Shadow Brokers leaks show U.S. spies successfully hacked Russian, Iranian targets
The leaked NSA documents and tools published in recent months by the mysterious Shadow Brokers group have provided rare insight into the clandestine digital espionage operations pursued by the spy agency over the past few years, including information on operations aimed at Iran and Russia.
Last Friday the rogue group released a new package of NSA files, this time detailing numerous tools designed to break into older versions of Microsoft Windows and a campaign to compromise banking networks in the Middle East. Additional targets were also mentioned one week prior in a separate archive that was largely ignored by most media outlets.
Yet the document cache published April 8 provides evidence that the NSA had once launched a series of successful computer-based intrusions against multiple high-profile foreign targets, including the Office of the President of Iran and the Russian Federal Nuclear Center, said two former intelligence officials who spoke to CyberScoop on the condition of anonymity due to their knowledge of internal operations. That release contained files with earmarked organizations and other evidence that explains how certain cyberattacks were engineered.
“The fact that this is in there the way it is means these targets were definitely owned,” one former intelligence official said. “It means it was a successful op, plain and simple.”
Another former intelligence official that worked at the NSA and also spoke on condition of anonymity said the April 8 document dump offered authentic internal information regarding past agency operations.
While the Shadow Brokers published a list of 300 IP addresses last October that were supposedly once compromised by the spy agency, it was not until recently that researchers were provided with more comprehensive targeting data.
An analysis of one archive presented by the Shadow Brokers reveals a collage of web domains and hardware systems that were at one point targeted by the NSA and attacked with a suite of hacking tools. These domains include:
A closer look at the full filenames in the archive provides additional insight. The websites themselves represent targeted host machines, or boxes, each of which is paired with two different codenames— one for the hacking tool used and another for the associated operation.
For example, one such file name is listed as:
Experts say stoicsurgeon is a post-exploitation tool, meaning that a different exploit was necessary to first compromise the target. “Ctrl” in the sample is the name of the loader. “x86-Linux” refers to the 32-bit Linux operating system used by the target in this case. “Vezarat,” a term referring to Iran’s Ministry of Intelligence, is the host box in the dolat.ir domain that was specifically compromised.
It all translates to an NSA operation that likely saw U.S. spies hack into a host box inside a computer network that was of high interest to national security analysts in Washington during the Obama administration. According to an internal PowerPoint presentation previously leaked by former agency contractor Edward Snowden, “Optimusprime” is related to the NSA’s SPINALTAP project, a program that was introduced to combine data from active operations and passive signals intelligence.
Stoicsurgeon is just one hacking tool used against the web domains listed above. Another tool, codenamed “suctionchar,” also features prominently in the archive filename list — for example: suctionchar_agent__v__2.0.27.18_x86-linux-tilttop-comet.vniitf.ru.
Security researcher x0rz described “suctionchar” as a “32 or 64 bit OS, solaris sparc 8,9, Kernel level implant” that provide an attacker with “transparent, sustained, or realtime interception of processes input/output vnode traffic,” that can also “intercept ssh, telnet, rlogin, rsh, password, login, [and] csh” data.
https://www.cyberscoop.com/nsa-shadow-brokers-leaks-iran-russia-optimusprime-stoicsurgeon/
Written by
Chris Bing Apr 18, 2017 | CyberScoopThe leaked NSA documents and tools published in recent months by the mysterious Shadow Brokers group have provided rare insight into the clandestine digital espionage operations pursued by the spy agency over the past few years, including information on operations aimed at Iran and Russia.
Last Friday the rogue group released a new package of NSA files, this time detailing numerous tools designed to break into older versions of Microsoft Windows and a campaign to compromise banking networks in the Middle East. Additional targets were also mentioned one week prior in a separate archive that was largely ignored by most media outlets.
Yet the document cache published April 8 provides evidence that the NSA had once launched a series of successful computer-based intrusions against multiple high-profile foreign targets, including the Office of the President of Iran and the Russian Federal Nuclear Center, said two former intelligence officials who spoke to CyberScoop on the condition of anonymity due to their knowledge of internal operations. That release contained files with earmarked organizations and other evidence that explains how certain cyberattacks were engineered.
“The fact that this is in there the way it is means these targets were definitely owned,” one former intelligence official said. “It means it was a successful op, plain and simple.”
Another former intelligence official that worked at the NSA and also spoke on condition of anonymity said the April 8 document dump offered authentic internal information regarding past agency operations.
While the Shadow Brokers published a list of 300 IP addresses last October that were supposedly once compromised by the spy agency, it was not until recently that researchers were provided with more comprehensive targeting data.
