Tampilkan postingan dengan label counterespionage. Tampilkan semua postingan
Tampilkan postingan dengan label counterespionage. Tampilkan semua postingan

Sabtu, 18 Februari 2012

COMSEC AUDIO JAMMER APP for iPHONE


itunes.apple.com

COMSEC AUDIO JAMMER

Keep your private conversations private!

The COMSEC AUDIO JAMMER protects your sensitive room conversations by generating a random masking sound, which desensitizes any near-by microphone. Effective against any microphone based eavesdropping device including tape recorders, RF transmitters, hard-wired microphones (including contact type) and shotgun microphones. It also protects against microwave or laser reflection pickups (when used correctly).
COMSEC AUDIO JAMMER uses specially designed audio speech patterns to mask your conversations from hidden microphones & eavesdroppers.
The speech patterns are randomly designed and generated to mask normal conversations from eavesdroppers. 


More...get the app here.

Minggu, 29 Januari 2012

DARPA-Funded Hacker's Tiny $50 Spy Computer Hides In Offices, Drops From Drones

forbes.com


Even more embarrassing than a student discovering your GPS tracking device on his car, as the FBI found out last year, is having to ask him to give the expensive piece of equipment back.
So security researcher Brendan O’Connor is trying a different approach to spy hardware: building a sensor-equipped surveillance-capable computer that’s so cheap it can be sacrificed after one use, with off-the-shelf parts that anyone can buy and assemble for less than fifty dollars.
At the Shmoocon security conference Friday in Washington D.C., O’Connor plans to present the F-BOMB, or Falling or Ballistically-launched Object that Makes Backdoors. Built from just the hardware in a commercially-available PogoPlug mini-computer, a few tiny antennae, eight gigabytes of flash memory and some 3D-printed plastic casing, the F-BOMB serves as 3.5 by 4 by 1 inch spy computer. And O’Connor has designed the cheap gadgets to dropped from a drone, plugged inconspicuously into a wall socket, thrown over a barrier, or otherwise put into irretrievable positions to quietly collect data and send it back to the owner over any available Wifi network. With PogoPlugs currently on sale at Amazon for $25, O’Connor built his prototypes with gear that added up to just $46 each.
“If some target is surrounded by bad men with guns, you don’t want to have to retrieve this, but you also don’t want to have to pay four or five hundred dollars for every use,” says O’Connor. “The idea is that it’s as close to free as possible. So you can throw a bunch of these sensors at a target and get away with losing a couple nodes in the process.”

Sabtu, 21 Januari 2012

Alleged spy fed false info in sting to hurt credibility

vancouversun.com

Authorities fed an alleged Canadian naval spy fabricated information as part of a classic "sour milk" counter-intelligence ploy to taint the credibility of secrets the man is suspected of passing to Russia, Postmedia has learned.
"This was done by the book - sour the milk so that you con-fuse the other side," Michel Juneau-Katsuya, a former spy service counter-intelligence officer with sources close to the Halifax case, revealed in an interview Friday.
Once naval officials suspected there was a spy in their midst, deliberately flawed information was baited and designed to eventually be discovered by its foreign recipients, casting doubt on the usefulness of any other classified data related to the case.
Juneau-Katsuya said the deception is believed to have worked, and now "they don't know what is true and what is not [and] will have to be suspicious of pretty much everything [given to] them."
While military and RCMP investigators are still gathering details, Juneau-Katsuya said he believes Russia may have been after North Atlantic Treaty Organization [NATO] secrets.
"When you talk about Halifax, you talk about the Atlantic and the Arctic. And when you talk about the Atlantic and Arctic, you talk NATO. And when you talk NATO, you talk Russia," he said.

Selasa, 03 Januari 2012

VoIP eavesdropping: Hardening network security to contain VoIP risks

searchsecurity.techtarget.com

Every organization considering a Voice over Internet Protocol (VoIP) telephone system deployment hears the same dire warnings: “Routing voice calls over a data network exposes calls to eavesdropping.”

While it’s certainly true that any telephone call carries a certain degree of eavesdropping risk, is it true that VoIP calls have an inherently higher degree of risk? In this tip, we explore the ins and outs of VoIP eavesdropping.

