The Terror of Hackers

U.S. arrests three men over hacking scheme targeting 60 million people

Cybersecurity researcher Billy Rios points to a computer line reading ''Gods Password,'' a password he was able to uncover by analyzing the software in a Pyxis medical supply dispenser that he says he purchased on Ebay for a few hundred dollars, in Redwood City, California October 10, 2014. REUTERS/Robert Galbraith

Reuters: Three men were arrested on Monday for engaging in a wide-ranging hacking and spamming scheme that targeted personal information of 60 million people including Comcast customers, U.S. prosecutors announced Tuesday.

Timothy Livingston, 30, Tomasz Chmielarz, 32, and Devin McArthur, 27, were named in an indictment filed in federal court in Newark, New Jersey that charged them with conspiracy to commit fraud and related activity among other offenses.

Prosecutors said Livingston, a Boca Raton, Florida, resident, was the leader of a series of computer hacking and illegal spamming schemes that targeted multiple companies and generated illegal profits exceeding $2 million.

The three men were arrested at their respective residences on Tuesday morning, a spokesman for U.S. Attorney Paul Fishman in New Jersey said.

Michael Koribanics, Chmielarz’s lawyer, said his client would plead not guilty at a court hearing on Tuesday. A lawyer for Livingston did not immediately respond to a request for comment, and an attorney for McArthur could not be identified.

Prosecutors said Livingston, who owned a spam company called “A Whole Lot of Nothing LLC,” hired Chmielarz of Rutherford, New Jersey to author hacking tools and other programs that facilitated the hacking and spamming schemes.

Among the companies they targeted was a Pennsylvania-based telecommunications company that employed McArthur, a resident of Ellicott City, Maryland, who installed hacking tools in company networks to gain access to records for 50 million people, prosecutors said.

The company was not identified by name in court papers. But McArthur’s LinkedIn page says he worked at Comcast Corp during the period in question. A Comcast spokeswoman had no immediate comment.

Livingston and Chmielarz also compromised tens of thousands of peoples’ email accounts, including customers of a New York telecommunications company, which they then used to send spam, the indictment said.

Other companies targeted in the schemes included a New York-based technology and consulting company whose website was compromised and a Texas-based credit monitoring firm that was hacked, the indictment said.

In the case of the unnamed credit monitoring firm, the indictment said Livingston paid Chmielarz to write a program to steal a database containing 10 million records.

When law enforcement seized Livingston’s computer in July, they discovered a database with 7 million of that company’s records, the indictment said.

New OPM Cyber Chief Is Bracing for an ISIS Hack

The new cybersecurity adviser hired by the Office of Personnel Management after a Chinese-originated hack says he expects ISIS may ultimately pierce the agency’s systems, too.

The historic data breach exposed the professional and private lives of 21.5 million individuals applying for clearances to handle classified information, plus their families. That kind of information, drawn from background investigations, would be perfect for blackmail attempts.

But Clifton Triplett—named OPM’s first-ever senior cyber and information technology adviser last month—says forthcoming access controls will blunt the severity of any future hack.

I think what I have to do is … assume that, at some point in time, they may be successful,” Triplett said when asked about the ISIS cyber threat during a webcast hosted by Bloomberg Government on Monday.

Going forward, OPM will “make it more of a need-to-know kind of access control,” he said, “so if we do have a compromise, it is far more contained than, for example, our last incident.”

The agency, he explained, will institute the equivalent of tear lines on network data to grant as little information as possible to authorized personnel.

Right now, I think, in some of our situations, the access control is broader than perhaps needs to be,” Triplett said, because OPM computer programs were developed before data security became a governmentwide priority.

So far, ISIS sympathizers have been hacking more for show, than for spying.

In early 2015, the self-described Cyber Caliphate group reportedly took control of the social network accounts of U.S. Central Command.

Then, global television network TV5Monde was disabled for hours in April, when the hacktivists apparently replaced the company’s channels, websites and social media accounts with pro-ISIS messaging.

ISIS’ online propaganda often directs followers to kill U.S. and allied troops and supplies the necessary contact information. But much of the data released has turned out to have already been in the public domain.

