Showing posts with label corporate espionage. Show all posts
Showing posts with label corporate espionage. Show all posts

Wednesday, April 16, 2008

Corporate suits targeted in spear phishing attack!

The mainstream media is reporting that the Phishermen attempted to spear a large number of corporate executive types this week.

This form of phishing is referred to as spear phishing, or whaling. The intent of phishing is to trick an unwary human being into giving up sensitive personal or financial information, which is later used to for illicit purposes. Spear phishing or whaling is simply a more focused approach designed to target more specific targets than everyday run of the mill phishing attacks, which are sent out by the millions via spam spewing botnets.

The New York Times is reporting:

Thousands of high-ranking executives across the country have been receiving e-mail messages this week that appear to be official subpoenas from the United States District Court in San Diego. Each message includes the executive’s name, company and phone number, and commands the recipient to appear before a grand jury in a civil case.

If any of them clicked on the link directing them to a view of the full subpoena, they probably downloaded malicious software with keylogging capabilities. Once this is dropped on a system, keystrokes are recorded and transmitted back to the criminals behind the attack.

The normal intent when this done is to commit financial crime, but given the targets in this attack, corporate espionage (information theft) could be the intention, also.

The malware bundle allegedly places the victim's computer under the control of the phishermen. When this occurs, the infected computer is often referred to as a zombie.

The latest attack has prompted warnings to be placed on the websites of two California Federal Courts, as well as, the administrative office of the United States Courts.

The New York Times article speculated that this attack was of Chinese origin, while Brian Kreb's article in the Washington Post speculated the attack could be of Romanian origin. Both of these speculations came from noted industry security experts. Unfortunately in the world of cybercrime, the activity often so anonymous, all the rest of us can do is speculate as to who might actually be behind it.

Please note that speculating that the activity might have come from either China or Romania is probably a good deduction. Both countries are known to host a lot of criminal activity of a cyber nature.

It is also being reported that not all the security products out there will detect this attack.

I guess that the only solace from this fact is that if you can teach the user to recognize the social engineering aspects of these attacks, they aren't going to click on the link and infect their system.

Even though "fear" is well-known social engineering technique, if you examine the attack it doesn't make very much sense. After all, the last time I checked, a subpoena delivered via electronic communication wouldn't be legally binding. It's probably a no-brainer that federal courts wouldn't issue a subpoena via an e-mail.

Sadly, more employees fall for phishing attempts than many might realize. In fact, some organizations are now testing their own employees with scary results. Most recently, this was done by both the U.S. Army and the IRS.

Update 4/19/08: The FBI announced that a new phishy e-mail is circulating regarding a grand jury summons. Not sure if this is a tie in, but as Alex Eckelberry lamented on the Sunbelt blog -- phishing attacks are becoming more specifically targeted and the intent might be more than to steal financial information. Of course, that's not to say there isn't financial motivation involved, there normally is.

Thursday, March 13, 2008

London e-crime conference suggests that hackers are becoming more organized and politically motivated

In the past several years, we've seen a lot of corporate and government systems compromised by hackers. With corporate systems, we assume the intent is financial, however more and more, we hear the term, "corporate espionage" being used. In the global economy, information is often worth more than money.

With regards to government systems being hacked, it's hard to speculate that the attack was financially motivated.

Mandy Clark of Voice of America wrote an interesting article on this subject, while covering an International e-crime congress in London:

British opposition lawmaker David Davis warned an e-crime conference in London that the danger of cyber terrorism is real.

"In America, hackers have already broken into the Pentagon's computer systems; in India, into government ministers' files; in Germany, into the chancellor's," Davis said. "Such attacks could be designed to compromise safety systems, critical national infrastructure, to overwhelm communication systems, or even to cause a run on the bank."

Included in the VOA article is a video containing a lot of commentary from experts from both the government and private sectors:

Cyber Threat report / Broadband - Download (WM)

Cyber Threat report / Broadband - Watch (WM)



Unfortunately, many consider this type of activity open to speculation, or point out that it might be mere propoganda. In the end -- IF this activity is caused by organized crime or those with more political intentions -- it's going to be hard to get the people behind it to comment.

