Kaspersky’s findings: Spy Virus Linked to Israel Targeted Hotels Used for Iran Nuclear Talks

Status
Not open for further replies.

Dima007

Level 23
Thread author
Verified
Well-known
Apr 24, 2013
1,200
When a cybersecurity firm discovered it had been hacked last year by a virus widely believed to be used by Israeli spies, it wanted to know who else was on the hit list.

The Moscow-based firm, Kaspersky Lab ZAO, checked millions of computers world-wide and three luxury European hotels popped up. The other hotels tested—thousands in all—were clean. Researchers at the firm weren’t sure what to make of the results. Then they realized what the three hotels had in common.

Each was infiltrated by the virus before hosting high-stakes negotiations between Iran and world powers over curtailing Tehran’s nuclear program.

The spyware, the firm has now concluded, was an improved version of Duqu, a virus first identified by cybersecurity experts in 2011, according to a Kaspersky report and outside security experts. Current and former U.S. officials and many cybersecurity experts say they believe Duqu was designed to carry out Israel’s most sensitive intelligence collection.

Senior U.S. officials learned Israel was spying on the nuclear talks in 2014, a finding first reported by The Wall Street Journal in March. Officials at the time offered few details about Israel’s tactics.

BN-IV736_ISIRAN_P_20150609225219.jpg


Kaspersky’s findings, disclosed publicly in a report on Wednesday, shed new light on the use of a stealthy virus in the spying efforts. The revelations also could provide what may be the first concrete evidence that the nuclear negotiations were targeted and by whom.

Israeli officials have denied spying on the U.S. or other allies, although they acknowledge conducting close surveillance on Iranians generally. Israeli officials declined to comment specifically on the allegations relating to the Duqu virus and the hotel intrusions.

But no intelligence-collection effort is a higher priority for Israel’s spy agencies than Iran, including the closed-door talks that have entered a final stage. Israeli leaders say the emerging deal could allow Iran to continue working toward building nuclear weapons, something Iran denies it is trying to do.

Kaspersky, in keeping with its policy, doesn’t identify Israel by name as the country responsible for the hacks. But researchers at the company indicate that they suspect an Israeli connection in subtle ways.

For example, the version of the company’s report viewed by the Journal before its release was titled “The Duqu Bet.” Bet is the second letter of the Hebrew alphabet. Kaspersky revised the title in the final version of the report released Wednesday, removing the “Bet” reference.

Kaspersky researchers acknowledge that many questions remain unanswered about how the virus was used and what information may have been stolen.

Costin Raiu, director of the global research and analysis team at Kaspersky, said the virus was packed with more than 100 discrete “modules” that would have enabled the attackers to commandeer infected computers.

One module was designed to compress video feeds, possibly from hotel surveillance cameras. Other modules targeted communications, from phones to Wi-Fi networks. The attackers would know who was connected to the infected systems, allowing them to eavesdrop on conversations and steal electronic files.

The virus could also enable them to operate two-way microphones in hotel elevators, computers and alarm systems. In addition, the hackers appeared to penetrate front-desk computers. That could have allowed them to figure out the room numbers of specific delegation members.

The virus also automatically deposited smaller reconnaissance files on the computers it passed through, ensuring the attackers can monitor them and exploit the contents of those computers at a later date.

The Federal Bureau of Investigation is reviewing the Kaspersky analysis and hasn’t independently confirmed the firm’s conclusions, according to people familiar with the discussions. U.S. officials, though, said they weren’t surprised to learn about the reported intrusions at the hotels used for the nuclear talks and took the findings seriously.

Read more: http://www.wsj.com/articles/spy-vir...hotels-used-for-iran-nuclear-talks-1433937601
 

Venustus

Level 59
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
When a cybersecurity firm discovered it had been hacked last year by a virus widely believed to be used by Israeli spies, it wanted to know who else was on the hit list.

The Moscow-based firm, Kaspersky Lab ZAO, checked millions of computers world-wide and three luxury European hotels popped up. The other hotels tested—thousands in all—were clean. Researchers at the firm weren’t sure what to make of the results. Then they realized what the three hotels had in common.

Each was infiltrated by the virus before hosting high-stakes negotiations between Iran and world powers over curtailing Tehran’s nuclear program.

