📡(RTP) Privacy & Tech Tips · @RTP
3444 followers · 4849 posts · Server fosstodon.org
Robert Jan Mora · @robertjanm
9 followers · 9 posts · Server infosec.exchange

The first anchored narrative of 2023 has just been released! This time it is quite an explosive one of an in-depth malware forensic follow-up on the famous Bhima Koregaon case, where a nation-state threat actor named  planted evidence on the computers of several activists in India and; as a result, have been put in jail. In this anchored narrative, the latest report V from Arsenal Consulting will be covered as well as their techniques they applied to reconstruct the uploading of incriminating documents to the computer of an 84-year-old Jesuit Priest, Father Stan Swamy. I was interviewed to review that case by award-winning journalist Niha Masih from The Washington Post. From her, I received court documents detailing the forensics of Mr. Rona Wilson. In those documents, I found an unreported and unidentified piece of malware by the Regional Forensic Science Laboratory in Pune dating back to 2017. This is a horrifying case of poor digital forensics performed by the government and a red flag for our forensic community.

In short, a must-read!

anchorednarratives.substack.co

@hegel @SentinelLabs @nihamasih @agreenberg @citizenlab @washingtonpost

#ModifiedElephant #MemoryForensics #dfir #apt #malware #investigations #humanrights #InnocenceProject #bhimakoregaon

Last updated 3 years ago

(RTP):tor:Privacy & Tech Tips · @RTP
3043 followers · 4216 posts · Server fosstodon.org

When share personal info w/#SocialMedia, they are more open to targeting.

Ex: Activists / Journalists Targeted 10yr + Framed For False Assassination Charges.

-free matters: these individuals had false evidence planted on their devices.

Thankfully saved their lives (won't always be case)

tube.tchncs.de/w/p3X6RRccMjBmi

#activists #ModifiedElephant #india #backdoor #encryption #forensics #activism

Last updated 3 years ago

Tom Hegel · @hegel
448 followers · 32 posts · Server infosec.exchange

Quick post to summarize happenings in the world of 'APTs fabricating evidence to throw people in jail':

This week a new report was released by Arsenal Consulting related to pro bono forensic work they’ve done for defendants in the Bhima Koregaon (aka BK16) case in India. In this report, we’ve learned that a second defendant in the case was framed. The digital evidence of their crimes (domestic terrorism) were documents planted by – specifically a variety of NetWire RAT samples. This framed individual (Stan Swamy) died while incarcerated – he was an 84 year old priest.

@agreenberg at Wired wrote about this news here (definitely read!): wired.com/story/modified-eleph

Now this confirmation of evidence planting is simply not that surprising to us. Another defendant in the case (Rona Wilson) was confirmed to have evidence planted as well – and we’ve had confidence the same is done to many others. In addition to these two individuals, we know this same threat actor targeted many more individuals – including those not involved in this case at all. This threat actor is working in collusion with the Indian government, plain and simple.

We named this threat actor after profiling an extensive cluster of infrastructure and malware. The IOCs we released are tied to the decade+ life of the group so far.

PDF Report: s1.ai/mod-elephant

@jags and I did a BlackHat talk on this actor - a good overview on how they operate: youtu.be/zGorOeQS5C8

So, what’s next? The threat actor remains a focus of mine, and new research is ongoing. I hope to have more to share publicly soon.

#malware #ModifiedElephant #staytuned #bestjobieverhad

Last updated 3 years ago

Tom Hegel · @hegel
518 followers · 39 posts · Server infosec.exchange

Quick post to summarize happenings in the world of 'APTs fabricating evidence to throw people in jail':

This week a new report was released by Arsenal Consulting related to pro bono forensic work they’ve done for defendants in the Bhima Koregaon (aka BK16) case in India. In this report, we’ve learned that a second defendant in the case was framed. The digital evidence of their crimes (domestic terrorism) were documents planted by – specifically a variety of NetWire RAT samples. This framed individual (Stan Swamy) died while incarcerated – he was an 84 year old priest.

@agreenberg at Wired wrote about this news here (definitely read!): wired.com/story/modified-eleph

Now this confirmation of evidence planting is simply not that surprising to us. Another defendant in the case (Rona Wilson) was confirmed to have evidence planted as well – and we’ve had confidence the same is done to many others. In addition to these two individuals, we know this same threat actor targeted many more individuals – including those not involved in this case at all. This threat actor is working in collusion with the Indian government, plain and simple.

We named this threat actor after profiling an extensive cluster of infrastructure and malware. The IOCs we released are tied to the decade+ life of the group so far.

PDF Report: s1.ai/mod-elephant

@jags and I did a BlackHat talk on this actor - a good overview on how they operate: youtu.be/zGorOeQS5C8

So, what’s next? The threat actor remains a focus of mine, and new research is ongoing. I hope to have more to share publicly soon.

#malware #ModifiedElephant #staytuned #bestjobieverhad

Last updated 3 years ago

Tech News Worldwide · @TechNews
11313 followers · 97998 posts · Server aspiechattr.me
Verfassungklage · @Verfassungklage
1606 followers · 51599 posts · Server mastodon.social

in :

Falsche Beweise untergejubelt.

Die Gruppe soll falsche Beweise auf den Computer des indischen geschmuggelt haben. :innen zeichnen den Hack nach. ...

netzpolitik.org/2022/trojaner-

#trojaner #indien #ModifiedElephant #menschenrechtsaktivisten #RonaWilson #sicherheitsforscher

Last updated 4 years ago

(RTP):tor:Privacy & Tech Tips · @RTP
2618 followers · 3880 posts · Server fosstodon.org
(RTP):tor:Privacy & Tech Tips · @RTP
2618 followers · 3880 posts · Server fosstodon.org
(RTP):tor:Privacy & Tech Tips · @RTP
2618 followers · 3880 posts · Server fosstodon.org

has been framing defenders/activists, , and by planting incriminating digital evidence on their devices...

for *over* 10 years now.

Speaks to a high level of motivation, and what could happen if goes unchecked.

#ModifiedElephant #humanrights #lawyers #academics #surveillance #news #privacy

Last updated 4 years ago

(RTP):tor:Privacy & Tech Tips · @RTP
2618 followers · 3880 posts · Server fosstodon.org

's main goal is long term /spying.

Researchers find they are also planting false evidence on devices: to wrongly incriminate activists. Dirty tricks.

Reminding fighting for : not necessarily safe as it should be.

+ enhancements in , even concealment of identity helpful.

#ModifiedElephant #surveillance #activist #humanrights #privacy #security #news #india #activism #anonymous #anonymity

Last updated 4 years ago