Menu
Navigation

Global articles on espionage, spying, bugs, and other interesting topics.

Keep abreast of the espionage threats facing your organisation.

New device lets you eavesdrop on others

    MIAMI – There’s a new device that lets you be James Bond. It’s called DetectiGo. DetectiGo can track someone anywhere in the world and listen to what they’re saying.

It’s small enough to be hidden in a backpack, a briefcase or in a glove compartment, according to founder Esteban Delaossa. Gustavo Roldan was one of the first people to own one of the devices. He wants to know where his teenage kids are.

“I use it for safety for my kids. It gives me an opportunity to know where they’re at, what they’re doing and when they’re doing it,” Roldan said.

“Why shouldn’t you have the right to know what you need to know?” said Delaossa.

If you set the device with a maximum speed, it can also alert you if the driver goes over it.

Soon it will give you constant, almost instant, GPS tracking and you will be able to set up a perimeter to notify you if the person you are tracking travels outside that zone.

“The typical average response by women is ‘I need this.’ The response of men is ‘You’re killing us,’ said Yesenia Hernandez of DetectiGo.

Legal expert David Milian says it’s not breaking the law to track someone. The legality of listening in on someone depends on where the person is located, he said.

“If it’s just tracking location, it’s the same thing you can do if you are watching someone and following them as long as you don’t do anything else,” said Milian.

DetectiGo costs $149 plus the cost of an air card to cover the cell charges.


Spying on compo claimants at Christmas

Judith Beck

HORRIFIED: Judith Beck was alarmed to find out she was under surveillance when awaiting compensatiojn for an injury. Picture: Annette Dew.
Source: The Sunday Mail (Qld)

A PRIVATE investigation firm has been branded “Scrooge” after offering to spy on compensation claimants over Christmas.

Surveillance Central at Toowong in Brisbane has emailed law firms offering “festive season surveillance” on injury compensation claimants.

The offer is aimed at lawyers representing insurers or firms sued for compensation. “It’s Scrooge-like,” said personal injury lawyer Ian Brown of Maurice Blackburn.

The Surveillance Central email says: “The holiday period often provides some tremendous surveillance opportunities.”

The investigator has offered to get footage of claimants putting up Christmas lights, going shopping and to parties and doing yard clean-ups.

Camping, fishing and beach trips, excursions to theme parks and holiday preparations also offered great opportunities for surveillance, according to the firm.

Mr Brown said often the footage was never shown in court because it proved that people were telling the truth about the physical effect of their injuries.

Sunshine Coast woman Judith Beck felt horrified after she found she had been under video surveillance over several years in the lead-up to an injury compensation case after a car accident.

When Ms Beck’s lawyer forced an insurer to reveal the video footage of her, which showed her claim was genuine, she saw she even had been filmed while walking inside her home.

Rod Trevor of Surveillance Central declined to comment.


Man sent to prison for economic espionage

BOSTON, Dec. 20 (UPI) — A Massachusetts man was sentenced to six months in prison and fined $25,000 for selling trade secrets of his employer, Akami Technologies Inc.

Elliot Doxer, 43, of Brookline pleaded guilty to one count of foreign economic espionage at a previous hearing. At his sentencing Monday, he also was given an additional six months of house arrest.

Federal prosecutors had sought a 36-month prison term.

During an 18-month period in 2009 and 2010, Doxer believed he was selling details of Akami contracts to an Israeli agent, who actually turned out to be an FBI investigator, Boston Business Journal reported.

A sentencing memorandum written by the government stated he tried to sell Israel “confidential contracts between Akami and the FBI, [Department of Homeland Security], a leading aerospace company and several Department of Defense contractors.” The total value of those contracts was near $10 million.

Doxer also insinuated to an agent that he wanted harm done to the mother of one of his children. “The mother is a terrible human being and has caused me tremendous suffering,” authorities said he told the agent. “Not enough bad things can happen to her, if you know what I mean.”


2012 Will See Rise in Cyber-Espionage and Malware, Experts Say

The security industry expects the number of cyber-espionage attacks to increase in 2012 and the malware used for this purpose to become increasingly sophisticated.

In the past two years there has been a surge in the number of malware-based attacks that resulted in sensitive data being stolen from government agencies, defense contractors, Fortune 500 companies, human rights organizations and other institutions. (See also “How to Remove Malware From Your Windows PC.”)

“I absolutely expect this trend to continue through 2012 and beyond,” said Rik Ferguson, director of security research and communication at security firm Trend Micro. “Espionage activities have, for hundreds of years, taken advantage of cutting-edge technologies to carry out covert operations; 2011 was not the beginning of Internet-facilitated espionage, nor will it be the end,” he added.

Threats like Stuxnet, which is credited with setting back Iran’s nuclear program by several years, or its successor, Duqu, have shocked the security industry with their level of sophistication. Experts believe that they are only the beginning and that more highly advanced malware will be launched in 2012.

“It is quite possible that we will see another of these threats in the near future,” said Gerry Egan, director of security response at Symantec. Duqu was used to gather design documents from companies that manufacture industrial control systems and could be a precursor to future Stuxnet-like industrial sabotage attacks, Egan explained.

“It is likely that new Duqu variations will cause mayhem in early 2012,” said Jeff Hudson, CEO of Venafi, a provider of enterprise key and certificate management solutions. “We have to be on a new state of alert to safeguard our assets and be better prepared to respond when the threat strikes.”

Battles, But Not Cyberwar

However, despite the emergence of Stuxnet and Duqu, security experts don’t believe that the world is actually watching a cyberwar in progress.

