Thursday, November 10, 2011

Boomerang; Is the Pentagon Field-Testing 'Son of Stuxnet'?


Boomerang! Is the Pentagon Field-Testing 'Son of Stuxnet'?


When the cybersecurity firm Symantec announced they had discovered a sophisticated Trojan which shared many of the characteristics of the Stuxnet virus, I wondered: was the Pentagon and/or their Israeli partners in crime field-testing insidious new spyware?

According to researchers, the malicious program was dubbed "Duqu" because it creates files with the prefix "~DQ." It is a remote access Trojan (RAT) that "is essentially the precursor to a future Stuxnet-like attack." Mark that carefully.

In simple terms, a Trojan is malicious software that appears to perform a desirable function prior to its installation but in fact, steals information from users spoofed into installing it, oftentimes via viral email attachments.

In the hands of enterprising security agencies, or criminals (the two are functionally synonymous), Trojans are primarily deployed for data theft, industrial or financial espionage, keystroke logging (surveillance) or the capture of screenshots which may reveal proprietary information.

"The threat" Symantec averred, "was written by the same authors (or those that have access to the Stuxnet source code) and appears to have been created since the last Stuxnet file was recovered."

The malware, which began popping-up on the networks of several European firms, captured lists of running processes, account and domain information, network drives, user keystrokes and screenshots from active sessions and did so by using a valid, not a forged certificate, stolen from the Taipei-based firm, C-Media.

Whereas Stuxnet, believed to be a co-production of U.S. and Israeli cyber-saboteurs, was a weaponized virus programmed to destroy Iran's civilian nuclear power infrastructure by targeting centrifuges that enrich uranium, Duqu is a stealthy bit of spy kit that filches data from manufacturers who produce systems that control oil pipelines, water systems and other critical infrastructure.

Sergey Golovanov, a malware expert at Kaspersky Labs told Forbes that Duqu is "is likely the brainchild of a government security apparatus. And it's that government's best work yet."

Speaking from Moscow, Golovanov told Forbes in a telephone interview that "right now were are pretty sure that it is the next generation of Stuxnet."

"We are pretty sure that Duqu is a government cyber tool and are 70% sure it is coming from the same source as Stuxnet," Golovanov said.

"The victims' computer systems were infected several days ago. Whatever it is," Golovanov noted, "it is still in those systems, and still scanning for information. But what exactly it is scanning for, we don't know. It could be gathering internal information for encryption devices. We only know that it is data mining right now, but we don't know what kind of data and to what end it is collecting it."

Whom, pray tell, would have "access to Stuxnet source code"?

While no government has claimed ownership of Stuxnet, IT experts told Forbes "with 100% certainty it was a government agency who created it."

Suspects include cryptologists at the National Security Agency, or as is more likely given the outsourcing of intelligence work by the secret state, a combination of designers drawn from NSA, "black world" privateers from large defense firms along with specialists from Israel's cryptologic division, Unit 8200, operating from the Israeli nuclear weapons lab at the Dimona complex, as The New York Times disclosed.

Analyst George Smith
noted: "Stuxnet was widely distributed to many computer security experts. Many of them do contract work for government agencies, labor that would perhaps require a variety of security clearances and which would involve doing what would be seen by others to be black hat in nature. When that happened all bets were off."

Smith averred, "once a thing is in world circulation it is not protected or proprietary property."

While one cannot demonstrably prove that Duqu is the product of one or another secret state satrapy, one can reasonably inquire: who has the means, motive and opportunity for launching this particular bit of nastiness into the wild?

"Duqu's purpose," Symantec researchers inform us, "is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party."

In other words, while Stuxnet was programmed to destroy industrial systems, Duqu is an espionage tool that will enable attackers "looking for information such as design documents that could help them mount a future attack on an industrial control facility."

Although it can be argued, as Smith does, that "source code for malware has never been secure," and "always becomes something coveted by many, often in direct proportion to its fame," it also can't be ruled out that military-intelligence agencies or corporate clones with more than a dog or two in the "cyberwar" hunt wouldn't be very interested in obtaining a Trojan that clips "industrial design" information from friend and foe alike.