An analysis of one archive presented by the Shadow Brokers reveals a collage of web domains and hardware systems that were at one point targeted by the NSA and attacked with a suite of hacking tools. These domains include:
- dolat.ir: Islamic Republic of Iran Presidential Office website
- vniitf.ru: Russian Federal Nuclear Center website
- mail.prf.gov.ru: a mail server for the Presidential Administration of Russia (aprf.gov.ru is no longer online)
- vega-int.ru: a website for Russian internet service provider, Vega-Internet
- snz.ru: a website for the office providing telecommunications and other internet support for Vniitf.ru
- minatom.ru: a website of the Ministry for Atomic Energy of the Russian Federation
- udprf.ru: the Office of the President of the Russian Federation website
- rowdaco.com: a defunct website once apparently used by a Somalia-based electronics store, Rowda Electronics Company
- ikoula.com: a website for a French data storage and server rental company
A closer look at the full filenames in the archive provides additional insight. The websites themselves represent targeted host machines, or boxes, each of which is paired with two different codenames— one for the hacking tool used and another for the associated operation.
For example, one such file name is listed as:
In this context, the term “stoicsurgeon” is a reference to the codename of the deployed tool. “Optimusprime” is the title of an NSA operation. “v__1.5.33.2” details the version of stoicsurgeon, a rootkit backdoor aimed at Linux’s MultiArch — which helps install library packages from multiple architectures on the same machine.stoicsurgeon_ctrl__v__1.5.33.2_x86-linux-optimusprime-vezarat.dolat.ir
Experts say stoicsurgeon is a post-exploitation tool, meaning that a different exploit was necessary to first compromise the target. “Ctrl” in the sample is the name of the loader. “x86-Linux” refers to the 32-bit Linux operating system used by the target in this case. “Vezarat,” a term referring to Iran’s Ministry of Intelligence, is the host box in the dolat.ir domain that was specifically compromised.
It all translates to an NSA operation that likely saw U.S. spies hack into a host box inside a computer network that was of high interest to national security analysts in Washington during the Obama administration. According to an internal PowerPoint presentation previously leaked by former agency contractor Edward Snowden, “Optimusprime” is related to the NSA’s SPINALTAP project, a program that was introduced to combine data from active operations and passive signals intelligence.
Stoicsurgeon is just one hacking tool used against the web domains listed above. Another tool, codenamed “suctionchar,” also features prominently in the archive filename list — for example: suctionchar_agent__v__2.0.27.18_x86-linux-tilttop-comet.vniitf.ru.
Security researcher x0rz described “suctionchar” as a “32 or 64 bit OS, solaris sparc 8,9, Kernel level implant” that provide an attacker with “transparent, sustained, or realtime interception of processes input/output vnode traffic,” that can also “intercept ssh, telnet, rlogin, rsh, password, login, [and] csh” data.
-In this Story-
cyber espionage, cybersecurity, FISA, insider threat, intelligence agencies, Iran, leaks, news, NSA, Russia, Shadow Brokers, spying, TAOhttps://www.cyberscoop.com/nsa-shadow-brokers-leaks-iran-russia-optimusprime-stoicsurgeon/
Today at 10:04 am by Rocky
» Al-Alaq: The monetary situation in Iraq is excellent and our reserves support the stability of the e
Today at 8:29 am by Rocky
» utube 11/23/24 MM&C Reporting-Expectations are High-IMF-Flexible Exchange Rate Regime-Pr
Today at 6:33 am by Rocky
» utube 11/25/24 MM&C MM&C Iraq News-CBI Building Final Touches-Oil Exports-Development Road-Turkey-B
Today at 6:33 am by Rocky
» Parliamentary movement to include the salary scale in the next session
Today at 5:11 am by Rocky
» Parliamentary Finance Committee reveals the budget paragraphs included in the amendment
Today at 5:10 am by Rocky
» Al-Maliki calls on the Bar Association to hold accountable members who violate professional conduct
Today at 5:08 am by Rocky
» Politician: The security agreement with America has many aspects
Today at 5:07 am by Rocky
» Kurdistan Planning: More than 6 million people live in the region, the oldest of them is 126 years o
Today at 5:05 am by Rocky
» Al-Alaq: Arab consensus on the role of central bank programs in addressing challenges
Today at 5:03 am by Rocky
» Economics saves from political drowning
Today at 5:02 am by Rocky
» Agriculture calls for strict ban on import of "industrial fats" and warns of health risks
Today at 5:01 am by Rocky
» Iraq is the fourth largest oil exporter to China
Today at 5:00 am by Rocky
» Railways continue to maintain a number of its lines to ensure the smooth running of trains
Today at 4:59 am by Rocky
» Parliament resumes its sessions tomorrow.. and these are the most important amendments in the budget
