This page has been archived and commenting is disabled.

Report From Russian Cybersecurity Firm Links Israel To Nuclear Talk Spy Virus

Tyler Durden's picture




 

Earlier this year, relations between the US and Israel frayed after Israeli PM Benjamin Netanyahu — in an attempt to rally support for his reelection bid — implied that Arab Israelis shouldn’t vote before suggesting that a two-state solution to the Palestinian ‘issue’ would happen over his dead body. The Obama administration took that as a sign that Netanyahu was not dedicated to peace in the region. 

The tension only grew when reports surfaced that Israel had spied on nuclear talks with Iran. Washington and Jerusalem have long played a kind of spy vs. spy game which both countries generally accept and tolerate, but this time around, Israel apparently passed the intelligence it gathered on to Congress in an attempt to undercut negotiations with Iran, something The White House did not appreciate. Here’s our rather amusing summary: 

The US spied on Israel and discovered that Israel was spying on the US, which under normal circumstances would be fine, but this time the Israeli spying was aimed at undermining US diplomacy, so this spying was unacceptable, but Israel contends that in fact, it did not spy on the US to obtain the sensitive information but in fact gathered it from spying on other countries. 

On Wednesday, new details emerged about espionage and the Iran nuclear negotiations when Moscow-based cybersecurity firm Kaspersky Lab ZAO (more here) released a report detailing how an internal systems breach at the company led to the discovery of hacks at hotels which hosted the P5+1 Iran talks. 

Via Kaspersky Lab:

Earlier this year, during a security sweep, Kaspersky Lab detected a cyber intrusion affecting several of its internal systems.

 

Following this finding, we launched a large-scale investigation, which led to the discovery of a new malware platform from one of the most skilled, mysterious and powerful groups in the APT world – Duqu. The Duqu threat actor went dark in 2012 and was believed to have stopped working on this project - until now. Our technical analysis indicates the new round of attacks include an updated version of the infamous 2011 Duqu malware, sometimes referred to as the step-brother of Stuxnet. We named this new malware and its associated platform “Duqu 2.0”.

 

Victims of Duqu 2.0 have been found in several places, including western countries, the Middle East and Asia. The actor appears to compromise both final and utilitarian targets, which allow them to improve their cyber capabilities.

 

Most notably, some of the new 2014-2015 infections are linked to the P5+1 events and venues related to the negotiations with Iran about a nuclear deal. The threat actor behind Duqu appears to have launched attacks at the venues for some of these high level talks.

 

In addition to the P5+1 events, the Duqu 2.0 group has launched a similar attack in relation to the 70th anniversary event of the liberation of Auschwitz-Birkenau. 

WSJ has more on the Israel connection:

When a cybersecurity firm discovered it had been hacked last year by a virus widely believed to be used by Israeli spies, it wanted to know who else was on the hit list.

 

The spyware, the firm has now concluded, was an improved version of Duqu, a virus first identified by cybersecurity experts in 2011, according to a Kaspersky report and outside security experts...

 

Senior U.S. officials learned Israel was spying on the nuclear talks in 2014, a finding first reported by The Wall Street Journal in March. Officials at the time offered few details about Israel’s tactics...

 

No intelligence-collection effort is a higher priority for Israel’s spy agencies than Iran, including the closed-door talks that have entered a final stage...


Kaspersky, in keeping with its policy, doesn’t identify Israel by name as the country responsible for the hacks. But researchers at the company indicate that they suspect an Israeli connection in subtle ways.

 

For example, the version of the company’s report viewed by the Journal before its release was titled “The Duqu Bet.” Bet is the second letter of the Hebrew alphabet. Kaspersky revised the title in the final version of the report released Wednesday, removing the “Bet” reference.

 

Costin Raiu, director of the global research and analysis team at Kaspersky, said the virus was packed with more than 100 discrete “modules” ...


One module was designed to compress video feeds, possibly from hotel surveillance cameras. Other modules targeted communications, from phones to Wi-Fi networks. The attackers would know who was connected to the infected systems, allowing them to eavesdrop on conversations and steal electronic files.


The virus could also enable them to operate two-way microphones in hotel elevators, computers and alarm systems. In addition, the hackers appeared to penetrate front-desk computers. That could have allowed them to figure out the room numbers of specific delegation members...

 


 

U.S. intelligence agencies view Duqu infections as Israeli spy operations, former U.S. officials said. While the new virus bore no overt links to Israel, it was so complex and borrowed so heavily from Duqu that it “could not have been created by anyone without access to the original Duqu source code,” Kaspersky writes in its report.