VoIP eavesdropping is possible First, it’s important to be clear about one thing: It is absolutely possible to eavesdrop on a VoIP telephone call. It’s also possible to eavesdrop on a telephone call placed using the traditional public switched telephone network (PSTN). The difference lies in the tools and skill set needed to conduct the eavesdropping.

On a traditional telephone network, someone seeking to eavesdrop on a call generally must have physical access to either the telephone or telephone cable, at least at the initiation of the attack. This type of attack is typical in the movies. Whether it’s the good guys or the bad guys conducting the eavesdropping, someone gains access to either a telephone handset or the telephone network interface box -- sometimes located outside a home or office -- places a wiretap listening device on the box, and then monitors calls on an ongoing basis.


More...

Minggu, 01 Januari 2012

Anonymous exposes 75,000 credit card numbers

washingtonpost.com

Hacker collective Anonymous has just dumped 200 GB of names, email addresses and passwords for around 860,000 Stratfor users. Anonymous also exposed credit card numbers for 75,000 paying customers of Stratfor.

Stratfor, a security think tank, provides reports on international security and related threats to government and military personnel as well as to the private sector. It is unknown whether Anonymous gained access to other, more sensitive information during the Stratfor hacks, which occurred on December 24.

“The time for talk is over,” wrote Anonymous last night on Pastebin.

“It’s time to dump the full 75,000 names, addresses, CCs and md5 hashed passwords to every customer that has ever paid Stratfor. But that’s not all: we’re also dumping ~860,000 usernames, email addresses, and md5 hashed passwords for everyone who’s ever registered on Stratfor’s site… Did you notice 50,000 of these email addresses are .mil and .gov?”

Anonymous’ motives for the attack are also somewhat hazy. In last night’s statement, representatives of the movement wrote, “All our lives we have been robbed blindly and brutalized by corrupted politicians, establishmentarians and government agencies sex shops, and now it’s time to take it back.”

In addition to the Stratfor attack and exposure, Anonymous is threatening a new action on New Year’s Eve, December 31.

More...

Rabu, 21 Desember 2011

Chinese hackers hit Boston Scientific

massdevice.com
Boston Scientific is one of 760 firms hit by China-based cyber attacks.
Med-tech titan Boston Scientific (NYSE:BSX) was one of 760 companies hit by Chinese cyber attacks that also targeted U.S. government agencies, research universities and Internet providers.
It's not clear whether the Natick, Mass.-based medical device maker lost any sensitive information in the attack.
"We're talking about stealing entire industries," Scott Borg, director of the U.S. Cyber Consequences Unit, told the news service. "This may be the biggest transfer of wealth in a short period of time that the world has ever seen."
The attacks were aimed at the medical device, biotechnology, clean energy, advanced semiconductor, high-end manufacturing and information technology industries, according toBloomberg
Along with BSX, Abbott Laboratories (NYSE:ABT) and pharmaceutical giant Pfizer's (NYSE:PFE) Wyeth subsidiary were victims. The Chinese government is denying responsibility for the attacks.
The cyber-warfare is just the latest item in a string of bad luck for Boston Scientific, which got hit with a half-billion-dollar tax bill from the U.S. Internal Revenue Service last week.
The latest tab, for $581 million plus interest and penalties, comes out of an IRS audit of Boston Scientific's 2006 acquisition of pacemaker firm Guidant Corp.

Selasa, 22 November 2011

Compliance vs. Security: The Multiple Dimensions of Corporate Espionage

sys-con.com

You've spent months fixing the red items on an internal audit report and just passed a regulatory exam. You've performed a network vulnerability assessment and network pen test within the last year and have fixes in place. You've tightened up your information security policy and recently invested in a security information and event management (SIEM) solution. You're secure, right?
Put yourself in the shoes of a criminal. He knows that most security programs focus on regulatory compliance. He knows that IT departments have limited budgets. He also knows that you must defend against an almost unlimited number of attack vectors, while he just has to find one way in.
How do you protect against a sophisticated, motivated criminal? A professional spy who has targeted your company's trade secrets? A skilled insider with a specific purpose in mind? These types of people know that information comes in many forms, not just electronic, and they are trained to exploit any vulnerability. An effective information security program must incorporate more than just traditional pen tests and vulnerability assessments. 

