Showing posts with label Stuxnet. Show all posts
Showing posts with label Stuxnet. Show all posts

Thursday, August 16, 2012

Dishonorable Disclosures

Intelligence and Special Operations forces are furious and frustrated at how President Obama and those in positions of authority have exploited their service for political advantage. Countless leaks, interviews and decisions by the Obama Administration and other government officials have undermined the success of our Intelligence and Special Operations forces and put future missions and personnel at risk.

The unwarranted and dangerous public disclosure of Special Forces Operations is so serious -- that for the first time ever -- former operators have agreed to risk their reputations and go 'on the record' in a special documentary titled "Dishonorable Disclosures." Its goal is to educate America about serious breaches of security and prevent them from ever happening again.

Use of military ranks, titles & photographs in uniform does not imply endorsement of the Dept of the Army or the Department of Defense. All individuals are no longer in active service with any federal agency or military service.




It is time to stop the leaks.  This film is 22 minutes of instruction into the basics of Intelligence and Special Operations units.  When the White House, Pentagon, Congress or any other government agency or personal leaks intelligence, they put every person working in the field in grave danger.  We have lost operatives when this has happened.  A thought that every person in the government should remember when they open their mouths and scream how they did an operation.

MR. PRESIDENT YOU DID NOT KILL BIN LADEN!!! 

A true leader does not leak information to make himself look great.  He keeps his mouth shut and lets other tell the story, knowing that when in the future is revealed, he would then look good.  He does NOT tell Hollywood idiots any real information nor does he use these men as political weapons against his political opponents.

Mr. President you have hundreds of Secret Service Agents to protect you and your family.  The families of Seal Team 6 don't have any protection.  If one is killed, it is on your head.

Watch this film.  Talk about this film.  Pass it on!  The leaks have to stop!

Friday, July 15, 2011

How Digital Detectives Deciphered Stuxnet, the Most Menacing Malware in History

This comes from a rather long article, but it is very insightful into the mystery that is Stuxnet.  It will take years to unravel the full story, but this is what has been discovered so far:
It was January 2010, and investigators with the International Atomic Energy Agency had just completed an inspection at the uranium enrichment plant outside Natanz in central Iran, when they realized that something was off within the cascade rooms where thousands of centrifuges were enriching uranium.

Natanz technicians in white lab coats, gloves and blue booties were scurrying in and out of the “clean” cascade rooms, hauling out unwieldy centrifuges one by one, each sheathed in shiny silver cylindrical casings.

Any time workers at the plant decommissioned damaged or otherwise unusable centrifuges, they were required to line them up for IAEA inspection to verify that no radioactive material was being smuggled out in the devices before they were removed. The technicians had been doing so now for more than a month.

Normally Iran replaced up to 10 percent of its centrifuges a year, due to material defects and other issues. With about 8,700 centrifuges installed at Natanz at the time, it would have been normal to decommission about 800 over the course of the year.

But when the IAEA later reviewed footage from surveillance cameras installed outside the cascade rooms to monitor Iran’s enrichment program, they were stunned as they counted the numbers. The workers had been replacing the units at an incredible rate — later estimates would indicate between 1,000 and 2,000 centrifuges were swapped out over a few months.

The question was, why?
It wasn't apparent to either the IAEA or the Iranians what was happening.  It took the Iranians a year to discover the culprit.
On June 17, 2010, Sergey Ulasen was in his office in Belarus sifting through e-mail when a report caught his eye. A computer belonging to a customer in Iran was caught in a reboot loop — shutting down and restarting repeatedly despite efforts by operators to take control of it. It appeared the machine was infected with a virus.

Ulasen heads an antivirus division of a small computer security firm in Minsk called VirusBlokAda. Once a specialized offshoot of computer science, computer security has grown into a multibillion-dollar industry over the last decade keeping pace with an explosion in sophisticated hack attacks and evolving viruses, Trojan horses and spyware programs.

The best security specialists, like Bruce Schneier, Dan Kaminsky and Charlie Miller are considered rock stars among their peers, and top companies like Symantec, McAfee and Kaspersky have become household names, protecting everything from grandmothers’ laptops to sensitive military networks.

VirusBlokAda, however, was no rock star nor a household name. It was an obscure company that even few in the security industry had heard of. But that would shortly change.