 

To check his conclusions, Mr. Raiu a few weeks ago emailed his findings to a friend, Boldizsár Bencsáth, a researcher at Budapest University of Technology and Economics’ Laboratory of Cryptography and System Security. Mr. Bencsáth in 2011 helped discover the original Duqu virus.


“They look extremely similar,” Mr. Bencsáth said in an interview Tuesday. He estimated a team of 10 people would take more than two years to build such a clean copycat, unless they were the original author.

In an interview with RT, Eugene Kaspersky says the sophisticated software would have cost at least $10 million to develop. He also notes that the P5+1 hotels may be just the tip of the iceberg in terms of "top ranking targets":

"There could be different motivations. Of course there is political information, which costs a lot, any other kind of data which is sensitive or very interesting to the attackers. As a software company, we can estimate the investment into a software project. This is a software project. How much did they invest to develop it, to test and to support it? I think it’s at least $10 million, maybe more. Maybe much more, because we still don’t know many victims there are affected around the world. The prevalence of this attack is much wider and has included more top ranking targets from various countries.”

 

(Kaspersky)

Of course no one should be particularly surprised that a state actor may have conducted large scale espionage around an event that has the potential to change the geopolitical landscape in the Middle East and could also impact global energy markets.

The more interesting story here may end up being the fact that Israel has targeted a Russian cybersecurity firm run by a KGB-educated CEO with strong ties to the FSB (Kaspersky reportedly never misses weekly sauna nights with Russian intelligence officers). We're sure there's more to come on the Israel connection especially given that nuclear negotiations with Iran are set to intensify in the coming weeks ahead of a June 30 deadline, but for now, we'll close with what Kaspersky told Bloomberg this year when asked about his loyalty to Vladimir Putin:

“I’m not the right person to talk about Russian realities, because I live in cyberspace,” 

*  *  *

Full Report:

The Mystery of Duqu 2 0 a Sophisticated Cyberespionage Actor Returns

 

- advertisements -

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Thu, 06/11/2015 - 15:22 | 6187396 Deathrips
Deathrips's picture

The truth is Anti Semitic?

No shit?

Faceplant

 

RIPS

Thu, 06/11/2015 - 15:39 | 6187449 0b1knob
0b1knob's picture

The way the Israelis act you would think the threat of a nuclear armed Iran was a matter of life and death to them.

Oh wait....

Thu, 06/11/2015 - 15:43 | 6187463 pods
pods's picture

This is okay because they are our "allies" right?

lol

pods

Thu, 06/11/2015 - 16:37 | 6187729 Anusocracy
Anusocracy's picture

China hired Israel to do this.

There, everything is alright now.

Thu, 06/11/2015 - 16:56 | 6187809 MonetaryApostate
MonetaryApostate's picture

If you were a multi-billionaire, would you get your hands dirty?

Thu, 06/11/2015 - 18:15 | 6188081 Billy the Poet
Billy the Poet's picture

 In addition to the P5+1 events, the Duqu 2.0 group has launched a similar attack in relation to the 70th anniversary event of the liberation of Auschwitz-Birkenau.

 

That's roughly equivalent to picking the pockets of mourners at your grandmother's funeral. Classy.

Thu, 06/11/2015 - 18:37 | 6188138 espirit
espirit's picture

We USSA'd Some Folks.

Thu, 06/11/2015 - 15:52 | 6187483 farflungstar
farflungstar's picture

oy the pain of being the eternal victim, such a burden...with the  chemical and biological WMD, nuclear missiles which can supposedly hit any Arab or European capital...this just means they have to cry ever harder to convince the world they are the victims...oy vey Iran has no nukes but we lie about it

Thu, 06/11/2015 - 19:32 | 6188351 THE 4th Quadrant
THE 4th Quadrant's picture

Theft is the # 1 industry in israel. Theft by deception is their absolute favorite. It cements their notion of superiority.

Thu, 06/11/2015 - 16:44 | 6187763 Consuelo
Consuelo's picture

It's been an 'immediate threat' to them for long about 20 years already.    Funny thing though, the Heebs possess the technological chops to eliminate any threat from Iran - real or perceived, so just what have they been waiting for?   It sure as hell isn't trying to get a gaggle of dumb Goy to 'do-my-dirtywork-scapegoat' for them ---  Nahhhh...

 

 

 

 

Thu, 06/11/2015 - 16:48 | 6187769 TheGreatRecovery
TheGreatRecovery's picture

Is a nuclear armed Israel a life or death threat to Iranians?

