German nuclear power plant found to be infected with computer viruses
April 29, 2016 1 Comment
The computers of a nuclear power plant in southern Germany have been found to be infected with computer viruses that are designed to steal files and provide attackers with remote control of the system. The power plant, known as Gundremmingen, is located in Germany’s southern district of Günzburg, about 75 miles northwest of the city of Munich. The facility is owned and operated by RWE AG, Germany’s second-largest electricity producer, which is based in Essen, North Rhine-Westphalia. The company provides energy to over 30 million customers throughout Europe.
On Tuesday, a RWE AG spokesperson said cybersecurity experts had discovered a number of computer viruses in a part of the operating system that determines the position of nuclear rods in the power plant. The software on the system was installed in 2008 and has been designed specifically for this task, said the company. The viruses found on it include two programs known as “Conficker” and “W32.Ramnit”. Both are responsible for infecting millions of computers around the world, which run on the Microsoft Windows operating system. The malware seem to be specifically designed to target Microsoft Windows and tend to infect computer systems through the use of memory sticks. Once they infect a computer, they siphon stored files and give attackers remote access to the system when the latter is connected to the Internet. According to RWE AG, viruses were also found on nearly 20 removable data drives, including memory sticks, which were in use by employees at the power plant. However, these data drives were allegedly not connected to the plant’s main operating system.
RWE AG spokespersons insisted this week that “Conficker”, “W32.Ramnit”, and other such malware, did not pose a threat to the nuclear power plant’s computer systems, because the facility is not connected to the Internet. Consequently, it would be impossible for an attacker associated with the viruses to acquire remote access to Gundremmingen’s computer systems. The company did not clarify whether it believed that the viruses had specifically targeted at the power plant. But they insisted that cyber security measures had been strengthened following the discovery of the malware, and said that they had notified Germany’s Federal Office for Information Security (BSI), which is now looking into the incident.
► Author: Ian Allen | Date: 29 April 2016 | Permalink
A member of a hacker group that took responsibility for breaking into the personal email account of the director of the Central Intelligence Agency last year has now hacked the email of the most senior intelligence official in the United States. In October 2015, the hacker group referred to by its members as “Crackas With Attitude” —CWA for short—
A security firm with headquarters in Israel and the United States says it detected and neutralized an extensive cyber espionage program with direct ties to the government of Iran. The firm, called Check Point Software, which has offices in Tel Aviv and California, says it dubbed the cyber espionage program ROCKET KITTEN. In a
A United States Congressional review into last month’s cyber theft of millions of government personnel records has concluded that its impact will go far “beyond mere theft of classified information”. Up to 21 million individual files were
A Patriot missile system stationed in Turkey by the North Atlantic Treaty Organization (NATO) was allegedly hacked by a remote source, according to reports. German magazine Behörden Spiegel
United States intelligence officials expressed concerns about a federal database containing details of security-clearance applications in the years prior to a massive cyber hacking incident that led to the theft of millions of personnel records. Up to
The Israeli government rejected reports yesterday that its spy agencies were behind a virus found on the computers of three European hotels, which hosted American and other diplomats during secret negotiations on Iran’s nuclear program. Cybersecurity firm Kaspersky Lab said on Wednesday that it first discovered the malware, which it dubbed “Duqu 2.0”, in its own systems. The Moscow-based firm said the sophisticated and highly aggressive virus had been designed to spy on its internal research-related processes. Once they detected the malicious software in their own systems, Kaspersky technicians set out to map Duqu’s other targets. They 













Islamic State’s online army is a Russian front, says German intelligence
June 20, 2016 by Ian Allen 1 Comment
Since its inception, the Cyber Caliphate has claimed responsibility for hacking a number of European government agencies and private media outlets. Its targets include the BBC and French television channel TV5 Monde, which was severely impacted by cyber sabotage in April of 2015. The Cyber Caliphate said it was also behind attacks on the servers of the United States Federal Bureau of Investigation, the Department of Defense, and the website of the Pentagon’s US Central Command. The US has since retaliated, both with cyber attacks and physical strikes. One such strike resulted in the killing of Junaid Hussain, a British hacker of Pakistani background, who was said to be among the Cyber Caliphate’s senior commanders. Hussain, 21, was reportedly killed in August 2015 in Raqqa, the Islamic State’s de facto capital in Syria, reportedly after clicking on a compromised link in an email, which gave away his physical whereabouts.
Now, however, a German intelligence report claims that the Cyber Caliphate is not associated with the Islamic State, but is rather a fictitious front group created by Russia. According to German newsmagazine Der Spiegel, which said it had seen the classified report, German authorities suggest that the Cyber Caliphate is in fact a project of APT28 (also known as ‘Pawn Storm’), a notorious Russian hacking collective with close ties to Russian intelligence. The German intelligence report echoes previous assessments by French authorities, which in 2015 stated that the TV5 Monde cyber attack was a false flag operation orchestrated by APT28. Also in 2015, a security report by the US State Department concluded that despite the Cyber Caliphate’s proclamations of connections to the Islamic State, there were “no indications —technical or otherwise— that the groups are tied”.
► Author: Ian Allen | Date: 20 June 2016 | Permalink
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with computer hacking, Cyber Caliphate, false flag operations, Islamic State, Junaid Hussain, News, Russia