Today at 4:58 am by Rocky
» Bitcoin Fails to Continue Rising as It Approaches $100,000
Today at 4:57 am by Rocky
» Minister of Planning: There will be accurate figures for the population of each governorate
Today at 4:56 am by Rocky
» Popular Mobilization Law is ready for voting
Today at 4:54 am by Rocky
» Mechanisms for accepting people with disabilities into postgraduate studies
Today at 4:52 am by Rocky
» Government coordination to create five thousand jobs
Today at 4:51 am by Rocky
» Transport: Next month, a meeting with the international organization to resolve the European ban
Today at 4:50 am by Rocky
» Census is a path to digital government
Today at 4:49 am by Rocky
» Calls to facilitate loans and reduce interest rates for the private sector
Today at 4:47 am by Rocky
» The launch of the third and final phase of the "population census"
Today at 4:46 am by Rocky
» Al-Sudani: We have accomplished a step that is the most prominent in the framework of planning, deve
Today at 4:44 am by Rocky
» Justice discusses modern mechanisms to develop investment in real estate and minors’ money
Today at 4:43 am by Rocky
» Dubai to host Arabplast exhibition next month
Today at 4:41 am by Rocky
» Al-Tamimi: Integrity plays a major role in establishing the foundations of laws that will uphold jus
Today at 4:39 am by Rocky
» Reaching the most important people involved in the "theft of the century" in Diyala
Today at 4:38 am by Rocky
» Transportation: Completion of excavation works and connection of the immersed tunnel manufacturing b
Today at 4:36 am by Rocky
» Between internal and regional challenges... Formation of the Kurdistan government on a "slow fire" a
Today at 4:35 am by Rocky
» Kurdistan Region Presidency: We will issue a regional order to determine the first session of parlia
Today at 4:34 am by Rocky
» The Minister of Foreign Affairs announces the convening of the Ambassadors Conference tomorrow, Mond
Today at 4:33 am by Rocky
» Al-Sudani: Iraq must always be at the forefront
Today at 4:32 am by Rocky
» Al-Mashhadani: We support the Foreign Ministry in confronting any external interference that affects
Today at 4:31 am by Rocky
» Al-Sudani chairs meeting with Oliver Wyman delegation
Today at 4:29 am by Rocky
» Half a million beggars in Iraq.. 90% of them receive welfare salaries
Today at 4:27 am by Rocky
» Sudanese announces preliminary results of the general population and housing census in detail
Today at 4:26 am by Rocky
» The centenary of the Iraqi Ministry of Foreign Affairs.. A journey of challenges and achievements
Today at 4:25 am by Rocky
» Prime Minister's Advisor Announces Assignment of Two International Companies to Study Iraqi Banking
Today at 4:23 am by Rocky
» Agriculture: Integrated Support Project Provides 1,333 Job Opportunities
Today at 4:22 am by Rocky
» The Media and Education Commission discuss introducing advanced curricula related to artificial inte
Today at 4:20 am by Rocky
» Al-Mashhadani’s First Test: Discussing Israeli Threats and Avoiding Controversial Laws
Today at 4:20 am by Rocky
» By name.. A parliamentary bloc reveals that five ministers will be questioned at the end of the legi
Today at 4:19 am by Rocky
» The financial budget is subject to political and economic amendments in the next parliamentary sessi
Today at 4:18 am by Rocky
» Will the government's efforts succeed in ending the electricity crisis in Iraq?
Today at 4:17 am by Rocky
» Baghdad Airport Customs Increased to 400% After Implementing Automation
Today at 4:16 am by Rocky
» EU: Integrated Support Project in Iraq Creates Jobs in Agriculture and Youth
Today at 4:15 am by Rocky
» Al-Sudani attends the centenary ceremony of the establishment of the Ministry of Foreign Affairs
Today at 4:13 am by Rocky
» Al-Mashhadani: We seek to keep foreign policy away from alignments that harm Iraq’s unity and sovere
Today at 4:12 am by Rocky
» The Iraqi government is working to develop a competitive banking system and support the private sect
Today at 4:10 am by Rocky
» Al-Alaq: Arab consensus on the role of central bank programs in addressing challenges
Today at 4:09 am by Rocky
» Regional markets rise in first session of the week
Today at 4:08 am by Rocky
» Kurdistan Region Presidency: We will issue an order to set the first session of the regional parliam
Today at 4:06 am by Rocky
» Political differences hinder oil and gas law legislation
Today at 4:05 am by Rocky
» Government coordination to create new job grades for graduates
Today at 4:04 am by Rocky
» The financial budget is subject to amendments in the next parliamentary session
Today at 4:03 am by Rocky
» Alsumaria Newsletter: Iraq reaches the final stages of the census and Parliament resumes its session
Today at 4:01 am by Rocky
» After the elites and workers... Iranian factories "migrate" to Iraq
Today at 3:58 am by Rocky
» Beggars in Iraq "refuse" welfare salaries.. Their profits are 10 times the salary!
