Feds Are Suspects in New Malware That Attacks Tor Anonymity

Locutus

Adorable Deplorable
Jun 18, 2007
32,230
45
48
65
Security researchers tonight are poring over a piece of malicious software that takes advantage of a Firefox security vulnerability to identify some users of the privacy-protecting Tor anonymity network.

The malware showed up Sunday morning on multiple websites hosted by the anonymous hosting company Freedom Hosting. That would normally be considered a blatantly criminal “drive-by” hack attack, but nobody’s calling in the FBI this time. The FBI is the prime suspect.

“It just sends identifying information to some IP in Reston, Virginia,” says reverse-engineer Vlad Tsyrklevich. “It’s pretty clear that it’s FBI or it’s some other law enforcement agency that’s U.S.-based.”

If Tsrklevich and other researchers are right, the code is likely the first sample captured in the wild of the FBI’s “computer and internet protocol address verifier,” or CIPAV, the law enforcement spyware first reported by WIRED in 2007.

Court documents and FBI files released under the FOIA have described the CIPAV as software the FBI can deliver through a browser exploit to gather information from the target’s machine and send it to an FBI server in Virginia. The FBI has been using the CIPAV since 2002 against hackers, online sexual predators, extortionists, and others, primarily to identify suspects who are disguising their location using proxy servers or anonymity services, like Tor.

The code has been used sparingly in the past, which kept it from leaking out and being analyzed or added to anti-virus databases.


more


Feds Are Suspects in New Malware That Attacks Tor Anonymity | Threat Level | Wired.com
 

Goober

Hall of Fame Member
Jan 23, 2009
24,691
116
63
Moving
I just got that when I opened FF. Kaspersky blocked it, denied access.
As I usually do - Used CC to clean and purge.Updated Kaspersky, daily, opened FF and bango.
I read the details and it had something about android in it. Me I know SFA about what these mean.
Cannot find the record on Kasperky or I would post more info.
Found the report- Hitchhikers guide to the universe
android guide -

Just tested about 30 different sites- This only comes up on CC so far.
 
Last edited: