link between nsa regin cyberespionage malware becomes more clear
Last Updated : GMT 05:17:37
Emiratesvoice, emirates voice
Emiratesvoice, emirates voice
Last Updated : GMT 05:17:37
Emiratesvoice, emirates voice

Link between NSA, regin cyberespionage malware becomes more clear

Emiratesvoice, emirates voice

Emiratesvoice, emirates voice Link between NSA, regin cyberespionage malware becomes more clear

Keylogging malware
Tehran - FNA

Keylogging malware that may have been used by the NSA shares signficant portions of code with a component of Regin, a sophisticated platform that has been used to spy on businesses, government institutions and private individuals for years.
The keylogger program, likely part of an attack framework used by the US National Security Agency and its intelligence partners, is dubbed QWERTY and was among the files that former NSA contractor Edward Snowden leaked to journalists. It was released by German news magazine Der Spiegel on Jan. 17 along with a larger collection of secret documents about the malware capabilities of the NSA and the other Five Eyes partners—the intelligence agencies of the UK, Canada, Australia and New Zealand, PCworld reported.
“We’ve obtained a copy of the malicious files published by Der Spiegel and when we analyzed them, they immediately reminded us of Regin,” malware researchers from antivirus firm Kaspersky Lab said Tuesday in a blog post. “Looking at the code closely, we conclude that the ‘QWERTY’ malware is identical in functionality to the Regin 50251 plugin.”
Moreover, the Kaspersky researchers found that both QWERTY and the 50251 plug-in depend on a different module of the Regin platform identified as 50225 which handles kernel-mode hooking. This component allows the malware to run in the highest privileged area of the operating system—the kernel.
This is strong proof that QWERTY can only operate as part of the Regin platform, the Kaspersky researchers said. “Considering the extreme complexity of the Regin platform and little chance that it can be duplicated by somebody without having access to its source code, we conclude the QWERTY malware developers and the Regin developers are the same or working together.”
Der Spiegel reported that QWERTY is likely a plug-in of a unified malware framework codenamed WARRIORPRIDE that is used by all Five Eye partners. This is based on references in the code to a dependency called WzowskiLib or CNELib.
In a separate leaked document authored by the Communications Security Establishment Canada, the Canadian counterpart of the NSA, WARRIORPRIDE is described as a flexible computer network exploitation (CNE) platform that’s an implementation of the “WZOWSKI” Five Eyes API (application programming interface).
The document also notes that WARRIORPRIDE is known under the code name DAREDEVIL at the UK Government Communications Headquarters (GCHQ) and that the Five Eyes intelligence partners can create and share plug-ins for it.

 

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

link between nsa regin cyberespionage malware becomes more clear link between nsa regin cyberespionage malware becomes more clear

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

link between nsa regin cyberespionage malware becomes more clear link between nsa regin cyberespionage malware becomes more clear

 



GMT 10:18 2016 Wednesday ,23 March

cartoon seven

GMT 05:06 2024 Tuesday ,06 February

New hunt for flight MH370 gets under way

GMT 02:16 2017 Saturday ,07 October

Bespoke jewellery is the way to go

GMT 12:02 2017 Thursday ,07 December

Mayor London Sadiq Khan arrives in city

GMT 12:03 2011 Friday ,17 June

Broadcaster Gaunt loses appeal

GMT 10:58 2017 Wednesday ,15 February

Benfica sneak win as Aubameyang fluffs Dortmund's lines

GMT 09:09 2016 Thursday ,17 November

More than 50 dead in heavy Yemen fighting

GMT 08:39 2012 Saturday ,21 January

Biofuel breakthrough: kelp could power cars

GMT 04:15 2015 Sunday ,19 April

China to allow guide dogs on trains

GMT 06:31 2018 Friday ,05 January

Injured Andy Murray out of Australian Open

GMT 05:42 2017 Thursday ,16 November

Da Vinci painting sells for $450mn in NY

GMT 08:10 2015 Monday ,02 November

Manchester City seek statement win in Seville

GMT 15:54 2016 Saturday ,24 December

148 tourists visit Saint Catherine

GMT 04:57 2013 Friday ,20 December

Kids as young as 3 grasp multi-digit numbers

GMT 08:54 2011 Thursday ,29 September

Anzhi Makhachkala fire coach Gadzhiev

GMT 19:18 2012 Wednesday ,18 July

Smartphone network links lovers
 
 Emirates Voice Facebook,emirates voice facebook  Emirates Voice Twitter,emirates voice twitter Emirates Voice Rss,emirates voice rss  Emirates Voice Youtube,emirates voice youtube  Emirates Voice Youtube,emirates voice youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2025 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2025 ©

emiratesvoieen emiratesvoiceen emiratesvoiceen emiratesvoiceen
emiratesvoice emiratesvoice emiratesvoice
emiratesvoice
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
emiratesvoice, Emiratesvoice, Emiratesvoice