Black Programs

The circulation of malicious code such as Duqu's is highly destabilizing. Considering that the U.S. Defense Department now considers computer sabotage originating in another country the equivalent to an act of war for which a military response is appropriate, the world is on dangerous new ground.

Speaking with MIT's Technology Review, Ronald Deibert, the director of
Citizen Lab, a University of Toronto think tank that researches cyberwarfare, censorship and espionage, told the publication that "in the context of the militarization of cyberspace, policymakers around the world should be concerned."

Indeed, given the fact that it is the United States that is now the biggest proliferator in the so-called cyber "arms race," and that billions of dollars are being spent by Washington to secure such weapons, recent history is not encouraging.

With shades of 9/11, the anthrax mailings and the Iraq invasion as a backdrop, one cannot rule out that a provocative act assigned to an "official enemy" by ruling elites just might originate from inside the U.S. security complex itself and serve as a convenient pretext for some future war.

A hint of what the Pentagon is up to came in the form of a controlled leak to The Washington Post.

Last spring, we were informed that "the Pentagon has developed a list of cyber-weapons and -tools, including viruses that can sabotage an adversary's critical networks, to streamline how the United States engages in computer warfare."

The list of "approved weapons" or "fires" are indicative of the military's intention to integrate "cyberwar" capabilities into its overall military doctrine.

According to Ellen Nakashima, the "classified list of capabilities has been in use for several months and has been approved by other agencies, including the CIA."

The Post reported that the new "framework clarifies, for instance, that the military needs presidential authorization to penetrate a foreign computer network and leave a cyber-virus that can be activated later."

On the other hand, and here's where Duqu may enter the frame, the "military does not need such approval, however, to penetrate foreign networks for a variety of other activities. These include studying the cyber-capabilities of adversaries or examining how power plants or other networks operate."

Additionally, Nakashima wrote, Pentagon cyberwarriors "can also, without presidential authorization, leave beacons to mark spots for later targeting by viruses, the official said."

As part of Washington's on-going commitment to the rule of law and human rights, as the recent due process-free drone assassination of American citizen Anwar Al-Awlaki, followed by that of his teenage son and the revenge killing of former Libyan leader Muammar Qaddafi by--surprise!--
Al Qaeda-linked militias funded by the CIA clearly demonstrate, the "use of any cyber-weapon would have to be proportional to the threat, not inflict undue collateral damage and avoid civilian casualties."

Try selling that to the more than 3,600 people killed or injured by CIA drone strikes, as
Pakistan Body Count reported, since our Nobel laureate ascended to his Oval Office throne.

As George Mason University researchers Jerry Brito and Tate Watkins described in their recent paper, Loving the Cyber Bomb? The Dangers of Threat Inflation in Cybersecurity Policy, despite overheated "rhetoric of 'cyber doom' employed by proponents of increased federal intervention," there is a lack of "clear evidence of a serious threat that can be verified by the public."

However, as Brito and Watkins warned, "the United States may be witnessing a bout of threat inflation similar to that seen in the run-up to the Iraq War," one where "a cyber-industrial complex is emerging, much like the military-industrial complex of the Cold War. This complex may serve to not only supply cybersecurity solutions to the federal government, but to drum up demand for them as well."

A "demand" which will inevitably feed the production, proliferation and deployment of a host of viral attack tools (Stuxnet) and assorted spybots (Duqu) that can and will be used by America's shadow warriors and well-connected corporate spies seeking to get a leg-up on the competition.

While evidence of "a serious threat" may be lacking, and while proponents of increased "cybersecurity" spending advanced "no evidence ... that opponents have 'mapped vulnerabilities' and 'planned attacks'," Brito and Watkins noted there is growing evidence these are precisely the policies being pursued by Washington.

Why might that be the case?

As a declining imperialist Empire possessing formidable military and technological capabilities, researcher Stephen Graham has pointed out in Cities Under Siege: The New Military Urbanism, the United States has embarked on a multibillion dollar program "to militarize the world's global electronic infrastructures" with a stated aim to "gain access to, and control over, any and all networked computers, anywhere on Earth."