Still, America viewed at least one ISIS hacker as enough of a threat to kill him in a targeted attack.

The Justice Department claims Ardit Ferizi breached a server to retrieve identifying details on about 1,350 military and other government personnel. He then allegedly passed the data on to Islamic State member and Cyber Caliphate ringleader Junaid Hussain, a British citizen. Hussain is accused of beckoning adherents to target U.S. personnel, posting links on Twitter to their names, email addresses, passwords, locations and phone numbers. Hussain was reportedly killed in a U.S. drone strike this summer.

But what really frightens Triplett is that OPM’s records sit beside smart toasters and air conditioners in the Internet of Things, he said.

We’re too interconnected. Not enough air gaps in our systems” that physically decouple networks from the Internet, he said. “We are trying to automate and connect one more thing to one more thing.”

Today, background check records are one of those things.

Eventually, Triplett said he fears, “I’ll have a reasonably minor event that will turn into a catastrophic event, and I won’t be able to find out where the root cause was because of the ripple potential.”

Currently, “there’s no way” to cut off the systems from the Internet, OPM’s IT security officer, Jeff Wagner, told Nextgov in October.

Wagner said, “even clearance data” must be online, because the only other option is to exchange paper folders with agency partners like the Social Security Administration.

Adversaries, however, would have to circumvent multiple identity checks and firewalled systems to peer at the personnel records, Wagner said.

 

 

Paris Attack Weapon Came From Florida

Gun linked to Paris Attack came through South Florida dealer

One of the guns linked to Islamic militants in the Paris attacks that killed 130 people was exported to the United States in 2013, the head of a Serbian arms factory said Thursday.

Milojko Brzakovic of the Zastava arms factory told The Associated Press that the M92 semi-automatic pistol’s serial number matched one his company delivered to an American online arms dealer in May 2013. It was not clear how the gun got back to Europe.

At least seven of the weapons used or discovered after the Nov. 13 attacks in Paris have been identified as being produced by the Serbian factory located in Kragujevac, in central Serbia. Most were manufactured before Yugoslavia broke up in a civil war in the 1990s and most of those are modified versions of the Soviet AK-47, or Kalashnikov.

Brzakovic said all the guns were delivered legally but could have later found their way into illegal channels.

“One was delivered to Bosnia in 1983, one to Skopje, Macedonia in December 1987, one to Golubici, near Knin (Croatia) in 1988, one to Zagreb (Croatia) 1987,” he said.

He said the M92 pistol “is a semi-automatic weapon, a hunting and sporting weapon … it cannot fire barrage fire, only single shots … which are legal in America.”

He said it was exported to an online arms seller in the United States, the Florida-based Century Arms, to which his factory exports up to 25,000 hunting and sports guns every year. He said the gun was delivered as a semi-automatic, but he did not know whether someone turned it into an automatic after delivery. The so-called “shortened Kalashnikov” is listed by U.S. arms dealers as selling for about $460 apiece.

In a video posted online in December 2013, Century Arms advertised they were selling the AK-style pistol PAP M92, “a brand new firearm from the Zastava factory in Serbia” and demonstrated its attributes.

The AP left messages seeking comment on the gun with Century Arms, the FBI and another U.S. government agency, the Bureau of Alcohol, Tobacco, Firearms and Explosives.

Brzakovic insisted that all arms exports from Serbia are under strict government control.

“We submit a request to our government to give consent and authorize the export. Until we receive that, we make no contract. Once we get a permission to export, we make a contract and arrange the dynamics,” he said.

A web of rules and a large U.S. bureaucracy oversee the legal import and export of weapons like the Serbian M92 semi-automatic pistol.

American government approval is required to import firearms into the U.S.

To legally ship firearms back out, the individual or company would have to be registered with the State Department, which controls items covered by the U.S. Munitions List. An export request is submitted to State and a decision to grant the request is based on a variety of factors, including the type of weapon and its eventual destination.

Individual weapons are not tracked by serial numbers unless a single weapon is being exported, according to the State Department. The U.S. does not make publicly available the names of licensed weapons exporters as that information is considered proprietary.

