PsyWar: COINTELPRO Infiltration Of Dissidents

From the War at Home Archive:

“False Media Stories: COINTELPRO documents expose frequent collusion between news media personnel and the FBI to publish false and distorted material at the Bureau’s behest. The FBI routinely leaked derogatory information to its collaborators in the news media. It also created newspaper and magazine articles and television “documentaries” which the media knowingly or unknowingly carried as their own. Copies were sent anonymously or under bogus letterhead to activists’ financial backers, employers, business associates, families, neighbors, church officials, school administrators, landlords, and whomever else might cause them trouble.

One FBI media fabrication claimed that Jean Seberg, a white film star active in anti-racist causes, was pregnant by a prominent Black leader. The Bureau leaked the story anonymously to columnist Joyce Haber and also had it passed to her by a “friendly” source in the Los Angeles Times editorial staff. The item appeared without attribution in Haber’s nationally syndicated column of May 19, 1970. Seberg’s husband has sued the FBI as responsible for her resulting stillbirth, nervous breakdown, and suicide.

Bogus Leaflets, Pamphlets, and Other Publications: COINTELPRO documents show that the FBI routinely put out phony leaflets, posters, pamphlets, newspapers, and other publications in the name of movement groups. The purpose was to discredit the groups and turn them against one another.

FBI cartoon leaflets were used to divide and disrupt the main national anti-war coalition of the late 1960s. Similar fliers were circulated in 1968 and 1969 in the name of the Black Panthers and the United Slaves (US), a rival Black nationalist group based in Southern California. The phony Panther/US leaflets, together with other covert operations, were credited with subverting a fragile truce between the two groups and igniting an explosion of internecine violence that left four Panthers dead, many more wounded, and a once-flourishing regional Black movement decimated.

Another major COINTELPRO operation involved a children’s coloring book which the Black Panther Party had rejected as anti-white and gratuitously violent. The FBI revised the coloring book to make it even more offensive. Its field offices then distributed thousands of copies anonymously or under phony organizational letterheads. Many backers of the Party’s program of free breakfasts for children withdrew their support after the FBI conned them into believing that the bogus coloring book was being used in the program.

Forged Correspondence: Former employees have confirmed that the FBI has the capacity to produce state-of-the-art forgery. This capacity was used under COINTELPRO to create snitch jackets and bogus communications that exacerbated differences among activists and disrupted their work.

One such forgery intimidated civil rights worker Muhammed Kenyatta (Donald Jackson), causing him to abandon promising projects in Jackson, Mississippi. Kenyatta had foundation grants to form Black economic cooperatives and open a “Black and Proud School” for dropouts. He was also a student organizer at nearby Tougaloo College. In the winter of 1969, after an extended campaign of FBI and police harassment, Kenyatta received a letter, purportedly from the Tougaloo College Defense Committee, which “directed” that he cease his political activities immediately. If he did not “heed our diplomatic and well-thought-out warning,” the committee would consider taking measures “which would have a more direct effect and which would not be as cordial as this note.” Kenyatta and his wife left. Only years later did they learn it was not Tougaloo students, but FBI covert operators who had driven them out.

Later in 1969, FBI agents fabricated a letter to the mainly white organizers of a proposed Washington, D.C. anti-war rally demanding that they pay the local Black community a $20,000 “security bond.” This attempted extortion was composed in the name of the local Black United Front (BUF) and signed with the forged signature of its leader. FBI informers inside the BUF then tried to get the group to back such a demand, and Bureau contacts in the media made sure the story received wide publicity.

The Senate Intelligence Committee uncovered a series of FBI letters sent to top Panther leaders throughout 1970 in the name of Connie Mathews, an intermediary between the Black Panther Party’s national office and Panther leader Eldridge Cleaver, in exile in Algeria. These exquisite forgeries were prepared on pilfered stationery in Panther vernacular expertly simulated by the FBI’s Washington, D.C. laboratory. Each was forwarded to an FBI Legal Attache at a U.S. Embassy in a foreign country that Mathews was due to travel through and then posted at just the right time “in such a manner that it cannot be traced to the Bureau.” The FBI enhanced the eerie authenticity of these fabrications by lacing them with esoteric personal tidbits culled from electronic surveillance of Panther homes and offices. Combined with other forgeries, anonymous letters and phone calls, and the covert intervention of FBI and police infiltrators, the Mathews correspondence succeeded in inflaming intra-party mistrust and rivalry until it erupted into the bitter public split that shattered the organization in the winter of 1971.