Ulasen’s research team got hold of the virus infecting their client’s computer and realized it was using a “zero-day” exploit to spread. Zero-days are the hacking world’s most potent weapons: They exploit vulnerabilities in software that are yet unknown to the software maker or antivirus vendors. They’re also exceedingly rare; it takes considerable skill and persistence to find such vulnerabilities and exploit them. Out of more than 12 million pieces of malware that antivirus researchers discover each year, fewer than a dozen use a zero-day exploit.

In this case, the exploit allowed the virus to cleverly spread from one computer to another via infected USB sticks. The vulnerability was in the LNK file of Windows Explorer, a fundamental component of Microsoft Windows. When an infected USB stick was inserted into a computer, as Explorer automatically scanned the contents of the stick, the exploit code awakened and surreptitiously dropped a large, partially encrypted file onto the computer, like a military transport plane dropping camouflaged soldiers into target territory.

It was an ingenious exploit that seemed obvious in retrospect, since it attacked such a ubiquitous function. It was also one, researchers would soon learn to their surprise, that had been used before.

VirusBlokAda contacted Microsoft to report the vulnerability, and on July 12, as the software giant was preparing a patch, VirusBlokAda went public with the discovery in a post to a security forum. Three days later, security blogger Brian Krebs picked up the story, and antivirus companies around the world scrambled to grab samples of the malware — dubbed Stuxnet by Microsoft from a combination of file names (.stub and MrxNet.sys) found in the code.

As the computer security industry rumbled into action, decrypting and deconstructing Stuxnet, more assessments filtered out.

It turned out the code had been launched into the wild as early as a year before, in June 2009, and its mysterious creator had updated and refined it over time, releasing three different versions. Notably, one of the virus’s driver files used a valid signed certificate stolen from RealTek Semiconductor, a hardware maker in Taiwan, in order to fool systems into thinking the malware was a trusted program from RealTek.

Finish reading here.
If they had known what they were dealing with they should have left it alone.  While not a Trojan Horse, Stuxnet acted like a Trojan Horse.  What scared the experts was that Stuxnet was so efficient at what it did and how it stayed hidden.  Its ability to remain in the system even after it was "removed" has driven the Iranians crazy.

Stuxnet was NOT written in someone's basement.  It was an effort by a government or governments to take out or at least slow down the Iranian Nuclear Program.  At best it has given the world a few years breathing room.

Hat tip to Israel Matzav

Tuesday, April 26, 2011

Do We Have Worm Sign?



Once again Iran has been hit by an computer worm.  Although Stuxnet is still running its course through the Iranian program (And still causing havoc.), now the Iranians are facing STARS.
Iranian civil defense commander Gholamreza Jalali said Monday the Islamic Republic's nuclear program has fallen prey to a computer virus called "Stars," Reuters reports.

The Stars virus is the second in the cyber war against Iran's bid for nuclear capability, following after the much-reported Stuxnet virus,

Jalalai said the introduction of the new virus is being investigated while admitting Stuxnet still posed a risk. "We should know that fighting the Stuxnet virus does not mean the threat has been completely tackled, because viruses have a certain life span and they might continue their activities in another way," Jalali said.

The revelation that Stuxnet is still hampering Iran's nuclear program runs counter to previous claims by Iranian officials that the destructive virus had been dealt with and buttresses Saudi concerns that Iran's intention to activate the Bushehr plant in May could lead to a 'second Fukushima.' Saudi concerns were based on reports attributed to a Russian engineer working at the site that metal shards were found in the coolant intakes for the reactor.

Iranian officials blamed Israel and the United States -- which believe Iran is seeking nuclear weapons -- for the Stuxnet virus, which some expert shave described as the first "guided cyber missile," aimed at Iran's atomic program.

"Stars," experts speculate, is the second.

"Fortunately," Jalali told Iran's press. "Our young experts have been able to discover this virus and the Stars virus is now in the laboratory for more investigations," Jalali was quoted as saying. He did not specify the target of Stars or its intended impact.

"The particular characteristics of the Stars virus have been discovered. The virus is congruous and harmonious with the [computer] system and in the initial phase it does minor damage and might be mistaken for some executive files of government organizations."

Bushehr is still not operational, having missed several start-up deadlines since the Stuxnet virus was introduced.

Full Story
This is starting to get interesting.  First Stuxnet, now Stars, I wonder how many more worms are out there?

Sunday, February 27, 2011

It's Cute, It's Cuddly, It Likes To Attack Iranian Computers!



