How foreign governments spy using PowerPoint and Twitter
washingtonpost.com
washingtonpost.com
PowerPoint is often introduced into an organization by highly sophisticated threat actors using deeply customized versions of the software. McKinsey, BCG, and Bain deploy the PowerPoint malware to a multiplicity of customers whose human capital and infrastructure become mired in endless recursive loops known as PowerPoint cycles.
The actual introduction of PowerPoint is typically merely incidental to these threat actors ambitions. Most often they derive substantial portions of their income by reselling organizations intellectual property which they already own.
Once the organizations systems become bogged in ever more bloated PowerPoint files productivity plummets. Morale drops among employees and management often re-engages the threat actors to attempt to right the ship.
The PowerPoint Malware is seemingly unstoppable at this point. Any computers that contain it should be air gapped and protected by highly restricted physical access.
Given I'm not American, so the US government is "foreign" to me.
Have you asked the people of Libya, Iraq and Syria what their world would be like without the USA?
Bullshit defense. There has never been a period in history with fewer wars and proportionally lower fatality rates due to violence. The existence of war at all does not somehow invalidate the value of American hegemony.
How long is your time frame? Many more people have died after Sep. 2001 than in the decades prior.
> The existence of war at all does not somehow invalidate the value of American hegemony.
What you seem to forget or don't realize is that the wars of the last decade are a direct result of what we're doing to maintain that American hegemony. So while it's been good for you because you're watching the wars on TV and reading it on the Internet, it's been very bad for those on whose land the wars are being fought.
That just isn't true at all[1]. Since the end of the Second Congo War[3] (in 2003) there hasn't been a conflict that's come close to 1MM causalities.
While the Iraq, Afghan and Syrian wars have been brutal and very well publicised they haven't been anywhere near as severe in terms of causalities.
(Don't take this as a comment either way on US policies though)
[1] https://en.wikipedia.org/wiki/File:List_of_wars_by_death_tol...
[2] http://www.smithsonianmag.com/smart-news/globally-deaths-war...
The US has big issues and internal ideological conflicts and many inconsistencies, for sure. But, if you randomly sample the population you'll find that most of us want peace, freedom, success and happiness for everyone.
It's a shame that doesn't come across in US foreign and economic policies.
Once upon a time, the British Empire took it upon itself to civilize the uncivilized world, bringing heavy-handed order in many faraway 'nasty, brutish' places for queen and country. The sun has since set on the British Empire, and yet the world is doing just fine. Empires rise and they fall all the time.
Sure, we're not jailing Twitter dissidents, but do you know what we do to whistleblowers? One of our whistleblowers has been forced to take up residence in Russia.
Of course we're not sniping protesters from rooftops, but our friends do it when we egg them on to further our interests in foreign lands.
> They aren't destroying the credit ratings of political dissenters.
You should probably listen to this talk.
https://media.ccc.de/v/32c3-7443-the_price_of_dissent
While it's primarily about the UK, the USGOV is defiantly involved.
(note: I trust that this crowd is mature enough to not let Applebaum's introduction taint the important message by the actual speakers)
It's not benevolent, that's pure propaganda at work. It's a nation that acts in its own interests like any other. It just disguises them extremely well.
Only killing people on the other side of the world with drones. And if the wrong people are killed, well, 'shit happens', let's just call those dead innocents 'collateral damage'.
> There are times I wish the US would disengage from the world so humanity can be reminded of what its like to live without a generally benevolent hegemonic power.
You should be made aware that the US isn't being a 'generally benevolent hegemonic power' out of the goodness of it's heart. It's doing so to protect its political and economic interests.
By all means, elect Trump, and secede back into isolationism. It's going to suck for you as well, as all that economic power you get from sweetheart deals from your military projection? It's going to fade away. As for foreign aid, US foreign aid is, per capita, well below that of other western democracies.
It's always amusing when USians pretend like they're doing the world an altruistic favour by being 'world cop', when in reality they get plenty of kickbacks. Ask yourself this: if the US was really the 'altruistic world cop', then why does it ignore so many trouble spots?
C'mon, aim higher. You're supposed to be in the big leagues now, compare yourself to developed countries if you want to see how well the USGOV is doing.
How is this even possible? I have always considered phones to be more secure then PC due to additional security measures (such as sandboxing for every app as well as more fine granted permission systems).
I'm aware that malware can be installed on a phone but I always though I was required to explicitly allow that (at least on android) and I thought it was impossible on iOS without jail breaking.
Or does this app use some zero days, that have been discovered years ago but have not been patched because of androids broken update policy?
More information on how this works would be highly appreciated.
* No root access required
* Bind the DroidJack server APK with any other game or app
Sounds like its delivered using an 'innocent' game or app in the Play store. Convincing someone to install a random Play app isn't that tough. Send them a powerpoint and leave a link to an 'innocent' Powerpoint Viewer. Voila! You have Droidjack.
If social engineering doesn't work you can bribe or compel someone close to the person you're monitoring to borrow his/her phone and have them install the infected Play store item. Or get pulled over by a cop or intelligence agent, who takes your phone for one moment and installs it behind your back. Non-technical people may not even think this suspicious.
http://www.symantec.com/connect/blogs/droidjack-rat-tale-how...