Anonymous Letters and Telephone Calls: During the 1960s, activists received a steady flow of anonymous letters and phone calls which turn out to have been from the FBI. Some were unsigned, while others bore bogus names or purported to come from unidentified activists in phony or actual organizations.

Many of these bogus communications promoted racial divisions and fears, often by exploiting and exacerbating tensions between Jewish and Black activists. One such FBI-concocted letter went to SDS members who had joined Black students protesting New York University’s discharge of a Black teacher in 1969. The supposed author, an unnamed “SDS member,” urged whites to break ranks and abandon the Black students because of alleged anti-Semitic slurs by the fired teacher and his supporters.

Other anonymous letters and phone calls falsely accused movement leaders of collaboration with the authorities, corruption, or sexual affairs with other activists’ mates. The letter on the next page was used to provoke “a lasting distrust” between a Black civil rights leader and his wife. Its FBI authors hoped that his “concern over what to do about it” would “detract from his time spent in the plots and plans of his organization.” As in the Seberg incident, inter-racial sex was a persistent theme. The husband of one white woman active in civil rights and anti-war work filed for divorce soon after receiving the FBI-authored letter reproduced on page 50.

Still other anonymous FBI communications were designed to intimidate dissidents, disrupt coalitions, and provoke violence. Calls to Stokely Carmichael’s mother warning of a fictitious Black Panther murder plot drove him to leave the country in September 1968. Similar anonymous FBI telephone threats to SNCC leader James Forman were instrumental in thwarting efforts to bring the two groups together.

The Chicago FBI made effective use of anonymous letters to sabotage the Panthers efforts to build alliances with previously apolitical Black street gangs. The most extensive of these operations involved the Black P. Stone Nation, or “Blackstone Rangers,” a powerful confederation of several thousand local Black youth. Early in 1969, as FBI and police infiltrators in the Rangers spread rumors of an impending Panther attack, the Bureau sent Ranger chief Jeff Fort an incendiary note signed “a black brother you don’t know.” Fort’s supposed friend warned that “The brothers that run the Panthers blame you for blocking their thing and there’s supposed to be a hit out for you.” Another FBI-concocted anonymous “black man” then informed Chicago Panther leader Fred Hampton of a Ranger plot “to get you out of the way.” These fabrications squelched promising talks between the two groups and enabled Chicago Panther security chief William O’Neal, an FBI-paid provocateur, to instigate a series of armed confrontations from which the Panthers barely managed to escape without serious casualties.

Pressure Through Employers, Landlords, and Others: FBI records reveal repeated maneuvers to generate pressure on dissidents from their parents, children, spouses, landlords, employers, college administrators, church superiors, welfare agencies, credit bureaus, and the like. Anonymous letters and telephone calls were often used to this end. Confidential official communications were effective in bringing to bear the Bureau’s immense power and authority.

Agents’ reports indicate that such FBI intervention denied Martin Luther King, Jr., and other 1960s activists any number of foundation grants and public speaking engagements. It also deprived alternative newspapers of their printers, suppliers, and distributors and cost them crucial advertising revenues when major record companies were persuaded to take their business elsewhere. Similar government manipulation may underlie steps recently taken by some insurance companies to cancel policies held by churches giving sanctuary to refugees from El Salvador and Guatemala.

Tampering With Mail and Telephone Service: The FBI and CIA routinely used mail covers (the recording of names and addresses) and electronic surveillance in order to spy on 1960s movements. The CIA alone admitted to photographing the outside of 2.7 million pieces of first-class mail during the 1960s and to opening almost 215,000. Government agencies also tampered with mail, altering, delaying, or “disappearing” it. Activists were quick to blame one another, and infiltrators easily exploited the situation to exacerbate their tensions.

Dissidents’ telephone communications often were similarly obstructed. The SDS Regional Office in Washington, D.C., for instance, mysteriously lost its phone service the week preceding virtually every national anti-war demonstration in the late 1960s.

Disinformation to Prevent or Disrupt Movement Meetings and Activities: A favorite COINTELPRO tactic uncovered by Senate investigators was to advertise a non-existent political event, or to misinform people of the time and place of an actual one. They reported a variety of disruptive FBI “dirty tricks” designed to cast blame on the organizers of movement events.”

