Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/21/2012
04:58 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Report: U.S., Israel Fingered In Latest Data-Annihilation Attack

But 'attribution obfuscation' impedes rooting out source of the attack

Remember that rudimentary data-wiping malware found on a few computers in Iran this month? Most security experts pegged it as a simple, unsophisticated copycat of more sophisticated data-destruction malware attacks.

But in the latest twist, Industrial Safety and Security Source reported this week that the malware was courtesy of a U.S.-Israel attack, citing unnamed CIA sources who also say the attacks preceded the August Shamoon attack that hit Saudi Aramco and Iran's oil ministry.

Security researchers are unconvinced, however, noting that malware attribution -- especially when it comes to espionage and sabotage -- is difficult. And Chester Wisniewski, a senior security adviser for Sophos who has studied the so-called Batchwiper/GrooveMonitor attack, says it's "highly unlikely" that a CIA official would confirm such an attack if it were true.

The real problem is "attribution obfuscation," says Roel Schouwenberg, senior researcher for global research and analysis at Kaspersky Lab. "Following Shamoon, I stated we'd likely start seeing a trend where supposed nation-state malware would become more simplistic. Only top teams can develop top malware, such as Stuxnet and Flame. So it's quite clear what type of entity is likely behind it. Simplistic attacks can come from anyone," he says.

With targeted attacks, it doesn't matter whether it's complex or simple, as long as it works, he says.

Still, he says Kaspersky doesn't know who or what type of entity is behind Batchwiper/GrooveMonitor. "The only thing the attacks have in common from what we can see is the geographic location. But as we don't have reports from the wild for this most recent piece of malware, we can't actually confirm that," he says.

Iran's CERT on Sunday first issued an alert about the relatively rudimentary malware, which was discovered to delete data off of various drives at specific times and dates. The malware is a "very simple" knockoff of other wiping malware with no relation to those previously discovered malware attacks, and "very few machines" were infected by it, according to the CERT.

Researchers from Symantec, Kaspersky Lab, AlienVault Labs, and SophosLabs all concurred that it's a simplistic yet lethal piece of malware that doesn't appear to be related to the nation-state-built Stuxnet and Wiper that hit Iran's nuclear facility, or the destructive Shamoon that wiped 30,000 workstations.

"[The malware] is really as basic as it gets. It couldn't really be dumbed down much more. It's easily the most simplistic piece of malware I've looked at all year, and well beyond that," Schouwenberg says. "In terms of 'unique' code, it's five to 10 lines. By itself nobody would have paid attention to this 10 years ago, let alone now."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVE-2019-18197
PUBLISHED: 2019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo...
CVE-2019-4409
PUBLISHED: 2019-10-18
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entere...