Sunday, December 1, 2013

Mandiant Intelligence Center Report APT1: Exposing One of China's Cyber Espionage Units

Mandiant Intelligence Center Report

APT1: Exposing One of China's Cyber Espionage Units

APT1

APT1: Exposing One of China's Cyber Espionage Units

This report is focused on the most prolific cyber espionage group Mandiant tracks: APT1. This single organization has conducted a cyber espionage campaign against a broad range of victims since at least 2006.
Download Report
Appendix

Digital Appendix & Indicators

Access more than 3,000 APT1 indicators including domain names, IP addresses, X.509 encryption certificates and MD5 hashes of malware in APT1's arsenal of digital weapons.
Download Appendix

Highlights

Our analysis has led us to conclude that APT1 is likely government-sponsored and one of the most persistent of China's cyber threat actors. The scale and impact of APT1's operations compelled us to write this report. In an attempt to bolster defenses against APT1 operations Mandiant is also releasing more than 3,000 indicators as part of the appendix to this report, which can be used with our free tools and our commercial products to search for signs of APT attack activity.
Highlights of the report include:
  • APT1 is believed to be the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, which is most commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.
  • APT1 has systematically stolen hundreds of terabytes of data from at least 141 organizations.
  • APT1 focuses on compromising organizations across a broad range of industries in English-speaking countries.
  • APT1 maintains an extensive infrastructure of computer systems around the world.
  • In over 97% of the 1,905 times Mandiant observed APT1 intruders connecting to their attack infrastructure, APT1 used IP addresses registered in Shanghai and systems set to use the Simplified Chinese language.
  • The size of APT1’s infrastructure implies a large organization with at least dozens, but potentially hundreds of human operators.
  • In an effort to underscore that there are actual individuals behind the keyboard, Mandiant is revealing three personas that are associated with APT1 activity.
  • Mandiant is releasing more than 3,000 indicators to bolster defenses against APT1 operations.
Mandiant_APT1_Report.pdf
MD5: 936FEB234F60CFBF6916BA61FBAB2781
SHA-1: 3974687624EB85CDCF1FC9CCFB68EEA052971E84
Mandiant_APT1_Report_Appendix.zip
MD5: FD103F16BBBB28162C23BE3A47371AA9
SHA-1: ABF9D09A991E56393D18433644FF0DBA907A9154


By on February 18, 2013

Mandiant Exposes APT1 – One of China’s Cyber Espionage Units & Releases 3,000 Indicators

Today, The Mandiant® Intelligence Center™ released an unprecedented report exposing APT1′s multi-year, enterprise-scale computer espionage campaign.  APT1 is one of dozens of threat groups Mandiant tracks around the world and we consider it to be one of the most prolific in terms of the sheer quantity of information it has stolen.

Highlights of the report include:
  • Evidence linking APT1 to China’s 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department (Military Cover Designator 61398).
  • A timeline of APT1 economic espionage conducted since 2006 against 141 victims across multiple industries.
  • APT1′s modus operandi (tools, tactics, procedures) including a compilation of videos  showing actual APT1 activity.
  • The timeline and details of over 40 APT1 malware families.
  • The timeline and details of APT1′s extensive attack infrastructure.

Mandiant is also releasing a digital appendix with more than 3,000 indicators to bolster defenses against APT1 operations. This appendix includes:
  • Digital delivery of over 3,000 APT1 indicators, such as domain names, and MD5 hashes of malware.
  • Thirteen (13) X.509 encryption certificates used by APT1.
  • A set of APT1 Indicators of Compromise (IOCs) and detailed descriptions of over 40 malware families in APT1′s arsenal of digital weapons.
  • IOCs that can be used in conjunction with Redline™, Mandiant’s free host-based investigative tool, or with Mandiant Intelligent Response® (MIR), Mandiant’s commercial enterprise investigative tool.

