IP EXPO Manchester Launches for 2017 as Government Announces New Investment...

Bringing the Latest and Greatest on Technology Industry Issues from Artificial Intelligence to Cyber Security to the North West, for a Third Successful Year

London, 25 January 2017 – IP EXPO Manchester, part of Europe's number one enterprise IT event series, today launches its 2017 showcase, which promises to be the most insightful and topical yet.

IP EXPO Manchester Be Inspired

2017 is a year of opportunity for Manchester, with Prime Minister Theresa May allocating £130.1 million in investment for the Greater Manchester region. Manchester City Council will also invest an additional £4 million in two new tech hubs to support the Northern cities booming technology, science and digital industries.

With additional focus on development in AI, AR, VR and automation technologies, Manchester is well placed to continue to grow its international technology reputation and be at the forefront of overcoming industry issues and challenges.

Be it Brexit, changes in European legislation such as General Data Protection Regulation (GDPR), or the advancement of artificial intelligence, there is a vast landscape of new issues for IT professionals to navigate.

For its 2017 event, IP EXPO Manchester will address all these changes in the region by providing local organisations with access to an unprecedented group of influential speakers and brands across central themes of Cloud, Cyber Security, Networks and Infrastructure, DevOps, Open Source and a brand new topic combining AI, Analytics and IoT. Now in its third successful year, the two-day event will take place on 26-27 April 2017 at the Manchester Central, Manchester.

“2017 is shaping up to be one of the most transformative years ever with so many disruptive and exciting new technologies now mature and available.

Add to this the growing need for businesses to digitally transform to stay competitive and the continued growth of the cyber threat landscape there is a crucial need for information, expertise and advice. Our mission is to provide our attendees with rare access to the industry leaders and the world class experts that are creating and shaping these technologies.” comments Bradley Maule-ffinch, EMEA Portfolio Director for the IP EXPO Event Series.

He continues, “IP EXPO Manchester is our fastest growing event and easily the largest enterprise IT event in the North.

Artificial Intelligence, going serverless, DevOps and Cloud technologies are just some of the areas we’ll be covering as well as our cyber security content around GDPR, ransomware, social engineering, and threat protection.
IP EXPO Manchester aims to bring together the right people and brands under one roof to help IT professionals discuss, debate and discover more about the challenges and opportunities these issues bring to the region and beyond.”

2017 Programme highlights include:

  • Panel debate on the ‘Future of Artificial Intelligence’ featuring Amy Nicholson, Tech Evangelist Microsoft UK
  • Live hack demonstration from Ken Munro, Founder of Pen Test Partners
  • Industry leading speakers such as:
    • David Lewis – Global Security Advocate at Akamai Technologies
    • James Akrigg – Head of Technology for Partners at Microsoft
    • Paul J Taylor – Detective Constable for Cyber Crime at Greater Manchester Police
    • Jenny Radcliffe – ‘The People Hacker’

For further information and to register free for IP EXPO Manchester 2017, please visit: www.ipexpomanchester.com.

Get involved on Twitter using #IPEXPOManchester

About IP EXPO Manchester
IP EXPO Manchester is part of Europe’s number one enterprise IT event series, IP EXPO.

The event series also includes IP EXPO Europe in London and IP EXPO Nordic in Sweden. Launched by organisers Imago Techmedia in 2015, the event now encompasses six events under one roof including Cloud, Cyber Security, Networks and Infrastructure, DevOps, Open Source and a brand new topic combining AI, Analytics and IoT.

Designed for those looking to find out how the latest IT innovations can drive and support their business and transition to a digital future

The event showcases brand new exclusive content and senior level insights from across the industry, as well as unveiling the latest developments in IT.
It covers everything you need to run a successful enterprise or organisation.