Graham writes that "the sorts of on-the-ground realities that result from attacks on ordinary civilian infrastructure are far from the abstract niceties portrayed in military theory."

Indeed, as "the experiences of Iraq and Gaza forcefully remind us," robotized drone attacks and already-existent cyberwar capabilities buried in CIA and Pentagon black programs demonstrate that "the euphemisms of theory distract from the hard fact that targeting essential infrastructure in highly urbanized societies kills the weak, the old and the ill just as surely as carpet bombing."

A Glimpse Inside the Complex

In the wake of the HBGary hack by Anonymous earlier this year, the secrecy-shredding web site
Public Intelligence released a 2009 Defense Department contract proposal from the firm.

Among other things, it revealed that the Pentagon is standing-up offensive programs that "examine the architecture, engineering, functionality, interface and interoperability of Cyber Warfare systems, services and capabilities at the tactical, operational and strategic levels, to include all enabling technologies."

HBGary, and one can assume other juiced defense contractors, are planning "operations and requirements analysis, concept formulation and development, feasibility demonstrations and operational support."

"This will include," according to the leaked proposal, "efforts to analyze and engineer operational, functional and system requirements in order to establish national, theater and force level architecture and engineering plans, interface and systems specifications and definitions, implementation, including hardware acquisition for turnkey systems."

Indeed, the company will "perform analyses of existing and emerging Operational and Functional Requirements at the force, theater, Combatant Commands (COCOM) and national levels to support the formulation, development and assessment of doctrine, strategy, plans, concepts of operations, and tactics, techniques and procedures in order to provide the full spectrum of Cyber Warfare and enabling capabilities to the warfighter."

During the course of their analysis Symantec learned that Duqu "uses HTTP and HTTPS to communicate with a command-and-control (C&C) server that at the time of writing is still operational."

"The attackers were able to download additional executables through the C&C server, including an infostealer that can perform actions such as enumerating the network, recording keystrokes, and gathering system information. The information is logged to a lightly encrypted and compressed local file, which then must be exfiltrated out."

To where, and more importantly by whom was that information "exfiltrated" is of course, the $64,000 question.

A working hypothesis may be provided by additional documents published by
Public Intelligence.

According to a cyberwar proposal to the Pentagon by General Dynamics and HBGary, "Project C" is described as a program for the development "of a software application targeting the Windows XP Operating System that, when executed, loads and enables a covert kernel-mode implant that will exfiltrate a file from disk (or other remotely called commands) over a connected serial port to a remote device."

We're informed that Project C's "primary objectives" was the design of an implant "that is clearly able to exfiltrate an on-disk file, opening of the CD tray, blinking of the keyboard lights, opening and deleting a file, and a memory buffer exfiltration over a connected serial line to a collection station."

"As part of the exploit delivery package," HBGary and General Dynamics told their prospective customers, presumably the NSA, that "a usermode trojan will assist in the loading of the implant, which will clearly demonstrate the full capability of the implant."

Duqu, according to Symantec researchers, "uses a custom C&C protocol, primarily downloading or uploading what appear to be JPG files. However, in addition to transferring dummy JPG files, additional data for exfiltration is encrypted and sent, and likewise received."

While we don't know which firms were involved in the design of Stuxnet and now, Duqu, we do know thanks to Anonymous that HBGary had a Stuxnet copy, shared it amongst themselves and quite plausibly, given what we've learned about Duqu, Stuxnet source code may have been related to the above-mentioned "Project C."

Kevin Haley, Symantec's director of product management told The Register that "the people behind Stuxnet are not done. They've continued to do different things. This was not a one-shot deal."

Monday, October 31, 2011

Karachi: un fantôme aux portes de l'Elysée....




Un protagoniste inattendu et insaisissable a surgi dans l'enquête des juges Renaud Van Ruymbeke et Roger Le Loire sur les dessous des ventes d'armes du gouvernement Balladur. Il s'agit d'un fantôme. Son nom : Akim Rouichi, mort il y a seize ans. Comme l'a révélé Le Pointde cette semaine, ce militant associatif de Garges-lès-Gonesse (Val d'Oise) avait été chargé d'espionner des membres de la campagne présidentielle d'Edouard Balladur pour le compte des réseaux chiraquiens, en 1995, selon des témoignages recueillis ces dernières semaines par les policiers de la Division nationale des investigations financières (Dnif).