Comment

Some of my experiences of internet harassment over the past five years sound a lot like this stuff. But in my case, I’m pretty sure that the people involved were private individuals, who maybe used some of their government connections or authority. At some point, one ex-CIA official [ a guy who had a history of out-of-control behavior and had had run-ins with the law] was actually writing nasty stuff on this blog, and may have been behind a few other things.

But the rest was private. Which suggests that between corporations (correction: criminal corporations) and  government (correction: unconstitutional governments), there’s not much to choose.

Anyway, this kind of history of government infiltration of activist groups  should make people very wary about their communications. The email in your inbox can be forged and your own name could be tacked onto things you never wrote.  With all the powers at their disposal, if the government decided to frame someone, they would be able to get or create all kinds of incriminating stuff.

That’s why I don’t buy the Gupta verdict at all. With five years of investigation by two different outfits, with thousands of wire-taps, they only got him talking to Raj once? And even then, there was nothing illegal in that conversation….

Hitler’s Pope And The Serbian Holocaust

The little known slaughter of Orthodox Christians, Jews, and Roma in Yugoslavia at the hands of Nazi-sponsored Croatian leadership had the full approval of the Catholic pope and the Grand Mufti of Jerusalem.

“During the Second World War in Yugoslavia, Catholic priests and Muslim clerics were willing accomplices in the genocide of the nations Serbian, Jewish and Roma population. From 1941 until 1945, the Nazi-installed regime of Ante Pavelic in Croatia carried out some of the most horrific crimes of the Holocaust (known as the Porajmos by the Roma), killing over 800,000 Yugoslav citizens750,000 Serbs, 60,000 Jews and 26,000 Roma. In these crimes, the Croatian Ustasha and Muslim fundamentalists were openly supported by the Vatican, the Archbishop of Zagreb Cardinal Alojzije Stepinac (1898-1960), and the Palestinian Grand Mufti of Jerusalem, Hajj Amin al-Husseini. Many of the victims of the Pavelic regime in Croatia were killed in the war’s third largest death camp – Jasenovac, where over 200,000 people – mainly Orthodox Serbs met their deaths. Some 240,000 were “rebaptized” into the Catholic faith by fundamentalist Clerics in “the Catholic Kingdom of Croatia” as part of the policy to “kill a third, deport a third, convert a third” of Yugoslavia’s Serbs, Jews and Roma in wartime Bosnia and Croatia (The Yugoslav Auschwitz and the Vatican, Vladimar Dedijer, Anriman-Verlag, Freiburg, Germany, 1988).

On April 6th 1941, Nazi Germany invaded Yugoslavia. By April 10th, Croatian fascists led by Ante Pavelic were allowed by Hitler and his ally Mussolini to set up a “independent” puppet state of Croatia. Hitler granted “Aryan” status to Croatia as his fascist allies carved up Yugoslavia. Pavelic had been awaiting these developments whilst under the auspices of Mussolini in Italy who had granted them the use of remote training camps on a Aeolian island and access to a propaganda station Radio Bari for broadcasts across the Adriatic. As soon as the new fascist state of Croatia was born, and campaign of cold-blooded terror began, as noted by John Cornwell in his book Hitler’s Pope: The Secret History of Pius XII (Viking, London, UK, 1999):

“(It was) an act of ‘ethnic cleansing’ before that hideous term came into vogue, it was an attempt to create a ‘pure’ Catholic Croatia by enforced conversions, deportations, and mass exterminations. So dreadful were the acts of torture and murder that even hardened German troops registered their horror. Even by comparison with the recent bloodshed in Yugoslavia at the time of writing, Pavelic’s onslaught against the Orthodox Serbs remains one of the most appalling civilian massacres known to history” (p 249)

Christmas 1914 in No Man’s Land

Christmas Eve 1914:

Christmas Eve 1914, stars were burning, burning bright
And all along the Western front guns were lying still and quiet
Men lay dozing in the trenches, in the cold and in the dark
And far away behind the lines the village dog began tae bark

Some lay thinking of their families, some sang songs while others were quiet
Rolling fags and playing brag to pass away that Christmas night
As they watched the German trenches, something moved in no man’s land
Through the dark there came a soldier carrying a white flag in his hand