The spyware, the firm has now concluded, was an improved version of Duqu, a virus first identified by cybersecurity experts in 2011, according to a Kaspersky report and outside security experts. Current and former U.S. officials and many cybersecurity experts say they believe Duqu was designed to carry out Israel’s most sensitive intelligence collection.

Senior U.S. officials learned Israel was spying on the nuclear talks in 2014, a finding first reported by The Wall Street Journal in March. Officials at the time offered few details about Israel’s tactics.

BN-IV736_ISIRAN_P_20150609225219.jpg


Kaspersky’s findings, disclosed publicly in a report on Wednesday, shed new light on the use of a stealthy virus in the spying efforts. The revelations also could provide what may be the first concrete evidence that the nuclear negotiations were targeted and by whom.

Israeli officials have denied spying on the U.S. or other allies, although they acknowledge conducting close surveillance on Iranians generally. Israeli officials declined to comment specifically on the allegations relating to the Duqu virus and the hotel intrusions.

But no intelligence-collection effort is a higher priority for Israel’s spy agencies than Iran, including the closed-door talks that have entered a final stage. Israeli leaders say the emerging deal could allow Iran to continue working toward building nuclear weapons, something Iran denies it is trying to do.

Kaspersky, in keeping with its policy, doesn’t identify Israel by name as the country responsible for the hacks. But researchers at the company indicate that they suspect an Israeli connection in subtle ways.

For example, the version of the company’s report viewed by the Journal before its release was titled “The Duqu Bet.” Bet is the second letter of the Hebrew alphabet. Kaspersky revised the title in the final version of the report released Wednesday, removing the “Bet” reference.

Kaspersky researchers acknowledge that many questions remain unanswered about how the virus was used and what information may have been stolen.

Costin Raiu, director of the global research and analysis team at Kaspersky, said the virus was packed with more than 100 discrete “modules” that would have enabled the attackers to commandeer infected computers.

One module was designed to compress video feeds, possibly from hotel surveillance cameras. Other modules targeted communications, from phones to Wi-Fi networks. The attackers would know who was connected to the infected systems, allowing them to eavesdrop on conversations and steal electronic files.

The virus could also enable them to operate two-way microphones in hotel elevators, computers and alarm systems. In addition, the hackers appeared to penetrate front-desk computers. That could have allowed them to figure out the room numbers of specific delegation members.

The virus also automatically deposited smaller reconnaissance files on the computers it passed through, ensuring the attackers can monitor them and exploit the contents of those computers at a later date.

The Federal Bureau of Investigation is reviewing the Kaspersky analysis and hasn’t independently confirmed the firm’s conclusions, according to people familiar with the discussions. U.S. officials, though, said they weren’t surprised to learn about the reported intrusions at the hotels used for the nuclear talks and took the findings seriously.

Read more: http://www.wsj.com/articles/spy-vir...hotels-used-for-iran-nuclear-talks-1433937601
Not surprised as they were also the ones, along with the US government implicated in the infamous Stuxnet worm!!;):)
 

comfortablynumb15

Level 7
Verified
May 11, 2015
326
And I fully support Israel doing it. Leaving be the debate over territory, Israel is in a hell of a precarious position out there. They literally have no allies there and are surrounded by nations that would rather see them gone. Iran is their number 1 threat, and the U.S is too hung up on a peace deal that would never be honored to give them the support they really need. Israel, very rightfully so, is no longer in a trusting mood as every time they do, it comes back to bite them. The U.S has done the same kind of spying, plenty of times.
 

ifacedown

Level 18
Verified
Jan 31, 2014
888
Let me be religious: Israel is God's chosen nation since the Old Testament. God specifically protects this nation against dangers from the other world. He has also blessed Israel with wisdom that it has many scientists and inventors.

History reveals itself that God has protected them time to time. Just have a read on the popular 6-Day War on how Israel defeated many surrounding Arab nations. They were heavily outnumbered but still won with God's help.
 

comfortablynumb15

Level 7
Verified
May 11, 2015
326
The mods are very tolerating and good about letting us have pretty free discussion, but I'm not too sure religion can work. It's just way too much of a hot button topic. I'm not at all saying shut up or trying to get you shut up, every one of us can believe what we darn well please, regardless of the insults or heat that comes our way. I was strictly speaking from a political survival perspective. Israel can take better care of itself than most realize, they indeed are survivors. But they are still always in serious danger, so using these spy methods is very much understandable.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top