News: 1647286095

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

China thrilled it captured already-leaked NSA cyber-weapon

(2022/03/14)


China claims it has obtained malware used by the NSA to steal files, monitor and redirect network traffic, and remotely control computers to spy on foreign targets.

The software nasty, dubbed NOPEN, is built to commandeer selected Unix and Linux systems, according to Chinese Communist Party tabloid Global Times, which [1]today cited a report it got exclusively from China's National Computer Virus Emergency Response Center.

Trouble is, NOPEN was among the files [2]publicly leaked in 2016 by the Shadow Brokers. If you can recall back that far, the Shadow Brokers stole and dumped online malware developed by the NSA's Equation Group.

[3]

At the time, security researchers at Vectra [4]analyzed NOPEN in the leaked Equation Group materials, and described it as a remote-access trojan for Unix-like systems, which matches the NOPEN Global Times got excited about today.

[5]

[6]

In effect, Global Times has told us China has "captured a spy tool deployed by the US National Security Agency," a spy tool that we've known about for years.

Why China would like the world to once again know about NOPEN is anyone's guess. Perhaps Beijing wanted to counter claims by the West that China has been spying on organizations and ripping off their intellectual property, or hoped to inject some extra mischief into the tense standoff between Russia, China, and the West over President Putin's bloody invasion of Ukraine.

[7]

The NSA used NOPEN to take over "a large number" of computers around the world, and the theft of data from this equipment has caused "inestimable losses," we were told today. The American malware would install a backdoor that once activated would allow miscreants to connect in, extract files, change the operation of the system, and explore the network for other resources to hijack or steal, it is claimed.

The NSA declined to comment on NOPEN and other claims of spies-doing-spying in the article.

Obviously the Middle Kingdom would never stoop to such tactics, such as being [8]a major source of cyber-attacks against the US; [9]targeting Microsoft Exchange Server; and exploiting a [10]cow-counting web app.

[11]

This follows a similar Global Times [12]report that claimed the NSA has been using cyber-weapons to attack almost 50 countries and regions for a decade with a specific focus on Chinese government agencies, high-tech firms, and military-related institutes.

[13]Cow-counting app abused by China 'to spy on US states'

[14]China: Attacks from US IP addresses hit us, moved on to Russia and Ukraine

[15]Viasat, Rosneft hit by cyberattacks as Ukraine war spills online

[16]Dunno about you, but we're seeing an 800% increase in cyberattacks, says one MSP

We note NOPEN wasn't the only NSA-developed code to land in the wrong hands. The [17]WannaCry ransomware outbreak of 2017 used the Equation Group's EternalBlue tool to exploit a vulnerability in Microsoft's SMB file sharing services. Eternalblue was stolen and [18]leaked online by the Shadow Brokers before [19]North Korean-backed criminals used it in WannaCry to infect hospitals, banks, and other businesses across 150 countries.

The Global Times also cited an anonymous Chinese cybersecurity expert who said NOPEN is or was the primary weapon in the NSA's cyber arsenal. "The vast majority of the NSA's arsenal consists of stealth fighters and submarines that can easily attack victims without their knowledge," the expert reportedly said. ®

Editor's note: This article was revised to include NOPEN's connection to the Equation Group and Shadow Brokers.

Get our [20]Tech Resources



[1] https://www.globaltimes.cn/page/202203/1254856.shtml

[2] https://www.theregister.com/2016/08/19/snowden_docs_shadow_brokers_nsa_exploits/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yi-JG6EaiS8XBd4zcAd27wAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.vectra.ai/media-coverage/nopen-is-the-equation-groups-backdoor-for-unix-systems

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yi-JG6EaiS8XBd4zcAd27wAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yi-JG6EaiS8XBd4zcAd27wAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yi-JG6EaiS8XBd4zcAd27wAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/02/03/fbi_china_threat_to_usa/

