Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Technology
Media
Small Business
Legal
Deals
Earnings
Social Pulse
Business Video
The Freeland File
Aerospace & Defense
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Campaign Polling
Tales from the Trail
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Social Pulse
Opinion
Opinion Home
Chrystia Freeland
John Lloyd
Felix Salmon
Jack Shafer
David Rohde
Bernd Debusmann
Nader Mousavizadeh
Lucy P. Marcus
David Cay Johnston
Bethany McLean
Anatole Kaletsky
Edward Hadas
Hugo Dixon
Ian Bremmer
Lawrence Summers
Susan Glasser
The Great Debate
Steven Brill
Jack & Suzy Welch
Frederick Kempe
Christopher Papagianis
Mark Leonard
Breakingviews
Equities
Credit
Private Equity
M&A
Macro & Markets
Politics
Breakingviews Video
Money
Money Home
Tax Break
Lipper Awards 2012
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Investing 201
Life
Olympics
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Full Focus
Video
Reuters TV
Reuters News
Article
Comments (8)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
Sensational China trial ends in seven hours, verdict later
|
5:17pm EDT
Assad replaces fugitive PM, Aleppo rebels pull back
|
3:29pm EDT
Virus found in Mideast can spy on bank transactions
4:33pm EDT
Exclusive: Justice Ginsburg shrugs off rib injury
08 Aug 2012
Mars rover Curiosity sends home first color photo
|
08 Aug 2012
Discussed
170
Obama urges ”soul searching” on ways to reduce gun violence
129
Obama’s lead over Romney grows despite voters’ pessimism
108
Chick-fil-A faces ”kiss-in” protest in gay marriage flap
Sponsored Links
Pictures
Reuters Photojournalism
Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography. See more | Photo caption
The surface of Mars
The continuing search for signs of life on the Red Planet. Slideshow
Agent Orange's legacy
The U.S. is now formally involved in the clean-up of Agent Orange contamination in Vietnam. Slideshow
Virus found in Mideast can spy on bank transactions
Tweet
Share this
Email
Print
Related News
White House may use executive order to protect key computer networks
Wed, Aug 8 2012
Egypt moves to seal Gaza tunnels after border attack
Wed, Aug 8 2012
Disinformation flies in Syria's growing cyber war
Tue, Aug 7 2012
U.S. nuclear bomb facility shut after security breach
Thu, Aug 2 2012
Hopes fade for new U.S. cybersecurity law in 2012
Thu, Aug 2 2012
Analysis & Opinion
Is the U.S. picking on our banks?
Romney’s tax audit, Aurora and risk, inside the IRS
Related Topics
Tech »
United Nations »
Kaspersky Lab CEO and Co-founder Eugene Kaspersky speaks during the Reuters Global Media and Technology Summit in London in this June 11, 2012, file photo.
Credit: Reuters/Benjamin Beavan/Files
By Jim Finkle
BOSTON |
Thu Aug 9, 2012 4:33pm EDT
BOSTON (Reuters) - A new cyber surveillance virus has been found in the Middle East that can spy on banking transactions and steal login information for social networking sites, email and instant messaging, according to a leading computer security firm, Kaspersky Lab.
Dubbed Gauss, the virus may also be capable of attacking critical infrastructure and was very likely built in the same laboratories as Stuxnet, the computer worm widely believed to have been used by the United States and Israel to attack Iran's nuclear program, Kaspersky Lab said on Thursday.
The Moscow-based firm said it found Gauss had infected more than 2,500 personal computers, the bulk of them in Lebanon, Israel and the Palestinian territories. Targets included Lebanon's BlomBank, ByblosBank and Credit Libanais, as well as Citigroup Inc's Citibank and eBay's PayPal online payment system.
Officials with the three Lebanese banks said they were unaware of the virus. PayPal spokesman Anuj Nayar said the company was investigating the matter but was not aware of any increase in "rogue activity" as a result of Gauss. A Citibank spokeswoman declined to comment.
Kaspersky Lab would not speculate on who was behind Gauss, but said the virus was connected to Stuxnet and two other related cyber espionage tools, Flame and Duqu. The U.S. Department of Defense declined to comment.
