[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Are Childhood Vaccines Safe? DTP Vaccine Was Not - and Was Given for Decades!

Can you name >5 unvaxxed Amish who died from COVID? Why not? They are "supposed to be" dying in droves!

On Becoming Lutheran: A Conversation with Pr Chad Bresson (Pastor, The Table, Los Fresnos)

Lighting a Candle to Rainbow Zeus

Luther: If you must allegory, allegory this way

HUGE DEMOCRATIC MONEY LAUNDERING SCHEME DISCOVERED IN INDIANA

The Drip, Governmental Lies and US Armed Forces Recruitment

It's Happening: Fisk Gives Slight Downgrade to US Credit

No Truce With the Heartland

Is This Why Pediatricians Push Vaccines?

The Cross Prepares a Way (John 14 reflections)

A WHO pandemic treaty would be a threat to our freedom

The debt ceiling melodrama is a Uniparty diversion from reality

Governor DeSantis Ban the Bioweapons or You May Become Complicit

Why Exactly Does the Government Dump Toxic Fluoride Into ¾ of the US Water Supply?

F-16s to Ukraine

DeSantis’ ‘big government’ extends to record state budget

Operation Stiff Upper Lip… British Minister Rushes to Kiev Following Artyomovsk Debacle

Hidden Christians’ Illicit Sacred Vase Brought to Light in Japan

CONNECTICUT SNEAKS PEDOPHILIA PROTECTIONS INTO LAW

Erik Sperling on the US Attempt to Keep the War in Yemen Going

Where Is That Darn Recession?

Fluoride Lawsuit Against EPA: Alleged Corruption, Shocking Under Oath Federal Statements

The Mind Virus of the Affluent Woke Left

An Interview with Satan on the Eve of His Retirement

Trump and his staffers conducted a 'dress rehearsal' to move sensitive documents even after the DOJ asked for them to be returned

DeSantis says he’ll consider pardoning Jan. 6 defendants, including Trump

Ex-Trump Advisor Bannon's Trial Over Border Wall Scheme Set for May 2024

Brickbat: Dirty Hands

Review: Animal Control Pokes Fun at Real-World Policing Problems

Texas Sues Biden Over Immigration ‘Parole’ Scam

Fisking a Turnip, Part 5: What If THEY Heard The Gospel. Bonus level: Woe’s False Standards.

Dave Smith & Konstantin Kisin on Ukraine

Hungary’s Orban Says Ukraine War Can Only End With Deal Between Russia and US

Boris Johnson Sent to Texas to Lobby Republicans to Keep Arming Ukraine

Neo-Nazi Militia Used US Armored Vehicles in Attack on Russia’s Belgorod Region

US aircraft carrier arrives in Norway to take part in drills with armed forces

The FTC should answer its Call of Duty to Gamers

Syracuse-based Christian adoption agency New Hope Family Services has entered into a favorable settlement agreement with the state of New York and may continue offering adoption services to children and families.

New York Settles Case with Christian Adoption Agency

Biden's economy leaving millions of families struggling to make ends meet

Report: China hacked critical networks to spy on U.S. military

IRS whistleblower accuses DOJ of protecting Hunter Biden

How the “Economics of War” Turns Goods Into “Bads”

Prigozhin Says 20,000 Wagner Fighters Were Killed in Bakhmut Battle

83 United Methodist Churches in Iowa Exit Denomination

Matt Taibbi shares details about being investigated by IRS

Major journal retracts study warning about transgenderism after activist threats

‘A day of sadness’: 193 Georgia churches vote to leave United Methodist Church

Church of Scotland loses over half its membership since 2000; age of average worshiper is 62: report


Status: Not Logged In; Sign In

Computers-Hacking
See other Computers-Hacking Articles

Title: New smoking gun further ties NSA to omnipotent “Equation Group” hackers
Source: Ars Technica
URL Source: http://arstechnica.com/security/201 ... potent-equation-group-hackers/
Published: Mar 11, 2015
Author: Dan Goodin
Post Date: 2015-03-11 12:05:00 by Tooconservative
Keywords: malware, NSA
Views: 451

New smoking gun further ties NSA to omnipotent “Equation Group” hackers
What are the chances unrelated state-sponsored projects were both named "BACKSNARF"?

