Friday, April 27, 2012

BKNT--Pierluigi Paganini: Iran vs. West, cyber war or media conflict?--LD

LIMITED DISSEMINATION
IranianCyberWarefare/LinkedIN; Red-DragonRISING.com; US/1;
ATTN: IT/3; HST/2; US/17; US/12; RT/66; CID/2; US/8    Member CONTRIBUTIONS


[ed.note: On FRIDAY the 13th of April 2012, it was claimed repeatedly by operators and supervisors at VERIZON, in the Baltimore-DC Metro corridor (ironic location of Ft. Humpty-Dumpty) that ALL the telephone CIRCUITS, landline and Mobile, to the rather tiny country (7 million) of ISRAEL were OVERLOADED. (Friday the 13th was a religious holiday in some quarters).



This OVERLOAD continued for at least FOUR HOURS. Reporting Member, US/1, never received ANYthing approaching an adequete explanation, despited his somewhat notorious insistence, persistence, and pestulance…MEMBERS PLEASE ADVISE if they have any INFORMATION on this subject?

This is analogous to the PIZZA Corralary first deployed by US/1, and certainly later by others, of monitoring PIZZA diliveries at White House (NSC, SIT-Room, specifically), and at the five-sided DoD-HQ (third-floor E-Ring), from 02 AUGUST 1990 until 16 JAN 1991...
Go figure.

On 18 MARCH 2003, it was the BlackNET that QUOTED “chatter” from amatuer Israeli radio-hams to the UPI that air campaign of OPERATION IRAQI FREEDOM would commence on ‘Tuesday.’ After the UPI wire went out on Tuesday, 19 MARCH 2003 at “3:59” – 1559 ET – about five hours later that “Tuesday” evening, ET, the air campaign of OPERATION IRAQI FREEDOM commenced.

Go figure further…]

<’…I think...a dangerous campaign [has begun for] the search
for consensus on a military attack against Iran…’>

Pierluigi Paganini
by paganinip on April 27th, 2012


Today I have read several articles where is hypothesized an imminent cyber-attacks of Iran cyber army against US infrastructures, this news seems alarming the international community. Are we close to a military attack of Iran? Why this news is circulating so closely?
Sources of intelligence report to Congress on Thursday that Iran is recruiting a hacker army to target the U.S. for cyber-attack against critical infrastructures such as power grid and water systems. Counterterrorism and Intelligence Subcommittee Chairman Pat Meehan, R-Pa declared:
“If Iran is willing to blow up a Washington restaurant and kill innocent Americans, we would be naive to think Iran would never conduct a cyber-attack against the U.S. homeland,”
                    [Video NOW up at BlackBOX Intel-CENTER – US/1]
Meanwhile Ilan Berman, vice president of the hawkish American Foreign Policy Council, said
“Over the past three years, the Iranian regime has invested heavily in both defensive and offensive capabilities in cyberspace,”
“For the Iranian regime the conclusion drawn from Stuxnet is clear: War with the West, at least on the cyberfront, has already been joined, and the Iranian regime is mobilizing,”
The growing tension between Iran, the U.S. and Israel do not bode well, however these reports persistently circulated in internet don’t add anything new to a scenario that has long been known. Iran has understood how much strategic is a strong presence in cyber space, just in this new battle field it has found vulnerable many of its opponents deciding to invest in cyber warfare.  The Washington Times reported some issues contained in the relation presented to the two House Homeland Security subcommittee. The security experts are convinced that Iran is arranging a very offensive cyber army composed by different cells of hackers ready to move cyber-attacks against the enemies.
But also this news is known the security sector, last year I wrote
The Iranian Revolutionary Guards Corps, IRGC, seems to have built one of the largest forces of hackers on the planet. “Emperor”, “Iran Hackers Sabotage” these are the names of the main group of hackers that during the last year have conducted several operation like destroy a government database or hack into two candidates’ websites. during the 2005 [2oo4 or 2oo8?] presidential election.
In May 2010, Ebrahim Jabbari, a provincial Revolutionary Guards commander, declared that the IRGC had the world’s second-largest cyber army at its disposal, the US intelligence is convinced of the potential of groups to the point of recognizing them as among the major cyber threats to the country.
In addition to cyber warriors and mercenaries, the Iran regime also has the control of the private IT firm Ashiyane Security Group, which has coordinated several cyber-attacks from Iran. Its illustrious victims are Mossad, defence minister Ehud Barak, NASA and several websites in the Arab world.
Of course I do not work for intelligence, but I’ve written before news that today someone would use as a pretext for a military attack. I think it is began a dangerous campaign the search for consensus on a military attack against Iran.