Political misfits, criminals, spies and hackers normally want to keep their activity confidential because transparency often compromises whatever goal they are trying to achieve.

Nonetheless, a lot of experts and lay people agree that we are seeing more of this type of activity and that it is becoming a lot more sophisticated than it used to be.

VOA article by Mandy Clark, here.

United Press International covered this story from a NATO cyber warfare perspective, here.

Saturday, January 19, 2008

Why Walmart might be looking for a few good spies

Ran into a interesting story alleging that large corporations -- in this instance Wal-Mart -- are hiring former government intelligence types to work in their corporate security departments.

The story that I found in RINF.com, which states that they monitor the "surveillance society," focused on Wal-Mart delving into the personal details of two of their former executives.

Apparently, the personal details of an affair became public, when one of the executives was being investigated for a conflict of interest with a advertising agency. The article also states that the executive being investigated got the other executive her job.

In all fairness -- despite the article's focus on privacy concerns -- conflicts of interest and intellectual property crimes are becoming a growing problem for corporations. The fact that one person got another person a job based on a personal relationship might be a little questionable, also?

Here is what the article, written by Douglas Frantz, had to say about former goverments running this investigation:

Largely overlooked in the furor was the role that Wal-Mart’s internal security department had played in digging up the salacious details. This department, a global operation, was headed by a former senior security officer for the Central Intelligence Agency and staffed by former agents from the C.I.A., the Federal Bureau of Investigation, and other government agencies. (See our Spy Slang guide) A person familiar with the episode said in an interview that an ex-C.I.A. computer specialist was involved in piecing together the email evidence—which included copies of Womack’s private Gmail messages, provided by his estranged wife—and that another former government agent had supervised the overall investigation.

Ex-government agents appear to be Wal-Mart’s investigators of choice. The retailer has emailed job listings to members of the Association for Intelligence Officers as well as posted ads on its site seeking to hire “global threat analysts” with backgrounds in intelligence. The job description for the analysts, who would have reported to a former Army intelligence officer, entailed collecting information from “professional contacts” to gauge threats from “suspect individuals and groups.” In practice, their responsibilities would have extended to gathering information about Wal-Mart employees, suppliers, and customers; Wal-Mart monitors shoppers for suspicious or potentially criminal activity. A Wal-Mart spokesman said the company does not comment on security matters.

Ex-government agents appear to be Wal-Mart’s investigators of choice. The retailer has emailed job listings to members of the Association for Intelligence Officers as well as posted ads on its site seeking to hire “global threat analysts” with backgrounds in intelligence. The job description for the analysts, who would have reported to a former Army intelligence officer, entailed collecting information from “professional contacts” to gauge threats from “suspect individuals and groups.” In practice, their responsibilities would have extended to gathering information about Wal-Mart employees, suppliers, and customers; Wal-Mart monitors shoppers for suspicious or potentially criminal activity. A Wal-Mart spokesman said the company does not comment on security matters.
While the article seems to target activity at Walmart, it alleges that their is a substantial market for this type of service:

The best estimate is that several hundred former intelligence agents now work in corporate espionage, including some who left the C.I.A. during the agency turmoil that followed 9/11. They quickly joined private-investigation firms whose U.S. corporate clients were planning to expand into Russia, China, and other countries with opaque business practices and few public records, and who needed the skinny on international partners or rivals.

With outsourcing becoming the norm for large corporations, I would imagine that experts in the espionage field might be a prudent investment for some of these corporations.

One reason might be counterfeiting, which the International Anticounterfeiting Association estimates to be a $600 billion dollar a year problem.

Intellectual property theft is being touted the crime of this century. While just about everything you can imagine is being counterfeited, technology seems to be targeted, most frequently.

In fact, IPhones, which were last years big tech item, were being cloned and sold on eBay by the time the product was rolled out in the United Kingdom.

There are constant reports of Chinese involvement in espionage from the corporate level to hackers breaking into government systems. Couple this with large corporations having their a lot of products manufactured in China and it's no wonder the services of a few good former spies might be prudent.

