A sophisticated piece of spyware has been quietly infecting hundreds of government computers across Europe and the US in one of the most complex cyberespionage programs uncovered to date.
Several security researchers and Western intelligence officers say they believe the malware, widely known as Turla, is the work of the Russian government and linked to the same software used to launch a massive breach on the US military uncovered in 2008.
It was also linked to a previously known, massive global cyberspying operation dubbed Red October targeting diplomatic, military and nuclear research networks.
Those assessments were based on analysis of tactics employed by hackers, along with technical indicators and the victims they targeted.
“It is sophisticated malware that’s linked to other Russian exploits, uses encryption and targets Western governments. It has Russian paw prints all over it,” said Jim Lewis, a former US foreign service officer, now senior fellow at the Center for Strategic and International Studies in Washington.
However, security experts caution that while the case for saying Turla looks Russian may be strong, it is impossible to confirm those suspicions unless Moscow claims responsibility.
Developers often use techniques to cloud their identity.
The threat surfaced this week after a little-known German anti-virus firm, G Data, published a report on the virus, which it called Uroburos, the name text in the code that may be a reference to the Greek symbol of a serpent eating its own tail.
Experts in state-sponsored cyberattacks say that hackers backed by the Russian government are known for being highly disciplined, adept at hiding their tracks, extremely effective at maintaining control of infected networks and more selective in choosing targets than their Chinese counterparts.
“They know that most people don’t have either the technical knowledge or the fortitude to win a battle with them. When they recognize that someone is onto them, they just go dormant,” one expert who helps victims of state-sponsored hacking said.
“They can draw on some very high-grade programmers and engineers, including the many who work for organized criminal groups, but also function as privateers,” a former Western intelligence official said.
Russia’s Federal Security Bureau declined comment, as did Pentagon and US Department of Homeland Security officials.
On Friday, Britain’s BAE Systems Applied Intelligence — the cyberarm of Britain’s premier defense contractor — published its own research on the spyware, which it called “snake.”
The sheer sophistication of the software, it said, went well beyond that previously encountered — although it did not attribute blame for the attack.
“The threat ... really does raise the bar in terms of what potential targets, and the security community in general, have to do to keep ahead of cyberattacks,” BAE Systems Applied Intelligence managing director Martin Sutherland said.
Security firms have been monitoring Turla for several years.
Symantec Corp estimates up to 1,000 networks have been infected by Turla and a related virus, Agent.BTZ. It named no victims, saying only that most were government computers.
BAE said it has collected more than 100 unique samples of Turla since 2010, including 32 from Ukraine, 11 from Lithuania and four from the UK. It obtained smaller numbers from other countries.
Hackers use Turla to establish a hidden foothold in infected networks from which they can search other computers, store stolen information, then transmit data back to their servers.
Republican US lawmakers on Friday criticized US President Joe Biden’s administration after sanctioned Chinese telecoms equipment giant Huawei unveiled a laptop this week powered by an Intel artificial intelligence (AI) chip. The US placed Huawei on a trade restriction list in 2019 for contravening Iran sanctions, part of a broader effort to hobble Beijing’s technological advances. Placement on the list means the company’s suppliers have to seek a special, difficult-to-obtain license before shipping to it. One such license, issued by then-US president Donald Trump’s administration, has allowed Intel to ship central processors to Huawei for use in laptops since 2020. China hardliners
A top Vietnamese property tycoon was on Thursday sentenced to death in one of the biggest corruption cases in history, with an estimated US$27 billion in damages. A panel of three hand-picked jurors and two judges rejected all defense arguments by Truong My Lan, chair of major developer Van Thinh Phat, who was found guilty of swindling cash from Saigon Commercial Bank (SCB) over a decade. “The defendant’s actions ... eroded people’s trust in the leadership of the [Communist] Party and state,” read the verdict at the trial in Ho Chi Minh City. After the five-week trial, 85 others were also sentenced on
Conjoined twins Lori and George Schappell, who pursued separate careers, interests and relationships during lives that defied medical expectations, died this month in Pennsylvania, funeral home officials said. They were 62. The twins, listed by Guinness World Records as the oldest living conjoined twins, died on April 7 at the Hospital of the University of Pennsylvania, obituaries posted by Leibensperger Funeral Homes of Hamburg said. The cause of death was not detailed. “When we were born, the doctors didn’t think we’d make 30, but we proved them wrong,” Lori said in an interview when they turned 50, the Philadelphia Inquirer reported. The
RAMPAGE: A Palestinian man was left dead after dozens of Israeli settlers searching for a missing 14-year-old boy stormed a village in the Israeli-occupied West Bank US President Joe Biden on Friday said he expected Iran to attack Israel “sooner, rather than later” and warned Tehran not to proceed. Asked by reporters about his message to Iran, Biden simply said: “Don’t,” underscoring Washington’s commitment to defend Israel. “We are devoted to the defense of Israel. We will support Israel. We will help defend Israel and Iran will not succeed,” he said. Biden said he would not divulge secure information, but said his expectation was that an attack could come “sooner, rather than later.” Israel braced on Friday for an attack by Iran or its proxies as warnings grew of