blame game for cyber attacks grows murkier
Last Updated : GMT 06:49:16
Arab Today, arab today
Arab Today, arab today
Last Updated : GMT 06:49:16
Arab Today, arab today

Blame game for cyber attacks grows murkier

Arab Today, arab today

Arab Today, arab today Blame game for cyber attacks grows murkier

man types on a computer keyboard in front of the displayed cyber code in this illustration picture
Tallinn (Estonia) - Arab today

 Veteran espionage researcher Jon DiMaggio was hot on the trail three months ago of what on the face of it looked like a menacing new industrial espionage attack by Russian cyber spies.

All the hallmarks were there: targeted phishing emails common to government espionage, an advanced Trojan horse for stealing data from inside organisations, covert communication channels for grabbing documents and clues in the programming code indicating its authors were Russian speakers. 

It took weeks before the lead cyber spying investigator at Symantec, a top U.S. computer security firm, figured out instead he was tracking a lone-wolf cyber criminal.

DiMaggio won't identify the name of the culprit, whom he has nicknamed Igor, saying the case is a run-of-the-mill example of increasing difficulties in separating national spy agency activity from cyber crime

The hacker comes from Transdniestria, a disputed, Russian-speaking region of Moldova, he said.

"The malware in question, Trojan.Bachosens, was so advanced that Symantec analysts initially thought they were looking at the work of nation-state actors," DiMaggio told Reuters in a phone interview on Wednesday. "Further investigation revealed a 2017 equivalent of the hobbyist hackers of the 1990s."

Reuters could not contact the alleged hacker.

The example highlights the dangers of jumping to conclusions in the murky world of cyber attack and defence, as tools once only available to government intelligence services find their way into the computer criminal underground.

Security experts refer to this as "the attribution problem", using technical evidence to assign blame for cyber attacks in order to take appropriate legal and political responses.

These questions echo through the debate over whether Russia used cyber attacks to influence last year's U.S. presidential elections and whether Moscow may be attempting to disrupt national elections taking place in coming months across Europe.

The topic is a big talking point for military officials and private security researchers at the International Conference on Cyber Conflict in Tallin this week. It has been held each year since Estonia was swamped in 2007 by cyber attacks that took down government, financial and media websites amid a dispute with Russia. Attribution for those attacks remains disputed.

"Attribution is almost never a clean, smoking-gun," said Paul Vixie, creator of the first commercial anti-spam service, whose latest firm, Farsight Security, helps firms track down cyber attackers to identify and block them.

Raising the stakes, a mystery group calling itself ShadowBrokers has taken credit for leaking cyber-spying tools that are now being turned to criminal use, including ones used in the recent WannaCry global ransomware attack, ratcheting up cyber security threats to a whole new level.

In recent weeks, ShadowBrokers has threatened to sell more such tools, believed to have been stolen from the U.S. National Security Agency, to enable hacking into the world's most used computers, software and phones.

"The bar for what's considered advanced is lowered as time goes by," said Sean Sullivan, a security researcher with Finnish cyber firm F-Secure.

The Moldovan hacker's campaign to steal data and resell it on the web came to light only after infections popped up last year at a major airline, an online gambling firm and a Chinese automotive software maker, which are all customers of Symantec products used to secure their business networks.

Igor appears to have targeted the auto-tech company to steal its car diagnostics software, which retails for around $1,100 but Igor sold for just a few hundred dollars on underground forums and websites he had created. His aims in trying to break into the airline and gambling firm remain a mystery.

"Considering the audacity of this attack, the financial rewards for Igor are pretty low,” DiMaggio wrote in a blog post on his findings to be published on Wednesday.

As a threat, Symantec rates Trojan.Bachosens as a very low risk virus, in part because the attack singles out only a handful of specific firms rather than the wide-ranging, random attacks used by many cyber criminals to scoop up the greatest number of victims.

"I think those days are over when we can say in black and white: We know this is an espionage group," DiMaggio said.

The Symantec researcher has not reported Igor to local authorities, calculating that exposing the methods of the attack will be enough to neutralise them.

Source: Timesofoman

 

 

arabstoday
arabstoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

blame game for cyber attacks grows murkier blame game for cyber attacks grows murkier

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

blame game for cyber attacks grows murkier blame game for cyber attacks grows murkier

 



GMT 09:26 2017 Wednesday ,06 September

Kuwait condemns violations against Muslims in Myanmar

GMT 08:57 2017 Thursday ,06 April

Turkey says chemical weapons used in Syria attack

GMT 22:47 2016 Saturday ,17 December

Ajman to host International Pro Jiu-Jitsu Championship

GMT 14:52 2018 Friday ,14 December

Michel Aoun meets Rahi in Baabda

GMT 09:20 2017 Thursday ,13 April

Trump Discusses Syria Strikes with Merkel and May

GMT 06:07 2017 Tuesday ,14 February

Rain hits UAE, major traffic jams follow

GMT 12:01 2017 Thursday ,28 September

Ben Stokes included in England's Ashes squad

GMT 14:45 2017 Thursday ,16 March

El Jaish Win Qatar Men's Basketball League

GMT 12:27 2017 Tuesday ,01 August

Tangier Charms Gabonese President Ali Bongo

GMT 02:35 2017 Saturday ,04 February

Sharif calls for solution to Palestinian issue

GMT 08:45 2017 Friday ,03 November

Apple delivers higher profit

GMT 11:27 2017 Wednesday ,08 February

First Turkish minister visits Israel since 2010

GMT 02:11 2017 Friday ,08 December

Princess Sabeeka receives UN Women executive director

GMT 12:43 2017 Saturday ,25 February

Shaikh Nasser following up on injured rider's health

GMT 05:20 2017 Tuesday ,24 October

Anti-Kremlin activist Browder blocked from US

GMT 21:16 2017 Sunday ,26 February

Two German archaeologists kidnapped in Nigeria freed

GMT 22:48 2016 Wednesday ,30 November

Egypt wins EuroMed Postal Union membership

GMT 07:11 2017 Thursday ,09 February

Portuguese president has lunch with refugees

GMT 11:33 2017 Sunday ,03 December

After hot debate, US tax bill a boon to businesses
Arab Today, arab today
 
 Arab Today Facebook,arab today facebook  Arab Today Twitter,arab today twitter Arab Today Rss,arab today rss  Arab Today Youtube,arab today youtube  Arab Today Youtube,arab today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

arabstoday arabstoday arabstoday arabstoday
arabstoday arabstoday arabstoday
arabstoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
arabstoday, Arabstoday, Arabstoday