We probably shouldn't be surprised that corporations are turning to espionage experts to protect their assets. In fact in the age of the global economy and outsourcing, we are going probably going to see a growing demand for this type of expertise in the private sector.

RINF.com article, here.

IAAC White Paper on intellectual property theft, here.

The FBI did an interesting (my opinion) press release showing a little corporate espionage with a Chinese connection in 2006, which can be seen by clicking here.

Sunday, November 18, 2007

One Bot herder facing 60 years is a small dent in the overall problem!


(Screen shot of botnets for rent courtesy of the Mind Streams of Information Security Knowledge blog)

While John Schiefer a.k.a. "acid and "acidstorm," is facing 60 years in prison and $1.75 million in fines for operating a botnet, the problem isn't likely to disappear anytime soon.

Schiefer was part of a hacker group known as Defonic, who gained a lot of notoriety for hacking Paris Hilton's cell phone and breaking into Lexis Nexis. Lexis Nexis is an information broker used by a lot of investigative and collection types to find people they are looking for.

Besides Paris, Defonic seemed to have a penchant for celebrity information, a lot of which they gathered by hacking Lexis Nexis, according to Brian Krebbs of the Washington Post.

While I knew this already, I ran into a very interesting blog written by Dancho Danchev that illustrates the problem that botnets have become, worldwide.

In his own words, Dancho describes how botnets can be bought, or rented fairly cheaply by spammers, phishermen and corporate spies, alike:

What about the prices? Differentiated pricing on a per country is an interesting pricing approach, for instance, 1000 infected hosts in Germany are available for $220, and 1000 infected hosts in the U.S go for half the price $110. It doesn't really feel very comfortable knowing someone's bargaining with your bandwidth and clean IP reputation, does it? What's worth discussing is the fact that the service isn't marketed as a DIY DDoS service, but as a simple acccess to a botnet one, where the possibilities for abuse are well known to everyone reading here. Spamming and phishing mailings, hosting and distribution of malware using the rented infrastructure, OSINT through botnets, corporate espionage through botnets, pretty much all the ugly practices you can think of.

The bottom line is that although Mr. Schiefer and some of his friends have been taken down, there are a lot of hackers ready to fill the small void he may have left in the botnet market.

Very INTERESTING read from Dancho on his blog, "Mind Streams of Information Security Knowledge," here.

A lot was written about John Schiefer when he pled guilty. Brian Krebs of the Washington Post deserves a "hat-tip" for giving everyone a lot of insight about Mr. Schiefer's previous dealings.

The post, he wrote about this in his blog, Security Fix can be read, here.

The best way to avoid having your computer becoming a zombie (botnet member) is to avoid clicking on any links in a spam e-mail, or downloading additional software that is presented to you after visiting a questionable website.

Most of the time, social engineering lures (trickery) is used to get a human being to put malicious software on their system.

Of course, trying to make sure your system is bulletproof (protected by reputable security software) is recommended, also.

Friday, November 16, 2007

U.S. China Commission Report reveals serious issues that need to be dealt with!

Reports of the Chinese hacking into government systems are nothing new. Along with the constant reports of substandard products being put on our shelves, there is little doubt that the Chinese pose a threat to our safety in a LOT of different ways.

The U.S. China Commission has just released a disturbing report, which indicates some alarming evidence that the Chinese might be a threat to our National security.

The first concern is what appears to be a growing capability to target satellites. I got the following directly from the report, which was provided to Congress:

The hearing was timely, coming only three months after a successful direct-ascent anti satellite test by China that destroyed one of its own aging weather satellites in low-earth orbit. This test was only the third of its kind by any nation in history and served as a useful reference point during the hearing to illustrate not only China’s advances in military capabilities, but also the extent to which China’s decision making process is still very much opaque. This incident raises questions about Chinese intentions in space. The Commission will address these questions as it continues to monitor developments.

In the same realm, it appears that China is actively developing capabilities to conduct "irregular warfare." It should be noted that in addition to this report there have been regular reports of hackers from China specifically targeting government systems.