Corporate espionage is on the rise for multiple reasons: the down economy, frequent job changes, and even governments that boost their economies through acquisition of trade secrets. In most cases, the end product is not as valuable as obtaining the means of production, the research and development, or the "know-how." This type of information will help to cut down on development costs and aid in the long-term production of a particular good. In the end, a company must get the best product to market first, at the best cost, through maneuvering around the competition.


Kamis, 03 November 2011

SpearTip Announces Strategic Alliance With ComSec


St. Louis, Missouri (PRWEB) November 03, 2011
SpearTip, LLC CEO Jarrett Kolthoff announced that SpearTip has formed a strategic alliance with ComSec, LLC, of Virginia Beach, VA, which provides professional technical surveillance counter measure (TSCM) services nationwide. ComSec’s expertise includes electronic eavesdropping detection, bug sweeps, counterespionage consulting, counter surveillance, cyber TSCM, and anti-surveillance services for businesses and individuals.
Kolthoff said the alliance continues SpearTip’s geographic growth to the eastern seaboard as well as adding skill sets and technical capabilities to SpearTip’s existing cyber counterespionage arsenal.
ComSec is headed by CEO/President J.D. LeaSure, a countersurveillance practitioner in defense and industrial sectors since 1984. LeaSure has extensive training, knowledge, and experience covering eavesdropping devices, detection methods and other surveillance tactics employed by those seeking to steal information. The SpearTip alliance expands ComSec’s capabilities in cyber counterespionage and computer forensics.
“We believe this combination of talents and expertise will strengthen the unique service SpearTip offers clients,” Kolthoff said. “We are able to offer the broadest range of countersurveillance protection of anyone in the industry.”  

Rabu, 02 November 2011

DC convention helps governments spy on citizens

rt.com


Representatives from governments across the globe gathered in Washington DC last month, but it wasn’t international affairs that they were there to discuss.

The meeting, rather, was an annual conference where figureheads far and wide come together to discuss the latest and greatest ways to spy on their own citizens.

At this year’s Intelligence Support Systems (ISS) World Americas conference, the only consumers were the governments of great nations far and wide who came together in DC last month to go over the newest achievements in “lawful interception” methods, reveals an article published this week in the UK’s Guardian. According to their filing, international figureheads came together on American soil to find the freshest ways to carry out clandestine surveillance on their own citizens back home by hacking smart phones, laptops and anything else with a circuit.

The actual roster from this year’s guest list is kept top-secret, much like the information inside the exclusive DC conference room, but past reports suggest it reads like a who’s who of foreign nations. In 2008, for examples, the Spanish biometrics company Agnito said they were proud to be a participant in that year’s conference, which it describes on their website as a meeting-place that focuses on Intelligence Gathering. As the worldwide leader in voice biometrics, Agnito’s list of clients includes the Spanish Ministry of Defense, the national police of France, the prosecutor’s office of South Korea and some of the biggest banks in Spain. Don’t let that list of “friendly” nations let you think that nothing is amiss here, however. In The Guardian’s article, Jerry Lucas, president of TeleStrategies, says that the manufacturers of surveillance technologies are free to pitch products to any nation they want.

"The surveillance that we display in our conferences, and discuss how to use, is available to any country in the world,"Lucas tells The Guardian. "Do some countries use this technology to suppress political statements? Yes, I would say that's probably fair to say. But who are the vendors to say that the technology is not being used for good as well as for what you would consider not so good?"

Senin, 31 Oktober 2011

FBI releases video, papers on Russian spy ring

WSJ

WASHINGTON — FBI surveillance tapes, photos and documents released Monday show members of a ring of Russian sleeper spies secretly exchanging information and money during a counterintelligence probe that lasted about a decade and ended in the biggest spy swap since the Cold War.
The tapes show a January 2010 shopping trip to Macy's in New York City's Herald Square by former New York real estate agent Anna Chapman, whose role in the spy saga turned her into an international celebrity. She bought leggings and tried on hats at the New York department store, investigators wrote in a document, and transmitted coded messages while sitting in a coffee shop.
On another occasion, Chapman is visible in a video setting up her laptop computer at a Barnes and Noble. "Technical coverage indicated that a computer signal began broadcasting at the same time," noted part of a heavily redacted FBI report on the incident, apparently showing an effort by Chapman to communicate with her handlers.
Other photos and video from the surveillance operation, which the FBI called "Ghost Stories," show some of the 10 other conspirators burying money in a patch of weeds, handing off documents in what looks like a subway tunnel, meeting during a stroll around Columbus Circle or just taking their kids for a walk.