Researchers from Moscow-based Kaspersky Lab have uncovered more evidence tying the US National Security Agency to a nearly omnipotent group of hackers who operated undetected for at least 14 years.

The Kaspersky researchers once again stopped short of saying the hacking collective they dubbed Equation Group was the handiwork of the NSA, saying only that the operation had to have been sponsored by a nation-state with nearly unlimited resources to dedicate to the project. Still, they heaped new findings on top of a mountain of existing evidence that already strongly implicated the spy agency. The strongest new tie to the NSA was the string "BACKSNARF_AB25" discovered only a few days ago embedded in a newly found sample of the Equation Group espionage platform dubbed "EquationDrug." "BACKSNARF," according to page 19 of this undated NSA presentation, was the name of a project tied to the NSA's Tailored Access Operations.

"BACKSNARF" joins a host of other programming "artifacts" that tied Equation Group malware to the NSA. They include "Grok," "STRAITACID," and "STRAITSHOOTER." Just as jewel thieves take pains to prevent their fingerprints from being found at their crime scenes, malware developers endeavor to scrub usernames, computer IDs, and other text clues from the code they produce. While the presence of the "BACKSNARF" artifact isn't conclusive proof it was part of the NSA project by that name, the chances that there were two unrelated projects with nation-state funding seems infinitesimally small.

The code word is included in a report Kaspersky published Wednesday detailing new technical details uncovered about Equation Group. Among other new data included in the report, the timestamps stored inside the Equation Group malware showed that members overwhelmingly worked Monday through Friday and almost never on Saturdays or Sundays. The hours in the timestamps appeared to show members working regular work days, an indication they were part of an organized software development team. Assuming they worked a regular 8 to 5 workday, the timestamps show the employees were likely in the UTC-3 or UTC-4 time zone, a finding that would be consistent with people working in the Eastern part of the US. The Kaspersky report discounted the possibility the timestamps were intentionally manipulated, since the years listed in various executable files appeared to match the availability of computer platforms the files ran on.

Previously found evidence suggesting a possible connection to the NSA included the Equation Group's aptitude for conducting interdictions that in 2009 placed highly advanced malware on a CD-ROM sent to a prestigious researcher who attended a scientific conference. That interdiction was similar to an NSA-sponsored one detailed in documents leaked by former NSA subcontractor Edward Snowden that installed covert implant firmware on a Cisco Systems router as it was being shipped to its unwitting customer. Still other ties included zero-day vulnerabilities shared between Equation Group malware and the NSA-led Stuxnet worm that sabotaged Iranian uranium enrichment efforts in 2009 or so. The countries that were and were not targeted are also consistent with Equation Group being a US-sponsored project.

Most of the new details included in Tuesday's report will be of interest only to hard-core researchers. Still, they only bolster previous findings that Equation Group was hands down the world's most advanced hacking operation ever to come to light. Whereas before the sprawling Equation Drug platform was known to support 35 different modules, Kaspersky has recently unearthed evidence there are 115 separate plugins. The architecture resembles a mini operating system with kernel- and user-mode components alike. Readers can expect more revelations to come as researchers continue to analyze new samples and further examine the malware that has already come to light.


Poster Comment:

Well, well, well. Those nice Russian fellows at Kaspersky are helping us learn more about NSA's hidden partnerships. We should write Vlad a thank-you note. (1 image)

Post Comment   Private Reply   Ignore Thread  


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Mail]  [Sign-in]  [Setup]  [Help]  [Register] 

Please report web page problems, questions and comments to webmaster@libertysflame.com