This is what the current report concluded:

Several experts testified that if China were to find itself in an armed conflict with the United States and its allies such as that resulting from a Taiwan dispute, China is likely to employ an array of irregular warfare strategies against its adversaries. According to Michael Vickers, Senior Vice President for Strategic Studies at the Center for Strategic and Budgetary Assessments, a Chinese attack on Taiwan could entail special operations and cyber attacks on U.S. regional bases in Japan and South Korea, and might even include cyber attacks on the U.S. homeland that target the U.S. financial, economic, energy, and communications infrastructure.

Also covered in the report are previously documented cyber-intrusions into U.S. Government systems:

As evidenced by the trajectory of its military modernization, Chinese defense planners are seeking to accomplish the goal of undermining the U.S. military’s technological edgethrough a variety of disruptive means. Among these is cyber warfare. USSTRATCOM Commander General Cartwright testified before the Commission that China is actively engaging in cyber reconnaissance by probing the computer networks of U.S. government agencies as well as private companies. The data collected from these computer reconnaissance campaigns can be used for myriad purposes, including identifying weak points in the networks, understanding how leaders in the United States think, discovering the communication patterns of American government agencies and private companies, and attaining valuable information stored throughout the networks. General Cartwright testified that this information is akin to that which in times past had to be gathered by human intelligence over a much longer period of time. He went on to say that in today’s information environment, the exfiltration that once took years can be accomplished in a matter of minutes in one download session.
The report also concludes that the Chinese have been building up their more traditional military capabilities since 1992.

Going into the reasons why China has been able to accomplish this, the report states:

China’s policies of market liberalization have resulted in rapid export-led economic growth prompting increased foreign investment; development of China’s manufacturing capabilities; and integration into the global supply chain. China’s abundant and inexpensive labor supply has made that country an obvious place for multinational companies to expand their production. However, as Dr. Peter Navarro, Professor of Business at the University of California, Irvine, observed in his testimony, five of eight factors identified as major drivers of China’s comparative advantage—i.e., its ability to undercut the prices of global competitors—are considered unfair trading practices. These include its undervalued currency, counterfeiting and piracy, export industry subsidies, and lax health, safety, and environmental regulations. These practices violate China’s WTO commitments, especially regarding workers’ rights, market access, currency manipulation, subsidies, and the protection of intellectual property rights. These violations and unfair practices also contribute to a growing U.S. trade deficit with China, one that U.S. Census Bureau statistics confirm increased 177 percent in the past six years from $83.8 billion in 2000 to $232.5 billion in 2006.

Granting China a "Permanent Normal Trading Relationship" six years ago was sold to the American public as a means of making China a better place (more democratic) place for it's people.

Instead, we have seen a lot of questionable government activity, which includes a variety of criminal enterprises when we consider all the hacking, counterfeiting and piracy that can be directly traced back to that country.

The lack of safe manufacturing practices and counterfeiting also poses a threat to our safety. It should be noted that according to International Anticounterfeiting Coalition, counterfeiting is a $600 billion a year problem, worldwide.

There are no figures on how much of this comes from China, although most experts on this subject speculate a lot of it does. Additionally, there is a lot of evidence that a lot of counterfeit merchandise is present in our supply chain. This evidence would include products of a consumable nature such as drugs, also.

The FDA estimates that 10 percent of the drugs in our supply system are counterfeit.

A lot of this probably tied into another phenomenon traced to the Chinese known as corporate (industrial) espionage. Of course, there is probably less of a need for the Chinese to plant spies in our industrial complexes anymore. With the amount of outsourcing going on, they probably never have to set foot out of China to steal a lot of secrets from us.

According to the Washington Post, American companies are even outsourcing the manufacture of military parts:

The Pentagon is increasingly buying planes, weapons and military vehicles from private contractors that outsource the manufacturing to plants in China and elsewhere in Asia, the report said. But when questioned by the commission, defense officials admitted that they do not have the ability to track where the components of military equipment are made.

To me, given all the recent implications of Chinese intentions, this makes the least sense!

All of these factors have led to a loss of jobs within our country as corporations take advantage of cheap labor, which is often the greatest expense in any business.

This translates into record profits for the Chinese and a select few people in the West.