The scale and impact of APT1′s operations compelled us to write this report.  The decision to publish a significant part of our intelligence about Unit 61398 was a painstaking one.  What started as a “what if” discussion about our traditional non-disclosure policy quickly turned into the realization that the positive impact resulting from our decision to expose APT1 outweighed the risk of losing much of our ability to collect intelligence on this particular APT group.  It is time to acknowledge the threat is originating from China, and we wanted to do our part to arm and prepare security professionals to combat the threat effectively.  The issue of attribution has always been a missing link in the public’s understanding of the landscape of APT cyber espionage.  Without establishing a solid connection to China, there will always be room for observers to dismiss APT actions as uncoordinated, solely criminal in nature, or peripheral to larger national security and global economic concerns.  We hope that this report will lead to increased understanding and coordinated action in countering APT network breaches.
We recognize that no one entity can understand the entire complex picture that many years of intense cyber espionage by a single group creates.  We look forward to seeing the surge of data and conversations a report like this will likely generate.
You can download the report, the appendices and view the video showing APT1 attacker activity at http://www.mandiant.com/apt1.
Dan McWhorter
Managing Director, Threat Intelligence

Category: The Suite Spot

US and China accuse each other of cyber warfare

US and China accuse each other of cyber warfare

Published time: February 19, 2013 19:23
Edited time: February 20, 2013 15:57
Reuters / Andrew Wong
Reuters / Andrew Wong
US security experts claim a 12-story office building outside of Shanghai is the headquarters of a hacking unit in China established to attack international computer networks. Beijing has rejected the allegations, calling the reports “unreliable”.
According to a report published Tuesday morning by a Northern Virginia-based information security company, an elusive squadron of Chinese cyberwarriors operating under the name Unit 61398 has engaged in countless battles with governments and entities around the globe for years under the umbrella of the People’s Liberation Army.
The group is accused of infiltrating the computers of some of the biggest businesses and agencies in the US, both public and private alike, and is assumed to still be at large.
Alexandria, Virginia’s Mandiant says they’ve been investigating PLA Unit 61398 for years now and has watched them compromise 141 companies across 20 major industries, infecting the computers at places like Coca-Cola and the Canadian arm of Telvent with malicious codes used to pilfer servers for privileged information and wreak havoc. In their report, the security experts say that they are all but certain that those attacks have originated out of an inconspicuous white office building on the outskirts of Shanghai that has been provided with a special fiber optic communications infrastructure from Chinese telecom providers in the name of national defense — but China maintains the claim that they have not engaged in any illegal hacks.
Unit 61398 Center Building. Image taken from Mandiant’s report.
Unit 61398 Center Building. Image taken from Mandiant’s report.

Mandiant founder Kevin Mandia begs to differ, and tells The New York Times that either those attacks are being waged by Unit 61398 out of the building in question, “or the people who run the most-controlled, most-monitored Internet networks in the world are clueless about thousands of people generating attacks from this one neighborhood.”
“It’s where more than 90 percent of the attacks we followed come from,” says Mr. Mandia, who adds that the unit is "chartered with hiring people that can speak English, and be able to exploit networks, and know computer security.”
“We thought that was an interesting combination, and that unit just so happens to be located in the same region of Shanghai where we're tracking over 90 percent of the connections coming from,” he tells the Times. Additionally, his company discovered that two sets of I.P. addresses used in the attacks being studied were registered in the same neighborhood as the building assumed to be used by Unit 61398.
“The totality of the evidence” leads to the company to conclude that the building described by the Times to be in a run-down neighborhood on the outskirts of Shanghai is the originating point of the attacks.
Unit 61398 Center Building. Image taken from Mandiant’s report.
Unit 61398 Center Building. Image taken from Mandiant’s report.