On one thing there can be no doubt, Iran is a dangerous country that has substantial financial resources, the proceeds of the oil market which is a leader, and that deeply hates the West and its policies. The military option is strongly supported in the U.S. and Israeli military echelons, give time to the government in Tehran would give it the opportunity to increase his attack power.
According to Frank J. Cilluffo, director of the Homeland Security Policy Institute at George Washington University,
” due the high availability of cyber weapons on black market “adversaries do not need capabilities, just intent and cash.”,
and Iran has both.
“Iran has a long history of demonstrated readiness to employ proxies for terrorist purposes,” he also added  ”There is little, if any, reason to think that Iran would hesitate to engage proxies to conduct cyber strikes against perceived adversaries.”
“We know that [the Iranians] will do something if they feel cornered,”
Declared Rep. Patrick Meehan, R-Pa., chairman of the subcommittee on counterterrorism and intelligence.
“We know they have a capacity, and I think it’s realistic to try to assess the scope of that.”
          [video cited above….]
U.S. intelligence officials declined to comment further on Iranian cyber capabilities, though they acknowledge the threat in general terms.
All the experts agree that Iran has dramatically increased its cyberwar capabilities, despite this consideration there is no evidence that Iran will use them against the US for striking attacks. A single attack could start the military reply of US and Israeli that despite the Iranian propaganda is a dreaded event for Teheran Government.
“Like most nation-states, [Iran] may want to develop a cyber capability for the same reason it would want a nuclear capability — as a shield,” says retired Marine Gen. James Cartwright, the former vice chairman of the Joint Chiefs of Staff.
Iranian Government is working on different fronts in my opinion, on one side it’s recruiting internal hackers in the name of religious motivations, on the other hand it is acquiring knowledge from mercenaries hackers coming from East Europe and also from Asia [i.e. PRC?]. It will no difficult for Iran to prepare its own cyber arsenal, and these cyber weapons could hit vulnerable western critical infrastructures.
Last and most important aspect that we must consider are the alliances that Iran has with Russia and China. These countries for several reasons are interested that Iran will maintains its strategic position. The oil and conventional weapon markets are just a couple of the these motivation, the presence of Iran is necessary to avoid the further infiltration of western legions .Thanks to these alliances Iran enjoys political and technology support of two major world powers, so I think unlikely an imminent military attack on Iran.
[The Russian Republic has another plan, apparently, (mitigating manufactured microphone malfunctions not-with-standing)—which proves the key point new Member Piefluigi makes above, if counter-intuitively--in the ‘Great Game’ of what Comrade STALIN used to call NORTH IRAN, currently named AZERBAIJAN. MUCH More To COME on this POINT. –US/1]
The way of diplomacy satisfies all, at this moment. We will assist to continuous and bilateral attacks between Iran and the Western countries, waiting for events mutate unpredictably.
What could push the U.S. in a military operation?
An attack on American soil, whether conventional or conducting with a cyber-attack, or the evidence, recognized by the international governments, that Tehran is really close to the establishment of a nuclear arsenal. The decision to attack should be taken as soon as possible, no more of two years, acting firmly and not spreading news like those with which I began the article with the sole purpose of gathering consents.
The risk of a cyber-attack is high, however the likelihood is not changed in recent months. A growing number of nations are taking steps in this direction by investing in cyberwarfare, today it is Iran which country will be tomorrow?

Thursday, April 26, 2012

CyBER-BlackSEC Hearing ON Iranian Cyber Threat to US Homeland // STUXNET & DUQU SITREP

- LIMITED DISSEMINATION
IranianCyberWarfareGroup; US/1


Subcommittee Hearing Chairman's Opening Statement (26 April 2012)





Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies | 311 Cannon House Office Building Washington, DC 20525 | Apr 26, 2012 10:00am 



 OPEN SOURCE
IranianCyberWARFARE; Red-DragonRISING.com; US/1; ATTN:

Stuxnet & Duqu, update on cyber weapons usage

by Pierluigi Paganini (paganinip)
 on April 19th, 2012

We all know about the malware Stuxnet and Duqu considered unanimously the first examples of cyber weapon developed by a government to silent attacks critical enemy infrastructures. We have wrote a lot on the topic, we have followed with attention the excellent analysis made by experts of the sector such as Ralph Langner and the researchers of the Kaspersky and Symantec security firms; during last days new updates have been published on the web regarding the two agents trying to explain their status and the mode used to spread them behind the enemy line.

Let’s start with the update on the Stuxnet virus that was implanted to damage Iran’s nuclear program. News of the days is that the operation was conducted by Israeli agents with the collaboration of Iranian spy, who used a corrupt “memory stick.32,” to sabotage the nuclear plant of Natanz infecting machines there according the declarations of a former and serving U.S. intelligence officials.