Given the safety, National security and economic implications, continuing down this road doesn't seem to be in the best interests of the average person.

The full report from the U.S. China Commission can be viewed, here.

Tuesday, August 28, 2007

China caught stealing government information again!

The Chinese, who were recently accused of poisoning pets and selling toxic toothpaste are now being accused of hacking into government computers in Germany.

Roger Boyes of the TIMESONLINE reports:

Der Spiegel, quoting senior officials from the German equivalent of Special Branch, said that the hacking operation was discovered in May. Computers in the Chancellery, the Foreign, Economics and Research ministries had been targeted. The Federal Office for the Protection of the Constitution (BfV) conducted a comprehensive search of government IT installations and prevented a further 160 giga-bytes of information being transferred to China. Commentators described it as “the biggest digital defence ever mounted by the German state”.

The information was being siphoned off almost daily by hackers in Lanzhou, northern China, in Canton province and in Beijing. The scale and the nature of the data being stolen suggest, the investigators say, that the operation must have been steered by the State and, in particular, the People’s Liberation Army.

Naturally, the Chinese are denying involvement, but this isn't the first time we've heard of them hacking into systems, or committing government/corporate espionage.

Here are a couple of posts, I wrote awhile ago where U.S. government computers were the target:

How Dangerous is China

The Hackers from China are at it AGAIN!

Last year, the FBI arrested two men stealing technology secrets and attempting to take them to China. Their press release on this matter can be seen, here.

USA Today (David J. Lynch) also did an excellent article quoting FBI sources about the problem, which can be seen, here.

We need to start considering the consequences of continuing to allow this to go on unchecked.

Roger Boyes story (worth reading), here.

Wednesday, June 20, 2007

FTC name impersonated to phish (steal information) from corporate executives

Spammers love to impersonate official agencies to hook their victims (phish). Recently, the attacks have become more specific targeting people by name, and or title. Here is a warning from the Federal Trade Commission (FTC):

Consumers, including corporate and banking executives, appear to be targets of a bogus e-mail supposedly sent by the Federal Trade Commission but actually sent by third parties hoping to install spyware on computers. The bogus e-mail poses as an acknowledgment of a complaint filed by the recipient, and includes an attachment. Consumers who open the attachment to this e-mail unleash malicious spyware onto their computer. The agency warns consumers who get this e-mail that purports to be from the FTC:

Don’t open the attachment.
Delete the e-mail.
Empty the deleted items folder.

The hoax e-mail is personalized, and contains the name of the recipient and their business. The bogus message explains how the complaint will be used, who will have access to it and states, “Attached you will find a copy of your complaint. Please print a hard copy of the complaint for your records in the upcoming investigation.” Opening the attachment downloads the malicious spyware.


The press release doesn’t specify exactly what the malicious spyware is.

Recently, the IRS and Better Business Bureau names were being used in a similar manner. In this attack, corporate executives were being specifically targeted, also. This type of attack is known as spear phishing.

Here is a post on the attack spoofing (impersonating) the IRS and BBB:

Spear phishermen target executives to steal company information

FTC release on this attack, here.

Sunday, May 20, 2007

Technology alone isn't going to stop phishermen and other cyber ghouls on the Internet

Not so long ago, I did a post about how the federal government was phishing their own employees.

It didn’t surprise me that many of the phish took the bait, pretty easily. It would just mean that the federal employees, who were phished are no different from the general population on the Internet.

After all, there wouldn’t be so much phishing, if it didn’t work.

Apparently, the practice is catching on and Amy Joyce of the Washington Post did an interesting article about why the idea might be a good one.

In the article, James MacDougall (South Carolina’s computer security guru) as saying:


You can spend all the money on the technology you want, MacDougall said. But if the end users are doing dangerous behavior, there is almost no cure for that.


Mr. MacDougall has hit an important point right on the head and phishing tends to set new records, every time the Anti Phishing Working Group issues their monthly report. Their most recent report (April) indicates that not only did the number of phishing sites set a new record, but their numbers more than doubled over the previous month (March).

Spam filters designed to stop phishy e-mails seem to be under major attack, and haven't been very effective in the recent past, either.