Head of GCHQ Robert Hannigan steps down for ‘personal reasons’

Cites demand on his family, will be replaced by 2019 The Director General of GCHQ, Robert Hannigan, has announced his intention to step down as leader of the signals intelligence agency. Citing "personal reasons", Hannigan informed the UK's Foreign Secretary of his decision in an exchange of letters. His departure comes at a difficult time for the agency as pro-torture President Trump is set to be on the other end of Cheltenham's phone. Hannigan said he was proud of the "relentless 24-hour operational effort against terrorism, crime and many other national security threats. While this work must remain secret, you will know how many lives have been saved in this country and overseas by the work of GCHQ." Underpinning this is our world-class technology and, above all, our brilliant people.

As you know, I have also initiated the greatest internal change within GCHQ for thirty years, and I feel that we are now well on the way to being fit for the next generation of security challenges to the UK in the digital age. GCHQ will be celebrating what it regards as its centenary in 2019, having originated as the Government Code and Cypher School, by which time Hannigan hopes a successor will be appointed. He said he was lucky to have had "some extraordinary roles in public service over the last 20 years, from Northern Ireland to Number 10, the Cabinet Office and the Foreign Office" but that such roles "demanded a great deal of my ever-patient and understanding family, and now is the right time for a change in direction". The Foreign Secretary responded by wishing Hannigan "the very best for your future career". There will now be an internal competition within government to identify candidates (our guess) to succeed Hannigan for onward recommendation to the Foreign Secretary and the Prime Minister.
In the meantime, the director and board will continue to oversee all the department's work. ® Sponsored: Next gen cybersecurity.
Visit The Register's security hub

The “EyePyramid” attacks

On January 10, 2017, a court order was declassified by the Italian police, in regards to a chain of cyberattacks directed at top Italian government members and institutions. The attacks leveraged a malware named “EyePyramid” to target a dozen politicians, bankers, prominent freemasons and law enforcement personalities in Italy.

These included Fabrizio Saccomanni, the former deputy governor of the Bank of Italy, Piero Fassino, the former mayor of Turin, several members of a Masonic lodge, Matteo Renzi, former prime minister of Italy and Mario Draghi, another former prime minister of Italy and now president of the European Central Bank. The malware was spread using spear-phishing emails and the level of sophistication is low. However, the malware is flexible enough to grant access to all the resources in the victim’s computer. During the investigation, involved LEAs found more than 100 active victims in the server used to host the malware, as well as indications that during the last few years the attackers had targeted around 16,000 victims.

