Regin: Nation-state ownage of GSM networks
securelist.com
securelist.com
This seems to be a very old mode: I have trouble finding references to it with less than 20 years. This mode is in [1, pg. 151] and [2, pg. 77], as far as I can find, both of which were published in 1982. [2] also introduced ciphertext stealing, albeit a bugged version [3, §6].
[1] http://faculty.nps.edu/dedennin/publications/Denning-Cryptog...
[2] http://www.amazon.com/Cryptography-Dimension-Computer-Securi... [sorry, no PDF link]
Do BSC/BTS typically have IP-accessible configuration ?
Regardless of how they connected (I thought SS7 ...) wouldn't there be a login to access the switch BSC controls ... how would the malware have that ?
I don't understand how the malware running on the windows system executed the commands on the BSC.
[1]: http://www.academia.edu/6018279/Oss_commands_-_Win_Fiol
If you're a mobile network operator, you use microsoft windows to access and administer the base stations out in the field.
Pray tell: how important or sensitive does something have to be before someone finally asks "hmm ... maybe we shouldn't use microsoft windows for this" ?
It doesn't change much because the base station software probably has more security bugs than Windows.
I didn't know about that relation for "willischeck", but since both NSA and GCHQ have used this, while I don't recognise those covernames, I'm guessing therefore those may well be Cheltenham's, whereas U_STARBUCKS (UNITEDSTARBUCKS?) is probably Fort Meade's.
Newbies need a reminder about meaningless covernames. :-)
Someone's boss is gonna be peeved! (Also, this would be a good indicator of a native English speaker developing the software; I doubt most developers put curse words into their code in a non-native language)
I don't find the GSM attacks unusual or interesting. Sure, it might be new for an Internet worm, but government-sponsored orgs have been pushing attacks on infrastructure like GSM networks since the L0pht days (though back then I think satellites were more in vogue), and they're constantly looking for new ways to infiltrate foreign networks of any type. This just shows someone's pet research project from a decade ago made it out of the lab.
It's also interesting to note that while this is useful for nation-states, they're not necessarily developed directly by a nation-state, and there could be multiple organizations using the same malware package. One way to see multiple independent actors using the same package would be to look for different cryptographic keys, C&C servers, and discrete distributed victim-networks.
GCHQ have definitely used it, I know that much.
I see nothing that looks Israeli to me in this one? Are you thinking about Myrtus?