Today at 3:57 am by Rocky
» Amending the Election Law... A Means to Restore the Dilapidated Legitimacy
Today at 3:56 am by Rocky
» Prime Minister announces population census results, Iraq reaches 45 million mark
Today at 3:54 am by Rocky
» Find out the dollar exchange rates in the Iraqi markets
Today at 3:53 am by Rocky
» Kurdistan Interior Ministry: General amnesty does not include those accused of killing women
Today at 3:52 am by Rocky
» utube 11/21/24 MM&C MM&C News Reporting-Global Trade-Best Route in World-Purchase Power-Justice-Cen
Yesterday at 6:58 am by Rocky
» Al-Sudani discusses with the Secretary-General of the Digital Cooperation Organization enhancing dig
Yesterday at 6:56 am by Rocky
» President of the Republic: Partnership with the United States is essential to achieve regional stabi
Yesterday at 6:54 am by Rocky
» Mazhar Saleh reveals details of the 2023 budget and the 2024 budget horizon
Yesterday at 5:18 am by Rocky
» Absent control and rising corruption.. Sudan faces a harsh political winter
Yesterday at 5:16 am by Rocky
» A representative shows the laws prepared for voting during the upcoming sessions.
Yesterday at 5:14 am by Rocky
» Corrupt people in it.. Independent MP criticizes the performance of Al-Sudani's government
Yesterday at 5:13 am by Rocky
» Parliamentary Oil Committee reveals government move to end electricity crisis
Yesterday at 5:11 am by Rocky
» The Administrative Court postpones consideration of the lawsuit on the legitimacy of the Kirkuk gove
Yesterday at 5:10 am by Rocky
» MP: The ministerial reshuffle depends on consensus within the state administration
Yesterday at 5:09 am by Rocky
» Politicians put question marks on Al-Sudani: corruption, espionage and serving foreign interests
Yesterday at 5:08 am by Rocky
» The International Union of Arab Bankers honors the Chairman of the Private Banks Association: A prom
Yesterday at 5:03 am by Rocky
» Industry: Contracts to supply state ministries with food products
Yesterday at 5:02 am by Rocky
» After Shell Withdrawal, American Company Heads to Implement Al-Nibras Project in Iraq
Yesterday at 5:01 am by Rocky
» Revealing the fate of the Chinese deal in Iraq.. It was disrupted by this party
Yesterday at 5:00 am by Rocky
» The Central Bank of Iraq 77 years of challenges and reforms
Yesterday at 4:57 am by Rocky
» "Unprecedented numbers"... American "CNN" talks about tourism in Iraq
Yesterday at 4:56 am by Rocky
» After implementing automation, Baghdad Airport Customs jumps 400 percent
Yesterday at 4:55 am by Rocky
» Iraq participates in sustainable development activities
Yesterday at 4:53 am by Rocky
» Al-Sudani opens 790 model schools
Yesterday at 4:52 am by Rocky
» Parliamentary Culture: The Right to Information Law will satisfy all parties
Yesterday at 4:51 am by Rocky
» Al-Mashhadani to {Sabah}: Tomorrow we will discuss the Zionist threats
Yesterday at 4:50 am by Rocky
» Industry to {Sabah}: Contracts to supply state ministries with food products
Yesterday at 4:49 am by Rocky
» Trade cooperation between Najaf and Isfahan
Yesterday at 4:48 am by Rocky
» {New building} and {electronic systems} to develop forensic medicine
Yesterday at 4:47 am by Rocky
» A specialized center for monitoring the environmental situation in the capital
Yesterday at 4:46 am by Rocky
» International and parliamentary praise for the success of the "population census" process
Yesterday at 4:45 am by Rocky
» The European Union organizes a workshop in Basra on central administration and the wealth distributi
Yesterday at 4:42 am by Rocky
» The Media Authority and the Ministry of Education discuss the importance of enhancing and introducin
Yesterday at 4:41 am by Rocky
» Iraq's oil exports to America rose last week
Yesterday at 4:40 am by Rocky
» Electricity announces loss of 5,500 megawatts due to complete halt of Iranian gas supplies
Yesterday at 4:39 am by Rocky
» Tomorrow.. The Arab League is looking to unify its position against Israeli intentions to strike Ira
Yesterday at 4:37 am by Rocky
» The Central Bank moves its secret vaults to its new building.. Clarification of the truth of the cla
Yesterday at 4:35 am by Rocky
» Network reveals the fate of the Chinese deal.. It was disrupted by "Iraqi officials"
Yesterday at 4:34 am by Rocky
» From the White House to the "Leaders of Iraq"... A Message Regarding the Targeting of Baghdad
Yesterday at 4:33 am by Rocky