BLN RSS

More Blacklisted News Blacklisted Newsletter Blacklisted Radio
On Twitter
On Youtube
On Roku
On Facebook
Podcasts on Demand
Podcasts on Spreaker
Podcasts on iTunes
Podcasts on Stitcher
Podcasts on Tunein Radio



Donate Today

Affiliates
6 Dollar T-Shirts
Nuvona Premium Foods GoldSilver.com
The Ready Store
Onnit Labs
Audible Audio Books
Amazon.com
Bulletproof Coffee
Blue Host

Blog Roll
What Really Happened
Cryptogon
Citizens for Legit Gov.
Full Specturm Dominance
Information Liberation
VICE
Cryptome
All Gov.
Michael Snyder
Tony Cartalucci
VoltaireNet
The New American
Raw Story
Truth Dig
Antiwar
Drudge Report
Breitbart
The Peoples Voice
Real News Network
Alternet
Information Clearing House
VOA News
Truth Out
Common Dreams
No Agenda News
Aangirfan
Old Thinker News
Activist Post
Dark Politricks
SGT Report
Andrew Gavin Marshall
Tom Burghardt
Dana Gabriel
Jacob Hornberger
Media Monarchy
Truth Is Treason
Reason
Lew Rockwell
Strike The Root
10th Amendment Center
Globalist Report
Survive Change
Explosive Reports
Vigilant Citizen
Red Ice
Wayne Madsen
WhoWhatWhy
Silent Crow
Wtfrly
From The Trenches
WhoWhatWhy
Liberty Garage
Boing Boing
Freedom Outpost
Resist Radio
Wide Awake News
News Blok 2
Against The Wall
End The Lie
Disinformation
SHTF Plan
ITHP
The Excavator
Open Secrets
Project Censored
Business / Economics
Gold and Metals Prices
Coin Values
Zero Hedge
Testosterone Pit
Washingtons's Blog
Of Two Minds
Money News
Max Keiser
Naked Capitalism
Sovereign Man
Business Insider
Market Watch
Bloomberg
Wall Street Journal
RTT News
CNN Money
Forbes
Business Week
Market Oracle
Money Morning
My Budget 360
Alt-Market
Shadow Stats
Azizonomics
Economist
Economy Watch
Financial Times
Fortune Magazine
Daily Crux
The Daily Economist
The Daily Reckoning
Energy Business Review
Faux Capitalist
Daily Bail
Hang The Bankers
Against Crony Capitalism
Economic Policy Journal
Gonzalo Lira
Liberty Blitzkrieg
The Burning Platform
The Daily Bell
Milplex / Intel / Defense
Strat Risks
Oil Price
Phantom Report
Global Research
Foreign Policy Journal
Global Post
Intel News
1913 Intel
F. William Engdahl
Rick Rozoff
Corbett Report
Public Intelligence
Boiling Frog Post
Danger Room
Washington Technology
Defense Industry Daily
Global Security
Geopolitical Monitor
Defense Link
Space War
Jane's
Defense Tech
Strategy Page
Military Info Tech
Strategy Page
Homeland Sec. Newswire Science / Tech News
Tech Dirt
Ars Technica
Wired
Blast Magazine
PHYSorg
Science Daily
Popular Science
Tech Eye
Engadget
New Scientist
DVice
Mother Board
EFF
Technovelgy
Next Big Future
Singularity Hub
H+ Magazine
Science Magazine
Seed Magazine
CBR Online
Science News
SlashDot
Scientific American
Spectrum IEEE
Technology Review
io9
ZD Net
Technology News
The Register
Tech News World
Health & Environment
Prevent Disease
Food Freedom
Farm Wars
Medical Express
Natural Society
Waking Times
Natural News
Major US Newspapers
New York Times
New York Post
New York Daily News
Washington Post
Washington Times
L.A. Times
USA Today
Magazines
The Atlantic
Salon
Slate
Time











‘Madi’ Cyber Espionage Campaign in Middle East Uncovered

July 17, 2012

cyber_securityThe active cyber-espionage campaign is targetting very specific victims including employees of critical infrastructure companies, financial services and government embassies, which are mainly located in Middle Eastern countries.

So far it is unclear whether or not this is a state-sponsored campaign like Stuxnet and Flame but the security company which first identified it, Seculert, has said the operation could require “a large investment and financial backing.” However the Madi info-stealing malware is also technically rudimentary in comparison to Stuxnet and Flame.

Seculert contacted Kaspersky Lab who discovered the highly-sophisticated Flame virus in order to help track the activity of the malware.

Seculert first noticed an interesting, yet simple, spearphishing attack which seemed to be targeting victims in the Middle East and relied on social engineering techniques to spread.

The malware was embedded within documents, such as text files and PowerPoint presentations, sent to specific victims. Once opened the malware would install on the victim’s PC and connect with one of four Command and Control (C&C) servers around the world – including Canada and Iran.

According to Kaspersky Lab, the Madi info-stealing Trojan enables remote attackers to steal sensitive files from infected Windows computers, monitor sensitive communications such as email and instant messages, record audio, log keystrokes, and take screenshots of victims’ activities. Data analysis suggests that multiple gigabytes of data have been uploaded from victims’ computers.

“While the malware and infrastructure is very basic compared to other similar projects, the Madi attackers have been able to conduct a sustained surveillance operation against high-profile victims,” said Nicolas Brulez, Senior Malware Researcher at Kaspersky Lab. “Perhaps the amateurish and rudimentary approach helped the operation fly under the radar and evade detection.”

While it is still unclear who is behind the Madi malware, one indicator of its provenance was discovered within the code: “Interestingly, our joint analysis uncovered a lot of Persian strings littered throughout the malware and the C&C tools, which is unusual to see in malicious code. The attackers were no doubt fluent in this language,” said Aviv Raff, Chief Technology Officer at Seculert.

While it seems clear that Madi is not directly related to Flame or Stuxnet, it is impossible to say for certain where this malware originated, and considering the range of countries targeted, it could suggest a perpetrator outside the Middle East.