Jumat, 28 Oktober 2011

German secret police arrest elderly Spies "Mr. & Mrs. Smith"

pravda.ru

Last week, the German counterintelligence arrested the spouses, who were suspected of industrial espionage. It was said that the spouses were working for Russia's Foreign Intelligence Service.
The German media do not have the right to expose the last name of the suspects. The spies, named only as Heidrun and Andreas A., have not been charged yet. Russian mass media say that the last name of the spouses is Anschlag. It was said that the two spies arrived in the Federative Republic of Germany 20 years ago from South America. It just so happens that the KBG recruited them during the time when officer Vladimir Putin was serving in Germany.
We would like to remind here that the Foreign Intelligence Service declared itself to be the official successor of the First Principal Directorate of the KGB in December 1991. It was a foreign intelligence department, whereas Putin always served in counterintelligence. To put it simply, Putin's job was to neutralize the colleagues of the detainees - he did not recruit and infiltrate anyone. Therefore, the sitting prime minister knew nothing about the activities of the two spies.
Heidrun and Andreas, who held Austrian passports, were living in the south-west of the FRG, in Landau, from 2002 to 2010. According to the Rheinpfalz newspaper, Andreas was collecting industrial secrets and sending them to Russia's Foreign Intelligence Service. Andreas, a professional machine-builder, was working at the firm called Faurecia (car supplies). He also owned an innovation center in Rheinland-Pfalz province. 
At the end of 2010, the spies were supposed to move to Marburg, where they rented a one-room house. Heidrun, 51, was arrested in that house. The woman was supposedly sitting in front of the transmitter and was about to receive a code telegram. Andreas, 45, was conducting his illegal activities at the time when he was officially serving as a car supplier in Heuchelheim in the state of Hesse. The man was arrested last week on Tuesday night by the federal department of criminal police and GSG 9 antiterrorist department.
The Rheinpfalz reporters found out that the married couple spoke German with an east-European accent. The couple also has a 20-year-old daughter, a student of a medical college in Marburg.

Russian spies suspected of stealing auto secrets from Germans

inautonews.com

A married couple was arrested in the German town Michelbach, suspected of stealing secrets from German car manufacturers, after it emerged one of them worked in the auto industry for the past 20 years.
German prosecutors stated that the couple had been arrested on accusations of spying for an unspecified foreign intelligence service, which media identified over the weekend as Russia’s Foreign Intelligence Service.
According to English-language German newspaper The Local, …
“intelligence service sources say the man, named only as Andreas A., had worked for Faurecia, one of Germany’s top car part manufacturers which supplies major companies including Volkswagen, Renault, Toyota and Ford,” where he is thought to have engaged in “industrial espionage.”
Andreas A., who was identified by the Daily Mail as Andreas Anschlag, 45, is believed to have been living in Germany for the past 20 years with his wife Heidrun, 51, “having used fake passports to enter the country, and then setting themselves up as a family, even having a daughter who is now said to be 20 years old and studying medicine in Marburg.”
The Moscow Times reports that Heidrun Anschlag “was caught by investigators while listening to encrypted radio messages” from Russia on a short-wave, which experts tell the paper is “bizarre” in this day and age, when internet and other forms of communication are available.
Russian newspaper Iswestija (via The Local) quotes a “Russian intelligence agent [as] saying the couple were long retired from the spy business and that they may have been used to transfer information, ‘like a kind of letter box.’”

Jumat, 07 Oktober 2011

SpearTip’s Top Cyber Counterespionage Expert Gives TV Interview on TRICARE Data Theft

prweb.com

Doubts custodian’s assurances. Fears possible extortion of military employees whose personal medical data was taken.