Then from both sides men came running, crossing into no man’s land
Through the barbed wire, mud and shell-holes, shyly stood there shaking hands
Fritz brought out cigars and brandy, Tommy brought corned beef and fags
Stood there talking, shyly laughing, as the moon shone down on no man’s land

Then Christmas Day we all played football in the mud of no man’s land
Tommy brought some Christmas pudding, Fritz brought out a German band
When they beat us at the football we shared out all our grub and drink
Then Fritz showed me a faded photo of a brown-haired girl back in Berlin

For four days after no one fired, not one shell disturbed the night
For old Fritz and Tommy Atkins, they’d both lost their will to fight
So they withdrew us from the trenches, sent us far behind the lines
Sent fresh lads to take our places and told the guns, Prepare to fire

And next night in 1914, flares were burning, burning bright
The orders came, Prepare offensive! Over the top your going tonight
And men stood waiting in the trenches, looked out across our football park
As all along the Western front the Christmas guns began tae bark

And men stood waiting in the trenches, looked out across our football park
As all along the Western front the Christmas guns began tae bark

[1987:]

In no-man’s-land, between the British and the German trenches during the Christmas truce of that year [1914], an extraordinary event occurred.

“The night was cold. We sang, they applauded. Our lines were only two hundred feet apart. We played the mouth organ, they sang, then we applauded. They produced a set of bagpipes and played their poetic tunes.
Men were waving torches and cheering. We had prepared grog and drank a toast.”

[Letter] from a German soldier. –

From both sides men came running, and soon were fraternizing “in the most genuine possible manner. Every sort of souvenir was exchanged, addresses given and received.” A German N.C.O. with an Iron Cross, gained “for conspicuous skill in sniping, started his fellows off on some marching tune. I set the note for the Bonnie Boys of Scotland, and so we went on and ended up with Auld Lang Syne which we all – English, Scots, Irish, Prussians and Wurttembergers – joined in.”

[Diary] of a British Captain. – From some old rags and cord a makeshift football was made, and by the light of flares the two sides played a game of soccer, their previous deadly activities forgotten. (Notes Danny
Doyle, ’20 Years A-Growing’)

[1988:] At some points a “live and let live” system evolved – a means of existence involving tacit co-operation between the sides, recognizing a rough parity of forces. […] One was to have an unspoken agreement […] not to shell latrines nor to open fire during breakfast. Another was to make as
much noise as possible before a minor raid, so that the other side could withdraw to their protected bunkers. This limitation on hostilities did not exist everywhere and was stamped on by command when it came to light. But even such informal arrangements as survived could be quickly buried,
along with men killed by snipers, by the odd shell, or gas. The fraternization that did go on briefly between the lines on Christmas Day 1914 did not characterize the way the war was fought in the trenches.
Violence was always below the surface, ready to explode. (J.M. Winter, The Experience of World War I, 133ff)

Stuxnet: A Chronology (Ongoing)

October 2, 2010

The NY Times now backtracks, claiming that Israeli cyber warfare experts are “too smart” to leave a clue behind. Thus..by inference…it must be a country that wants to implicate Israel, which..by inference…is Iran (surprise).  Too clever by half, these folks. Another reason I believe Israel or an Israeli-backed team is behind Stuxnet is the fact that Wikileaks apparently had a reference to a possible nuclear “accident” in Iran in July 2009. That is around the time when some researchers argue Stuxnet infections first began.

October 2, 2010

Jeffrey Carr backs off from the allegation that Israel is the culprit, claiming that Ralph Langner was the sole source of the allegation and was irresponsible in posting it on his blog as though it were the opinion of the intelligence community. Carr quotes an earlier piece of his, along with these words:

“Last week I wrote about how the Israel-Iran conspiracy theory around the Stuxnet worm was built entirely on one security engineer’s personal conjecture (Ralph Langner) with absolutely no weighing of alternative possibilities for attribution, nor any objective assessment of the evidence.”

