UPDATED 23:21 EDT / FEBRUARY 16 2015

NEWS

NSA-linked “Equation Group” caught hiding spying software in hard disk firmware

4231585229_1955e505ce_nA new report from security software provider Kaspersky Lab has found that a group they’ve dubbed “Equation Group” has been hiding spying software deep within hard drives made by leading manufacturers including Seagate and Western Digital, in an attempt to eavesdrop on the majority of computers worldwide.

Kaspersky said it found the spyware in computers across 30 countries, with the list reading like a geopolitical wet dream of countries the United States either doesn’t like, or is highly competitive with; Iran had the highest number of infections, followed by Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria. The targets included government and military institutions, telecommunication companies, banks, energy companies, nuclear researchers, media, and Islamic activists.

The report explained that the advantage of burying the spyware on a hard drive is in providing an level of persistence that helps to survive disk formatting and OS reinstallation; Kaspersky notes that if the malware gets into the firmware, it is available to “resurrect” itself forever.

Director of the Global Research and Analysis Team at Kaspersky Costin Raiu added that “another dangerous thing is that once the hard drive gets infected with this malicious payload, it is impossible to scan its firmware. To put it simply: for most hard drives there are functions to write into the hardware firmware area, but there are no functions to read it back. It means that we are practically blind, and cannot detect hard drives that have been infected by this malware.

Where hard drives weren’t already affected, Kaspersky claims that the attackers used other methods to infect targets; not only the internet, but also in the physical world.

The group is claimed to have intercepted physical goods and replaced them with Trojanized versions, and in one example participants of a scientific conference were sent conference materials on a CD-ROM which was then used to install the group’s DoubleFantasy implant into the target’s machine.

Kaspersky said that it had observed seven exploits used by Equation Group in their malware with at least four being zero-day attacks. At least one unknown exploit was observed that specifically attacked the Tor browser.

Kaspersky declined to name the country behind the spying campaign but said Equation Group was linked to Stuxnet, a National Security Administration (NSA) tool that was used to attack Iran’s nuclear program;  it’s a fair guess that this link implies that Equation Group is a section of the NSA itself, which means that the spyware is being placed by the Government of the United States of America.

photo credit: Hardware Porn 21 of 23 via photopin (license)


A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.