Maybe, we are spending too much money on technology to solve the problem rather than using some good old fashioned common sense?

One of the reasons, technology tends to be defeated, or used by criminals – is that it is too easily compromised by human beings. Most financial scams rely on the greed factor, or getting people to fall for something that's too good to be true.

It doesn’t take a genius to buy DIY (do it yourself) crime kits, which are readily available over the Internet, and commit what some might consider, sophisticated criminal activity.

Relying on technology to protect us without human oversight is a big mistake, and this holds true, for more than financial crimes.

Government and private systems are attacked all the time for their information.

Technology is a wonderful tool and makes things easier, but it has limitations. Instead of throwing all of our resources into technology, which seems to have a limited life span, maybe we need to focus more on the human factors that put us at risk, daily.

Thought provoking story by Amy Joyce, here.

Saturday, September 30, 2006

HP Investigators Used the Same Tools as Phishermen and Fraudsters

Technology has taken away a lot of personal privacy. We often "cringe" when fraudsters and phishermen try to steal our personal information, but the sad truth is that there are many "so called" legitimate people out there doing the same thing.

Jon Schwartz of USA Today reported:

In snooping on a reporter to pinpoint internal news leaks, Hewlett-Packard used high-tech tools common to spammers, phishers, retailers, suspicious employers and investigators.

Those tools, including phishing-style e-mail and tracing software, underscore the growing use of electronic surveillance to monitor consumers' every digital move, computer-security experts say.

Misleading e-mails from HP investigators to CNet reporter Dawn Kawamoto "smacked of phishing tactics" to trick her into divulging information, says Dave Jevans, chairman of the Anti-Phishing Working Group.
USA Today story, here.

What the computer security experts might be referring to are "keyloggers."

If you would like to see how (anyone) can use this technology, link here.

Unfortunately, it doesn't take a private investigator, or computer security expert to electronically invade someone's privacy.

My question is - with the abuses of this technology - why is it legal?

Saturday, June 17, 2006

How Big a Problem is Corporate Espionage?

I came across an interesting article by By Patrick J. Smith and Kevin Barrows of the New York Law Journal about the legal implications of corporate espionage.

In the article, Patrick Smith and Kevin Barrows write:

Stealing confidential information or valuable intellectual property no longer requires hours of surreptitious photocopying or the smuggling of overstuffed briefcases past building security. Corrupt employees need not even transfer data to a disk. Any employee with access to the Internet can copy and upload data to Web-based e-mail services with a few simple keystrokes and mouse clicks.

Among the most common acts of corporate espionage is the theft of personal data regarding individuals for the purpose of engaging in identity theft schemes. These are often inside jobs: It is estimated that as much as 50 percent of companycomputer security breaches are perpetrated by insiders.


The theft of confidential information is by no means limited to identity theft schemes. Organizations are also at risk of having their current employees paid off by others to steal valuable proprietary information and intellectual property that is then used against the organization in the marketplace. Or, perhaps a former employee steals the information prior to leaving in an effort to jump start his or her own business venture.


For the full story, link here.

Reading this made me think - with all the unresolved data breaches we've seen recently - could the true intent have been to steal inside information rather than commit "identity theft?"

Take the recent series of laptops stolen from Ernst and Young - which were stolen during audits - and contained a lot of information from numerous companies. In at least one instance cited, the laptops were stolen from a meeting room; while the auditors lunched. Not sure, but I would imagine that the building where they were taken from was at least somewhat secure.

The sad truth is since most of these data intrusions are never solved, we will probably never know.

Then there was the scandal in Israel about a year ago, where private investigators were hired to steal information via a Trojan put into various computer systems. The scandal was pretty widespread and with the "global economy" had worldwide implications.

No matter how you look at it, corporate espionage can be added to the list of reasons why it is important to protect "electronic information." As "technology" continues to grow the potential for information to be exposed to criminals, terrorists and even "corporate spies" is a very real threat.

All too often, we look to technology fixes - when in fact - no technology created to date can defeat the human mind and until we address the "social" aspects of this problem, it will continue to be a major issue.