However, if you click on the earlier piece he cites, he wrote nothing of the sort in it. Nowhere in that piece did Carr claim that Langner was the sole source of the allegation; he quotes the NY Times as noting several people who’d reached the same conclusion. Also, there is no hint in the piece that he considered Langner’s allegation speculative or poorly founded. He cited it instead as a likely possibility. This is clear back-pedaling, probably provoked by the fear that the story might lead to a crackdown on Iranian dissidents and foreigners. Well, of course it will. But that’s not the fault of journalists reporting on the story. Or of Ralph Langner, who clearly states on his blog that he is “speculating” (see previous link).

The fault lies with the unknown cybercriminal/s who came up with Stuxnet.

“Stuxnet Speculation Fuels Crackdown By Iranian Intelligence,” Jeffrey Carr, The Firewall, Forbes, October 2, 2010/

*October 1, 2010

[See “Clues Emerge About Genesis Of Stuxnet Worm,” CS Monitor, October 1, 2010]

*October 1, 2010

[“Israel: Smart Enough To Create Stuxnet; Stupid Enough To Use It” War In Context, Oct. 1, 2010]

*October 1, 2010

Cryptome is arguing that Israel would never have done anything so sloppy as what’s alleged. Could it be that some group is deliberately playing off one side against the other, that is, playing divide-and-conquer? Or is this more “plausible deniability”?

On looking back, I notice that one of the first people to launch the “Israel did it” allegation is one Richard Falkenrath, who works for the Chertoff Group (my emphasis).

That makes me wonder.

Here’s Cryptome:

“Really? Personally I’d be surprised if a crack team of Israeli software engineers were so sloppy that they relied on outdated rootkit technology (e.g. hooking the Nt*() calls used by Kernel32.LoadLibrary() and using UPX to pack code). Most of the Israeli developers I’ve met are pretty sharp. Just ask Erez Metula.

http://www.blackhat.com/presentations/bh-usa-09/METULA/BHUSA09-Metula-ManagedCodeRootkits-
PAPER.pdf

“It may be that the “myrtus” string from the recovered Stuxnet file path

“b:\myrtus\src\objfre_w2k_x86\i386\guava.pdb” stands for “My-RTUs”

as in Remote Terminal Unit. See the following white paper from Motorola, it examines RTUs and PICs in SCADA systems. Who knows? The guava-myrtus connection may actually hold water.

http://www.motorola.com/web/Business/Products/SCADA%20Products/_Documents/Static%20Files/SCADA_
Sys_Wht_Ppr-2a_New.pdf

As you can see, the media’s propaganda machine is alive and well.”

I am completely out of my depth in the technical part of this. But not in the propaganda part.

As an instance of the way group conflicts can be set off, think of how during the financial crisis there were an inordinate number of Indians being trotted out to do the explaining…and taking the brunt of the public’s anger, although last I looked, despite a respectable number of Indian billionaires, the head honchos of the major banks (with one exception) and the biggest and most important speculators, managers, and  international officials were not Indian, to phrase it as politely as possible.

Setting race and nation each against other is of course the modus operandi of the power elite, and both Kashmir and Israel have played that divisive role in the past….and continue to do so.

*October 1, 2010

A link to an Examiner piece is coming up right at the top of a Google search of Stuxnet and Israel. With all due respect to the author, who probably thinks he/she is on the side of the angels and simply preempting an outburst of anti-Semitism by this effort, the piece is quite misleading….and, apparently, deliberately so, as an examination of the other links listed here, from a variety of  sources in the West (see this NY Times pieces) will prove.

For instance, the Examiner piece doesn’t cite the reports from many western security companies and research teams (see links below) that have extensively researched the issue, nor does it acknowledge that it was these sites that first advanced the claim that Israel/Israeli hackers were likely responsible. Instead, it cites a Times of India piece that republishes the claims.

The attempt, apparently, is to mislead the public into thinking that the allegation of Israeli involvement is one mainly advanced by untrustworthy foreigners with axes to grind (note the description “Iran’s friend, India”).

“Another of Iran’s friends, India, is pushing the notion that Israel did it. According to an http://timesofindia.indiatimes.com on Friday, “A Biblical reference has been detected in the code of the computer virus that points to Israel as the origin of the cyber attack.” It’s further explained that the word “myrtus” is in the code, and that this is a “reference to the myrtle tree”

In point of fact, it was western security companies and western researchers who came to that conclusion.  Moreover, the targets of the worm fit very well with Anglo-Zionist imperial objectives – covering as they do the largest Muslim populations in Asia.

