"We're not creative enough when we imagine cyber warfare," F-Secure Security Advisor Sean Sullivan recently told me. "It's not kinetic explosions. It could be a guy whose crimeware business has dried up and is looking for new business."
Over the last week, F-Secure Labs has taken a look at attacks from the "Energetic Bear" hacking group, Havex, which targets the energy sector, and now CosmicDuke, which is aimed at targets in Ukraine, Poland, Turkey, and Russia.
The goal of these attacks seems to be espionage or gathering information up for a buyer, which could be a government. But the methods don't match the precision and massive investment of manhours that went into an attack like Stuxnet, which was designed to take down Iran's nuclear capabilities.
"They rely on plausible deniability and using resources that don't seem to be created specifically for the task," Sean said. "It matches the modular methodology of what we conventionally think of as crimeware."
"You look at one element and it looks like crimeware," said F-Secure Senior Researcher Timo Hirvonen, who wrote the CosmicDuke analysis. "You look at it from a different angle and you say, 'I've never seen it aimed like that before.'"
"The conventional wisdom is that anything related to cyber warfare will be shiny and new," Sean said. These attacks instead suggest "semi-professionalism".
Here are three questions Sean is pondering in the wake these attacks:
What do we mean when we say state-sponsored?
"Cyber warfare models real life," Sean said. "Some countries have a massive cyber intelligence infrastructure that works from the top down. Others seem to have a more grassroots origin, co-opting existing technologies that seem to be built on existing crimeware."
He wonders if state-focused campaigns are using malware that isn't necessarily state-sponsored. "Countries who use troops with black masks and no insignias standing on a peninsula may have the same kind of thing going online."
Opportunistic and pragmatic governments may be paying people to co-opting technology that exist for international espionage purposes.
He suggests the goals of such attacks may fit into Sun Tzu's advice from The Art of War: know your enemy.
Armed with information, countries can use soft power to turn allies against each other and dissuade retribution like economic sanctions.
What do we mean by APT -- advanced persistent threat?
These attacks are not complex in the way Stuxnet was. And they don't need to be.
CosmicDuke -- a variant of a malware family that has existed since 2001-- infects by tricking targets into opening either a PDF file which contains an exploit or a Windows executable whose filename makes it look like a document or image file.
Once the target opens the malicious file, CosmicDuke gains access starts collecting information with a keylogger, clipboard stealer, screenshotter, and password stealers for a variety of popular chat, e-mail and web browsing programs. CosmicDuke also collects information about the files on the system, and has the capability to export cryptographic certificates and their private keys. Once the information has been collected, it is sent out to remote servers via FTP. In addition to stealing information from the system, CosmicDuke allows the attacker to download and execute other malware on the system. Pretty standard stuff.
Is the war against crimeware driving criminals to cyber espionage? Or: Could be fighting cybercrime be counterproductive?
"Some of these guys may be working for the government and themselves," Sean said.
A wave of successes in the international war on cybercrime may be driving criminals to new buyers.
"The talent developed on its own," he said. "And now there's a government taking advantage of talent in their borders. Law enforcement has been going after crimeware. But it doesn't go away. It's fungible. The talent's still there it needs to make a buck."
Sean believes there's a message in these attacks for everyone.
"It's not just the NSA that hunts system admins. If you have any sort of credentialed access to important systems, you are a target. Keep calm and secure your stuff."
He hopes that businesses will recognize that prevention is always the best remedy.
"For IT managers: ask for the security budget you need – and fight for it. There is more evidence than ever that letting cost dictate security is bad management."
If governments are willing to work with increasingly opportunistic malware authors, risks could grow exponentially.
"Is today's crimeware botnet, tomorrow's national security nightmare?" Sean asks. "What happens when these guys get out of jail? I'm sure they won't let the talent go fallow."