It is back, or it never left, either way it is driving the Iranians meschuge!  It is the worm Stuxnet and this is its latest round of carnage upon the Iranian Nuclear Program:
In a major setback to Iran's nuclear program, technicians will have to unload fuel from the country's first atomic power plant because of an unspecified safety concern, a senior government official said.

The vague explanation raised questions about whether the mysterious computer worm known as Stuxnet might have caused more damage at the Bushehr plant than previously acknowledged. Other explanations are possible for unloading the fuel rods from the reactor core of the newly completed plant, including routine technical difficulties.

While the exact reason behind the fuel's removal is unclear, the admission is seen as a major embarrassment for Tehran because it has touted Bushehr -- Iran's first atomic power plant -- as its showcase nuclear facility and sees it as a source of national pride. When the Islamic Republic began loading the fuel just four months ago, Iranian officials celebrated the achievement.

Iran's envoy to the U.N. nuclear monitoring agency in Vienna said that Russia, which provided the fuel and helped construct the Bushehr plant, had demanded the fuel be taken out.

"Upon a demand from Russia, which is responsible for completing the Bushehr nuclear power plant, fuel assemblies from the core of the reactor will be unloaded for a period of time to carry out tests and take technical measurements," the semiofficial ISNA news agency quoted Ali Asghar Soltanieh as saying. "After the tests are conducted, (the fuel) will be placed in the core of the reactor once again."

"Iran always gives priority to the safety of the plant based on highest global standards," Soltanieh added.

Calls to the Russian nuclear agency Rosatom for comment were not answered Saturday afternoon.

The spokesman of the Atomic Energy Organization of Iran said the fuel unloading was nothing unusual.

"It's a kind of technical inspection and to obtain confidence about the safety of the reactor," Hamid Khadem Qaemi told the official IRNA news agency. He accused foreign media of blowing the issue out of proportion.

The Bushehr plant is not among the aspects of Iran's nuclear program that are of top concern to the international community and is not directly subject to sanctions. It has international approval and is supervised by the U.N.'s nuclear monitoring agency, the International Atomic Energy Agency.

In a report released Friday about Iran's nuclear program, the IAEA said that Tehran informed the agency on Wednesday that it would have to unload the fuel rods. The agency said it and Tehran have agreed on the "necessary safeguards measures."

A senior international official familiar with Iran's nuclear program said the IAEA had no further details. He said unloading and reloading fuel assemblies is not unusual before any reactor startup. The official asked for anonymity because his information was confidential.

Soltanieh and other officials have not specified why the fuel had to be unloaded, but Iranian officials denied any link to the Stuxnet computer virus.

"Stuxnet has had no effect on the control systems at the Bushehr nuclear power plant," Nasser Rastkhah, a senior official in charge of nuclear security, told the official IRNA news agency.

Foreign intelligence reports have said the control systems at Bushehr were penetrated by the malware -- malicious software designed to infiltrate computer systems -- but Iran has all along maintained that Stuxnet was only found on several laptops belonging to plant employees and didn't affect the facility's control systems.

Some computer experts believe Stuxnet was the work of Israel or the United States, two nations convinced that Iran wants to turn nuclear fuel into weapons-grade uranium.

The Islamic Republic is reluctant to acknowledge setbacks to its nuclear activities, which it says are aimed at generating energy but are under U.N. sanctions because of concerns they could be channeled toward making weapons. Only after outside revelations that its enrichment program was temporarily disrupted late last year by Stuxnet did Iranian officials acknowledge the incident.

The startup of the Bushehr power plant, a project completed with Russian help but beset by years of delays, would deliver Iran the central stated goal of its atomic work -- the generation of nuclear power.

But the inauguration of the facility has been delayed for years. Iran said when it began inserting the fuel rods in October that the 1,000-megawatt light-water reactor would begin pumping electricity to Iranian cities by December. But it pushed back the timing to February, citing a "small leak" and other unspecified reasons.

The Bushehr plant itself is not among the West's main worries because safeguards are in place to ensure that the spent fuel will be returned to Russia and cannot be diverted to weapons making.

The United States and some of its allies believe the Bushehr plant is part of a civil energy program that Iran is using as cover for a covert program to develop a nuclear weapons capability. Iran denies the accusation.

