Many news sources are reporting on how Google and other corporations were hacked by China.
The reports, depending on vendor, blame either PDF files via email as the original perpetrator, or lay most of the blame on an Internet Explorer 0day.
Unlike my colleagues (save for the ones reporting), I rather not discuss this too much before more data is available.
Regardless of what really happened, which I hope we will know more on later, these things are clear:
1. Unlike GhostNet, which showed an interesting attack, but unfortunately many of us jumped to conclusions without evidence that it was China behind them -- based on Ethos alone I'd like to think that when Google says China did it, they know. Although being a commercial company with their own agenda, I am saving final judgement.
2. The 0day disclosed here shows a higher level of sophistication, as well as m.o. which has been shown to be used by China in the past.
3. If this was China, which some recent talk seems to make ambiguous, but still likely; they would have more than just one weapon in their arsenal.
4. This incident has brought cyber security once again to the awareness of the public, in a way no other incident since Georgia has succeeded, and to political awareness in a way no incident since Estonia has done.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts
Friday, January 15, 2010
Wednesday, March 25, 2009
Phishing attacks against ISPs (also with Google translations)
In this email message I'd like to discuss two subjects:
a. Phishing against ISPs.
b. Phishing in different languages against ISPs as soon as Google adds a new translation module.
[My apologies to those who receive this email more than once.]
In the past few weeks there has been an increasing number of phishing attacks against clients of Israeli ISPs. I've only seen a few of these, but the local ISPs confirm it's happening across the board.
In all these cases, the phishing email is in Hebrew.
While we have seen ISP phishing and Hebrew phishing before, these attacks started when Google added translation into Hebrew.
Is this a trend? Have other countries (or populations) been targeted when Google added a translation module for more languages?
Notes:
a. Some Israeli ISPs emailed their clients warning against such attacks. Saying they'd never ask for their password, etc.
b. While I was certainly heavily involved with phishing originally and even started the first coordination group to deal with the issue, I am somewhat removed from it now, dealing more with phishing/banking Trojan horses.
Can anyone educate me as to how often ISPs get phished, if at all?
c. If you get phished, what strategies if any have you taken to prevent the attacks/respond to them/educate your clients? What worked?
d. I wonder if these translation misuses could eventually translate into some intelligence we will see in Google security reports, such as on malware.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
a. Phishing against ISPs.
b. Phishing in different languages against ISPs as soon as Google adds a new translation module.
[My apologies to those who receive this email more than once.]
In the past few weeks there has been an increasing number of phishing attacks against clients of Israeli ISPs. I've only seen a few of these, but the local ISPs confirm it's happening across the board.
In all these cases, the phishing email is in Hebrew.
While we have seen ISP phishing and Hebrew phishing before, these attacks started when Google added translation into Hebrew.
Is this a trend? Have other countries (or populations) been targeted when Google added a translation module for more languages?
Notes:
a. Some Israeli ISPs emailed their clients warning against such attacks. Saying they'd never ask for their password, etc.
b. While I was certainly heavily involved with phishing originally and even started the first coordination group to deal with the issue, I am somewhat removed from it now, dealing more with phishing/banking Trojan horses.
Can anyone educate me as to how often ISPs get phished, if at all?
c. If you get phished, what strategies if any have you taken to prevent the attacks/respond to them/educate your clients? What worked?
d. I wonder if these translation misuses could eventually translate into some intelligence we will see in Google security reports, such as on malware.
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Labels:
Google,
Hebrew,
incident response,
Intelligence,
ISPs,
phsihing,
translation,
user education
Subscribe to:
Posts (Atom)