Brzakovic said it would be wrong to accuse Zastava of selling weapons to terrorists.

“Here’s where the weapons ended, there’s the data. Zastava cannot be blamed for where it went afterward,” Brzakovic said.

But he agreed that an illicit gun deal could have taken place even after arms were delivered legally.

“Wherever there are wars, there are bigger possibilities for abuse and to hide the channels for guns. They end up where they shouldn’t,” he said, adding: “We have a data base in the factory for the last 50 years, we know where a gun has been delivered.”

***

Zastava Arms (Serbian Cyrillic: Застава oружје) is a Serbian manufacturer of firearms and artillery, based in Kragujevac, Serbia. It was founded in 1853 when it cast its first cannons. It is the leading producer of firearms in Serbia and is a large contributor to the local defense industry. Zastava Arms produces and exports a wide variety of products to over forty countries.

Zastava Arms was heavily damaged during World War II. When Kragujevac was liberated in October 21, 1944, the weapons factory was put back into working order within months and production began shortly after, with the 9mm M 1944 B2 submachine gun developed during the same year. The next postwar production rifle was the 7.92×57mm Mauser Model 1948 on the basis of Model 24. The production of air rifles and sporting rifles on the basis of rifle M48 started in 1953. In 1954 the Zastava started the production of shotguns and small bore rifles, as well as machine gun 7,9 mm M42 ¨Sarac¨. Batch production of semi-automatic rifle PAP M59 7.62×39mm started in 1964. In the 1964, the factory started the development of automatic rifle, of Kalashnikov system, which was named M67 in 1967. On the basis of rifle M67, the factory developed automatic rifle in caliber 7.62×39mm, which was named Zastava M70 in the following year. Yugoslav People’s Army included assault rifle M70 in calibre 7.62 x 39 mm into its armament in 1970. Small arms derivatives of the M70 produced rifles chambered in Western bloc ammunition such as 7.62×51mm NATO and 5.56×45mm NATO. In 1988, the factory developed a compact design pistol in 9 mm Parabellum model M88.

PAP M59/66 (Yugo SKS) with a rifle grenade launcher and folding bayonet.

In the 1980s, the plant for action of machine guns M84, M86 in 7.62×54mmR and heavy machine gun in 12.7 NSV M87 was set to operation as well. In July 1989 Zastava started the development of the double-action pistol in calibre 9mm PARA CZ 99. In 1992, the factory finished the development and testing and started batch production of 7.62 mm submachine gun M92, based on submachine gun M85. Using the Mauser mechanism, the factory developed 12.7 mm long range rifle Black Arrow M93. During the Yugoslav Wars of 1991 to 1995, the United Nations placed economic sanctions on the import and export of weapons from Yugoslavia, production slowed as a result. In 1999 the factory was damaged by NATO bombing. In 2005 Zastava Arms underwent restructuring. The same year, a memorandum of understanding was signed with Remington Arms to export hunting and sporting guns to the United States, Canada and Mexico.

Ollie North with the Peshmerga vs. Islamic State

By the way, the Peshmerga are Muslims.

Obama’s non-war and the consequence on humanity versus Islamic State:

TheHill: A U.S. aircraft carrier passed through the Suez Canal on Tuesday, creating a presence that will allow the U.S. to ramp up airstrikes against the Islamic State in Iraq and Syria (ISIS). The USS Harry S. Truman is due to arrive in the Persian Gulf right around Christmas, where it will begin striking the terrorist group, a Navy official told The Hill.

The Truman and its accompanying carrier strike group will join the French aircraft carrier Charles De Gaulle in the Gulf, which reportedly arrived earlier this month.

The U.S. has steadily increased airstrikes against ISIS, with November hitting a high of 3,271 bombs, according to U.S. Central Command statistics.