[See “German Firm Employee May Have Created Stuxnet; Israel Blames.” Examiner.com, October 1, 2010

*September 30, 2010

Quote:

“Buried in Stuxnet’s code is a marker with the digits “19790509” that the researchers believe is a “do-not infect” indicator. If the marker equals that value, Stuxnet stops in its tracks, and does not infect the targeted PC. The researchers — Nicolas Falliere, Liam O Murchu and Eric Chen — speculated that the marker represents a date: May 9, 1979. While on May 9, 1979, a variety of historical events occurred, according to WikipediaHabib Elghanian was executed by a firing squad in Tehran sending shock waves through the closely knit Iranian Jewish community,” the researchers wrote. Elghanian, a prominent Jewish-Iranian businessman, was charged with spying for Israel by the then-new revolutionary government of Iran, and executed May 9, 1979.”

Quote:

“Last weekend, Iranian officials confirmed that tens of thousands of PCs in their country had been infected by Stuxnet, including some used at a nuclear power plant in southwestern Iran that’s planned to go online next month. The Symantec researchers also revealed a host of other Stuxnet details in their paper, including a “kill date” of June 24, 2012, after which the worm will refuse to execute.”

[See “Stuxnet Code Hints At Possible Israeli Origin, Researchers Say,” by Gregg Keizer, Symantec, Sept. 30, 2010]

*September 30, 2010

Symantec puts out a dossier of information on Stuxnet that includes the following:- attack scenario and timeline, infection statistics, malware architecture, description of all the exported routines, injection techniques and anti-AV, the RPC component, propagation methods, command and control feature, and the PLC infector.

Eric Chien summarizes findings about the worm:

“Only more recently did the general public realize Stuxnet’s ultimate goal was to sabotage an industrial control system.

Analyzing Stuxnet has been one of the most challenging issues we have worked on. The code is sophisticated, incredibly large, required numerous experts in different fields, and mostly bug-free, which is rare for your average piece of malware. Stuxnet is clearly not average. We estimate the core team was five to ten people and they developed Stuxnet over six months. The development was in all likelihood highly organized and thus this estimate doesn’t include the quality assurance and management resources needed to organize the development as well as a probable host of other resources required, such as people to setup test systems to mirror the target environment and maintain the command and control server.”

[See W32.Stuxnet Dossier, Eric Chien, Sept. 30, 2010]

*September 25, 2010

Quote:

The director of the Information Technology Council of the Industries and Mines Ministry has announced that the IP addresses of 30,000 industrial computer systems infected by this malware have been detected, the Mehr New Agency reported on Saturday. An electronic war has been launched against Iran,” Mahmoud Liaii added.“This computer worm is designed to transfer data about production lines from our industrial plants to (locations) outside of the country,” he said.

[See “Iran Successfully Battling Cyber Attack,” Mehr News, Sept. 25, 2010]

*September 24, 2010

A piece in the Guardian suggests that a government agency is most likely behind the worm but warns against leaping to conclusions. It notes that many hackers/criminals might have become sophisticated enough to create a worm of this type. The piece notes that attacks against Iran have increased and that the identification of the worm was originally made by a Belarus security firm for an Iranian client and that Iran had been experiencing problems with their nuclear facility at Bushehr for months. It notes that the worm uses a stolen cryptographic key from the Taiwanese semiconductor manufacturer Realtek.

[See “Stuxnet Worm Is The Work Of A National Government Agency,” Josh Halliday, Guardian, Sept. 24, 2010]

“Stuxnet: The Trinity Test Of Cyberwarfare,” War In Context, Sept. 23, 2010

*September 16, 2010

Symantec researchers say that Stuxnet had to be created by a state, because it was the most devious and sophisticated malware they’d come across.

Quote:

“I don’t think it was a private group,” said O Murchu. “They weren’t just after information, so a competitor is out. They wanted to reprogram the PLCs and operate the machinery in a way unintended by the real operators. That points to something more than industrial espionage.”

The necessary resources, and the money to finance the attack, puts it out the realm of a private hacking team, O Murchu said.

“This threat was specifically targeting Iran,” he continued. “It’s unique in that it was able to control machinery in the real world.”

“All the different circumstances, from the multiple zero-days to stolen certificates to its distribution, the most plausible scenario is a nation-state-backed group,” said Schouwenberg, who acknowledged that some people might think he was wearing a tin foil hat when he says such things. But the fact that Iran was the No. 1 target is telling.”