"After looking at Stuxnet, Duqu and Flame, we can say with a high degree of certainty that Gauss comes from the same 'factory' or 'factories,'" Kaspersky on its website. "All these attack toolkits represent the high end of nation-state-sponsored cyber-espionage and cyber war operations."
Kaspersky's findings are likely to fuel a growing international debate over the development and use of cyber weapons and espionage tools. Those discussions were stirred up by the discovery of Flame in May by Kaspersky and others.
Jeffrey Carr, an expert on cyber warfare who runs a small security firm known as Taia Global, said the U.S. government has long monitored Lebanese banks for clues about the activities of militant groups and drug cartels. He said Gauss was likely built by adapting technology deployed in Flame.
"You've got this successful platform. Why not apply it to this investigation into Lebanese banks and whether or not they are involved in money laundering for Hezbollah?" he said.
Several analysts said they were not surprised to hear that most of the Gauss infections were discovered in Lebanon. "Beirut is a hot spot for the clandestine movement of money by states," said a former U.S. intelligence expert on money laundering who asked not to be named.
New York's state banking regulator this week accused Britain's Standard Chartered Plc of violating U.S. anti-money laundering laws by scheming with Iran to hide more than $250 billion of transactions.
Experts said that surveillance viruses like Gauss are perfect tools for government intelligence units to gather information for such investigations, though they did not specifically link Gauss to the Standard Chartered case.
"Espionage happens all the time," said Mikko Hypponen, chief research officer at anti-virus software maker F Secure. "In the old days you had to go where the information was to copy it. Today it is on computers and networks."
HOMAGE TO MATHEMATICIANS
According to Kaspersky Lab, Gauss can also steal Internet browser passwords and other data, and send information about system configurations.
Modules in the virus have internal names that Kaspersky Lab researchers believe were chosen to pay homage to famous mathematicians and philosophers, including Johann Carl Friedrich Gauss, Kurt Godel and Joseph-Louis Lagrange.
Kaspersky Lab said it called the virus Gauss because that is the name of the most important module, which implements its data-stealing capabilities.
One of the firm's top researchers said Gauss also contains a module known as "Godel" that may include a Stuxnet-like weapon for attacking industrial control systems. Stuxnet, discovered in 2010, was used to attack computers that controlled the centrifuges at a uranium enrichment facility in Natanz, Iran.
Roel Schouwenberg, a senior researcher with Kaspersky, said the Godel code may include a similar "warhead."
Godel copies a compressed, encrypted program onto USB drives. That program will only decompress and activate when it comes in contact with a targeted system.
While Kaspersky has yet to fully crack Godel's code, Schouwenberg said he suspects it is a cyber weapon designed to cause physical damage and that its developers went to a lot of trouble to hide its purpose, using an encryption scheme that could take months or even years to unravel.
UN TO ISSUE WARNING
A United Nations agency that advises countries on protecting infrastructure plans to send an alert on the mysterious code.
"We don't know what exactly it does. We can have some ideas. We are going to emphasize this," said Marco Obiso, a cyber security coordinator for the Geneva-based International Telecommunications Union, or ITU.
Kaspersky estimates the total number of victims in the tens of thousands. More than half of the 2,500 found since May were in Lebanon, while only 43 were in the United States.
The U.S. Department of Homeland Security said it was analyzing the potential threat posed by Gauss.
"The department's cyber security analysts are working with organizations that could potentially be affected to detect, mitigate and prevent such threats,' said DHS spokesman Peter Boogaard.
Researchers at Symantec Corp, the biggest maker of security software, have begun analyzing Gauss and said it appeared at first blush to be related to Stuxnet, Duqu and Flame, according to a spokeswoman for the company.
(Additional reporting by Erika Solomon in Beirut, Tabassum Zakaria and Phillip Stewart in Washington and Alistair Barr and Joseph Menn in San Francisco; editing by Tiffany Wu, John Wallace and Matthew Lewis)
Tech
United Nations
Related Quotes and News
Company
Price
Related News
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (8)
politicaljunkie wrote:
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
AdChoices
Copyright
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.