In the continuing battle to hold off the Iranian nuclear program, Iranian proxies have also been active in assassinating Iran’s nuclear scientists, these sources said. Key figures of the operations seems to be groups of Iranian dissidents also involved the assassinating og Iran’s nuclear scientists. Of course the choice to use human vector to spread the malware is to reach a more efficient diffusion of the virus avoiding it was discovered before to attack the target.

“They said using a person on the ground would greatly increase the probability of computer infection, as opposed to passively waiting for the software to spread through the computer facility. ‘Iranian double agents’ would have helped to target the most vulnerable spots in the system.”

Iran’s intelligence suspected the infiltration of spies inside their plants and arrested an unspecified number of person accused to have supported the operations related to the diffusion of the Stuxnet Virus.

Who are the Iranian spies that have supported the Israeli operations?

Former and senior U.S. officials believe Iranian support belonged to the Mujahedeen-e-Khalq (People’s Mujahedin of Iran , alias MEK, also PMOI, MKO).

The group is an exile-Iranian organization that advocates the overthrow of the Islamic Republic of Iran, founded in September 5, 1965 by a group of leftist Iranian university students as an Islamic and Marxist political mass movement. MEK was originally devoted to armed struggle against the Shah of Iran, capitalism, 

and Western imperialism, during the Iran-Iraq War, the group was given refuge by Saddam Hussein and mounted attacks on Iran from within Iraqi territory.  MEK is considered as the military wing of the National Council of Resistance of Iran (NCRI) and has targeted Iranian officials and government facilities in Iran and abroad.

The United States, Canada, Iraq and Iran consider the MEK a terrorist organization. On January 26, 2009, the Council of the European Union removed the MEK from the EU list of organizations it designates as terrorist and United States have received support for intelligence operations against the Iran’s nuclear program in 2002 and 2008.
The report of  from Isssource.com says:

 “Former and senior U.S. officials believe nuclear spies belonged to the Mujahedeen-e-Khalq (MEK), which Israel uses to do targeted killings of Iranian nationals, they said. “The MEK is being used as the assassination arm of Israel’s Mossad intelligence service,” said Vince Cannistraro, former head of the CIA’s Counterterrorism. He said the MEK is in charge of executing “the motor attacks on Iranian targets chosen by Israel. They go to Israel for training, and Israel pays them.” Other former agency officials confirmed this.”

We have always sustained the Israeli has worked close to US government and this is true in the specific campaign against Iranian nuclear program at least for the development of the cyber weapons, but  since 2007, five Iranian nuclear scientists have been killed in Iranian territory and the American forces seems to be extraneous to the facts, Israel has used as killer MEK spies well infiltrated in the foreign social context and with a deep knowledge of the activities performed inside the nuclear plants of Iran.


Stuxnet was discovered for the first time by Ukrainian firms VirusBlokAda based in Minsk, [BELARUS?] that was contacted by Iranian dealer that was having problem with several computer of its clients. Apparently the computers were constantly turning off and restarting, but the antivirus were not able to detect the agents because Stuxned used knowledge on zero-day vulnerabilities. Let’s consided also the the source code of the agent was also signed using digital certificates by Realtek Semiconductor and JMicron Technology Corp giving appearance of legitimate software to Microsoft Windows.

Stuxnet was a perfect example of cyber weapon developed to surgical select its targets remaining uncovered and avoiding to infected not target machines. With Stuxnet was in fact introduced a new concept of malware, broad-spectrum deadly weapon capable of hitting in a silent and surgical mode an high number of objectives located anywhere on the planet.

The researchers of the major antivirus companies have identified Stuxnet as the progenitor of another malware, Duqu, it also classified as a cyber weapon developed by a government commitment. Duqu is quite different from its relative, it has a modular structure like Stuxnet but it isn’t equipped with modules for SCADA systems attack.
It is only able to steal information from the host system.

On March 2012 a new instance of Duqu has been isolated in a variant designed to evade detection mechanism of antivirus products and other security systems, its the source code appears to be reshuffled and compiled with a different set of options and it also contains a different subroutine for decrypting the configuration block and loading the malware’s body. A similar operation has been already observed in October 2011. Of course also the references to C&C server are changed because all old structures were shut down on Oct. 20, 2011.

Duqu is so still operating, in the last week several instances are creating several in Philippines where Duqu malware is infecting several computers spreading hidden in documents such as Microsoft Word files. The emergency is high according Kaspersky Lab because the malware may begin to affect newly industrialized countries in Asia, including the Philippines that is one of the major IT outsourcing services provider.