All identified victims are in Italy, most of them being Law Firms, Consultancy services, Universities and even Vatican Cardinals. Evidence found on the C&C servers suggests that the campaign was active since at least March 2014 and lasted until August 2016. However, it is suspected that the malware was developed and probably used years before, possibly as far back to 2008. Two suspects were arrested on January 10th, 2017 and identified as 45-year-old nuclear engineer Giulio Occhionero and his 47-year-old sister Francesca Maria Occhionero. Investigation Although the Italian Police Report doesn’t include malware hashes, it identified a number of C&C servers and e-mails addresses used by the malware for exfiltration of stolen data. Excerpt from the Italian court order on #EyePyramid(http://www.agi.it/pictures/pdf/agi/agi/2017/01/10/132733992-5cec4d88-49a1-4a00-8a01-dde65baa5a68.pdf) Some of the e-mail addresses used for exfiltration and C&C domains outlined by the police report follow: E-mail Addresses used for exfiltration gpool@hostpenta[.]com hanger@hostpenta[.]com hostpenta@hostpenta[.]com purge626@gmail[.]com tip848@gmail[.]com dude626@gmail[.]com octo424@gmail[.]com tim11235@gmail[.]com plars575@gmail[.]com Command-and-Control Servers eyepyramid[.]com hostpenta[.]com ayexisfitness[.]com enasrl[.]com eurecoove[.]com marashen[.]com millertaylor[.]com occhionero[.]com occhionero[.]info wallserv[.]com westlands[.]com Based on these indicators we’ve quickly written a YARA rule and ran it through our systems, in order to see if it matches any samples. Here’s how our initial “blind”-written YARA rule looked like: rule crime_ZZ_EyePyramid { meta: copyright = ” Kaspersky Lab”author = ” Kaspersky Lab”maltype = “crimeware”filetype = “Win32 EXE”date = “2016-01-11”version = “1.0” strings: $a0=”eyepyramid.com” ascii wide nocase fullword$a1=”hostpenta.com” ascii wide nocase fullword$a2=”ayexisfitness.com” ascii wide nocase fullword$a3=”enasrl.com” ascii wide nocase fullword$a4=”eurecoove.com” ascii wide nocase fullword$a5=”marashen.com” ascii wide nocase fullword$a6=”millertaylor.com” ascii wide nocase fullword$a7=”occhionero.com” ascii wide nocase fullword$a8=”occhionero.info” ascii wide nocase fullword$a9=”wallserv.com” ascii wide nocase fullword$a10=”westlands.com” ascii wide nocase fullword$a11=”″ ascii wide nocase fullword$a12=”″ ascii wide nocase fullword$a13=”″ ascii wide nocase fullword$a14=”″ ascii wide nocase fullword$a15=”″ ascii wide nocase fullword$a16=”MN600-849590C695DFD9BF69481597241E-668C” ascii wide nocase fullword$a17=”MN600-841597241E8D9BF6949590C695DF-774D” ascii wide nocase fullword$a18=”MN600-3E3A3C593AD5BAF50F55A4ED60F0-385D” ascii wide nocase fullword$a19=”MN600-AD58AF50F55A60E043E3A3C593ED-874A” ascii wide nocase fullword$a20=”gpool@hostpenta.com” ascii wide nocase fullword$a21=”hanger@hostpenta.com” ascii wide nocase fullword$a22=”hostpenta@hostpenta.com” ascii wide nocase fullword$a23=”ulpi715@gmx.com” ascii wide nocase fullword$b0=”purge626@gmail.com” ascii wide fullword$b1=”tip848@gmail.com” ascii wide fullword$b2=”dude626@gmail.com” ascii wide fullword$b3=”octo424@gmail.com” ascii wide fullword$b4=”antoniaf@poste.it” ascii wide fullword$b5=”mmarcucci@virgilio.it” ascii wide fullword$b6=”i.julia@blu.it” ascii wide fullword$b7=”g.simeoni@inwind.it” ascii wide fullword$b8=”g.latagliata@live.com” ascii wide fullword$b9=”rita.p@blu.it” ascii wide fullword$b10=”b.gaetani@live.com” ascii wide fullword$b11=”gpierpaolo@tin.it” ascii wide fullword$b12=”e.barbara@poste.it” ascii wide fullword$b13=”stoccod@libero.it” ascii wide fullword$b14=”g.capezzone@virgilio.it” ascii wide fullword$b15=”baldarim@blu.it” ascii wide fullword$b16=”elsajuliette@blu.it” ascii wide fullword$b17=”dipriamoj@alice.it” ascii wide fullword$b18=”izabelle.d@blu.it” ascii wide fullword$b19=”lu_1974@hotmail.com” ascii wide fullword$b20=”tim11235@gmail.com” ascii wide fullword$b21=”plars575@gmail.com” ascii wide fullword$b22=”guess515@fastmail.fm” ascii wide fullword condition: ((uint16(0) == 0x5A4D)) and (filesize < 10MB) and((any of ($a*)) or (any of ($b*)) )} To build the YARA rule above we’ve used every bit of existing information, such as custom e-mail addresses used for exfiltration, C&C servers, licenses for the custom mailing library used by the attackers and specific IP addresses used in the attacks. Once the YARA rule was ready, we’ve ran it on our malware collections.

Two of the initial hits were: MD5 778d103face6ad7186596fb0ba2399f2 File size 1396224 bytes Type Win32 PE file Compilation Timestamp Fri Nov 19 12:25:00 2010 MD5 47bea4236184c21e89bd1c1af3e52c86 File size 1307648 bytes Type Win32 PE file Compilation timestamp Fri Sep 17 11:48:59 2010 These two samples allowed us to write a more specific and more effective YARA rule which identified 42 other samples in our summary collections. At the end of this blogpost we include a full list of all related samples identified. Although very thorough, the Police Report does not include any technical details about how the malware was spread other than the use of spear phishing messages with malicious attachments using spoofed email addresses. Nevertheless, once we were able to identify the samples shown above we used our telemetry to find additional ones used by the attackers for spreading the malware in spear-phishing emails.

