Amid ongoing geopolitical tension, researchers find Pakistani hacking operation aimed at India

As well-crafted hacking tools become more ubiquitous, long simmering rivalries between developing nations take on a new dimension: cyber espionage runs rampant. Research released Thursday by Talos Security, Cisco’s internal cybersecurity unit, describes how a long running computer spying campaign against India was likely controlled by operators in Pakistan. Researchers highlighted a stealthy remote access trojan, dubbed “GravityRAT,” that’s been repetitively used to target Indian organizations since at least 2016. During that timeframe, the author of GravityRAT added new features and changed certain capabilities to make it more difficult to detect. This also included making the malware multilingual, so that whenever it was packaged inside a phishing email it had a better chance at tricking people who speak Chinese, Italian, French, German or Spanish. India’s computer emergency response team (CERT) previously published an advisory about GravityRAT, which suggests it targeted multiple Indian entities, according to Talos. The Indian CERT, however, only […]

The post Amid ongoing geopolitical tension, researchers find Pakistani hacking operation aimed at India appeared first on Cyberscoop.

Continue reading Amid ongoing geopolitical tension, researchers find Pakistani hacking operation aimed at India

Microsoft-led industry group pledges to not assist government cyberattacks

A cohort of major technology companies led by Microsoft committed Tuesday to a core set of principles for behavior in cyberspace, including not helping any government mount a cyberattack against “innocent civilians and enterprises.” For the last several weeks, Microsoft has been seeking support from companies in order to define a common standard of behavior, or norms, for the broader software making community. The announcement was spearheaded by Brad Smith, president and chief legal officer of Microsoft. Smith spoke Tuesday morning at the RSA cybersecurity conference in San Francisco to an audience mostly comprised of cybersecurity industry insiders and marketers. These norms spelled out in the agreement cover more than government relations. They contain the concept of “collective action” between technology companies to eliminate some of the more expansive cybersecurity threats facing the global economy. Dubbed the “Cybersecurity Tech Accord,” the agreement showcases the signatures of more than 30 chief executives from some of […]

The post Microsoft-led industry group pledges to not assist government cyberattacks appeared first on Cyberscoop.

Continue reading Microsoft-led industry group pledges to not assist government cyberattacks

Rex Tillerson proposes new ‘cyber bureau’ at the State Department

Secretary of State Rex Tillerson has a plan to create a new “cyber bureau” within the State Department that would focus on building relationships with foreign governments to coordinate on international cybersecurity priorities, according to a letter sent Tuesday to the chairman of the House Foreign Affairs Committee. The proposition first surfaced publicly during a committee hearing Tuesday on the state of U.S. cyber diplomacy. Former State Department Cybersecurity Coordinator Christopher Painter and former Pentagon cybersecurity adviser Michael Sulmeyer criticized Tillerson for shuttering one such office, which Painter previously oversaw, last year during a myriad other cuts. “The Department of State must be organized to lead diplomatic efforts related to all aspects of cyberspace,” says Tillerson’s letter to committee Chairman Edward Royce, R-Calif. Since Tillerson took the helm, the State Department’s cyber diplomacy mission had been consolidated and wrapped into the Bureau of Economic Affairs’ Office of International Communications and Information Policy. The decision was […]

The post Rex Tillerson proposes new ‘cyber bureau’ at the State Department appeared first on Cyberscoop.

Continue reading Rex Tillerson proposes new ‘cyber bureau’ at the State Department

Experts warn Congress of the return of Chinese IP theft

Hackers working for the Chinese government again appear to be conducting economic espionage against private U.S. companies and other American organizations, experts told lawmakers Tuesday during an open Senate Committee on Foreign Relations hearing. Cybersecurity experts have stated that Chinese cyber espionage operations — hacking activities aimed at stealing trade secrets, intellectual property or other confidential business information — has substantially declined in the wake of an agreement struck between former President Barack Obama and Chinese President Xi Jinping in September 2015. But at least “anecdotally,” there has been a re-emergence of related economic espionage by Chinese hackers aimed at U.S. entities, according to Samantha Ravich, a current senior adviser to D.C.-based think tank the Foundation for Defense of Democracies. Over the last year, the FDD has established a team to study what it defines as “economic warfare.” “It seems there was a dip at first but the anecdotes that are […]

The post Experts warn Congress of the return of Chinese IP theft appeared first on Cyberscoop.

Continue reading Experts warn Congress of the return of Chinese IP theft

Mounting evidence points to North Korean group for global ransomware attack

In the aftermath of a global ransomware attack, which impacted more than 300,000 computers in over 150 countries, a small, select group of security researchers announced they had found evidence suggesting a group previously linked to the North Korean government was likely behind the international cyber incident. Their theory gained new found credibility Monday when U.S. cybersecurity firm Symantec said it too discovered “strong links” between WannaCry ransomware and the so-called Lazarus Group. Researchers originally came across WannaCry in February when it was first found on a Symantec client’s network — a full three months prior to the global outbreak. By obtaining an early sample, analysts were able to comprehensively study and identify individual components within the malware, some of which shared similarities to hacking tools used in late 2014 against Sony Pictures. The attacks against Sony Pictures have been widely attributed to hackers linked to North Korea by both […]

The post Mounting evidence points to North Korean group for global ransomware attack appeared first on Cyberscoop.

Continue reading Mounting evidence points to North Korean group for global ransomware attack