Singapore-based Group-IB listed the Equation Group, which is generally acknowledged as being a part of the NSA. It was originally discovered and named by Russian security outfit Kaspersky. In its latest Hi-Tech Crime Trends report for 2019-20, Group-IB pointed out that the Equation Group was operating against Russia and countries formed from the break-up of the former Soviet Union.
Of itself, GroupIB says it is a leading provider of highfidelity adversary tracking and threat attribution framework, and bestinclass antiAPT and online fraud prevention solutions
It claims to have been in business for 16 years, with more than 60,000 hours of incident response experience, says it has carried out more than 1000 cyber crime investigations globally and has more than 360 top-drawer cyber security experts on its staff.
When Kaspersky described the Equation Group, it characterised the entity as the one of the most sophisticated cyber attack groups in the world and "the most advanced ... we have seen", operating alongside but always from a position of superiority with the creators of Stuxnet and Flame.
Kaspersky says most of the Equation Group's targets had been in Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali.
According to Wikipedia, the name Equation Group was chosen because of the group's choice of sophisticated encryption methods in their operations. By 2015, Kaspersky had documented 500 malware infections by the group in at least 42 countries, while acknowledging that the actual number could be in the tens of thousands due to its self-terminating protocol.
The geographical areas that various APTs focus on. Courtesy Group-IB
In 2017, WikiLeaks published a discussion held within the CIA on how it had been possible to identify the group. One commenter wrote that "the Equation Group as labelled in the report does not relate to a specific group but rather a collection of tools" used for hacking.
Kaspersky announced the existence of the Equation Group during its annual summit in Mexico in 2015, saying the group had been active at least since 2001 and had more than 60 actors. The malware it used, dubbed EquationDrug and GrayFish, was found to be capable of reprogramming hard disk drive firmware.
Because of the advanced techniques involved and high degree of covertness, the group is suspected of ties to the NSA, but Kaspersky has not identified the actors behind the group.
In August 2016, a group calling itself The Shadow Brokers, widely suspected to be NSA insiders, released stolen exploits from the Equation Group on the web. Kaspersky cited similarities between the stolen code and earlier known code from the Equation Group malware samples it had in its possession, including quirks unique to the Group's way of implementing the RC6 encryption algorithm, and concluded that this announcement was legitimate.
The stolen files date from as recent as June 2013, thus prompting NSA whistleblower Edward Snowden to speculate that a likely lockdown resulting from his leak of the NSA's global and domestic surveillance efforts stopped The Shadow Brokers' breach of the Equation Group.
Exploits against Cisco Adaptive Security Appliances and Fortinet's firewalls were featured in some malware samples released by the Shadow Brokers. EXTRABACON, a Simple Network Management Protocol exploit against Cisco's ASA software, was a zero-day exploit at the time of the announcement.
Network equipment maker Juniper also confirmed that its NetScreen firewalls were affected. The EternalBlue exploit was used to conduct the damaging worldwide WannaCry ransomware attack in May 2017.
Apart from the Equation Group, the Group-IB report also lists what it claims are APTS from Russia, Iran, North Korea, Pakistan, the Middle East, China, Gaza, Vietnam, the UAE, Turkey and India. Several of these groups have more than geographical area of operation, according to Group-IB.
The report said the key threat to telecommunications networks was hijacking of the border gateway protocol, with nine of the APTs posing a threat to the sector, more than the number of groups that were considered a threat to the financial sector.
The firm said that as 5G networks expanded, the cyber security problems of each company's gear would reflect their share of the market.
"In a few years, telecom companies will struggle to detect hardware and firmware backdoors in 5G infrastructure equipment," Group-IB predicted.
"Many telecom operators are managed service providers and provide security services to government and commercial organisations. Threat actors will attack operators to penetrate the networks they protect."
The 63-page Group-IB report said that only two Russian-linked groups showed an interest in attacking the energy sector by compromising networks and using traditional malware.
Regarding the financial sector, the report said SilentCards was a new group that was focused on attacking banks in Africa.
The trend of attacks had changed since 2017, Group-IB claimed, pointing to big ransomware attacks like WannaCry, NotPetya and Bad Rabbit in 2017, followed by side-channel attacks and targeting vulnerabilities in processors the following year and moving to overt military operations in cyber space in 2019.
One incident of sabotage was noticed in March 2019 when Simn Bolvar Hydroelectric Plant, also known as the Guri Dam, was attacked. This resulted in a mass-scale blackout in Caracas and 22 of the 23 states. The Russian news agency TASS, cited the Venezuelan Communications Minister Jorge Rodriguez as saying there had been a cyber attack against the automated control system. This is the first time large parts of a country have been left without power for many days due to an attack of this kind.