[See “Is Stuxnet the Best Malware Ever?” Gregg Keizer, Symantec Security Response, Sept. 16, 2010]

*September 13, 2010

German computer security research Ralph Langner speculates that Stuxnet is part of cyberwar:

Ralph’s theory — completely speculative from here

“It is hard to ignore the fact that the highest number of infections seems to be in Iran. Can we think of any reasonable target that would match the scenario? Yes, we can. Look at the Iranian nuclear program. Strange — they are presently having some technical difficulties down there in Bushehr. There also seem to be indications that the people in Bushehr don’t seem to be overly concerned about cyber security. When I saw this screenshot last year (http://www.upi.com/News_Photos/Features/The-Nuclear-Issue-in-Iran/1581/2/) I thought, these guys seem to be begging to be attacked. If the picture is authentic, which I have no means of verifying, it suggests that approximately one and a half year before scheduled going operational of a nuke plant they’re playing around with software that is not properly licensed and configured. I have never seen anything like that even in the smallest cookie plant. The pure fact that the relevant authorities did not seem to make efforts to get this off the web suggests to me that they don’t understand (and therefore don’t worry about) the deeper message that this tells.

Now you may ask, what about the many other infections in India, Indonesia, Pakistan etc. Strange for such a directed attack. Than, on the other hand, probably not. Check who comissions the Bushehr plant. It’s a Russian integrator that also has business in some of the countries where we see high infection rates. What we also see is that this company too doesn’t seem to be overly concerned about IT security. As I am writing this, they’re having a compromised web site (http://www.atomstroyexport.com/index-e.htm) that tries to download stuff from a malware site that had been shut down more than two years ago (www.bubamubaches.info). So we’re talking about a company in nukes that seems to be running a compromised web presence for over two years? Strange.
I could give some other hints that have a smell for me but I think other researchers may be able to do a much better job on checking the validity of all this completely non-technical stuff. The one last bit of information that makes some sense for me is the clue that the attackers left in the code, as the fellows from Symantec pointed out — use your own imagination because you will think I’m completely nuts when I tell you my idea.

Welcome to cyberwar.”

[See “Stuxnet is a directed attack: hack of the century,” Ralph Langner]

*September 8, 2010

German computer security expert Ralph Langner writes to a friend:

Historical document: Ralph informs Joe Weiss what Stuxnet is. Note the date of the email.

*July 22, 2010

Symantec analyzed W32.Stuxnet as a worm that uses a  hitherto unknown Windows bug to attack and then searches the target for SCADA systems and design documents. SCADA is a network used to control utilities, transportation and other critical infrastructure. The worm then contacted Command &Control servers that control the infected machines and retrieved the stolen information. The servers were located in Malaysia and Symantec redirected traffic away from them to prevent the take-over of the information.

Within a 72 hours period Symantec identified close to 14,000 IP addresses infected with W32.Stuxnet trying to contact the C&C server. 58.85 % came from Iran, with the rest coming from Indonesia (18.22%), India (8.31%), with the Azerbaijan, US, and Pakistan making up the other affected countries, with under 2% each (this information is also provided at the Microsoft website).

[See Symantec Security Response,W32.Stuxnet – Network Information, Vikram Thakur, July 22, 2010]

*July 21, 2010

Quote:

“The zero-day vulnerability, rootkit, main binaries, stolen digital certificates, and in-depth knowledge of SCADA software are all high-quality attack assets. The combination of these factors makes this threat extremely rare, if not completely novel.

Quote:

The complexity and quality of the attack assets lead some to believe only a state would have the resources to conduct such an attack. However, the usage of the second digital certificate is a bit odd. One could make the case that once the first attack succeeded, a state would take cover and not waste the second digital certificate. Instead, by signing a very similar binary, security companies were immediately able to detect the second stolen certificate, making it useless in further compromises…..

Quote:

.. Hackers bound by a common cause may target another country, organization, or company that they feel are their enemies. Such hacking groups often have the patience and expertise to gather such attack assets. Further, their goals of continued attack may lead them to continue to refine their attack as they are thwarted or discovered, such as resigning their driver files with a newly stolen digital certificate, modifying their binaries to avoid security product detection, and moving their command-and-control hosts as they are decommissioned…..