The Bushehr project dates back to 1974, when Iran's U.S.-backed Shah Mohammed Reza Pahlavi contracted with the German company Siemens to build the reactor. The company withdrew from the project after the 1979 Islamic Revolution toppled the shah and brought hard-line clerics to power.

In 1992, Iran signed a $1 billion deal with Russia to complete the project and work began in 1995.

Under the contract, Bushehr was originally scheduled to come on stream in July 1999 but the startup has been delayed repeatedly by construction and supply glitches.
The spokesman of the Atomic Energy Organization of Iran said the fuel unloading was nothing unusual.

The unloading of fuel rods only a few months of loading is NOT a routine occurance at any Nuclear Power Plant in the world. It is a sign of a problem either within the plant, with the fuel rods, or both.  I doubt that the Iranians will be able to bring the plant back on-line any time soon.

Whatever was paid for the Stuxnet worm was money very well spent.  It has out performed expectation and is still going strong.

Thursday, December 16, 2010

The Little Worm That Could

I don't think anyone who owns a computer hasn't heard of or have been infected by a virus, or worm. This is one reason why companies such as Norton are doing well even in this economy.  Yet for the last 17 months a worm has been causing mayhem and havoc to Iranian computer systems at their nuclear facilities.
The future of warfare may have just begun, but rather than being heralded by an explosion, it began without a sound or a single casualty.

It is the first of its kind, and could be a signal of the ways all wars are fought from now on. It is a cyber weapon so precise that it can destroy a target more effectively than a conventional explosive, and then simply delete itself, leaving the victims left to blame themselves. It is a weapon that is so terrible that it could conceivably do more than just damage physical objects, it could kill ideas. It is the Stuxnet worm, dubbed by many as the world first real weapon of cyberwarfare, and its first target was Iran.

The dawn of cyberwarfare

Stuxnet is almost like something out of a Tom Clancy novel. Rather than sending in missiles to destroy a nuclear plant that threatens the entire region and the world, and is overseen by a president who has claimed that he would like to see an entire race of people “wiped off the map,” a simple computer virus can be introduced that will do the job far more effectively. To attack a structure with missiles can lead to war, and besides, buildings can be rebuilt. But to infect a system so completely that the people using it begin to doubt their faith in their own abilities will have far more devastating long-term effects.

In a rare moment of openness from Iran, the nation has confirmed that the Stuxnet malware (the name stems from keywords buried in the code) that was originally discovered in July, has damaged the country’s nuclear ambitions. Although Iran is downplaying the incident, some reports suggest that the worm was so effective, it may have set back the Iranian nuclear program by several years.

Rather than simply infect a system and destroy everything it touches, Stuxnet is far more sophisticated than that, and far more effective as well.

The worm is smart and adaptable. When it enters a new system, it remains dormant and learns the security system of the computer. Once it can operate without raising alarm, it then seeks out very specific targets and begins to attack certain systems. Rather than simply destroy its targets, it does something far more effective—it misleads them.

In a nuclear enrichment program, a centrifuge is a fundamental tool needed to refine the uranium. Each centrifuge built follows the same basic mechanics, but the German manufacturer Siemens offers what many consider to be the best in the industry. Stuxnet sought out the Siemens controllers and took command of the way the centrifuge spins. But rather than simply forcing the machines to spin until they destroyed themselves—which the worm was more than capable of doing—Stuxnet made subtle, and far more devious changes to the machines.

When a uranium sample was inserted into a Stuxnet-infected centrifuge for refinement, the virus would command the machine to spin faster than it was designed for, then suddenly stop. The results were thousands of machines that wore out years ahead of schedule, and more importantly, ruined samples. But the real trick of the virus was that while it was sabotaging the machinery, it would falsify the readings and make it appear as if everything was operating within the expected parameters.

After months of this, the centrifuges began to wear down and break, but as the readings still appeared to be within the norms, the scientists associated with the project began to second guess themselves. Iranian security agents began to investigate the failures, and the staff at the nuclear facilities lived under a cloud of fear and suspicion. This went on for over a year. If the virus had managed to completely avoid detection, it eventually would have deleted itself entirely and left the Iranians wondering what they were doing wrong.

For 17 months, the virus managed to quietly work its way into the Iranian systems, slowly destroying vital samples and damaging necessary equipment. Perhaps more than the damage to the machinery and the samples was the chaos the program was thrown into.