“To have any opposing action earn the title of ‘War’, there must be a declared state of conflict, and to my recollection, this has never happened in the case of CyberWar,” said professor John Walker, a member of the Security Advisory Group at ISACA, an organization that certifies IT professionals, via email.

“However, if we were to frame the question relating to ‘CyberConflict’, then I would consider this to be a very different case, where regular aggressive deployment of such capabilities occurs in one form of another in support of either a political or military purpose,” he added.

Countries like the U.S., U.K., Germany, China and India have established specialized teams and centers to defend government assets against cyberattacks and to even retaliate, if necessary. However, determining who is behind Internet-based hostile operations with certainty is impossible most of the time and that’s just one of the problems.

“All countries are wrestling with the question of retaliation,” Gerry Egan said via email. “If a blatant act of cyber war has occurred, how does one country retaliate and to what extent? What is a proportionate response?”

Threats like Stuxnet and Duqu could very well lead to major international cyber-conflicts in the future, but for now companies and governments should be more worried about cyber-espionage attacks that use simpler data exfiltration tools.

These unsophisticated, yet effective, pieces of malware are known in the security industry as Advanced Persistent Threats (APTs) and are usually distributed via social engineering. Operation Aurora, Shady RAT, GhostNet, Night Dragon and Nitro, are all examples of APT attacks reported during the last couple of years that have affected hundreds of organizations worldwide.

Bracing and Training

The number of APT attacks is likely to escalate in 2012 and defending against them requires frequent employee training and more aggressive protection technologies like those based on white-listing, file reputation, and application behavior.

“People still represent the weakest link in security for a large amount of enterprises and that is the reason they are targeted,” Ferguson said. “Training still has an important place in an organization’s security planning but it needs to be ongoing training, not a one-time only event.”

“So far we have been doing a much better job patching software than patching people,” said Amichai Shulman, CTO at security firm Imperva. “I spent time in the military trying to educate people about information security. It didn’t work there and it won’t work anywhere else.”

There should be a shift in protection paradigms and more control should be put around the data source. Restricting which applications can read certain information and detecting anomalous behavior, like sensitive data being accessed at strange hours of the day or being transferred in large quantity, is part of the solution, Shulman believes.

Technologies that can check a file’s reputation, age and regional popularity, before allowing it to be executed on a system can also be used to block APTs that were designed to evade traditional anti-malware detection methods.

“There is no doubt that major organisations need to be far more aware of the potential effects of malware,” said Jeff Hudson. “If this issue isn’t on the agenda of your board right now then the board is negligent,” he concluded.


Loyal accused of spying in Sydney-Hobart

AAP

Investec LOYAL’s thrilling Sydney to Hobart line honours win is under threat after its crew was accused of using an ABC helicopter pilot to spy on rival Wild Oats XI.

The race committee, and not the runner-up, has lodged a protest against the stunning victory – the fourth closest in race history – under a rule which polices outside assistance to boats.

LOYAL was on Wednesday night declared the provisional winner after its captain Anthony Bell was handed the protest documents on crossing the finish line in Hobart.

But the news, delivered by Cruising Yacht Club of Australia Commodore Garry Linacre, stunned the thousands lining the shore around Constitution dock as LOYAL lingered for close to an hour before docking.

A hearing will take place at the Royal Yacht Club of Tasmania at 10am (AEDT) on Thursday.

The race committee, chaired by Tim Cox, alleges the incident occurred at 6.30am on Tuesday, 30 nautical miles south of Merimbula on the NSW south coast.

The protest papers described the incident as: “Audio recording of conversation between ABC helicopter and Investec LOYAL.

“Crewman from Investec LOYAL seeking information from the helicopter of the sail plan in use on Wild Oats XI.

“In particular, information as to whether Wild Oats XI was flying a trysail.”

Linacre said the helicopter pilot would be a witness at the hearing, to be heard by an international panel, and if the protest was upheld the sanctions could include time penalties and even disqualification.

Bell attempted to explain the situation on reaching the shore, saying it was a misunderstanding involving an ABC interview with crewman Michael Coxon, who is also the chief executive of a company that supplies the sails to Wild Oats.

“It was the ABC who actually asked for the interview off us, it wasn’t actually the other way round,” Bell said.

“It was just a question by Michael saying, `oh geez, are they all right and I hope they haven’t broken their mainsail’.

“These things cost a quarter-of-a-million dollars and of course he would be concerned as to his business reputation.”

Bell said he was confident the victory would be confirmed by the panel.

“Michael (Coxon) is probably one of Australia’s most decorated yachtsman and he’s never had a skerrick in his whole career of any protest for improper behaviour,” he said.

“It is a bit anti-climactic.

“One thing that can’t be taken away from us, no matter what happens, no matter what’s said, is we sailed one hell of a race out there.”

LOYAL fought off a thrilling, last-ditch attacking onslaught from Wild Oats on the Derwent River to claim what would have been a first line honours victory for the boat.

Still eyeballing each other as they hit the river, LOYAL saw off some desperate manoeuvring from the five-time winner and race record holder to cross the finish line at 7.14pm (AEDT).

In one of the tightest finishes in the race’s history, LOYAL won with a margin of 3 minutes 8 seconds in a time of 2 days, 6 hours, 14 minutes and 18 seconds.

The ABC posted audio of the conversation between Coxon and its helicopter crew on its website.

Coxon is heard to say: “Can you confirm, does Wild Oats have their trysail up? … What colour is the mainsail they’ve got up?”

He is answered that both sails are grey and replies: “Copy that. That’s great news. Thanks, bye.”