Quote:

…..This scenario [terrorism] is like something out of movie and, while for most attacks we’d immediately dismiss this as a possibility, given the amount and quality of the attack assets, terrorism even seems within the realms of possibility in this case.

[See “The Hackers Behind Stuxnet” by Patrick Fitzgerald, Symantec Security Response,  July 21, 2010]

*July 17, 2010

Researchers find that Stuxnet targets industrial control systems of the kind that control manufacturing and utility companies. It targets Siemens management software called Simatic WinCC, which runs on the Windows operating system.

The systems that run the Siemens software, called SCADA (supervisory control and data acquisition) systems, aren’t usually connected to the Internet, but the virus spreads when an infected USB stick is inserted. If it detects the Siemens software, the virus logs in using a default password.

[See “New Virus Targets Industrial Secrets,” Robert McMillan, Computer World, July 17, 2010]

*July 16, 2010

Symantec starts a blog series on the Stuxnet infection that continues through the summer and into September

[See also Microsoft Security Advisory, July 16, 2010 and Krebson Security, July 16, 2010]

*July 7, 2010

Stuxnet could well have caused the glitch in the solar panels of India’s Insat-4B satellite on July 7, 2010. That led to the shutting down of 12 out of 24 of the transponders and 70% of the customers dependent on Direct to Home (DTH) including those using Doordarshan (Indian TV), Sun TV and Tata’s VSNL. The customers were redirected to point to the Chinese satellite  ASIASAT-5, owned and operated by Asia Satellite Telecommunications Co., Ltd (AsiaSat) whose two main shareholders are General Electric (GE) and China International Trust and Investment Co. (CITIC), a state-owned company

[See “Did The Stuxnet Worm Kill India’s INSAT-4B Satellite?” by Jeffrey Carr, The Firewall, Forbes.com, Sept. 29, 2010]

*June 16, 2010

Symantec Security Response Team begins its investigation into the Stuxnet worm. The first sample dates from June 2010, but the team believes the worm dates back a year, or maybe even earlier.

*June 2010

The malware is first identified by a Belarus security company, Virusblokada, for its Iranian client.

[See Symantec Security Response, webpage, Sept 30, 2010]

*January 2010

Stuxnet infection begins, according to Symantec

*July 2009

Stuxnet infection begins, according to to Kasperksy

CIA Funds Both Sides Of War, Uses NY Times For Psyops (Yawn)

David DeGraw at Alternet.org describes how US intelligence ishas been behind both sides of the war on terror and how the media aids the war effort with calculated psyops like the recent “finding” of mineral deposits in Afghanistan that was trumpeted in the New York Times. Continue reading

Indian versus Israeli Reactions To Provocation

The Great Bong on the difference between the Indian and the Israeli approach to provocation:

“As someone primarily interested in sub-continental politics, what is most interesting for me however, more than the role of Turkey, is the difference between India and Israel in their reactions to provocation, being in similar boats—– — democratic countries with strong militaries, surrounded by antagonistic countries on many sides, eager to provoke them to conflict over disputed territories. Continue reading

Afghanistan Has Trillion Dollar Deposits Of Iron, Copper, and Lithium

So now we know the real reason for the Afghan war.. I wonder how long the Pentagon has had this information? BBC reports on June 14, 2010:

“Afghanistan may have more than a trillion dollars worth of untapped mineral deposits, a spokesman for the ministry of mines has suggested. The statement came after reports in the New York Times of the work of a team of Pentagon officials and US geologists. They discovered large quantities of iron and copper as well as valuable deposits of lithium. However, questions are being asked about the timing of the release of the latest information. Continue reading

Experts Trumpet ISI-Taliban Link As Excuse For US “Counter-Measures”

Shock. Pakistani intelligence (the ISI) might be involved with the Taliban.

When the obvious is stated with all the fanfare of a papal decree from such organs of the ruling class as the London School of Economics and our own JFK School of Government (Harvard), can military action be far behind? File this along with my previous post, Mad Dog alerts.

The Associated Press reports (June 13, 2010):

“Pakistan’s main spy agency continues to arm and train the Taliban and is even represented on the group’s leadership council despite U.S. pressure to sever ties and billions in aid to combat the militants, said a research report released Sunday.

Continue reading