A second incident involved a group affiliated to the Palestinian group Hamas. Group-IB said cited Israeli sources as saying on 4 May 2019, hackers tried to carry out a cyber attack but did not reveal details. The Israel Defence Forces launched an air strike on a building in the Gaza Strip in retaliation, where the hackers; headquarters is believed to have been located. This is said to be the first time that a missile strike has been launched in response to a cyber attack.
A third incident was recorded in June 2019. On 20 June, Iran's Islamic Revolutionary Guard Corps shot down a US drone. The US retaliated a few days later by launching a cyber attack on IRGC's missile control systems.
As this kind of attack needs months of preparation, the systems had probably been compromised some time ago, Group-IB reasoned.
BGP hijacking occurs when traffic is directed to the wrong sources. When it came to inter-carrier routing, carriers (and content providers like Google, Facebook etc) often need to send traffic to each other.
Launtel ISP chief Damian Ivereigh explained it this way: "They rely on a protocol called BGP Border Gateway Protocol which essentially allows each carrier to broadcast to each other what IP address ranges (called 'prefixes') should be sent to them. We, for example, announce to the world that any traffic for the IP address range 103.216.190.0 to 103.216.191.255 should be sent to us."
The security of the process was "not great" and one carrier could announce incorrect prefixes and effectively take over the address ranges of another provider (and take them down).
"This is limited only by the level of trust that each carrier places in another carrier when they receive an advertisement.
Group-IB listed three BGP incidents in 2018 and 2019 which had affected traffic on the Internet. On 25 November 2018, a small Russian operator Krek made a mistake in its BGP configuration which led to between 10% and 20% of Russian Internet users losing access for more than an hour.
Companies like Amazon, YouTube, Russian social network VK and online video streaming service ivi.ru and a number of other organisations were also affected.
The same month, MainOne, a Nigerian ISP, made a configuration error that changed routes in such a way that traffic to Google services was sent to China, with a total of 180 prefixes being affected. The problem was fixed after 74 minutes.
A third incident, on 6 June 2019, the Swiss company Safe Host caused a leak of 70,000 routes to China Telecom. Swisscom, the Dutch ISP KPN and French ISPs Bouygues Telecom and Numericable-SFR were all affected for two hours.
Group-IB said during the period covered by the report, its researchers had analysed attacks carried out by 38 groups from Russia, North Korea, Pakistan, China, Vietnam, Iran, the US, the UAE, India, Turkey and unspecified South American countries.
"It is important to note that there is still no public information about attacks originating from developed countries. This again confirms that well-orchestrated attacks are difficult to detect or attribute to a specific group or country," the report said.
Group-IB said its previous report had identified BIOS/UEFI attacks as a prominent trend, with experts predicting that the main targets would be firmware and motherboard makers in the Asia-Pacific region where many big companies have their production facilities.
Soon after the report was published, news of a malware campaign called Operation ShadowHammer came to light, with malware being delivered through the ASUS Live Update, a legitimate utility that automatically updates BIOS, UEFI, drivers and applications.
The malicious utility was signed with a legitimate certificate from ASUSTeK Computer and hosted on an ASUS server.
In July 2018, experts found a new malware campaign involving the Plead backdoor, which was digitally signed using a valid D-Link Corporation certificate. At the end of April 2019, these experts identified multiple attempts to deploy the same malware in an unusual way. The Plead backdoor was created and executed by a legitimate process named AsusWSPanel.exe.
The executable file was digitally signed by ASUS Cloud Corporation. Plead malware has always been most widely deployed in Taiwan.
In December 2018, Chinese attackers reportedly infiltrated the networks of Hewlett Packard Enterprise and IBM as part of the Cloudhopper campaign. By gaining access to the networks, they were subsequently able to break into computers belonging to HPE and IBM clients.
Cloudhopper compromised client data in 12 countries, including Brazil, Germany, India, Japan, the United Arab Emirates, Great Britain, and the United States.
The clients were from industries such as finance, electronics, medical equipment, biotechnology, automotive, mining, and oil and gas.
The Group-IB report also contains exhaustive details of JavaScript sniffers used to attack content management systems. details of other BGP attacks, details about attacks on ATMs and financial institutions and numerous other cyber heists, including PC banking trojans and bog-standard phishing exploits.