Twisted logic designed by the Obama White House and the new ISIS Czar:

    President Obama’s new ISIS czar said yesterday that resolving the Israel Palestine conflict is necessary to defeating Islamist extremists. Rob Malley, senior advisor to Obama “for the Counter-ISIL Campaign in Iraq and Syria” and White House Coordinator for the Middle East and North Africa, said at a New York conference that the conflict enables ISIS in two ways. Extremists “refer constantly” to the situation of Palestinians. So they would lose a recruiting tool if the matter were resolved. And the failure to resolve the conflict makes it “very difficult” to get “the kind of open cooperation that we really need to get changes on the ground”– because Saudi Arabia and other states can’t work openly with Israel as matters stand. Malley said that resolving the conflict was not a “magic wand” to ending problems in the Middle East, but asked if ISIS’s next stop was going to be Gaza or the West Bank, he went on: I don’t know where the next stop will be but I think there’s a more basic point, which is that the absence of a resolution is fueling extremism. If you want to go to Gaza that’s self-evident. Whether ISIS is going to have a foothold there.. that’s a separate question. But I think it stands to reason that resolving this conflict would at least help, it wouldn’t resolve– but it would be a major contribution to stemming the rise of extremism, and to allow the kind of cooperation that is needed [to take on] what should be a common challenge, which is the challenge of ISIS, and of other extremist organizations.

As Oliver North described in the video above, the Baghdad government is directed by Iran, a rogue nation sponsor of terror of which Obama and John Kerry have normalized relations forcing the world to accept the whole Tehran regime.

But what about our own hemisphere?

Iran Taking Over Latin America

  • “This is a matter of life or death. I need you to be an intermediary with Argentina to get help for my country’s nuclear program. We need Argentina to share its nuclear technology with us. It will be impossible to advance with our program without Argentina’s cooperation.” – Iran’s former President Mahmoud Ahmadinejad to the late Venezuelan President Hugo Chávez.
  • According to Venezuelan informants, whitewashing Iran’s accused from the AMIA attack was only a secondary objective in its outreach to Argentina. The primary objective was to gain access to Argentina’s nuclear technology and materials — a goal Iran has for more than three decades.
  • During the last 32 years, Iran has achieved a resounding success in promoting an anti-US and anti-Israel message in Latin America. Its state-owned television network, HispanTV, broadcasts in Spanish 24 hours a day, seven days a week in at least 16 countries throughout the region.
  • The lifting of sanctions and influx of billions of dollars as a result of Iran’s nuclear deal will undoubtedly help Iran in Latin America, where many countries face economic turmoil and can use an Iranian “stimulus.”
  • While Latin America is often regarded as a foreign policy backwater for the United States, it is the geopolitical prize for the Islamic Republic of Iran.

During the last couple months, Iran and Saudi Arabia have been playing a political tug of war over Latin America. On November 10, 2015, Iran’s deputy foreign minister held a private meeting with ambassadors from nine Latin American countries to reaffirm the Islamic Republic’s desire to “enhance and deepen ties” with the region. This was followed by similar statements from Iranian President Hassan Rouhani and Supreme Leader Ayatollah Ali Khamenei at the Gas Exporting Countries Forum (GECF) in Tehran later that month.

The same day, the Saudi Foreign Minister, Adel al-Jubeir, presided over a South American-Arab world summit in Riyadh. FM al-Jubeir, while Ambassador to the United States in 2011, had himself been the target of an Iranian-Latin American assassination plot. Read the full summary complete with citations here.

Introducing the New Terror Alert System

From the White House in 2011:

Homeland Security Secretary Janet Napolitano announces the launch of the new National Terrorism Advisory System, which will replace the old color-coded system with more detailed and more complete information for your safety. (Summary from the White House here)
Only 5 years later:

Feds Tweak Terror Alert System

The new “bulletin” alerts will describe developments and trends in “persistent and ongoing threats”

Time: Federal officials will begin issuing “bulletins” describing non-specific and ongoing terrorist threats to the U.S., according to a senior official at the Department of Homeland Security who spoke to the press Tuesday night

The idea is that these bulletins will add a third, more general threat level to the federal government’s current terror warning system, which the official said did not provide enough “flexibility.”

NTAS Guide in .pdf

The current National Terrorism Advisory System (NTAS) currently has only two levels. An “elevated” alert flags a credible terrorist threat to the U.S. and an “imminent” alert flags a “credible, specific, and impending” threat to the U.S., the official explained. Neither advisory has been used since the system was launched in 2011.