St. Louis, Missouri (PRWEB) October 07, 2011
Jarrett Kolthoff, CEO of Cyber Counterespionage firm SpearTip, was interviewed by CBS-affiliate KMOV about the recent theft of two-decades-worth of medical data on nearly five million military personnel. Part of the interview was broadcast. An expansion of that interview is included here.
The custodian of the records, Science Applications International Corporation (SAIC), reported the data breach had occurred two weeks earlier, when numerous back-up tapes were assertively stolen in a break-in of an employee’s car, while the tapes were in transit across town.
SAIC downplayed the breach, saying no financial information was involved, although SAIC acknowledged the tapes contained sensitive medical information. SAIC discounted harm from the loss of this information, saying: “The risk of harm to patients is judged to be low despite the data elements involved, since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure.” Kolthoff said this statement is not an assurance that data was encrypted. The news report indicated that only “some” of the tapes were encrypted.

Rabu, 05 Oktober 2011

Social media for corporate networking or corporate espionage?

informationweek.in

Today, corporates are looking at social media like Twitter, LinkedIn and Facebook to broaden their online outreach. In a session at INTEROP Mumbai 2011, Abilash Sonwane, Senior-VP, Elitecore Technologies, talked about how social media networks are the next frontier of corporate espionage



Around 13 percent of corporate losses occur due to corporate espionage, as per a recent KPMG report. The number is less as most of the companies usually don’t admit it. In a session at INTEROP Mumbai 2011, Abilash Sonwane, Senior-VP, Elitecore Technologies, talked about how social media networks are the next frontier of corporate espionage.
Today, corporates are looking at social media like Twitter, LinkedIn and Facebook to broaden their online outreach. As per Nielsen Online study, social networking is now officially more popular then e-mail. Considering the popularity of social media among corporates, Elitecore Technologies did a research on 20 companies to find out how social media can be used for corporate espionage.
To conduct the research, Elitecore selected companies that were active on social media from a mix of industries and geographies. The company found out that though on one hand social media can enable an enterprise to enhance its relationship with customers, on the other hand it can adversely affect a company’s reputation.

More...

Selasa, 04 Oktober 2011

In face of massive cybersecurity threat, government security dawdles

networkworld.com

Despite efforts to improve, GAO report says most government agencies are at risk of security attack.

At a time when the cyberthreat level is at its peak, many federal agencies continue to struggle with IT security.
Weaknesses in information security policies and practices at 24 major federal agencies continue to place the confidentiality, integrity and availability of sensitive information and information systems at risk. Consistent with this risk, reports of security incidents from federal agencies are on the rise, increasing more than 650% over the past five years, concluded a report from the watchdogs at the Government Accountability Office this week.
"Each of the 24 agencies -- including the Departments of Agriculture, Commerce, Defense, Education, Energy, Health and Human Services, Homeland Security and the IRS -- reviewed had weaknesses in information security controls. An underlying reason for these weaknesses is that agencies have not fully implemented their information security programs. As a result, they have limited assurance that controls are in place and operating as intended to protect their information resources, thereby leaving them vulnerable to attack or compromise," the report stated.

McAfee reveals ‘Shady RAT’ espionage ring

c4isrjournal.com

The massive cyber espionage operation disclosed by the security company McAfee began with its 2009 discovery of a suspicious command-and-control server.
The server contained logs showing the Internet Protocol addresses for the firewalls and email gateways of dozens of companies and organizations around the world.
Intruders possibly working for a “state actor” used this server to steal secrets from at least 72 victims in 14 countries, according to McAfee’s new report, “Revealed: Operation Shady RAT.” Rat is the cyber industry’s term for the remote access tools used by the intruders.
McAfee will not say which country it suspects might be behind the intrusions or provide details about the server, except to say it was located in a Western country and that the IP logs were acquired legally.
After the 2009 discovery, the company began quietly notifying law enforcement agencies and signing nondisclosure agreements with some of the victims. McAfee said it has briefed foreign governments, congressional staff members and White House officials.
Because of countermeasures, the Shady RAT intruders have adjusted their tactics, but their operation is “still going on today,” McAfee’s Dmitri Alperovitch, vice president for threat research, said in a teleconference with reporters in August.

Sabtu, 01 Oktober 2011

Pentagon seeks probe of the cost of hacking

washingtontimes.com

The Pentagon is asking the nation’s 16 spy agencies to investigate the cost of theft of commercial secrets by foreign computer hackers, a loss some analysts say could be costing the U.S. economy hundreds of billions of dollars a year.