Details of an advanced cyberwar against the US by way of China has been hinted at by members of the Obama administration since the president began his first term in office in 2009, although publically little information about the actual threat posed by Far East hackers has been officially divulged. Through documents obtained by the website WikiLeaks, however, information has emerged that only begins to discuss the intensity of the threat. US State Department diplomatic cables released in 2010 by WikiLeaks and attributed to accused whistleblower Bradley Manning discus sophisticated cyberattacks against the US waged by a Chinese unit given the codename “Byzantine Candor,” or BC. The Times reports that that moniker for Unit 61398 — formally, the Second Bureau of the People’s Liberation Army’s General Staff Department’s Third Department — was dropped by American officials following the highly publicized disclosure of the hundreds of thousands of sensitive State Department documents.
In one cable from November 2008, a State Department official writes, “hackers based in Shanghai and linked to the PRC’s People’s Liberation Army (PLA) Third Department have been using these compromised systems as part of the larger BC attack infrastructure to facilitate computer network exploitation (CNE) of U.S. and foreign information systems.”
“A October 23 DoD cable states Shanghai-based hackers associated with BC activity and linked to the PLA have successfully targeted multiple U.S. entities,” the memo continues. “In the US, the majority of the systems BC actors have targeted belong to the U.S. Army, but targets also include other DoD services as well as DoS, Department of Energy, additional USG entities and commercial systems and networks.”
But despite the State Department cables spawning an insurmountable number of media articles and remarks, the publishing of the Mandiant report presents an American audience for the first time with detailed claims about intrusions and attacks waged against countries around the globe with undoubtedly damaging repercussions. It also comes on the heels of a renewed call for federal cybersecurity legislation in the United States, which could now be sooner than ever thanks to the latest revelations regarding Unit 61398.
Geographic location of those targeted. Image taken from Mandiant’s report.
Geographic location of those targeted. Image taken from Mandiant’s report.

On Wednesday last week, Rep. Mike Rogers (R-Mich.) and Sen. Dutch Ruppersberger (D-Calif.) reintroduced the Cyber Intelligence Sharing and Protection Act (CISPA), a bill that was touted as being a solution to America’s mysterious cyberwar woes when first brought up last year but was eventually stalled before it could reach a vote in the Senate. On the eve of the reintroduction, Rep. Rogers wrote an op-ed for The Detroit News in which he says, “Every morning in China, thousands of highly-trained computer engineers wake up with one mission: Steal American intellectual property that the Chinese can in turn use to compete against us in the international market.” During a formal unveiling of the rekindled CISPA, Sen. Ruppersberger claimed that the US loses around $300 billion in trade secrets annually because of foreign cyberattacks.
Now to address the latest news from Mandiant, the White House is reportedly in discussion with the Chinese to snuff any possible cyberwar before it escalates. According to Foreign Policy, a senior White House official says on condition of anonymity that the Obama administration is speaking with Chinese government officials "at the highest levels" about the attacks.
"The United States has substantial and growing concerns about the threats to US economic and national security posed by cyber intrusions, including the theft of commercial information," the source says.
Unit 61398’s position within the People's Liberation Army. Image taken from Mandiant's report.
Unit 61398’s position within the People's Liberation Army. Image taken from Mandiant's report.