And what are Israelis, anyway?  Abraham came from Iraq, right?  Everybody is related.  Everyone has the same genes, just in slightly different combinations.  People are people.

The Kingdom of Heaven is within.  So why not use the limited time each of us has, not at going around saying "I'm more of a victim than you are", but rather at doing helpful things.

Thu, 06/11/2015 - 15:24 | 6187404 CarpetShag
CarpetShag's picture

Yes, very good, but where is John Kerry?

Thu, 06/11/2015 - 15:30 | 6187420 me or you
me or you's picture

He's vanished.  May be dead by now. 

Thu, 06/11/2015 - 15:39 | 6187451 Berspankme
Berspankme's picture

Something about he won the triple crown last weekend..................oops  wrong horse

Thu, 06/11/2015 - 16:49 | 6187783 TheGreatRecovery
TheGreatRecovery's picture

The Russians know.  NATASHA, VICCA, PETRA, TANIA, is John okay?  Love!  Bye.  :-)

Thu, 06/11/2015 - 15:31 | 6187409 JustObserving
JustObserving's picture

If you are surprised then I can sell you Manhattan for a few shiny beads.

America and Israel Created a Monster Computer Virus Threatening Nuclear Reactors Worldwide Even Threatens the International Space Station

In their obsession to stop Iran from developing nuclear weapons, the U.S. and Israel created a computer virus (called “Stuxnet”) to take out Iran’s nuclear reactors.

The virus appears to have spread to other countries.

One of the world’s top computer security experts – Eugene Kaspersky – said this week that the virus has attacked a Russian nuclear reactor.   As The Register notes:

The infamous Stuxnet malware thought to have been developed by the US and Israel to disrupt Iran’s nuclear facilities, also managed to cause chaos at a Russian nuclear plant, according to Eugene Kaspersky.

The revelation came during a Q&A session after a speech at Australia’s National Press Club last week, in which he argued that those spooks responsible for “offensive technologies” don’t realise the unintended consequences of releasing malware into the wild.

“Everything you do is a boomerang,” he added. “It will get back to you.”



http://www.globalresearch.ca/america-and-israel-created-a-monster-comput...

 

Thu, 06/11/2015 - 15:29 | 6187415 decon
decon's picture

If you ain't cheat'n you ain't try'n

Thu, 06/11/2015 - 17:01 | 6187830 Anusocracy
Anusocracy's picture

Well, looks like they're going to have to hold their important meetings in unconnected zero-star hotels in slum areas.

Thu, 06/11/2015 - 15:30 | 6187419 I Write Code
I Write Code's picture

Sounds like good clean fun to me.  So far.  I mean, it's just computer viruses.  So far.

Thu, 06/11/2015 - 18:40 | 6188156 espirit
espirit's picture

I'll give you a +1 for omitting the /sarc tag. 

Thu, 06/11/2015 - 18:51 | 6188193 I Write Code
I Write Code's picture

I mean, what if they snuck in there and short-sheeted the beds and mullahs.

Thu, 06/11/2015 - 15:34 | 6187435 Winston Churchill
Winston Churchill's picture

So kosher bears also shit in the woods.

Thu, 06/11/2015 - 15:51 | 6187500 youngman
youngman's picture

When the USA built a new Embassy in Moscow....it was so filled with bugs..they had to do it over......lol....Russia knows spying...

 

Thu, 06/11/2015 - 16:14 | 6187615 where_is the_nuke
where_is the_nuke's picture

Israel, a nation built on lies, spying, stealing, genocide etc. etc.....

Thu, 06/11/2015 - 16:17 | 6187628 DutchBoy2015
DutchBoy2015's picture

Ask any Jew why Jews are so hated throughout history and watch him run like hell.

Lying, thieving, exploiting and deception is built into their DNA. thats why

 

Thu, 06/11/2015 - 17:03 | 6187838 where_is the_nuke
where_is the_nuke's picture

You are wrong.

Thu, 06/11/2015 - 16:22 | 6187650 44magnum
44magnum's picture

So of course we MUST trust what they tell us?

Thu, 06/11/2015 - 18:33 | 6188058 Jorgen
Jorgen's picture

"Israel, a nation built on lies, spying, stealing, genocide etc. etc....."

(Just being the devil's advocate) Most of the New World countries were built in the same way, so unless you are a native of Andorra, Monaco, Luxembourg or San Marino, it may be refuted as pot calling the kettle black...