“The spread of Duqu in the Philippines could have dire effects on its multibillion-dollar outsourcing business,”

Kaspersky Lab said in a statement.

Kaspersky’s director of global research & analysis, Costin Raiu with his team, gathered evidence that shows that behind the Stuxnet and Duqu there is the same development team that has used a common platform to build the malwares, but what is really interesting and new is that the researcher is convinced that the same framework has been also used to create at least three other pieces of malware.

We are dealing with an application that consists of several modules each responsible for a specific function to perform. The behavior of the malware to be produced is given by the way in which these modules are made ​​to interact in the same agent. We are facing with a powerful a weapon for the following reasons:
  • Mutable and non-deterministic behavior of the final agent resultant of the module used.
  • Possibility of development of additional modules designed for specific categories of targets .
  • Opportunities for collaboration of multiple groups of developer component of different organizations. Having a common platform it is possible in the future to create a real library of modules, functions that can be called like in any other program to infect specific objectives.
Costin Raiu said “It’s like a Lego set. You can assemble the components into anything: a robot or a house or a tank,”

The statement is the perfect syntesis of the key concept behind the new cyber weapons, just as with Lego you can dial any “shape” of malware assembling the individual components in a manner to be able to attack a specific target. Researchers with Kaspersky have named the platform “Tilded” because many of the files in Duqu and Stuxnet have names beginning with the tilde symbol “~” and the letter “d.”

Let’s also consider that in the past malware have been already used for sabotage purpose and intelligence purposes, in the 1980s, the United States had considerable success installing viruses inside Soviet military-industrial structure, a process still continuing with China.

“We put in bugs inside the Soviet computers to feedback satellite information that had been ‘leeched’ off hard drives, in the Soviet Defense Ministry and others,” said a former U.S. intelligence official.

Also during Desert Storm, the CIA and the British Government Communication Headquarters (GCHQ) have used malware agents to attack Iraq’s computers deploying a Command & Control server in the enemy infrastructures. CIA operatives, working in Jordan, infiltrated bugs into hardware smuggled across the border and into Baghdad. In that occasion the compromised devices weren’t used due the beginning US air strikes that destroyed Saddam’s command and control network, including the buildings where the infected computer hardware was deployed.

What we expect from the future?

For sure we will assist to the born of new version of the existing agents equipped with more sophisticated modules that include new features and that are also able to avoid antivirus detection.

We will face with also the development of new malware based on the same platform and with the creation of new sophisticated platform used as malware factory.

The war is began!

Pierluigi Paganini


[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]

Sunday, April 22, 2012

Iran says is building copy of captured US spy drone, releases what it says is recovered data

- LIMITED DISSEMINATION


US/1; ATTN: RedDragonRISING.com



I

By Associated Press, Updated: Sunday, April 22, 6:41 AM

TEHRAN, Iran — Iran claimed Sunday that it had reverse-engineered an American spy drone captured by its armed forces last year and has begun building a copy.

Gen. Amir Ali Hajizadeh, chief of the aerospace division of the powerful Revolutionary Guards, related what he said were details of the aircraft’s operational history to prove his claim that Tehran’s military experts had extracted data from the U.S. RQ-170 Sentinel captured in December in eastern Iran, state television reported.

Among the drone’s past missions, he said, was surveillance of the compound in northwest Pakistan in which Osama Bin Laden lived and was killed.

Tehran has flaunted the capture of the Sentinel, a top-secret surveillance drone with stealth technology, as a victory for Iran and a defeat for the United States in a complicated intelligence and technological battle.

U.S. officials have acknowledged losing the drone. They have said Iran will find it hard to exploit any data and technology aboard it because of measures taken to limit the intelligence value of drones operating over hostile territory.

Hajizadeh told state television that the captured surveillance drone is a “national asset” for Iran and that he could not reveal full technical details. But he did provide some samples of the data that he claimed Iranian experts had recovered.

“There is almost no part hidden to us in this aircraft. We recovered part of the data that had been erased. There were many codes and characters. But we deciphered them by the grace of God,” Hajizadeh said.

He said all operations carried out by the drone had been recorded in the memory of the aircraft, including maintenance and testing.

Hajizadeh claimed that the drone flew over Osama Bin Laden’s compound in Pakistan two weeks before the al-Qaida leader was killed there in May 2011 by U.S. Navy SEALs. He did not say how the Iranian experts knew this.

Before that, he said, “this drone was in California on Oct. 16, 2010, for some technical work and was taken to Kandahar in Afghanistan on Nov. 18, 2010. It conducted flights there but apparently faced problems and (U.S. experts) were unable to fix it,” he said.