Additionally, Foreign Policy says Rep. Rogers told them in a candid interview just last week that America is in need of having “direct talks with China,” with cyber espionage being top priority for the bilateral discussions. "This is a problem of epic proportions here and they need to be called on the carpet. There has been absolutely no consequences for what they have been able to steal and repurpose to date,” he told them.
For now, though, the Chinese are refuting the claims made by Mandiant and the US government. Mandiant says the cybercrimes in question “are based primarily in China and that the Chinese Government is aware of them,” but Hong Lei, a spokesman for China’s foreign ministry, said on Tuesday that his country disavowed hacking while discrediting the report.
“Groundless criticism is irresponsible and unprofessional, and it will not help to solve the problem," he said of the Mandiant analysis.
"Hacking attacks are transnational and anonymous. Determining their origins are extremely difficult. We don't know how the evidence in this so-called report can be tenable," Lei added.
China's Defense Ministry on Wednesday issued a statement arguing the report’s accusations are scientifically flawed and not reliable.
"The report, in only relying on linking IP address to reach a conclusion the hacking attacks originated from China, lacks technical proof," the statement said. "Everyone knows that the use of usurped IP addresses to carry out hacking attacks happens on an almost daily basis."
The ministry also suggested that gathering information is not “online spying”.
Screenshot taken from www.mod.gov.cn
Screenshot taken from www.mod.gov.cn
Speaking to the Times, officials at the Chinese embassy in Washington have also dismissed the allegations while noting the epidemic of international hacks originating in the US. "They describe China itself as a victim of computer hacking, and point out, accurately, that there are many hacking groups inside the United States," the Times' report reads.
Just last month, the Chinese Defense Ministry issued a statement saying “it is unprofessional and groundless to accuse the Chinese military of launching cyber attacks without any conclusive evidence.” And while Mandiat’s report include a good number of information that suggests attacks on US entities are coming from the rumored Unit 61398 headquarters, at the same time they still lack cold hard proof.
The same could be said about the United States’ own attacks, though, after testimonies offered to The New York Times last year linked both the George W. Bush and Obama administrations to a program nicknamed ‘Olympic Games’ that was put together with Israeli allies to wage a covert cyberwar on Iranian nuclear facilities. The White House has yet to formally admit to the allegations, but former administration officials attributed attacks on Iran to the US. Meanwhile, Iranian hackers are being blamed for recent assaults on the US banking industry.
"We are in a cyberwar [but] most Americans don’t know it,” Sen. Rogers said during last week’s CISPA unveiling.
Discussing the need for cybersecurity legislation during the event, Rogers urged Congress to approve the bill he co-authored with Rep. Ruppersberger before a cyberattack of epic proportions prompts Washington to act urgently and perhaps without oversight. The senator warned of what an assault on the US infrastructure conducted by cybercriminals could mean and said, "We don’t do anything well after a significant emotional event."
Should there be a cyberattack on America on par with the September 11, 2001 tragedy, Rep. Ruppersberger said Congress “will get all the bills passed we want.”
Should Mandiant’s assumptions prove correct, though, it would pin the blame on China for a number of high-profile hacks. Among the entities that the security experts say were targeted by Chinese hackers are defense contractors Lockheed Martin; the National Geospatial-Intelligence Agency; lobbyists the National Electrical Manufacturers Association; Coca-Cola; the Chertoff Group and Telvent. According to the Times, computers at Telvent are used to design software “that gives oil and gas pipeline companies and power grid operators remote access to valves, switches and security systems” in Canada. Coincidently, last month China's state-owned CNOOC spent $15 billion to buy-out Canadian oil and gas company Nexen Inc. in China's largest-ever foreign takeover.

Rockefeller attaches cybersecurity bill to NDAA 2014

Rockefeller attaches cybersecurity bill to NDAA 2014

Published time: November 22, 2013 20:19
Senator Jay Rockefeller (Reuters / Mike Segar)
Senator Jay Rockefeller (Reuters / Mike Segar)
The chairman of the Senate Commerce Committee submitted on Thursday an already-approved cybersecurity bill to be considered as an amendment to next year’s National Defense Authorization Act.
If the amendment manages to stay intact as Congress prepares to approve the 2014 NDAA, Sen. Jay Rockefeller (D-West Virginia)’s Cybersecurity Act of 2013 may finally be codified into law.
Rockefeller’s proposal, S.1353, was unanimously approved by the Commerce Committee in July but has stayed relatively dormant ever since. On Thursday he submitted that bill as an amendment to be considered as part of an annual Pentagon spending plan that could fast track his attempts to land his proposal on President Barack Obama’s desk after attempts in Congress to adopt cybersecurity legislation have largely proven to be futile.

