Cyber Attack From Inside India Hits Pakistan Government
judgecorp writes "Government institutions are among the targets of an attack on Pakistani bodies, which originates in India, according to reports. The campaign is using vulnerabilities in Microsoft software to install the HangOver malware, according to Norwegian security firm Norman Shark (PDF). From the article: 'In the attacks on Pakistani organizations, spear phishing emails were sent out purporting to contain information on "ongoing conflicts in the region, regional culture and religious matters," according to Norman. Norman could not provide direct attribution to the attacks, but its report did note the following: "The continued targeting of Pakistani interests and origins suggested that the attacker was of Indian origin." Snorre Fagerland, principal security researcher in the Malware Detection Team at Norman, told TechWeekEurope it appeared Pakistani government bodies had been attacked.'"
If India were actually behind this, why would it appear to come from India?
If someone else were doing this, wouldn't India be the obvious choice for your final leg?
Sig Battery depleted. Reverting to safe mode.
Next time I get a new cat I am going to call it "Snorre Fagerland." I need to figure out which Monty Python routine included that name now.
Oh, and.... um... now for the gratuitous MS bashing: Microsoft security is bad bad bad! (Social engineering for the win, though.)
From the first article:
Norman could not provide direct attribution to the attacks, but its report did note the following: “The continued targeting of Pakistani interests and origins suggested that the attacker was of Indian origin.”
From the PDF:
None of the information contained in the following report is intended to implicate any individual or entity, or suggest inappropriate activity by any individual or entity mentioned.
Prominently displayed centered on the very first page of the report after the cover.
... whatever
The only "proof" of that it originated from India is... still searching and can't find anything in the article.
Probably the last-hop IP in the spear phishing mail headers.
That is the only IP address you can (somewhat) trust, because it is inserted by your own mail server.
Is it proof?, certainly not.
Sig Battery depleted. Reverting to safe mode.
mySQL is a fine database and anybody who complains about it is just a hater. /sarc
John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
Maybe Pakistan are just bunging on an act as a pretext to attack non-Muslims again?
Or maybe they're telling the truth for once, but it's the Chinese hacking their fair-weather friend? The Chinese have the market cornered on immorality in general, and criminal hacking in particular, so it wouldn't surprise me.
Or, maybe the Paks want to provoke a war?
http://www.aninews.in/newsdetail2/story112519/growing-intolerance-in-pak-occupied-kashmir.html
There's a lot going on, and I'm nowhere close to pulling it all together. Gotta keep in mind that the Taliban runs half of the country, but instead of Pakistan fighting the Taliban, they're instigating confrontations with India. Strange . . .
"Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
Recently they had election and an old disgraced politician named Nawaz Shariff has formed a new government. So as usual they are thumping their chests and beat the war drums in some attempt to unify the country behind him. Hope he calls the yelping dogs off before serious permanent damage is done.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Who have been indulging in a lot of terrorism recently, so adding some cyber attacks would merely be broadening their palate. And blaming it on India is always good for misdirection.
The title says "Attack from inside India". But the quote only seems to say "Since the target is Pakistan, the attacker can only be India". That doesn't sound like very solid evidence...
Of course, I haven't read the article (yet?), but the summary doesn't really suggest I would learn anything more.
Sending malware laden phishing emails is an attack now? Hmm, what's the appropriate Monty Python line for that ... Oh yeah: Help, help, I'm being oppressed! Come and see the violence inherent in the system! So, now the USA's Cyber-terrorism defenses are going to ramp up to hunt down and "yada yada with extreme prejudice" spammers, script kiddies, and botnet herders?
Wouldn't it be simpler to lobby Microsoft to get them to stop pushing out crappy, vulnerable software?
I think I'll blame the Pakistanis for this whole incident. If they weren't running pirated versions of abysmally maintained/supported software, they wouldn't have fallen victim to this.
"Tongue tied and twisted, just an Earth bound misfit
"Government institutions are among the targets of an attack on Pakistani bodies, which originates in India, according to reports. The campaign is using vulnerabilities in Microsoft software to install the HangOver malware"
Sep 2003: CyberInsecurity: The Cost of Monopoly
AccountKiller
Hello,
Norman has done an excellent job with their report on the malware; however, it should be noted that the initial report came from ESET last week at the CARO anti-malware conference:
Targeted information stealing attacks in South Asia use email, signed binaries
I would also like to point out that while it is easy to assume that the Indian government (or someone connected with it) was responsible for these targeted attacks given the seemingly poor job in hiding their tracks (domain name registrations, embedded metadata, et cetera), it could also be a more sophisticated adversary who specifically manufactured those in an attempt to divert attention from themselves. After all, Pakistan shares borders with Afghanistan, China and Iran, and there are other countries who are likely interested as well, for geopolitical and even economic reasons.
Threat attribution is incredibly difficult, and attempts to blame India at this point may not just be foolish, but counterproductive as well.
Regards,
Aryeh Goretsky
Dexter is a good dog.
I guess it was your turn :)
Google "Religion and IQ"
* Muslim IQ = 104.87
* Hindu IQ = 103.9
Google "National IQ estimates"
* Pakistan = 84
* India = 82
https://en.wikipedia.org/wiki/Folk_devil
Casteism