The discovery of the worm

In June of this year, the Belarus-based antivirus specialists, VirusBlokAda found a previously unknown malware program on the computer of an Iranian customer. After researching it, the antivirus company discovered that it was specifically designed to target Siemens SCADA (supervisory control and data acquisition) management systems, which are devices used in large-scale manufacturing. The first clue that something was different about this worm was that once the alert had been raised, every company that tried to pass on the alert was subsequently attacked and forced to shut down for at least 24 hours. The methods and reasons for the attacks are still a mystery.

Once the virus had been discovered, companies like Symantec and Kaspersky, two of the largest antivirus companies in the world, as well as several intelligence agencies, began to research Stuxnet, and found results that quickly made it obvious that this was no ordinary malware.

By the end of September, Symantec had discovered that nearly 60-percent of all the machines infected in the world were located in Iran. Once that had been discovered, it became more and more apparent that the virus was not designed simply to cause problems, as many pieces of malware are, but it had a very specific purpose and a target. The level of sophistication was also well above anything seen before, prompting Ralph Langner, the computer security expert who first discovered the virus, to declare that it was “like the arrival of an F-35 into a World War I battlefield”.

How it worked

Stuxnet specifically targets Windows 7 operating systems, which is, not coincidentally, the same operating system used at the Iranian nuclear power plant. The worm uses four zero-day attacks and specifically targets Siemens’ WinCC/PCS 7 SCADA software. A zero-day threat is a vulnerability that is either unknown or unannounced by the manufacturer. These are generally system-critical vulnerabilities, and once they are discovered, immediately patched. In this case, the two of the zero-day elements had been discovered and were close to having a fixes released, but two others had never been discovered by anyone. Once the worm was in the system, it then began to exploit other systems in the local network it was targeting.

As Stuxnet worked its way through the Iranian systems, it was challenged by the system’s security to present a legitimate certificate. The malware then presented two authentic certificates, one from the circuit manufacturer JMicron, and the other from computer hardware manufacturer Realtek. Both companies are located in Taiwan just blocks away from each other, and both certificates were confirmed to have been stolen. These authentic certificates are one of the reasons that the worm was able to remain undetected for so long.

But where did it come from, and who developed it?

Suspicions of where the worm originated are rampant, and the most likely single suspect is Israel. After thoroughly researching the virus, Kaspersky Labs announced that the level of attack, and the sophistication with which it was executed could only have been carried out “with nation-state support”, which rules out private hacker groups, or even larger groups that have been using hacking as a means to an end, such as the Russian Mafia, which is suspected of creating a Trojan worm responsible for stealing over $1 million from a British bank.

Israel fully admits that it considers cyberwarfare to be a pillar of its defense doctrine, and the group known as Unit 8200, an Israeli defense force considered to be the rough equivalent of the United States’ NSA, would be the most likely group responsible.

Unit 8200 is the largest division in the Israeli Defense Force, and yet the majority of its operations are unknown- even the identity of the Brigadier General in charge of the unit is classified. Among its many exploits, one report claims that during an Israeli airstrike on a suspected Syrian nuclear facility in 2007, Unit 8200 activated a secret cyber kill switch that deactivated large sections of the Syrian radar.

To further lend credence to this theory, in 2009, Israel pushed back the date of when it expects Iran to have rudimentary nuclear weaponry to 2014. This may have been a result of hearing of problems, or it could suggest that Israel knew something no one else did.

The U.S. is also a prime suspect, and in May of this year, Iran claimed to have arrested 30 people it claims were involved in helping the U.S. wage a “cyber war” against Iran. Iran has also claimed that the Bush administration funded a $400 million plan to destabilize Iran by using cyber attacks. Iran has claimed that the Obama administration has continued that same plan, and even sped up some of the projects. Critics have stated that Iran’s claims are simply an excuse to stamp out “undesirables”, and the arrests are one of many points of contentions between Iran and the U.S.

But as the virus continues to be studied and more answers emerged regarding its function, more mysteries are being raised about its origins.

Full story
Take the time to read the full story.  The details of this worm are still being discovered, and there is speculation that what was discovered is only one of many worms as part of a multi-level attack.

One thing about Stuxnet that justifies its use, it is better to send a worm to destroy a target then to risk the life of a pilot.  I can accurately claim that no Israeli or American pilots were injured or killed by this action.  The nerves and reputations of many Iranian scientists and technician were shattered.  And confidence in their nuclear technology has been destroyed.

And I thought worms were only good for fishing and gardening.