NationStateSponsoredMalware:Nation State Sponsored Malware ... ·...
Transcript of NationStateSponsoredMalware:Nation State Sponsored Malware ... ·...
![Page 1: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/1.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Nation State Sponsored Malware:Nation State Sponsored Malware: StuxnetGoh Su GimSecurity Advisor APAC, F-Secure Labs
07 November 2012
![Page 2: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/2.jpg)
About meAbout me
Technology Evangelist
Protecting the irreplaceable | f-secure.com
Evangelist
![Page 3: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/3.jpg)
• 16 November, 2012
![Page 4: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/4.jpg)
F-Secure - Summary
1988 Founded
Today
1999 IPO (Helsinki Stock Exchange)
• “P t ti th i l bl ”• “Protecting the irreplaceable”
• Enabling the safe use of computers and smartphones
• Strong solution portfolio covering both consumers and business
h l d f ( ) f l b ll• The leading Software as a Service (SaaS) partner for operators globally
• Over 200 operator partnerships in more than 40 countries
• Strong market presence in Europe, North America and Asia
2007• Distributors/resellers in more than 100 countries
• 20 offices globally and over 800 professionals worldwide
![Page 5: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/5.jpg)
![Page 6: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/6.jpg)
Where it all started..
© F-Secure / PublicNovember 16, 20126
![Page 7: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/7.jpg)
7
![Page 8: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/8.jpg)
http://campaigns.f-secure.com/brain/index.html
© F-Secure / PublicNovember 16, 20128
![Page 9: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/9.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 10: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/10.jpg)
People First,Performance Now
Ministry of Science,Technology and InnovationStuxnetStuxnet
![Page 11: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/11.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 12: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/12.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 13: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/13.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 14: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/14.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 15: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/15.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
STUXNETWindows Uses 5Windows
WormUses 5Vulnerabilities*
Spreads via
USBUSB sticks
* 4 zero-days
![Page 16: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/16.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
5 Vulnerabilities, 4 Zero Day
• LNK (MS10-046)• Print Spooler (MS10 061)• Print Spooler (MS10-061)• Server Service (MS08-067)• Privilege escalation via Keyboard layout
file• Privilege escalation via Task Scheduler
![Page 17: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/17.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
LNK (MS10-046)• 1st surprise• Spreads first via removable and networkSpreads first via removable and network
storage
![Page 18: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/18.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Server Service (MS08-067)• Conficker anyone?• Vulnerability in Server Service Could AllowVulnerability in Server Service Could Allow
Remote Code Execution (958644)
![Page 19: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/19.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Server Service (MS08-067)• Here comes the best part• this vulnerability makes it possible forthis vulnerability makes it possible for
malicious code to be passed to, and then executed on a remote machineexecuted on, a remote machine
• Print Spooler Service Impersonation VulnerabilityVulnerability
![Page 20: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/20.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Signed component the stolenSigned component – the stolen certificate
![Page 21: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/21.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Stuxnet is bigStuxnet1 5 MB1,5 MB
AAverageMalware50-100 KB
![Page 22: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/22.jpg)
People First,Performance Now
Ministry of Science,Technology and InnovationSiemens Simatic Step7 WinCC p
PLC
![Page 23: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/23.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
6es7-417
![Page 24: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/24.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 25: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/25.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Bushehr / Natanz
![Page 26: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/26.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 27: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/27.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 28: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/28.jpg)
![Page 29: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/29.jpg)
![Page 30: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/30.jpg)
![Page 31: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/31.jpg)
The 20th day of the first month of the Iranian calendar year (Farvardin)The 20th day of the first month of the Iranian calendar year (Farvardin) which falls on April 8 this year, was announced as National Nuclear Technology Day by President Ahmadinejad last year.
The day marks the victory of the Iranian scientists in producing uranium enriched to 3 5 percent in Natanz facility two years agoenriched to 3.5 percent in Natanz facility two years ago.
The achievement made Iran self-sufficient in production of nuclear fuel and the country along with Brazil was recorded as the 8th country possessing nuclear fuel cycle in the world, thanks to the efforts of its young talented expertsexperts.
![Page 32: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/32.jpg)
![Page 33: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/33.jpg)
![Page 34: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/34.jpg)
![Page 35: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/35.jpg)
![Page 36: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/36.jpg)
![Page 37: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/37.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Case Flame• Flame is huge • It sends the stolen• Flame is huge• It has a keylogger and
a screengrabber
• It sends the stolen info out even from organizations with no network connectivity• Has SSH, SSL and
LUA libraries• It collects excerpts
network connectivity• It’s connected to
StuxnetIt collects excerpts from documents
• It collects coordinates from image files
• It spreads via Microsoft Update, is signed by Microsoft from image files
• Checks paired Bluetooth devices
g yand the Certificate has been brute-forced by a supercomputerby a supe co pute
![Page 38: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/38.jpg)
![Page 39: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/39.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
So what about Nation States sponsored malware?
![Page 40: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/40.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 41: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/41.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 42: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/42.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 43: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/43.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 44: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/44.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
![Page 45: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/45.jpg)
Protecting the irreplaceable | f-secure.com
![Page 46: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/46.jpg)
Protecting the irreplaceable | f-secure.com
![Page 47: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/47.jpg)
![Page 48: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/48.jpg)
People First,Performance Now
Ministry of Science,Technology and InnovationWho fights the attackers?Who fights the attackers?
POLICE POLICE
![Page 49: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/49.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Nuclear physics lost it's innocence in 1945
![Page 50: NationStateSponsoredMalware:Nation State Sponsored Malware ... · NationStateSponsoredMalware:Nation State Sponsored Malware: Stuxnet Goh Su Gim Security Advisor APAC, F-Secure Labs](https://reader034.fdocuments.us/reader034/viewer/2022042217/5ec1efd120c47059a80172b2/html5/thumbnails/50.jpg)
People First,Performance Now
Ministry of Science,Technology and Innovation
Computer science lost it's
6es7-315-2 / 6es7-417
innocence in 2009