[9] https://www.theregister.com/2021/07/22/china_pushes_back_against_exchange/

[10] https://www.theregister.com/2022/03/09/china_apt41_mandiant_usaherds/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yi-JG6EaiS8XBd4zcAd27wAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.globaltimes.cn/page/202203/1253697.shtml

[13] https://www.theregister.com/2022/03/09/china_apt41_mandiant_usaherds/

[14] https://www.theregister.com/2022/03/14/china_attackers_with_us_ips/

[15] https://www.theregister.com/2022/03/14/viasat_rosneft_ukraine_cyberattacks/

[16] https://www.theregister.com/2022/03/11/russia-invasion-cyber-war-rages/

[17] https://www.theregister.com/2017/05/13/wannacrypt_ransomware_worm/

[18] https://www.theregister.com/2017/04/14/latest_shadow_brokers_data_dump/

[19] http://wsj.com/articles/its-official-north-korea-is-behind-wannacry-1513642537

[20] https://whitepapers.theregister.com/



Every country does this. Every country whines about it.

ecarlseen

What's worse than nation-states not being able to keep their cyberweapons under control?

The endess self-righteous pearl-clutching over other contries doing it (especially here in the US).

Selling the bizarre fantasy that this will ever stop being a thing.

Pretending that solutions other than better security exist.

Re: Every country does this. Every country whines about it.

Blazde

I doubt any of that is the motivation for such announcements. It always feels more like:

- Our own counter-intelligence is awesome, we're on top of this stuff

- We've captured their thing (go us)

- We're watching what they're up to, so they better watch out!

- Average Joe don't panic

- Law-makers keep giving us the resources to do our jobs

- Security pros help us by looking out for these attack signatures

- And now here's a 30 second message from our partner Symantec

Great

Anonymous Coward

I like a bit of cyber-espionage. It's exciting.

I do wonder though, at what point do we decide we're at war with a country in the cyber space?

It's kinda easy to determine a war in Ukraine (I'm not trivializing this, I am appalled by it) because there are tanks rolling down the street.

But is there a classification for 'war' when it's happening in cyber space? Is there a point that must be reached, is there an research on this?

Re: Great

Jellied Eel

We'll probably get there soon. If I bomb a power plant as an individual, I'd be a terrorist. If as instructed by a nation, it could be a causus belli, or act of war. If I use a cyberattack, it's all good.

I think it's the same for economic warfare. We've frozen the assets of Russia's central bank, which is pretty hostile. We've frozen or seized assets of other civilians, which is pretty hostile. Especially given that's arguably collective punishment, and against Article 3 of the Geneva Convention. Which is probably why Russia insists this is a 'special' operation. Rules change once it's an officially declared war.

But for a long time, we've had wars that looked like wars, were described as wars, but legally were not. No war declarations for Gulf War 1 or 2, the Afghan War, the Syrian War. Or the general 'War on Terror'. But then wars are between nations.

Sorting the mess out and modernising the Geneva Convention to cover stuff like economic and cyber warfare is probably long overdue, and find out the hard way. But then economic warfare has been extremely profitable, so countries might be reluctant to give that up.

Re: Great

Anonymous Coward

Given my error.log files and any measure I'm apparently at war with OVH, Azure and DigitalOcean already, globally..

Wrong hands versus right hands

VoiceOfTruth

-> NOPEN wouldn't be the first time that NSA-developed offense code landed in the wrong hands

The usual nationalist western orientated (meaning USA) view that there are wrong and right hands, and of course the only 'right' hands are the USA's.

It's OK for the USA to spy on the world, but if anyone does it back, it's considered a bad thing. Please stop this nonsense. It is the act which is bad in itself. Taken to the logical conclusion, it's OK for the USA to commit genocide but not for anyone else.

Taken to the logical conclusion...

fxkeh

> Taken to the logical conclusion, it's OK for the USA to commit genocide but not for anyone else.

The USA was literally formed by the genocide of the native peoples of north America and it was justified as OK by calling it their Manifest Destiny.

somebody was calculating pi on the server