Air-Gap Cyber Attack Detection

Air-Gap Cyber Attack Detection

On December 30th 2013 the ANT Catalogue, a 50-page classified document listing technology available to the United States National Security Agency (NSA) Tailored Access Operations (TAO) by the Advanced Network Technology (ANT) Division to aid in cyber surveillance, was leaked.

Since then numerous entities have been trying to reproduce these technologies.

Recently, one such entity developed and released a version of the ANT Catalogue’s COTTONMOUTH.

COTTONMOUTH provides air-gap bridging, software persistence capability, ‘in-field’ re-programmability and covert communication with a host software implant over a USB.

In essence it links an attacker with the target network remotely over an RF link.

 

Air-Gap Cyber Attack

USB Air-Gap Cyber Attack

 

Verrimus’s Critical Information Defence team obtained a commercially copied version of this cyber attack and set about testing it for function, capability and footprint.

The manufacturer claims it to be ‘’Undetectable to Firewalls, Anti-Virus Software or Visual Inspection’’ and these claims are in the main, absolutely true!

However…Verrimus has now completed testing, identified a significant flaw in its security, and designed into our operational protocol the capability to detect, identify and pinpoint locate this particular cyber attack.

All of our operations and training courses will now contain this capability.

For more information, contact Sarah@verrimus.com