U.S. deploys fake internet profiles to snoop & spread propaganda: HBGate

Hacked emails from US security contractor HBGary reveal sophisticated plans to spread fake Facebook profiles and other social networking utilities. The U.S. government contracted private companies to manage fake profiles that snoop on suspicious people and spread propaganda. Anyone on your friends list you don't actually know in person? You might want to delete them...

The software allegedly plants IPs from around the world so that a single computer can manage an "army" of fake people. The profiles are designed to coordinate with each other to glean a maximum amount of private information.

"Those names can be cross-referenced across Facebook, twitter, MySpace, and other social media services to collect information on each individual. Once enough information is collected this information can be used to gain access to these individuals social circles...

Even the most restrictive and security conscious of persons can be exploited. Through the targeting and information reconnaissance phase, a person’s hometown and high school will be revealed. An adversary can create a account at the same high school and year and find out people you went to high school with that do not have Facebook accounts, then create the account and send a friend request.

Under the mutual friend decision, which is where most people can be exploited, an adversary can look at a targets friend list if it is exposed and find a targets most socially promiscuous friends, the ones that have over 300-500 friends, friend them to develop mutual friends before sending a friend request to the target. To that end friend’s accounts can be compromised and used to post malicious material to a targets wall. When choosing to participate in social media an individual is only as protected as his/her weakest friend."

HBGary was developing methods of adding realistic elements to the profiles:

“There are a variety of social media tricks we can use to add a level of realness to all fictitious personas… Using hashtags and gaming some location based check-in services we can make it appear as if a persona was actually at a conference and introduce himself/herself to key individuals as part of the exercise, as one example.”

They claimed to use the software to find possible families of the CIA:

“and now social networks are closing the gap between attacker and victim, to the point I just found (via linked-in) 112 females, wives of service men, all stationed at Hurlbert Field FL – in case you don’t know this is where the CIA flies all their “private” airlines out of. What a damn joke – the U.S. is no longer the super power in cyber, and probably won’t be in other areas soon.”

More recent disclosures from HBGate include Cyber Chinese espionage details and a more complete binary of the Suxnet virus.