See the original post here:
Equation Group is alive and kicking and active in Russia: Group-IB report - iTWire
- New York Times pushes clemency for Edward Snowden. Justified? (+video) [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Napolitano Says No Clemency for Edward Snowden [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Hero Edward Snowden? [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- What to do about Snowden: The NY Times gets it right [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Snowden 'an aberration': Booz Allen CEO [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Edward Snowden - Wikipedia, the free encyclopedia [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Will Obama Help Edward Snowden? - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- 2 Newspapers Call For Clemency For Edward Snowden - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Editorials Argue Why Edward Snowden Should Get Clemency - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- EDWARD Snowden - IS HE A HERO OR A TRAITOR??? - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Snowden seeks extra Russian protection after U.S. threats [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Edward Snowden denies that he's a Russian spy [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Snowden Denies Working as Foreign Spy, New Yorker Reports [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Glenn Greenwald I Defend Edward Snowden Like MSNBC Defends Obama "24 Hours A Day" - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Former CIA insider on Sochi Olympics security, Edward Snowden - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Airdate : January 4, 2014 : Clemency for Edward Snowden - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- #10 Edward Snowden a Hoax?? Rockefeller: Human Cloning in Film Documentary Series Jan 20 2014 - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Double Standards - Edward Snowden: Traitor or hero - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Edward Snowden NSA Spying HOAX BUSTED fraud Jan 19 2014 Rockefeller net Ron Rand Paul Breaking News - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Philip and Edward Snowden. - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Did Snowden Act Alone? - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Edward Snowden Denies Russian Spy Theory - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Coastal Today Show, January 20 - 26, 2014 | Full Episode - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- BREAKING! Edward Snowden LIVE in New York Snowed-in Snowden Blizzard Snow Storm - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- New York Times editorial defends Edward Snowden - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- The People's Republic of Edward Snowden - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Snowden says mass collection must end [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Russian lawmaker says Snowden asylum period to be extended [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Snowden Says Whistle-Blower Law Gaps Preclude His Return [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden Denies 'Stealing' NSA Co-Workers' Passwords [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden's Asylum in Russia Extended [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden: 'Not Possible' to Return to U.S. Now [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- What Do We Know About Edward Snowden? Webster G. Tarpley - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- On Edward Snowden, Privacy, NSA, and Accountability - Quick Thought #632 - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Edward Snowden is a SPY? How do you kill a spy? - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Scooter and Snowden [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Edward Snowden: Did the American whistleblower act alone? [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Snowden Says Whistle-Blower Law Gaps Preclude Return [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Hükümete protesto, Snowden'e destek - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Edward Snowden NSA leaker asks for extra security after receiving death threats from US officials !! - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Snowden says officials want to kill him [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- edward_snowden_portrait_twitter_reuters.JPG [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Edward Snowden: There Are 'Significant Threats' To My Life [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Snowden Says ‘No Doubt’ NSA Engages in Industrial Spying [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Edward Snowden Biography - Facts, Birthday, Life Story ... [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Alex Jones Show Friday 1 24 14 Piers Corbin - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- The People's Republic of Edward Snowden part 2 - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Snowden interview turns up few key revelations [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- edward-snowden-reuters-120313.JPG [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Edward Snowden - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- German Television To Air NEW Edward Snowden Interview TONIGHT - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Edward Snowden is nominated for the 2014 Nobel Peace Prize [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Snowden Nominated by Norwegian Lawmakers for Nobel Peace Prize [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Snowden nominated for Nobel Prize [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Snowden Gets Nobel Peace Prize Nomination From Norwegian MP - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- BREAKING: Edward Snowden Nomination For Nobel Peace Prize! - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Edward Snowden's Psychic Human ETs - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Report puts Snowden-like leaks as No. 2 threat to US security [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Why Silicon Valley sticks up for Snowden [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Snowden nominated for Peace Prize [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Edward Snowden Nominated For Nobel Peace Prize - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- UK spy chief to step down: GCHQ boss Iain Lobban leaves in wake of Edward Snowden NSA leaks - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Is Edward Snowden Behind Target Hacking? - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Snowden: NSA Mining App Data to Track Targets - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Snowden nominated for Nobel Peace Prize [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- [CCTV FOOTAGE]Edward Snowden Gunshot January 31, 2014 - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Obama administration nominates new NSA director - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden nominated for Nobel Peace Prize: NSA whistleblower has exposed US spying - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden's Norwegian Nobel nomination called into question - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden the Peace Prize Winner? - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Edward Snowden, a Party to Subverting Nations in Latin America [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Edward Snowden: World's most wanted man [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Politicians attack Great Barrier Reef, Edward Snowden and TV Reporter - TFU Friday - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- WikiLeaks, Greenwald Blast Guardian Journalist’s Book On ‘FSB Prisoner’ Snowden [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Killing Edward Snowden on Occupy The Microphone - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Edward Snowden January 25, 2014 Interview Links - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Edward Snowden Documents reveal Canadian Spies Exist! - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- 20140203 - Barking at the moon - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Snowden aftermath: Defense contractors revamp policies, practices [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Booz Allen Exec Describes How Snowden Stole Millions of Documents [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]