The new, “bulletin” alert level, which goes into effect Wednesday, will describe “current developments and trends” regarding “persistent and ongoing threats” to the U.S. or the American people, the official said. In some cases, a bulletin might include a description of the threat, what federal agencies are doing to address it, and what the American people can do to keep their families and communities safe.

“The secretary believes that he needs a more flexible way of communicating threats to the American people and will put in a third level of advisory, known as the bulletin,” the official said during a media phone call in which he spoke on background.

“We have witnessed constantly evolving threats across the world, from Garland to the streets of Paris, to San Bernardino,” he added. “We have also heard repeated calls from ISIL against our citizens, our military and our law enforcement personnel. In light of these persistent activities, the secretary thought it necessary to… share more information with our fellow citizens.”

The Homeland Security Department and other government agencies have been reviewing NTAS for the last nine months, the official said. The addition of the bulletin is not a direct response to any recent terrorist activity.

In 2011, former Homeland Security Secretary Janet Napolitano launched NTAS to replace the older, five-tiered, color-coded terror warning system created after the Sept. 11 attacks. The color-coded system was criticized for its vagueness, for never dropping below yellow, signifying “significant risk,” and for requiring that the alert color be reported, via automated recordings, at airports and other public spaces. It was widely mocked by comedians and political satirists.

NTAS was designed in 2010 to be more specific. Both “elevated” and “imminent” alert levels would include information about which geographic region, mode of transportation, or type of infrastructure is under threat. Both alert levels also include an expiration date, after which time the alert expires. The new bulletin alerts will be ongoing.

Valerie Jarrett has Stepped up Islamic Protection

The Muslim organizations around the country have become a de-facto protected class and what is worse, the Obama administration is in full lock step to reciprocate the protections. The next huge question is exactly how does the White House know the names of all of them and the top leadership individual names and phone numbers to have a full call to action? (rhetorical)

A full court press, but not so much for the victims of militant jihad in America. Anymore questions about where the White House lays it true loyalty?

WashingtonExaminer: The White House on Monday began “staff-level” meetings and calls with religious leaders to discuss how they could help combat growing anti-Muslim sentiment in the United States.

Valerie Jarrett, senior adviser to President Obama, and Melissa Rogers, who leads the White House Office of Faith-Based and Neighborhood Partnerships, held a conference call with leaders of all religions from across the country.

“Spoke with 890+ religious leaders to thank them for speaking up for every American’s right to be free from religious discrimination,” Jarrett tweeted on Monday.

Administration officials “routinely” interact with religious leaders, White House spokesman Josh Earnest said on Monday, stressing that the latest round of talks is being led by staff members, not the president.

The call Jarrett led was a “conversation to discuss efforts to combat discrimination and highlight the need for welcoming all faiths and beliefs,” Earnest said. “It certainly seems a timely topic for a conversation like that,” he said, noting the uptick in anti-Muslim rhetoric since the radical Islamic terrorist group, the so-called Islamic State, launched deadly attacks in Paris and inspired a shooting spree in San Bernardino, Calif.

The “hateful, divisive” comments of a “handful of Republicans running for president is hurtful and dangerous” to the nation’s national security, Earnest said, presumably referring to candidates such as Donald Trump, who has proposed banning all Muslims from the U.S.

Also on Monday, Jarrett, Director of the White House’s Domestic Policy Council Cecilia Munoz, and Deputy National Security Advisor Ben Rhodes are hosting a group of Muslim-American leaders at the White House, Earnest said.

And finally, Munoz is meeting with representatives of America’s Sikh community, Earnest said.

In addition to a massacre at a Sikh temple in Wisconsin in 2012, hate crimes against Sikhs have spiked since the Sept. 11, 2001 terrorist attacks, often because attackers mistook Sikhism adherents for Muslims.

The White House is hosting similar meetings all week, including one on Thursday, Earnest said.

“Again these are all slated to be staff-level meetings but yet, are representative of the kind of ongoing dialogue that the White House maintains with religious leaders of all faiths all across the country,” Earnest said.