Jump to content

Hacker group hijack satellite links to steal data and stay undetected

dbinoj

Original article: http://arstechnica.com/security/2015/09/how-highly-advanced-hackers-abused-satellites-to-stay-under-the-radar/

 

The Turla group which hit the news last year (http://www.symantec.com/connect/blogs/turla-spying-tool-targets-governments-and-diplomats / https://securelist.com/analysis/publications/65545/the-epic-turla-operation/) for using the usual excel, PDF, Flash vulnerabilities and the unusual stealthy Trojan for Linux systems was found to be routing traffic via satellites and using DVB-S receivers to receive data from its bots making it impossible to zero in on the location of the computer which downloads the stolen data.

 

Even though the article says that they target only high profile targets (should linus be worried? ;) ), the thought of everyone was able to bounce traffic via a satellite without being detected for all these years scares me.

 

 The hack allowed computers infected with Turla spyware to communicate with Turla C&C servers without disclosing their location. Because the Turla attackers had their own satellite dish receiving the piggybacked signal, they could be anywhere within a 600-mile radius. As a result, researchers were largely stopped from shutting down the operation or gaining clues about who was carrying it out.

Binoj D

Link to comment
Share on other sites

Link to post
Share on other sites

It is a bit scary to imagine a hacker group with so much power and knowledge, but I can't help marveling at the devious ingenuity of it all. This is a system that probably took a long time to develop so they probably only had specific targets to attack. I don't think they'd want to attack some random 20TB archive server full of Youtube videos so I'm sure LTT is fine.

  Christian 

 

Use the following style specs in your sig to spread the LTT revolution!

Rig Specs:

Screeninator: Gigabyte GeForce GTX960

Powermathingy: Corsair CX600W

Stickiminator: 2x G.Skill ARES 4GB DDR3-1866

Procrastinator: AMD FX-8350 @4.1GHz 1.3V

Holdametalicizor: DIYPC Gamemax-BK

Noisoundacreator: Cyber Acoustics CA-3072 (loudamagargle) Onn Wireless FM Radio Headset (earamagargle)

Attachamathingy: ASRock 990FX Extreme9

Remembrerthing: Western Digital 1TB Blue, Western Digital 40GB Blue

Flat-Colorful-Thing: Acer K272HL

See-A-Move-O: Logitech Hyperion Fury G402

ButtonBoard: Cooler Master CMSTORM Devastator Blue

Talkamagargle: Blue Snowball Ice

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Yeah, but unless all satellite based ISPs secure their system, nothing prevents anyone (with some skills) to try the attack now that the basic method/idea is public.

Binoj D

Link to comment
Share on other sites

Link to post
Share on other sites

It was China!

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

says that they target only high profile targets (should linus be worried?)

 

 

 

r u srs...

 

Linus is a tiny blip in the world compared to what these people would actually go after..

Stuff:  i7 7700k @ (dat nibba succ) | ASRock Z170M OC Formula | G.Skill TridentZ 3600 c16 | EKWB 1080 @ 2100 mhz  |  Acer X34 Predator | R4 | EVGA 1000 P2 | 1080mm Radiator Custom Loop | HD800 + Audio-GD NFB-11 | 850 Evo 1TB | 840 Pro 256GB | 3TB WD Blue | 2TB Barracuda

Hwbot: http://hwbot.org/user/lays/ 

FireStrike 980 ti @ 1800 Mhz http://hwbot.org/submission/3183338 http://www.3dmark.com/3dm/11574089

Link to comment
Share on other sites

Link to post
Share on other sites

There have been presentations at security conferences like Blackhat that pointed out the lack of security in satellite communication. It seems only the wrong people listened to them.

Here is an interview with one guy who managed to intercept signals with equipment for under 1000$ and found out that all the traffic was completely unencrypted:

https://twit.tv/shows/this-week-in-enterprise-tech/episodes/155 (skip to 32:00)

Link to comment
Share on other sites

Link to post
Share on other sites

I don't think they'd want to attack some random 20TB archive server full of Youtube videos so I'm sure LTT is fine.

 

Yeah, I agree. That statement was supposed to be a bad joke. Forgot to add a smiley. Edited the original post.

 

 

It seems only the wrong people listened to them.

 

Really wish all product developers take security seriously.

Binoj D

Link to comment
Share on other sites

Link to post
Share on other sites

It seems like a rock could land on a keyboard and hack into anything these days.

 

It was China!

 

No, it was Russia!

|  The United Empire of Earth Wants You | The Stormborn (ongoing build; 90% done)  |  Skyrim Mods Recommendations  LTT Blue Forum Theme! | Learning Russian! Blog |
|"They got a war on drugs so the police can bother me.”Tupac Shakur  | "Half of writing history is hiding the truth"Captain Malcolm Reynolds | "Museums are racist."Michelle Obama | "Slap a word like "racist" or "nazi" on it and you'll have an army at your back."MSM Logic | "A new command I give you: love one another. As I have loved you, so you must love one another"Jesus Christ | "I love the Union and the Constitution, but I would rather leave the Union with the Constitution than remain in the Union without it."Jefferson Davis |

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×