Thu, 06/11/2015 - 16:19 | 6187637 DutchBoy2015
DutchBoy2015's picture

The nuclear shit is just a smoke screen.  Its all about regime change in Iran for the KIKE roaches of Israel.   And installation of another Rothschild central bank.

 

Thu, 06/11/2015 - 19:40 | 6188365 THE 4th Quadrant
THE 4th Quadrant's picture

The USSA goy shitcock tax donkey's get to pay for the CONflict. lol.

Thu, 06/11/2015 - 16:38 | 6187734 Grouchy Marx
Grouchy Marx's picture

I don't see this as news. All countries conduct cyber-espionage.

Much ado about not much. 

Thu, 06/11/2015 - 16:47 | 6187773 Bob
Bob's picture

Interesting that Kaspersky himself got hacked and it took so long for him to catch on. 

If I were in Russian IT, I can imagine exactly how pissed off I would be. 

Thu, 06/11/2015 - 16:54 | 6187800 Grouchy Marx
Grouchy Marx's picture

Cyber security is an oxymoron anyway. Hardware and software is all full of back doors and gaping holes.

Thu, 06/11/2015 - 17:20 | 6187910 goldhedge
goldhedge's picture

Those Sneaky fuckers again.

Thu, 06/11/2015 - 19:27 | 6188333 Fun Facts
Fun Facts's picture

"by way of deception thou shalt do war"

- Mossad Motto

Thu, 06/11/2015 - 17:23 | 6187921 The Delicate Genius
The Delicate Genius's picture

Given that Netanyahu has spent twenty years "crying wolf" regarding an Iranian bomb being potentially months away - all as Israel built longer range missiles and backpack nukes, and continued to bulldoze Arab homes, even entire villages -

Seems like the nuclear issue is a ruse.

At no point were inspections of Israeli facilities, in some kind of quid pro quo, ever on the table. Agreements to make the ME nuke free also won't fly because Israel insists on its nukes.

The typical American view is that Israel has the right to defend itself, inand of itself a facially sensible claim - but curiously, that's where it ends.

At no point is the right of Palestinians or Iranians to defend themselves from Israel {or the US} even brought up as a topic.

Hence the entire conversation is skewed, in an Israel-centric militarist bubble.

Israel has also sought, repeatedly to move the goalposts as talks were coming close to resolution. The "just one more thing" tactic often done with the PLO. No country is going to agree to let Israel's spies entry into any and all military facilities upon request merely to be able to do what they have the absolute right to do under the NPT.

When Israel talks about allowing inspections, we may presume they are serious about being worried Iran might one day decide to build a small bomb.

the additional aspect is the absurd idea Iran would build a bomb and use it. Here, the narrative relies on Iranian mullahs being irrational, while the Jewish State is per se rational.

This is absolutely nothing more than racism, and given the beliefs of the Orthodox/Hasidim, the United States and Europe should be far more worried about Israel's arsenals than the outside chance Iran may one day decide to pursue a bomb or two to defend itself from regime change or bombing - by the US or Israel.

Thu, 06/11/2015 - 17:31 | 6187938 asfffasfff
asfffasfff's picture

the first virus jews created is judaism  the second, much more dangerous is the talmud.

 

the virus is like aids   there is no cure and it spread and mutates

its fruts are christianity and islam

and they mutate too

evangelism katholizism orthodoxsim

sunnitism shiainism

AND MUTATES EVEN FURTHER

KOMMUNISM      and yes FASCISM NATIONALISM (its a copy of parts of the talmud but without god)

 

banking system is created by who? 

 

can anyone stop this virus? in all of its forms

Thu, 06/11/2015 - 19:14 | 6188285 kchrisc
kchrisc's picture

At least the devils weren't "dancing" this time.

Liberty is a demand. Tyranny is submission..

Thu, 06/11/2015 - 22:41 | 6188818 falconflight
falconflight's picture

Israel has every right to spy on US negotiations with the Ayatollahs.  Just like the US spies on the entire fucking world?  Fucking weak ZH ass koshered hypocrites.   I hope the story is true, but it does read like a PutinHasbara TMZ tickler.  

Fri, 06/12/2015 - 01:44 | 6189171 onmail
onmail's picture

Jewhad

Fri, 06/12/2015 - 05:57 | 6189355 Allen_H
Allen_H's picture

Could somebody please kill Satanyahoo and then proceed to destry izraHELL, fuck it's been long enough.

Do NOT follow this link or you will be banned from the site!