Akim Rouichi avait-il fait des découvertes compromettantes sur Nicolas Sarkozy et sur d'autres ministres du gouvernement Balladur? Son frère, François Rouichi, qui a décidé de briser plus de quinze ans de silence, le laisse entendre aujourd'hui à Mediapart.
A. RouichiA. Rouichi© (dr)
Ancien responsable de l'UMP à Garges-lès-Gonesse, François Rouichi assure qu'il avait surpris, en 1995, une conversation de son frère avec l'un de ses "officiers traitant" des Renseignements généraux (RG) durant laquelle il évoquait «l'autre de Neuilly», avant de citer son nom — Nicolas Sarkozy —, comme étant impliqué dans les troubles dessous financiers des ventes d'armes du gouvernement Balladur. Et il rapporte que son frère avait alors fait état de l'existence d'une société au Luxembourg, surnommée «la tirelire», qui aurait été liée à M. Sarkozy.
Auteur d'écoutes téléphoniques clandestines compromettantes pour plusieurs personnalités du camp Balladur -écoutes que les enquêteurs recherchent activement depuis plusieurs jours-, Akim Rouichi a été retrouvé pendu en août 1995 au domicile de l'une de ses sœurs, à Pierrefitte-sur-Seine (Seine-Saint-Denis).
A rebours des conclusions de la police et de la justice, sa famille n'a jamais cru que le jeune homme s'était donné la mort. Elle continue aujourd'hui de penser qu'il a été "suicidé", peut-être à cause des missions secrètes dont il a été chargé en pleine guerre homérique entre deux clans de la droite, les chiraquiens et les balladuriens.
D'après les éléments recueillis par les policiers, Akim Rouichi aurait été "traité" par deux anciens agents des services de renseignements français, l'un aux RG, l'autre à la DST, qui travaillaient en sous-main pour le clan Chirac. Pour mener à bien sa mission clandestine, il s'était vu confier tout l'attirail du parfait espion : scanner fréquentiel, numéros des téléphones portables visés, codes de déchiffrement pour les appareils cryptés et les agendas des "cibles".
Le jeune homme serait ainsi parvenu à surprendre pendant plusieurs mois les conversations de François Léotard, alors ministre de la défense du gouvernement Balladur, de son conseiller spécial Renaud Donnedieu de Vabres, de Charles Pasqua, ministre de l'intérieur, de l'ancien patron de Thomson, Alain Gomez, et de Jacques Douffiagues, ancien président d'un office d'armement, la Sofresa, récemment décédé.
Voici notre entretien vidéo avec François Rouichi :

Des écoutes clandestines sur des ministres

Ces personnalités sont au cœur des investigations des juges Van Ruymbeke et Le Loire. Depuis bientôt un an, les deux magistrats enquêtent sur l'existence, au sein du gouvernement Balladur, d'un système de détournement d'argent lié à deux marchés d'armement - l'un avec le Pakistan, l'autre avec l'Arabie saoudite - mis en place fin 1994 dans le but de financer de manière occulte la campagne présidentielle de l'ancien premier ministre. Voire, pour certains, de s'enrichir personnellement.
N. BazireN. Bazire© Reuters
Plusieurs personnes sont aujourd'hui mises en examen dans ce dossier qui remonte jusqu'à l'Elysée, parmi lesquelles le marchand d'armesZiad Takieddine, l'un des principaux intermédiaires sur les ventes d'armes incriminées, et deux intimes de Nicolas Sarkozy, à l'époque ministre du budget du gouvernement : son ancien collaborateur à Bercy, Thierry Gaubert, et l'ancien directeur de cabinet de M. Balladur, Nicolas Bazire, qui fut témoin de mariage du président de la République avec Carla Bruni, en 2008.
Au moins deux témoins directs ont affirmé ces derniers jours sur procès-verbal aux policiers de la Dnif avoir entendu le fruit de ces écoutes illégales d'Akim Rouichi. Il s'agit de François Rouichi, le frère de l'espion improvisé, et Jean-Charles Brisard, ancien responsable de la cellule "Jeunes" de la campagne d'Edouard Balladur.
En effet, en avril 1995, se disant «lâché» par les réseaux chiraquiens, Akim Rouichi est venu monnayer son trésor clandestin aux équipes d'Edouard Balladur. Arrivé au siège de campagne, rue de Grenelle, le jeune homme avait demandé à voir le directeur de la campagne, Nicolas Bazire. Il fut orienté ailleurs.
Et c'est finalement Jean-Charles Brisard qui l'a reçu, a pris connaissance de son histoire folle et a écouté des extraits de ses enregistrements pirates, en présence d'un témoin, dit-il aujourd'hui à Mediapart, avant de rédiger une note adressée Nicolas Bazire.
«J'ai reçu à sa demande il y a quelques jours une personne dénomée Akim Rouichi (...). Celui-ci nous a présenté un ordinateur contenant des enregistrements sonores de conversations téléphoniques interceptées. Ces enregistrements concernaient notamment MM. François Léotard et Renaud Donnedieu de Vabres, ainsi que plusieurs dirigeants d'entreprises d'armement», peut-on lire dans cette note aujourd'hui entre les mains des policiers.
Le document, daté du 5 avril 1995, a été publié par Le Pointdans son édition du 27 octobre:

Les révélations du frère

«Je n'ai eu aucun retour sur ma note, malgré le fait que je sollicitais des instructions», explique M. Brisard à Mediapart, qui confirme avoir reconnu, stupéfait, les voix de MM. Léotard et Donnedieu de Vabres dans les enregistrements qu'il a pu entendre. Le contrat des sous-marins Agosta vendus au Pakistan, au cœur de l'enquête des juges, et une histoire de livraison de missiles à l'Iran viaChypre, alimentaient certaines conversations, selon Jean-Charles Brisard. Devenu consultant international spécialisé dans le terrorisme, il dit toutefois n'avoir pas entendu parler de commissions occultes dans les extraits qu'il a écoutés.
Ce n'est pas le cas de François Rouichi, frère et confident d'Akim, que Mediapart a rencontré à deux reprises les 27 et 28 octobre. «Je me souviens très bien d'une discussion entre Pasqua et Léotard. L'un demandait à l'autre si le contrat était signé et s'il allait toucher sa commission. L'autre lui a dit que oui. Puis le premier a dit qu'il ne fallait surtout pas qu'un troisième soit au courant, comme s'ils se faisaient de l'argent sur le dos de quelqu'un», avance aujourd'hui le quadragénaire, ancien directeur d'un centre social.
© Reuters
Selon son récit, Akim Rouichi s'est très rapidement pris au jeu et, au fil des mois, aurait même été destinataires, grâce à ses « sources » policières, de documents compromettants sur les ventes d'armes françaises. Pour quelles raisons précises ? François Rouichi ne le sait pas.
Les années ont passé et les souvenirs ne sont pas toujours très nets dans son esprit. Il évoque néanmoins l'existence d'un document de la Sofresa, office d'armement qui a eu à gérer le versement au réseau Takieddine des commissions occultes du contrat des frégates saoudiennes Sawari 2, et d'un autre document lié, lui, à une société luxembourgeoise. «Mon frère me les a montrés», jure-t-il.
Puis il lâche ce qui pourrait ressembler à une bombe, si ces allégations venaient à être confirmées. «C'est là que mon frère a évoqué, alors qu'il était au téléphone avec une de ses sources aux RG, un homme qu'il appelait "l'autre de Neuilly", avec un nom à consonance étrangère qui venait de l'Est. Je pensais à un nom polonais. Puis il a cité son nom. Il l'a cité au moment où il a eu entre les mains ce document sur une société au Luxembourg, qu'il appelait "la tirelire"»,confie François Rouichi. M. Rouichi avoue qu'il ne savait pas à l'époque qui était Nicolas Sarkozy. Les choses, depuis, ont changé...
«Le document comportait un texte et un chiffrage, cela apparaissait comme une sorte de compte bancaire. Mon frère l'appelait "la tirelire". L'"autre de Neuilly" était dedans, d'après mon frère», assure François Rouichi, qui ne se sait pas si Nicolas Sarkozy a fait partie des personnalités écoutées.Aucun élément matériel ne vient aujourd'hui corroborer ce témoignage, les enquêteurs recherchant les écoutes pirates réalisées en 1995.

