Information Assurance Situation in Switzerland and Internationally
Total Page:16
File Type:pdf, Size:1020Kb
Federal IT Steering Unit FITSU Federal Intelligence Service FIS Reporting and Analysis Centre for Information Assurance MELANI www.melani.admin.ch Information Assurance Situation in Switzerland and Internationally Semi-annual report 2011/II (July – December) MELANI – Semi-annual report 2011/II Information Assurance – Situation in Switzerland and Internationally Contents 1 Focus Areas of Issue 2011/II ....................................................................................... 3 2 Introduction .................................................................................................................. 4 3 Current National ICT Infrastructure Situation ............................................................ 5 3.1 Calls by scammers claiming to be employees of Microsoft customer service ... 5 3.2 Increase in hacked e-mail accounts ................................................................. 6 3.3 A holiday card to steal passwords .................................................................... 7 3.4 Phishing attacks: Technical optimisation .......................................................... 9 3.5 Now also in Switzerland: Malware blocking PCs and demanding payment .... 10 3.6 Politicians targeted by hackers ....................................................................... 11 3.7 Mass hacking of webshops ............................................................................ 12 3.8 Bogus websites of real estate companies advertise jobs for financial agents . 12 3.9 Control systems with Internet connections – Special security awareness necessary ....................................................................................................... 13 4 Current International ICT Infrastructure Situation ................................................... 15 4.1 Attack on Dutch certificate authority ............................................................... 15 4.2 SCADA – Malware, attacks and vulnerabilities ............................................... 17 4.3 Anonymous .................................................................................................... 19 4.4 Alleged state actor spied on computer systems worldwide for many years, including the UN in Geneva and the IOC ........................................................ 20 4.5 Various hacking attacks ................................................................................. 21 4.6 Deactivation of DNSChanger botnet .............................................................. 22 4.7 Law enforcement trojans ................................................................................ 22 4.8 WikiLeaks divulges trade in surveillance and forensic software ...................... 24 4.9 Strategies and exercises ................................................................................ 25 5 In-depth Analyses and Trends .................................................................................. 27 5.1 Smart grid and home automation ................................................................... 27 5.2 Anonymous – the advantages and disadvantages of the open structure ........ 28 5.3 "Good" and "bad" surveillance on the Internet ................................................ 29 5.4 Security in the mobile age – How do I protect my smartphone? ..................... 30 5.5 Attacks on certificate service providers and their impact ................................ 32 6 Glossary ..................................................................................................................... 33 2/2 MELANI – Semi-annual report 2011/II Information Assurance – Situation in Switzerland and Internationally 1 Focus Areas of Issue 2011/II • Attacks on certificate service providers and their impact In the course of an attack on DigiNotar, a Dutch certificate authority, more than 530 bogus certificates were issued, including for the domain windowsupdate.com, which is home to the update function for all Microsoft Windows products, and various Google domains. ► Current situation internationally: Chapter 4.1 ► Trends / Outlook: Chapter 5.5 • Cyberactivism "Anonymous" once again caught the media's interest with various operations in cyberspace over the past months. But who exactly is behind "Anonymous"? According to numerous statements, "Anonymous" is not an organisation per se, but rather something more like an attitude to life. Support is not tied to any particular form: Every activist does what he or she believes to be right. This may in fact also lead to actions that do not enjoy broad support in the movement and thus provoke contradictory messages. ► Current situation internationally: Chapter 4.3 ► Trends / Outlook: Chapter 5.2 • "Good" and "bad" surveillance on the Internet The analysis of the German law enforcement trojan (often referred to using the undifferentiated term "federal trojan") by the Chaos Computer Club triggered debates about its use not only in Germany, but also in Switzerland. Additionally, WikiLeaks began to publish numerous documents on 1 December 2011, which are purported to show that private security companies are selling ICT solutions to states with predominantly autocratic governments and lack of respect for human rights. This debate, which is in fact old but has been rekindled, arises from one of the fundamental problems of the Internet, the networked society, and ICT. The emergence of new options all the time to communicate, to exchange data and information, and to make them available everywhere and always, has consequences: The measures to locate and obtain information, and generally the work of the security authorities of a state, are becoming much more complicated. ► Current situation internationally: Chapter 4.7, Chapter 4.8 ► Trends / Outlook: Chapter 5.3 • Phishing, fraud and ransomware on the rise A new phenomenon observed in Switzerland since summer 2011 is calls by scammers who pretend to be employees of Microsoft customer service, in order to gain access to computers. Phishing has also increased heavily in the last 6 months and is targeting primarily e-mail providers and credit card companies. To keep fraudulent websites active for as long as possible, criminals are trying new methods intended to make it more difficult to shut down phishing sites. At the beginning of November, ransomware was disseminated, claiming to be from the Federal Department of Justice and Police. ► Current situation in Switzerland: Chapters 3.1, 3.2, 3.3, 3.4, 3.5 3/3 MELANI – Semi-annual report 2011/II Information Assurance – Situation in Switzerland and Internationally 2 Introduction The fourteenth semi-annual report (July – December 2011) of the Reporting and Analysis Centre for Information Assurance (MELANI) presents the most significant trends involving the threats and risks arising from information and communication technologies (ICT). It provides an overview of the events in Switzerland and abroad, illuminates the most important developments in the field of prevention, and summarises the activities of public and private actors. Explanations of jargon and technical terms (in italics) can be found in a Glossary (Chapter 6) at the end of this report. Comments by MELANI are indicated in a shaded box. Selected topics covered in this semi-annual report are outlined in Chapter 1. Chapters 3 and 4 discuss breakdowns and failures, attacks, crime and terrorism connected with ICT infrastructures. Selected examples are used to illustrate important events of the second half of 2011. Chapter 3 discusses national topics, Chapter 4 international topics. Chapter 5 includes in-depth analyses and trends on current topics. 4/4 MELANI – Semi-annual report 2011/II Information Assurance – Situation in Switzerland and Internationally 3 Current National ICT Infrastructure Situation 3.1 Calls by scammers claiming to be employees of Microsoft customer service Recently there has been an increase worldwide, and also in Switzerland, of calls by scammers claiming to be employees of Microsoft or other ICT support companies. The callers generally speak English and claim to be from the United States, England or Australia. In many cases, the callers refer to error messages that supposedly had been transmitted by the computers of the contacted business or individual. The persons called are, for instance, told to launch the Event Viewer1, which can be used to display all events and activities running on the computer. It should be noted in this regard that even a perfectly functioning system may on occasion generate error messages. Depending on the age and configuration of the computer, the list of error messages in the Event Viewer may even be very long, although the system does not have any fundamental problems. The launch of this programme is generally used by the "support" callers to present a credible backdrop for the victims and to scare them. The scammers' goal is to convince the persons called that they should download a programme, thereby giving the scammer remote access to the computer. Once this access is granted, the caller has the same options to manipulate the computer as if he were sitting directly at the computer (copy/change/delete data, install programmes, set up a "back door" to access the system at a later time, etc.). Sometimes, the callers also offer to set up a support subscription or a guarantee and ask for credit card data or other form of payment for that purpose. The callers apparently look for victims using public directories, such as the Swiss Commercial Register or public telephone books.