Hajizadeh said the drone was taken to Los Angeles in December 2010 where sensors of the aircraft underwent testing at an aerospace factory.

“If we had not achieved access to software and hardware of this aircraft, we would be unable to get these details. Our experts are fully dominant over sections and programs of this plane,” he said. “It’s not that we can bring down a drone but cannot recover the data.”

There are concerns in the U.S. that Iran or other states may be able to reverse-engineer the chemical composition of the drone’s radar-deflecting paint or the aircraft’s sophisticated optics technology that allows operators to positively identify terror suspects from tens of thousands of feet in the air.

There are also worries that adversaries may be able to hack into the drone’s database, as Iran claimed to have done. Some surveillance technologies allow video to stream through to operators on the ground but do not store much collected data. If they do, it is encrypted.

Media reports claimed this week that Russia and China have asked Tehran to provide them with information on the drone but Iran’s Defense Ministry denied this.

CONTINUE READING Full Story Here...

Copyright 2012 The Associated Press. All rights reserved.
© The Washington Post Company

[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]

Thursday, April 19, 2012

FLASH - Member Michael McNULTY on www.americanewsnet.com – 1800 ET about his new film "Blood on their Hands"- FLASH


-FLASH- OPEN SOURCE
US/1; ATTN:


[ed.note: ‘Happy” WACO Remembrance Day. For those MEMBERs old enough to recall, TODAY is the 19th ‘ANNIVERSARY’ of APRIL 19th.

The SECOND ANNIVERSARY was rather loudly, not to mention murderously, but Timothy MCVIEGH and CREW, et.all., in OKALAHOMA CITY.


PLEASE TUNE IN TO MEMBER MICHAEL McNULTY’s first LIVE interview about is NEW FILM:


-FLASH-
www.americanewsnet.com 1800 ET      -1700 CT         -1600 MT  -1500 PT

-FLASH-

And please VISIT Mike’s explanatory website for MORE INFO:




COMING Next: http://www.kickstarter.com/  on 25 APRIL 2012 - Rpt - 25 APRIL 2012


MIKE will be on the radio show this afternoon at 4PM Mountain Time 6pm east coast time and 3 pm west coast time. It will run for 2 hours. We will be taking about the launch of the new film "Blood on their Hands" (OUTLINE at MIKE’s WEBSITE, cited ABOVE) the show is Colorado originated but can be heard over the Internet at:


This is the BIG Launch and MIKE et. al. can use all the exposure we can muster starting today.

MORE  radio shows with better advanced warning to follow…]


There is some additional “good news.”  There are some fantastic “Rewards” for those that participate in the making of the movie. We have some very exciting access opportunities and tokens of participation like signed certificates of appreciation from the Producers, and an “Honor coin” commemorating the making of “Blood on their Hands.”  And at-cost or Free copies (depending on contribution level) on DVD of the finished film and much more by way of access to the World premier planned for September of 2012 in Los Angeles, California.  At certain contribution levels, there will also be some very special personalized occasions such as a special screening in your home for your family and friends with the Producers in attendance! 

NEXT Wednesday, 25 APRIL 2012 - Please go to KickStarter for the details and join us by helping us reach our goal and be a part of producing this film and making History with COPS Productions.  Our start date will officially be Thursday, April 19, 2012 – we’ll have 30 days, until May 20, 2012 to reach our goal.  It is a large goal but with all of our supporters from over the years, we know we can do it.  The sad thing is, if we don’t make the goal, none of the pledges will be activated and we won’t get the funding.

So Please, go to our KickStarter entry and give what you can, and spread the word to all of your friends and acquaintances… “Blood on Their Hands”.  Let’s make a movie and History! Will you help find the truth and fund the making of an important documentary film – “Blood on Their Hands”?  This moment is yours.  What will you do with it?

SO on 25 APRIL 2012, Please go to http://www.kickstarter.com/  and find the “Blood on Their Hands”- A Documentary, entry and make a pledge, become part of the COPS Posse and ride for Justice.  What’s next at COPS Productions … 
What’s next at COPS Productions Blog…launch week, Radio shows & special staffing announcements in COPS Productions Blog #5.2 !  


US/1

Follow The Money. in HAWALA - EdgeHEDGE

Follow The Money. in HAWALA - EdgeHEDGE
NEW - Muslim who financed Times Square jihad bomber pleads guilty

FLASH - DigitalBLACK: GERONIMO ACQUIRED - FLASH - NavySEALs Capture UBL...

BlackNET Member James Bamford: Inside the NSA's Largest Secret Domestic Spy Center