Symantec code posted despite attempt to trap suspect

   Email correspondence between a hacker and undercover agent may provide a glimpse into the type of blackmail that takes place when intellectual property is stolen.

   The Anonymous hacking group said Tuesday that it always intended to release the source code for Symantec's Norton AntiVirus and pcAnywhere remote access software -- despite publishing emails Monday in which a supposed member of the group negotiates to sell the code back to the security company.

   The emails, released Monday night EST to Pastebin, chronicle communications between a hacker using the alias "Yamatough" -- who is part of the Anonymous-affiliated group The Lords of Dharmaraja -- and a supposed Symantec employee, Sam Thomas, who turned out to be a law enforcement official.

  The conversations begin around Jan. 18 with Thomas, communicating from a Symantec email account, trying to confirm that Yamatough was in possession proprietary code, which Symantec has confirmed on a number of occasions was stolen by hackers.

   For several days after, the pair go back and forth on how Yamatough can best deliver the files so Symantec can confirm their validity. On Jan. 24, after Thomas fails to send credentials to access an FTP server, the hacker writes: "If you are trying to trace with the FTP trick, it's just worthless. If we detect any malevolent tracing action, we cancel the deal. "

   After not hearing back on where to send the proof, on Jan. 25, Yamatough threatens to put the code up for sale if Thomas doesn't respond. A day later, the money discussion begins, with Yamatough asking how much Symantec is willing to pay. Thomas responds on Jan. 26 that he needs two to three days to come up with an answer.

   On Jan. 30, Thomas changes the subject: "Before we can discuss a dollar amount, we need to figure out how the payment is going to be made." The hacker suggests depositing the money into an account with Liberty Reserve, a Costa Rica-based payment processor.  A day later, Thomas says it would be "complicated" to get money into the account, so he suggests depositing $1,000 into a PayPal account as a gesture of good faith.

   The hacker declines, saying he will wait "till we agree on a final amount." On Wednesday, Thomas offers to pay $50,000.

   "However, we need assurances that you are not going to release the code after payment," he writes. "We will pay you $2,500 a month for the first three months. Payment starts next week. After the first three months, you have to convince us you have destroyed the code before we pay the balance."

   On Thursday, Yamatough responded, saying the deal has to be nixed because "our offshore people won't let us securely get the money because they won't process amounts less than 50k (thousand) a shot." Yamatough then accuses Thomas of coordinating with the FBI, which he denies.

   The negotiations reach a stalemate, and on Monday night EST, Anonymous posted a 1.2GB file, titled "Symantec's pcAnywhere Leaked Source Code," on torrent website The Pirate Bay.

   In a statement Tuesday, Symantec spokesman Cris Paden confirmed the sting operation.

   "The email string posted by Anonymous was actually between them and a fake email address set up by law enforcement," the statement said. "Anonymous actually actually reached out to us first, saying that if we provided them with money, they would not post any more source code. At that point, given that it was a clear cut case of extortion, we contacted law enforcement and turned the investigation over to them. All subsequent communication was actually between Anonymous and law enforcement agents -- not Symantec. This was all part of their investigative techniques for these types of incidents."

(责任编辑:)

分享到:

更多
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
  • 微笑/wx
  • 撇嘴/pz
  • 抓狂/zk
  • 流汗/lh
  • 大兵/db
  • 奋斗/fd
  • 疑问/yw
  • 晕/y
  • 偷笑/wx
  • 可爱/ka
  • 傲慢/am
  • 惊恐/jk
用户名: 验证码:点击我更换图片
资料下载专区
图文资讯

英国官员:让华为参与英国5G建设风险可控

英国官员:让华为参与英国5G建设风险可控

2月21日,英国金融时报报道称,在布鲁塞尔发表的一次演讲中,英国信号情报机构政府通...[详细]

西媒:以色列打造网络安全“硅谷”

西媒:以色列打造网络安全“硅谷”

2月13日报道 西媒称,凭借每年超过10亿美元的企业投资,以色列已经成为全球网络安全领...[详细]

俄罗斯力推脱离互联网计划 确保应急状态下

俄罗斯力推脱离互联网计划 确保应急状态下网络安全

俄罗斯新闻机构 RosBiznesKonsalting(RBK)上周报道称:作为计划实验的一部分,当局正...[详细]

GSMA呼吁欧洲守住网络安全和网络基建供应竞

GSMA呼吁欧洲守住网络安全和网络基建供应竞争力

5G将改变欧洲公民的生活和工作方式。5G作为现有4G网络的补充,与之协同工作将比以往更...[详细]

涉嫌窃取近千政界人士信息 德国20岁黑客遭

涉嫌窃取近千政界人士信息 德国20岁黑客遭逮捕

涉嫌窃取德国近千政界人士信息的黑客落网 政府拟修法加强网络安全 德国当局8日宣布,...[详细]

返回首页 返回顶部