ALKHOBAR: A front page story in yesterday’s Arab News reported on an electronic spying operation called GhostNet, which infiltrated computers in 103 countries. The computers were taken over by social malware. Basically, the computers were infected through what appeared to be legitimate e-mails which carried attachments with malicious payloads. Getting into the computers was really only half the story. Perhaps the bigger issue is what this means in terms of cybercrime.
In its report on the ten-month investigation into the spying operation, the Information Warfare Monitor noted that beyond the issue of state-sponsored espionage, “the threshold for engaging in cyber espionage is falling. Cybercrime kits are now available online, and their use is clearly on the rise, in some cases by organized crime and other private actors. Socially-engineered malware is the most common and potent; it introduces Trojans onto a system, and then exploits social contacts and files to propagate infections further. Furthermore, the Internet was never built with security in mind. As institutions ranging from governments through to businesses and individuals depend on 24-hour Internet connectivity, the opportunities for exploiting these systems increase.”
The unmasking of such a large spynet should be a warning to all organizations, public and private, that their data is under threat. The investigation determined that GhostNet easily infiltrated many high-value targets. The spynet was considered to be technically unsophisticated yet it was able to penetrate the computers at security agencies, ministries and nongovernmental organizations. It was only uncovered because the office of the Dalai Lama suspected that their computers had been hacked. The other affected groups were apparently oblivious.
The Principal Investigators and co-founders of the Information Warfare Monitor, Rafal Rohozinski, principal and CEO, The SecDev Group, and Ronald Deibert, director, the Citizen Lab asserted that computer penetration of the type used in GhostNet is not uncommon, particularly for cybercrime networks. GhostNet is not the only such network uncovered. Several other similar significant networks have been uncovered recently.
“The tools we profile in our investigation, though apparently amassed in a complex way to achieve a definite purpose, are not restricted to an exclusive guild of experts with specialized and confidential knowledge,” explained Deibert and Rohozinski. “Today, pirated cybercrime kits circulate extensively on the Internet and can be downloaded by anyone about as easily as the latest pirated DVD.51 Cyberspace has empowered individuals and small groups of non-state actors to do many things, including executing sophisticated computer network operations that were previously only the domain of state intelligence agencies.”
Another report on the same topic, “The snooping dragon: social-malware surveillance of the Tibetan movement,” is very clear in its recommendations to businesses. Where industrial espionage is a concern, strict separation is needed between computers and networks that connect to the Internet, and those that are used to hold corporate secrets and confidential data.
The report’s authors, Shishir Nagaraja, Information Trust Institute, University of Illinois at Urbana-Champaign and Ross Anderson, Cambridge University, Computer Laboratory also point out that it would be “prudent practice to run a high-value payment system on a PC that does not contain a browser or e-mail client, or indeed any other software at all. Perhaps within a few years banks will insist on this, and design payment applications that won’t run otherwise. Perhaps a few years later we will see the payment function becoming a hardware appliance: a tamper-resistant device supplied by the bank that does nothing except display payments and signs them when the approval button is pressed.”
The report mentions that banks find it difficult to cope with the consequences of phishing attacks where the PCs of less than one percent of their customers have been infiltrated at any one time. Just imagine the damage control operation that would be required if corporate accounting and payments systems were attacked.
Sounds like something farfetched and Nagaraja and Anderson predict that initially banks and their major clients will believe that their security will be good enough to counter cybercrime networks. However, as losses grow, the finger pointing will start with banks, businesses and makers of accounting and payment software blaming each other. It is only when litigation and regulations force change that the cybercriminals will be shut down. That will be in the distant future.
“In short, we predict that the criminals who adapt social malware to fraud will enjoy many years of rich pickings,” conclude Nagaraja and Anderson. “Indeed, if either of us were inclined to crime, this would be what we’d go for.”