Vrai ou faux suicide ?

C'est la première fois que François Rouichi parle de «l'autre de Neuilly», dit-il. Il n'en avait rien dit aux policiers qui l'ont entendu sur l'affaire, le 13 octobre. Il a alors hésité à se confier, assure-t-il à Mediapart, mais a préféré «fermer sa gueule». «J'avais peur, glisse-t-il. Cela fait quinze ans que quand on parle de cette histoire, on nous prend pour des fous ou des menteurs. Aujourd'hui il faut que je le dise. Devant les policiers, j'avais la peur de citer quelqu'un qui est peut-être au-dessus de tout. Mais je dois le faire pour mon frère et pour que cette personne (Nicolas Sarkozy, ndlr) sache que quelqu'un sait».
Il se dit prêt aujourd'hui à coucher sur procès-verbal ces nouvelles confidences, s'il venait à être convoqué de nouveau par les enquêteurs.
© (Reuters)
L'apparition d'une société luxembourgeoise dans les propos de M. Rouichi est pour le moins troublante.Selon un rapport de la police luxembourgeoise de janvier 2010, Nicolas Sarkozy, ministre du budget, et Nicolas Bazire, alors à Matignon, auraient en effet supervisé et validé la création au Luxembourg d'une société-écran, baptisée Heine, par laquelle ont justement transité les commissions occultes du réseau Takieddine sur le contrat des sous-marins pakistanais.
Or, Ziad Takieddine est soupçonné d'avoir redistribué une partie de cet argent noir pour des financements politiques.
Dans leur enquête qui prend désormais des allures de thriller invraisemblable, les juges sont donc partis à la recherche des enregistrements clandestins d'Akim Rouichi. Car selon François Rouichi, son frère avait fait des copies sur des disquettes informatiques. «Ces disquettes ont été remises d'une part à nos avocats, du cabinet Lombard, et d'autre part à la secrétaire de Jean-Luc Mano, alors directeur de l'information à Antenne 2, qui n'en a rien fait», explique-t-il.
Jean-Luc Mano, cité par Le Point, dément catégoriquement. Quant au cabinet Lombard, il dément aussi, par la voix de Me Olivier Baratelli, contacté par Mediapart. «Nous n'avons jamais entendu parlé de ces enregistrements», affirme l'avocat.
Le mystère reste donc entier ; et ce n'est pas le seul. Les magistrats ont également chargé les policiers de la Dnif d'éclaircir les circonstances de la mort d'Akim Rouichi.
La famille Rouichi, persuadée qu'Akim a été "suicidé", avait déjà chargé en 1996 le cabinet de l'avocat Paul Lombard de déposer plainte pour «assassinat» devant le doyen des juges du tribunal de grande instance de Bobigny.

« La République a les pieds dans le sang ».

Une instruction, confiée au juge Noël Miniconi, avait finalement débouché deux ans plus tard sur un non-lieu et conclu au suicide d'Akim Rouichi, notamment sur la foi d'un rapport de l'Institut médico-légal de Paris du 29 août 1995 qui se concluait ainsi : «Il résulte que la mort de M. ROUICHI Akim est consécutive à sa pendaison. L'autopsie n'a pas relevé d'éléments infirmant la thèse du suicide».
Entendue le 21 janvier 1997 par le juge Miniconi, l'une des sœurs d'Akim Rouichi, Suzanne (aujourd'hui décédée), avait cependant évoqué les enregistrements clandestins sur le camp Balladur et s'était étonnée que «que le cartable de son frère soit vide alors qu'il contenait des disquettes», selon le procès-verbal de son audition obtenu par Mediapart. Les révélations de la jeune femme ne semblent pas avoir beaucoup piqué la curiosité du magistrat, à la lecture du PV de deux pages.
MM. Léotard, Juppé et BalladurMM. Léotard, Juppé et Balladur© Reuters