In a statement made by Rockefeller that circulated earlier this week, the 75-year-old senator suggested that the time is now upon Congress to finally enact a bill that would mandate precautions be taken to protect America’s cyber infrastructure and the private entities attached to it amid ongoing reports of high-powered attacks aimed at the likes of government computers and the networks of critical services.
“The Commerce Committee took action months ago and unanimously passed this bipartisan bill that will improve the nation’s cybersecurity. But it’s been sitting on the sidelines for too long and there’s too much at stake to not look for every opportunity to pass it in the Senate,” Rockefeller said in a statement first published on Wednesday by John Eggerton at Multichannel News. “So I’m introducing that legislation as an amendment to the Defense Authorization bill and imploring my colleagues to join me in supporting this effort.”
According to Rockefeller, his bill “creates an environment that will cultivate the public-private partnerships essential to strengthening our nation’s cybersecurity.” When it was first introduced in the Senate earlier this year, the Commerce Committee said passage of the bill would “Formalize cybersecurity as one of [National Institute of Standards and Technology]’s priority areas of focus” and “create a NIST-facilitated, industry-driven process for developing a set of voluntary cybersecurity standards for critical infrastructure.” At the time it received endorsements from the likes of AT&T, Verizon, Motorola Solutions, the Electric and Nuclear Power Coalition, IBM and the US Chamber of Congress.
I’ve always thought this was a great way to emphasize the critical need for a public-private approach when it comes to solving our most pressing cybersecurity issues,” Rockefeller said then.
Since Congress will need to approve a version of the NDAA in order to authorize the Pentagon’s funding for the next fiscal year, the addition of Rockefeller’s bill as an amendment ensures that it will at least be considered by his colleagues for passage in the coming weeks, setting the stage for lawmakers to finally let a cybersecurity bill of this capacity become codified.
In 2012, attempts in Congress to pass the Cyber Intelligence Sharing and Protection Act, or CISPA, ultimately failed due largely in part to a major public campaign that condemned the would-be law due to allegations that it would erode privacy on the web by encouraging the growth of a public-private partnership between internet companies and the federal government.
Proponents of CISPA, including then-Secretary of Defense Leon Panetta, said at the time that America was at a “pre-9/11 moment” and warned that a “Cyber-Pearl Harbor that would cause physical destruction and the loss of life” could soon occur on American soil if the country’s critical infrastructure and top-tier businesses weren’t obligated to come together and share information about potential hacks waged at US networks.
The architects of CISPA have since reintroduced their bill, and Pres. Obama signed an executive order in February that mandated administration officials to come up with standards to reduce cybersecurity risks and encourage companies to adopt the new framework.
“We know hackers steal people’s identities and infiltrate private e-mail,”Obama said after signing the order in February.“We know foreign countries and companies swipe our corporate secrets. Now our enemies are also seeking the ability to sabotage our power grid, our financial institutions, and our air traffic control systems.”

PA Vows ‘Unending Violence’ At Memorial Event for Yasser Arafat

PA Vows ‘Unending Violence’ At Memorial Event for Yasser Arafat

Golda Meir: When The Arabs Love Their Children More Than They Hate Jews, There Will Be Peace
11-30-13 At an event marking nine years since former Palestinian Authority (PA) Chairman Yasser Arafat’s death, a PA supported foundation hosted a musical performance that was broadcast on PA TV. In it, performers sang a song glorifying martyrdom and vowing violence “no force can stop” on Israel. In addition to the song, PA Prime Minister Rami Hamdallah gave a speech at the event, and numerous PA and Fatah officials were in attendance. The Popular Arts and Military Music group performed “My weapon has emerged” at the event while dressed in military uniforms. The song features such lines as “there is no force in the world that can remove the weapon from my hand,” and “as the weapon of the revolution is in my hand, so my presence will be forced (upon Israel).”
The memorial event was organized by the Yasser Arafat Foundation, which according to its website was “established by Presidential decree” in 2007 and receives “governmental support,” even while it is run independently. The organization states is goal is to preserve “the heritage and legacy of the late President Yasser Arafat among the Palestinian, Arab and friendly peoples.” Regarding Arafat’s legacy, a Fatah official recently claimed on PA TV that Arafat taught “all liberation movements in the world” that Israel is the “prime enemy…of all nations in the world.” Arafat’s memorial comes amid conspiracy theories from the PA that Israel poisoned the late leader. Swiss scientists recently asserted that lab test results “moderately” support the theory that Arafat died of polonium poisoning in 2004. While PA officials jumped to accuse Israel, the US was also accused by the PA of being involved in the supposed “assassination.”President Shimon Peres rejected the theories, saying it would have been easier for an assassin to simply shoot Arafat.