Zero Day Exploits are frequently unpatched unless you have a Nexus phone for Android or an iOS device. :/
and/or
https://www.usenix.org/system/files/conference/woot12/woot12...
> We have demonstrated that memory corruptions in baseband firmwares exist and can be practically exploited. These security problems are to be taken seriously: practical exploitation of these completely compromises the integrity of the attacked handset. Merely coming into the proximity of a malicious base station is is sufficient to take over any vulnerable handset – no user interaction is required by the bugs we have outlined above. The cost of exploitation is low enough to make these attacks a reality even for attackers with a limited budget: for the price of a mid-range laptop – USD 1500 – an attacker can buy the hardware to operate a malicious GSM cell with OpenBTS.
User interaction isn't even really required, just a rogue base station + a vulnerable baseband (and those are updated even less frequently, iirc, Apple and the Nexus line are the only ones that update those)
https://developer.android.com/about/dashboards/index.html
Only 13.3% are up to date :/
As far as I can tell, you can package this software with any legitimate game or application. Mix in some social engineering and spear phishing, and it wouldn't take much effort to get this installed either on a targeted victim, or a large number of random victims.
I'm trying to remember where I saw it, but there was a journalist who showed over the past year how much food 1000 bolivars bought. At the beginning of the photo essay, she could have fed a family for a week. By the end, it was barely enough for 1 person for a meal.
Anyone can really help out and make a difference too. Not just in LATAM, but around the world. The amount of knowledge about cybersecurity, threat models, and risks associated with electronic communications spans a wide range. Of course you have civil society groups who know how to use PGP, but there are others who still rely on Facebook Messenger to communicate with sources and keep passwords sticky noted to their computer screen.
Edit: Also wanted to note that it's pretty great what Citizen Labs is doing. Other great resources for learning/teaching/staying updated ( in both English and Spanish and several others) can be found on the EFF's website - https://ssd.eff.org/en/playlist/journalist-move
[0]: http://www.symantec.com/connect/blogs/droidjack-rat-tale-how...
[1] https://citizenlab.org/2016/08/group5-syria/
[2] https://citizenlab.org/2016/08/group5-syria/#part4
Good old fake Flash update. But still relies on user to be installed, so nothing sophisticated or "Android is bad" here.
If anything the Powerpoint malware looks interesting. The .ppsx extension kinda gives it away, since it's unusual for casual presentations, but that's hard to spot for Joe User.
Besides, there are loads of legitimate reasons to, there's a reason Humble Bundles aren't a thing on iOS.
The person who decides to explicitly opt in to allowing side-loading. Just don't allow apps, web pages, etc etc to opt-in for you to ensure the technically non-adept have a difficult time getting themselves into trouble.
But yes, android is a bit more "wild west"/less curated so that plus the fragmentation/lack of good update channels leads to lots of attack vectors.
From what I've read and seen, those virus scanners are of little help, mainly because they are subject to the same sandbox restrictions as all the other apps (and aren't going to break the sandbox like the viruses). Most of them appear to be as good as those "Android cleanup" apps that do nothing but constantly clear caches (meaning they will be rebuilt unnecessarily) and bother the user with notifications and adverts.
Yes it's possible to escape from a VM, but it's significantly harder to code executable malware that will escape from, for example, a Windows 10 VM running inside Virtualbox on an XUbuntu/XFCE4 host laptop.
I wonder what kind of programmer works for companies that produce this spyware...
i.e. only sold to friendly oppressive regimes? :(
This is why Schneier is calling it "surveillance as a business model":
https://www.schneier.com/blog/archives/2013/11/surveillance_...
no offense intended, but ...
Nicolas Sarkozy saw Libya as his chance to top what Bush did in Iraq.
I think you have a mix of ideas:
"I'm the best at what I do and I deserve to be rewarded for that, particularly when vulnerabilities are so valuable today."
(and for some) "If other people aren't smart enough, they deserve to be exploited."
(and for some) "The governments I work for* are the good guys and their targets are the bad guys."
I've said before that people reading these threads on HN have a chance to influence culture to make these ideas less appealing to people.
* particularly for people who work full time for a single government agency or military service, or for companies that have a list of which governments they will and won't sell to
One that likes high salary and hefty bonuses. Being mixed with the security services gives you great access to otherwise unobtainable information and connections. You may be a lowly codemonkey, but talk with government agencies heads. And they will listen. And emitting cloak and dagger vibe definitely helps in the dating scene.
Googling around there's several similar tools available on GitHub... so I guess the answer to your question is lots of people would do it mostly for fun. Definitely sounds more interesting than the stuff I work on most days. And you're not even really involved in the exploitation, just the post-exploitation control.
From the article:
> In May 2016, we uncovered a Twitter-based digital malware campaign seemingly orchestrated by the United Arab Emirates, which resulted in the arrest and torture of numerous activists and journalists there.
https://www.fireeye.com/blog/threat-research/2015/07/hammert...
PDF has more details here: https://www2.fireeye.com/APT29-HAMMERTOSS-WEB-2015-RPT.html