For example: From: Di Marco GianmariaSubject: ricezione e attivazioneTime:2014/01/29 13:57:42Attachment: contatto.zip//Primarie.accdb (…) .exe From: Michelangelo GiorgianniSubject: R: Re: CONVOCAZIONE]Time: 2014/01/28 17:28:56]Attachment: Note.zip//sistemi.pdf (…) .exe Other attachment filenames observed in attacks include: Nuoveassunzioni.7z Assunzione.7z Segnalazioni.doc (…) 7z.exe Regione.7z Energy.7z Risparmio.7z Pagati.7z Final Eight 2012 Suggerimenti Uso Auricolari.exe Fwd Re olio di colza aggiornamento prezzo.exe Approfondimento.7z Allegato.zip Eventi.bmp (…) .exe Quotidiano.mdb (…) _7z.exe Notifica operazioni in sospeso.exe As can be seen the spreading relied on spearphishing e-mails with attachments, which relied on social engineering to get the victim to open and execute the attachment.

The attachments were ZIP and 7zip archives, which contained the EyePyramid malware. Also the attackers relied on executable files masking the extension of the file with multiple spaces.

This technique is significant in terms of the low sophistication level of this attack. High profile victims Potential high-profile Italian victims (found as recipients of spear-phishing emails according to the police report) include very relevant Italian politicians such as Matteo Renzi or Mario Draghi. It should be noted however there is no proof than any of them got successfully infected by EyePyramid – only that they were targeted. Of the more than 100 active victims found in the server, there’s a heavy interest in Italian law firms and lawyers.

Further standout victims, organizations, and verticals include: Professional firms, Consultants Universities Vaticano Construction firms Healthcare Based on the KSN data for the EyePyramid malware, we observed 92 cases in which the malware was blocked, of which the vast majority (80%) of them were in Italy. Other countries where EyePyramid has been detected includes France, Indonesia, Monaco, Mexico, China, Taiwan, Germany and Poland. Assuming their compilation timestamp are legit – and they do appear correct, most of the samples used in the attacks have been compiled in 2014 and 2015. Conclusions Although the “EyePyramid” malware used by the two suspects is neither sophisticated nor very hard to detect, their operation successfully compromised a large number of victims, including high-profile individuals, resulting in the theft of tens of gigabytes of data. In general, the operation had very poor OPSEC (operational security); the suspects used IP addresses associated with their company in the attacks, discussed the victims using regular phone calls and through WhatsApp and, when caught, attempted to delete all the evidence. This indicates they weren’t experts in the field but merely amateurs, who nevertheless succeeded in stealing considerably large amounts of data from their victims. As seen from other known cyberespionage operations, it’s not necessary for the attackers to use high profile malware, rootkits, or zero-days to run long-standing cyberespionage operations. Perhaps the most surprising element of this story is that Giulio Occhionero and Francesca Maria Occhionero ran this cyber espionage operation for many years before getting caught. Kaspersky Lab products successfully detect and remove EyePyramid samples with these verdicts: HEUR:Trojan.Win32.Generic Trojan.Win32.AntiAV.choz Trojan.Win32.AntiAV.ciok Trojan.Win32.AntiAV.cisb Trojan.Win32.AntiAV.ciyk not-a-virus:HEUR:PSWTool.Win32.Generic not-a-virus:PSWTool.Win32.NetPass.aku A full report #EyePyramid, including technical details of the malware, is available to customers of Kaspersky APT Intelligence Services.

Contact: intelreports (at) kaspersky [dot] com
. To learn how to write YARA rules like a GReAT Ninja, consider taking a master class at Security Analyst Summit. – https://sas.kaspersky.com/#trainings References and Third-Party Articles Indicators of Compromise 