link between nsa regin cyberespionage malware becomes more clear
Last Updated : GMT 09:07:40
Egypt Today, egypt today
Egypt Today, egypt today
Last Updated : GMT 09:07:40
Egypt Today, egypt today

Link between NSA, regin cyberespionage malware becomes more clear

Egypt Today, egypt today

Egypt Today, egypt today Link between NSA, regin cyberespionage malware becomes more clear

Keylogging malware
Tehran - FNA

Keylogging malware that may have been used by the NSA shares signficant portions of code with a component of Regin, a sophisticated platform that has been used to spy on businesses, government institutions and private individuals for years.
The keylogger program, likely part of an attack framework used by the US National Security Agency and its intelligence partners, is dubbed QWERTY and was among the files that former NSA contractor Edward Snowden leaked to journalists. It was released by German news magazine Der Spiegel on Jan. 17 along with a larger collection of secret documents about the malware capabilities of the NSA and the other Five Eyes partners—the intelligence agencies of the UK, Canada, Australia and New Zealand, PCworld reported.
“We’ve obtained a copy of the malicious files published by Der Spiegel and when we analyzed them, they immediately reminded us of Regin,” malware researchers from antivirus firm Kaspersky Lab said Tuesday in a blog post. “Looking at the code closely, we conclude that the ‘QWERTY’ malware is identical in functionality to the Regin 50251 plugin.”
Moreover, the Kaspersky researchers found that both QWERTY and the 50251 plug-in depend on a different module of the Regin platform identified as 50225 which handles kernel-mode hooking. This component allows the malware to run in the highest privileged area of the operating system—the kernel.
This is strong proof that QWERTY can only operate as part of the Regin platform, the Kaspersky researchers said. “Considering the extreme complexity of the Regin platform and little chance that it can be duplicated by somebody without having access to its source code, we conclude the QWERTY malware developers and the Regin developers are the same or working together.”
Der Spiegel reported that QWERTY is likely a plug-in of a unified malware framework codenamed WARRIORPRIDE that is used by all Five Eye partners. This is based on references in the code to a dependency called WzowskiLib or CNELib.
In a separate leaked document authored by the Communications Security Establishment Canada, the Canadian counterpart of the NSA, WARRIORPRIDE is described as a flexible computer network exploitation (CNE) platform that’s an implementation of the “WZOWSKI” Five Eyes API (application programming interface).
The document also notes that WARRIORPRIDE is known under the code name DAREDEVIL at the UK Government Communications Headquarters (GCHQ) and that the Five Eyes intelligence partners can create and share plug-ins for it.

 

egypttoday
egypttoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

link between nsa regin cyberespionage malware becomes more clear link between nsa regin cyberespionage malware becomes more clear



GMT 08:32 2011 Monday ,25 July

Sabri accuses Yusri in Souad Hosni’s murder

GMT 23:58 2011 Thursday ,10 November

A look inside Victoria’s secret fashion show

GMT 10:43 2014 Saturday ,31 May

Wonderful boys bedrooms interior design

GMT 09:27 2018 Sunday ,21 January

Ex-employee accuses Michael Douglas

GMT 16:22 2015 Wednesday ,20 May

President to approve electricity bill within days

GMT 07:14 2017 Friday ,23 June

(September24th-October23rd)

GMT 17:20 2014 Thursday ,06 March

Fascinating idea for small interiors

GMT 08:41 2017 Saturday ,30 September

Hussein Fahmy choose 3 films to be presented

GMT 09:43 2017 Thursday ,04 May

'Cautious' as Giro d'Italia tips Quintana

GMT 08:32 2017 Saturday ,12 August

Nesrine Ameen participates in three drama shows

GMT 07:36 2017 Tuesday ,03 October

Skipping breakfast may double risk

GMT 19:53 2017 Wednesday ,10 May

Gold falls to its lowest
 
 Egypt Today Facebook,egypt today facebook  Egypt Today Twitter,egypt today twitter Egypt Today Rss,egypt today rss  Egypt Today Youtube,egypt today youtube  Egypt Today Youtube,egypt today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

egypttoday egypttoday egypttoday egypttoday
egypttoday egypttoday egypttoday
egypttoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
egypttoday, Egypttoday, Egypttoday