HomeinetFBI allegedly behind massive malware attacks

FBI allegedly behind massive malware attacks

FBI allegedly behind massive malware attacks

He managed to control servers that were sending malware to users!

Without anyone ever seriously questioning it, the FBI acknowledged a few days ago that it secretly took control of Freedom Hosting last July, a few days before the servers of the largest anonymous hosting provider were found to be hosting malicious material specifically designed to identify visitors.

Freedom Hosting’s administrator, Eric Eoin Marques, had rented the servers from an anonymous hosting service in France, which he paid for through a Las Vegas bank account. It’s unclear how the FBI managed to hack the servers, but the Bureau had its own adventure: Marques managed to temporarily regain control of the servers, changing the passwords and eventually kicking the FBI out, before the Bureau regained control of the service for the second time! The battle is indeed on…

Details of the case were leaked to local press from a hearing in Dublin, Ireland, where Marques, 28, is fighting extradition to the United States on charges that Freedom Hosting hosted child pornography on a large scale. He was arrested in July and has been denied bail for the second time.

Freedom Hosting was one of the providers of “Tor hidden service” websites, that is, special sites (with addresses ending in .onion) that hide their geographical location well and are accessible exclusively by the anonymous Tor community. Tor hidden services are used by websites that seek to avoid surveillance attempts and protect the anonymity of the user to an unimaginable extent. Despite the fact that the Tor network hosts everything from human rights sites to free and independent voices, the exceptional anonymity it offers was later used for criminal activities, such as the trafficking of child pornography.

On August 4th, all sites hosted on Freedom Hosting started displaying an error message with a hidden code embedded in the page. The user community managed to “crack” the code and found that the malware was exploiting a security flaw in the Firefox browser to identify users of the Tor Browser Bundle, directly pointing to a mysterious server in Northern Virginia! The FBI was the obvious suspect, but declined to comment on the incident.

fbsrv1FBI Special Agent Brooke Donahue, however, was much more vocal when she appeared in Dublin court to make sure Marques stays behind bars, according to the Irish Independent. While the agent talked about how the 28-year-old was a flight risk, she also boasted about the FBI's cyberattack on Marques' rented servers! At the same time, it became clear that Freedom Hosting hosts 95% of the child pornography circulating on the Tor network: more than 100 child pornography websites with thousands of members.

The apparent FBI malware attack was detected on August 4th, when all of Freedom Hosting’s backdoor services hosted the malware, even legitimate websites like the email provider TorMail. Users began noticing the strange code, and by midday it had been cracked by the online community. Mozilla itself confirmed that the code was indeed exploiting a critical vulnerability in Firefox’s memory management, which had been made clear since June 25th. It was clear that the malware was trying to identify anonymous users of the Tor network.

The strongest indication that the attack came from a secret service or the clutches of the law was the limited functionality of the malicious material and its clear differentiations from "traditional" viruses: all it sought to do was identify the victim.

The addresses reported by the malware were located in Virginia (where the Bureau's secret servers are also hosted), with the behavior of the code and the entire scenario "smelling" of the infamous CIPAV, the FBI spyware that became known as early as 2007 and was aimed directly at hackers, extortionists, pedophiles and any cybercriminal hiding behind the deafening anonymity of the Tor network.

The FBI has been operating CIPAV since 2002, but before the Freedom Hosting attack, the malicious code had been used with extreme sparingly, which saved it from being leaked and "broken"..

 

Source: newsbeast.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS