foes.

For instance, it noted that American troops in 1989 had tried to force the Panamanian president, Manuel Noriega, from his refuge in the Vatican embassy by bombarding it with loud music. The blog told of military DJs taking requests and creating a playlist that included AC/DC’s “You Shook Me All Night Long.”

More recently, Foreign Policy said, the United States Psychological Operations Company “admitted to the use of heavy metal in Iraq as a mechanism to break uncooperative prisoners’ resistance.” And the International Committee of the Red Cross, it noted, had reported the use of similar tactics against Guantánamo inmates.

Alas, the Iranian episode seems too good to be true.

Specialists in cyberwarfare said the e-mails could have easily been faked, including the seeming return address from the Iranian atomic program. Simple logic, one expert noted, suggested that an Iranian scientist writing such a report to a foreigner might quickly join the ranks of the martyrs. Finally, the tone of the alleged e-mails from the Iranian scientist seemed suspicious in their self-congratulatory tone about the success of the computer attack and its heavy-metal explosion.

“I doubt it,” a senior administration official who closely follows the Iranian program said of the cyber claim.

Sunday, July 29, 2012

The Lede Blog: Iranian Scientist Claims U.S. Cyberattack Was ... Loud

The United States has a rather bizarre history of blasting rock music into the ears of presumed enemies, so it seemed plausible when a prominent security expert reported Monday that a new cyberattack on Iran’s atomic program included workstations erupting in booms of “Thunderstruck” by AC/DC, an Australian rock band.

In a blog post, Mikko Hypponen, the chief research officer of F-Secure, a computer security company based in Finland, cited “a series of e-mails” he had received from “a scientist working at the Atomic Energy Organization of Iran.” He admitted he was unable to confirm any details of the alleged attack but said the sender was using the correct e-mail address, aeoi.org.ir.

Mr. Hypponen quoted the scientist as saying the music hit “in the middle of the night with the volume maxed out.”

His report created a sensation as blogs and news reports around the globe repeated the claim. ForeignPolicy.com went further, noting on its blog that the United States had repeatedly blasted loud music at supposed foes.

For instance, it noted that American troops in 1989 had tried to force the Panamanian president, Manuel Noriega, from his refuge in the Vatican embassy by bombarding it with loud music. The blog told of military DJs taking requests and creating a playlist that included AC/DC’s “You Shook Me All Night Long.”

More recently, Foreign Policy said, the United States Psychological Operations Company “admitted to the use of heavy metal in Iraq as a mechanism to break uncooperative prisoners’ resistance.” And the International Committee of the Red Cross, it noted, had reported the use of similar tactics against Guantánamo inmates.

Alas, the Iranian episode seems too good to be true.

Specialists in cyberwarfare said the e-mails could have easily been faked, including the seeming return address from the Iranian atomic program. Simple logic, one expert noted, suggested that an Iranian scientist writing such a report to a foreigner might quickly join the ranks of the martyrs. Finally, the tone of the alleged e-mails from the Iranian scientist seemed suspicious in their self-congratulatory tone about the success of the computer attack and its heavy-metal explosion.

“I doubt it,” a senior administration official who closely follows the Iranian program said of the cyber claim.