“We expect it is very substantial — substantial in monetary terms, substantial in security terms,” said James N. Miller, principal deputy undersecretary of defense for policy. “The nation has a substantial interest in protecting intellectual property.”

The Pentagon’s request for an estimate went to the National Intelligence Council, which produces National Intelligence Estimates (NIEs), said Deputy Secretary of Defense William J. Lynn, adding that its report will likely be classified when the assessment is complete.

Security specialists say that hackers, many thought to be operating on behalf of communist China, are stealing vast quantities of proprietary data from U.S. defense, energy and other firms every year, compromising the nation’s security and economic advantage.

“It is a massive transfer of wealth,” said Phyllis Schneck, chief technology officer for public-sector business at computer security firm McAfee Inc.“Things that would have created money and jobs for one company in one country are instead creating them for other companies in another country.”

More...

Selasa, 27 September 2011

SpearTip's Counterespionage Expert Warns of Emerging Cyber Threats to Private Industry

prweb.com

Former U.S. Counterintelligence Agent Jarrett Kolthoff keynotes conference of counterespionage practitioners and technologists.

St. Louis, Missouri (PRWEB) September 27, 2011

Espionage Research Institute (“ERI”) Conference – This year’s keynote speaker was Jarrett Kolthoff, a former U.S. Counterintelligence Agent, now CEO of cyber counterespionage firm SpearTip. Kolthoff provided valuable insights into recent and emerging domestic and foreign cyber espionage threats. Kolthoff was recognized with a plaque presented by ERI President, former CIA officer, Glenn Whidden.

SpearTip’s Kolthoff described a number of “incidents” he has dealt with for his Fortune 100 and other national and international clients to emphasize the increasing prevalence of internet-based surveillance techniques, cyber espionage, malware, APT (Advanced Persistent Threats) that requires his team to learn and adapt constantly to the ever-changing playing field.

Whidden created ERI in an effort to bring together Technical Surveillance Countermeasures (“TSCM”) specialists, security practitioners, businessmen and corporate security executives to share information about hostile global espionage targeting business and industry.

Additionally, Kolthoff sees more and more corporate espionage by departing employees electronically transferring large amounts of competitively sensitive company data. The ease with which such data can be copied and transported requires far higher levels of vigilance by company executives. According to Kolthoff, it is not a matter of “if” data theft will occur, but what the company is prepared to do in mitigation of such losses “when” a company discovers that it has already been breached.

Kolthoff notes that threats exist for enterprises of all types and sizes, from governmental to non-profits to low tech service providers, in addition to obvious targets such as technology driven multinationals. No matter the organization, corporate espionage and cyber warfare are not simply on the doorstep – they are already a dramatic reality.

More...

Senin, 12 September 2011

And, Speaking of Spies....2011 Espionage Research Institute Conference


2011 Espionage Research Institute Conference

This week marks the annual ERI conference in Reston, VA.

The Espionage Research Institute is dedicated to collecting and promulgating information on hostile espionage activity. That is done through the process of accepting, screening and editing reports of hostile activity as they are received from ERI Associates and its Advisors.

The motto of ERI is: "The Biggest Mistake That We Can Make Would Be To Miss The Changes". That expresses the basic reason that ERI exists. It attempts to keep all informed on hostile espionage activity that is directed against business and industry.

Stay tuned later this week for some interesting reports.... ~JDL

Minggu, 17 Juli 2011

Rebekah Brooks Arrested for Cellphone Hacking, Bribery

mashable.com
Rebekah Brooks, who was in charge of Rupert Murdoch’s vast media empire in the UK, was arrested Sunday on allegations of cellphone hacking and paying off corrupt cops for information.

She’s the highest official of News Corp. to be arrested so far. According to The Washington Post, she was arrested for “conspiring to intercept communications and on corruption allegations.”

Brooks had resigned her position on Friday as chief executive of News International, according to The Telegraph. She is alleged to have authorized electronic eavesdropping of the cellphones of hundreds of unknowing victims, tapping into the voicemail of a 13-year-old murder victim, and intercepting phone calls of numerous politicians and scores of celebrities.

More...
Related Posts Plugin for WordPress, Blogger...