Obama’s first college now offers a whole class on ‘RuPaul’s Drag Race’

Obama’s first college now offers a whole class on ‘RuPaul’s Drag Race’

The mediocre private liberal arts college that President Barack Obama attended from 1979 to 1981 before wisely transferring to Columbia University as a junior will now offer real academic credit for students who want to study the reality show “RuPaul’s Drag Race.”
The spring course at Occidental College in Los Angeles is entitled “Reading RuPaul: Camp Culture, Gender Insubordination, and the Politics of Performance,” reports Campus Reform.
The class will analyze “RuPaul’s Drag Race” from both gay and feminist gay viewpoints. Coursework will include watching a bunch of episodes of the Logo TV reality show and reading “Workin’ It,” a book RuPaul wrote in 2010.
In case you don’t watch a lot of Logo TV, “RuPaul’s Drag Race,” is basically a conventional reality show with cross-dressing. There are contestants who get eliminated based on their performances in challenges including fashion design, musical performance and getting doused with water while dressed in full drag.
Daniel Williford, the course professor, told Out.com that “the overarching premise” of the class is to examine the reality show “as an example of the creative techniques that marginalized people use to grapple with the violence, shame and social illegitimacy that are the stuff of daily life.”
Williford added that liking “RuPaul’s Drag Race” isn’t a prerequisite.
“Students will be encouraged to critique this premise of the class and the show itself,” he told Out.com. “But they will have to do so by immersing themselves in it.”
The course is offered through Occidental’s critical theory and social justice program.
Other courses in this vital and obviously grueling major include “Whiteness,” “Rasatafari” and a class called “Stupidity.”
The total cost for tuition, room and board and required fees this academic year at Occidental is $59,592.
Here is how the private college describes the RuPaul course:
This course introduces methods in Queer Theory and Feminist Theory by taking as the central object of study the reality competition show “RuPaul’s Drag Race.” As the show brings the art of drag performance and issues attendant to contemporary queer subcultures to a wide audience, the course will consider how it addresses histories of drag and U.S. gay culture, as well as a broad range of issues such as transgender identity, HIV/AIDS, bullying and violence, racial identity, gender identity, body size, and LGBT political activism. Students will consider claims about the transformative, recuperative, and empowering art of drag performance. The course will draw from readings on the history of sexuality, feminist critiques of gender identity, transgender affect and embodiment, the history of race and racial identity, and drag and the politics of camp.
Follow Eric on Twitter and on Facebook, and send education-related story tips to erico@dailycaller.com.

Obama to Netanyahu: Stop Criticizing Iranian Nuke Deal

Obama to Netanyahu: Stop Criticizing Iranian Nuke Deal

Obama to Netanyahu1

U.S. President Barack Obama has reportedly asked Prime Minister Binyamin Netanyahu to stop being so vocal with his criticism of the deal reached between Iran and the West, reports The Washington Post.
The newspaper’s columnist David Ignatius wrote on Thursday, “Obama has asked Netanyahu to take a breather from his clamorous criticism and send to Washington a team that can explore with U.S. officials a sound end-state strategy.”
“Perhaps the United States and Israel need a back channel, outside the bombastic pressure campaign by Israeli advocates,” he added in the column, which dealt with Washington’s plans for the next six months, during which the Western powers and Iran are supposed to work out a permanent agreement.
Netanyahu has openly criticized the deal that was reached between Iran and Western powers in talks in Geneva, explaining that it allows Iran to continue its nuclear program while getting sanctions relief.
Netanyahu slammed the deal on Sunday, shortly after it was reached, saying, “As we learn more and more details about the agreement that was achieved last night in Geneva, it becomes increasingly clear how bad and dangerous this agreement is to the world, the region and Israel.”
Shortly after his remarks on Sunday evening,  Netanyahu received a phone call from Obama to discuss the deal.
During that conversation, the two reportedly agreed that Israeli and American teams would hold consultations on the permanent agreement.
On Wednesday, a high-ranking Israeli officer said that Israel and the United States plan to hold a joint military drill in six months, just as the interim agreement between Iran and the West is due to expire.
“The wind from the Americans into the Israeli sails is, ‘We will maintain our capability to strike in Iran, and one of the ways we show it is to train.’ It will send signals both to Israel and to the Iranians that we are maintaining our capabilities in the military option. The atmosphere is we have to do it big time, we have to do a big show of capabilities and connections,” the official told TIME magazine.
SOURCE: Israel National News