This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Threat Watch. Show all posts
Showing posts with label Threat Watch. Show all posts

The Need for a Cyber Attack Warning System

I was recently asked to write a brief guest blog entry on Recorded Future about some of the work I've done with Threat Watch, as well as present on the topic at the Recorded Future Users Network (RFUN2013) conference.

For those interested, the blog entry has been posted on Recorded Future's blog. Also, the slides for my RFUN2013 presentation are now available here.

Recorded Future Announces Cyber Threat Intelligence Application

Recorded Future recently announced the release of their Cyber Threat Intelligence Application. The new app adds a set of real-time trend signals for attackers, TTPs, targets, and hacktivist operations.  You can see what's trending for each of the four categories, brush across entities to see cross-linkages, and drill down on interesting items to dig in and analyze.

The application presents a real-time dashboard of cyber threats, and allows filtering based upon threat, target, operation, or any other criteria.

One of the staff from Recorded Future was kind enough to demo the application for me today, and I am very impressed.

You can get a brief glimpse of the app through the YouTube video.

For examples of the data available, check out my Threat Watch site, which is powered by Recorded Future.


OpPetrol - It's Not About the Oil

I've posted a new Threat Watch bulletin for OpPetrol - a multi-target operation being run by Anonymous.

Updates to the bulletin can be read here.

Below is the bulletin posted in its entirety.


INTEL BRIEF
First Release: 19MAY2013
Updated: 19MAY2013
Subject: Anonymous "OpPetrol"

Target: United States, Canada, United Kingdom, Israel, Saudi Arabia (only Government), China, Italy, France, Germany, Kuwait (only government) and Qatar (only government)

Specific named targets:
Saudi Arabia government emails (Most likely Phishing - http://pastebin.com/0Yr6kyWA)

Additional high probability targets:
Pending

Date: June 20, 2013

Attackers:
AnonGhost
Others Pending
Attack types:
Distributed Denial of Service Attacks (DDoS)
Website Defacement
Possible leak of sensitive information
Details:
Original announcement on Pastebin: http://pastebin.com/Xsewfqvr
Second announcement on Pastebin: http://pastebin.com/38kvvD1S

Quote: “As petrol is sold with the dollar currency of the U S we find this not acceptable when the oil should be sold at the country of Origin, making petrol a lot less then what you the citizens is paying for it.”

Additional Analysis:
A look at the target list vs. top oil producers of the world (data from CIA World Factbook)
 Rank Target List Top Oil Producers Amount Produced (BBL/Day)
 1 No Russia 10,370,000
 2 Yes Saudi Arabia 10,000,000
 3 Yes United States 9,023,000
 4 No Iran 4,231,000
 5 Yes China 4,150,000
 6 Yes Canada 3,592,000
 7 No United Arab Emirates 3,087,000
 8 No Mexico 2,934,000
 9 No Iraq 2,900,000
 10 Yes Kuwait 2,682,000
 11 No Brazil 2,633,000
 12 No Nigeria 2,525,000
 13 No Venezuela 2,470,000
 14 No Norway 1,998,000
 15 No Algeria 1,885,000
 16 No Angolia 1,840,000
 17 No Kazakhstan 1,635,000
 18 Yes Qatar 1,631,000
 19 Yes United Kingdom 1,099,000
 ... ... ...
 43 Yes Germany 165,300
 50 Yes Italy 99,200
 60 Yes France 49,530
 101 Yes Israel 100
 102 No Jordan 20
 103 No Slovenia (Last Place) 5
Based upon the above target list, this attack has nothing to do with oil exports, especially since Israel only produces 100 BBL/Day and is third from the bottom.

Also of interesting note, the announcement speaks about Syria stealing your retirement and savings, but it was Cyprus, not Syria, that raided savings accounts when the country went bankrupt.

This operation appears to simply be an attempt at OpUSA and OpIsrael again, with a few extra countries thrown into the mix so that the operation can be declared a "success" even if only of the target countries is compromised.  This operation is simply a publicity stunt, and not by any means a meaningful attempt to change anything.


Recommendations: Standard recommendations apply
Note: Based upon the past failures of OpIsrael and OpUSA, do not expect a large turnout for this operation either.

Prior to June 20 - In order for multiple sites to be defaced at the same time, malware infection or compromise of credentials must occur ahead of time.  Change passwords, and perform full antivirus scans of systems.  Monitor firewall logs for suspicious activity involving external IP addresses.  Be vigilant, and warn employees of highly targeted phishing attacks.
On June 20 - Monitor network traffic, and coordinate with ISP should any signs of DDoS be seen.
After June 20 - Look for signs of compromise after DDoS attack.  A common technique now being employed by multiple organizations is to mask hacking attacks with DDoS attacks.

OpUSA to Strike US Government and Banking Infrastructure May 7

Anonymous and several other hacking groups are planning to attack the US Government and Banking Infrastructure on May 7, 2013.

I added a threat briefing on OpUSA, what's being targeted, and by who, to my Threat Watch site.

Currently, the only named targets of this attack are Whitehouse.gov, FBI, and Bank of America.  However, I'm sure other targets will be included.

If you work for a government agency, or in the banking agency, be vigilant, and be on the lookout for highly targeted phishing attacks.

You can read the full briefing at my Threat Watch site.

Guest Post: I Can Have Most of My Threat Research Tools in a Single Interface?

The following is a guest post submitted to Caffeine Security. The owner of Caffeine Security is not responsible for its content.  This post is being shared because I feel this has the potential to be a very informative webinar.  I previously attended a TrainACE "Hacker's Breakfast" which you can read about in a previous post.

The answer is “Yes”! Join Advanced Security by TrainACE in this FREE, hour long webinar covering a few aspects of Advanced Threat Intelligence. During this webinar, you’ll be part of a live demo analysis of suspected malicious URL.  Each malicious URL has the potential to completely cripple a company’s network infrastructure and it’s important that any string which looks suspicious be fully analyzed before it falls into the hands of an unsuspecting victim. Attendees will also be shown how to effectively complete the majority of threat research from a single interface. Compiling all data into one spot will make it more manageable and make analysis much more effective.  REGISTER HERE NOW; space is limited!

TrainACE is an IT Certification and cyber security training company. This is only one of many free hacking tutorials they provide to the public. They also host regular meet-ups and events to discuss the latest and greatest topics in cyber security. 


About the Author

This is a guest post from Megan Horner, Marketing Coordinator at TrainACE. TrainACE offers advanced cyber security training such as Mobile Hacking and Wireless Security. Follow TrainACE on Twitter @pentesttraining.

Voices in the Static: Proactive Cyber Threat Monitoring

Your network is under attack. Right now. This very moment your public facing IP address space is being scanned and probed by someone. In fact, the entire Internet is being scanned by so many malicious attackers on a 24/7 basis that the most amount of time an unprotected computer can hope to last on the Internet without being compromised is seven minutes according to SANS.

So what can you do to help determine what threats to monitor for and which ones to ignore?

Read my Guest Blog Post at Recorded Future to find out more!

Threat Watch Updated with Cyber Threat Forecasting

Thanks to the folks at RecordedFuture I have updated the Threat Watch page with a 90 day cyber threat forecast monitor.


The monitor is also reproduced in this post below:

Cyber Threat Forecast - Next 90 Days via Recorded Future

New Resource: Threat Watch

The "bad guys" never sleep.

I'm happy to announce that now even when I'm sleeping, my blog will be able to bring up-to-date news alerts relevant to computer security.

Check out the Threat Watch page today!