«Il y avait notamment des documents concernant des conversations téléphoniques entre M. Pasqua et M. Léotard, faisant état de missiles vendus à l'étranger, que mon frère avait pu écouter, avait pourtant assuré le témoin devant le juge. Mon frère avait reçu la visite de fonctionnaires du ministère de l'intérieur lui demandant de ne pas en parler (...) C'est à la suite de ces problèmes d'écoutes que mon frère m'a dit qu'il craignait pour sa vie, qu'il se sentait épié».
«Convaincue qu'on a aidé (son) frère à mourir», Suzanne Rouichi avait indiqué au juge ne pas savoir si la mort de son frère était directement liée aux écoutes ou à un différend avec une famille de leur quartier.
Mais pour Suzanne, comme pour sa mère, Rachida, ou ses frères, une chose semble certaine : Akim ne s'est pas suicidé. Deux éléments les interpellent. D'abord, l'une des lettres retrouvées sur les lieux de la découverte du corps, adressée à une certaine Sophie (qui serait l'ex-secrétaire de Jean-Luc Mano), ne comporte aucune faute d'orthographe. «C'est l'écriture de mon frère (...) Il a dû faire des efforts car il n'y a pas de faute alors qu'il en faisait dix à la ligne».
La lettre, qui fait état de problèmes sentimentaux, se termine ainsi : «Je prends le temps de t'écrire avant de partir. Ils m'ont tué et toi tu m'as achevé». François Rouichi est formel, la "Sophie" en question n'a jamais été la petite amie de son frère. Une deuxième lettre a également été retrouvée près du corps. Elle commence par les mots «mes dernières volontés» et comporte la mention «Je regrette le suicide».
Ensuite, Suzanne a dit au juge Miniconi avoir découvert - et photographié - à l'emplacement du cadavre «des traces de sang» et «une grande flaque au sol qui avait coulé jusqu'aux toilettes et des projections aux murs». La mère du d'Akim Rouichi a même évoqué dans le cabinet du magistrat l'existence de «tâches sur le haut des portes».
D'après les résultats d'une expertise médicale en date du 24 novembre 1997, signée par le Dr Jean-Pierre Campana (voir ci-dessous), la flaque en question «évoque les liquide brunâtres qui s'écoulent des corps putréfiés, la décomposition provoquant toujours une liquéfaction de tissus». De fait, le corps d'Akim Rouichi a été découvert plusieurs jours après la pendaison, vraie ou fausse.
«Une flaque de l'importance de celle que l'on voit sur les photographies, à supposer qu'elle était sanguine, aurait impliqué une hémorragie externe très importante et donc une plaie bien visible», précise encore le rapport, dont les constations finales «sont en faveur d'un suicide».
Contacté, le juge de l'époque, Noël Miniconi, aujourd'hui en poste à Lyon, dit se souvenir «difficilement» de l'affaire, mais garde en mémoire qu'il n'y avait «pas d'éléments dans le dossier qui permettaient de conclure à autre chose qu'un suicide».
Pour le frère d'Akim Rouichi, il faut reprendre l'enquête du début. «Mon frère était menacé. Il est allé trop loin dans son "enquête". Ses sources lui avaient demandé d'arrêter. Il ne l'a pas fait. Il soupçonnait l'une d'entre elles de jouer un double jeu. Il avait tellement peur qu'il était allé se planquer chez l'une de nos sœurs, là où on l'a retrouvé pendu», raconte-t-il.
Puis il ajoute : «La République Francaise a les pieds dans le sang».....

Thursday, October 27, 2011

Multiple casing activities of government buildings during San Antonio intelligence conference. Mossad fingered....


Multiple casing activities of government buildings during San Antonio intelligence conference. Mossad fingered....


October , 2011 -- San Antonio court house break-in has national security ramifications...


Retired CIA sources in Texas tell us that the recent break-in of the Bexar County Court House in San Antonio was not the work of a few drunk French nationals, said to be of Moroccan descent, but part of a larger intelligence operation directed against the United States by a foreign intelligence service, reportedly that of Israel.

On October 22, 2011, WMR reported: "although they broke into a court house and were, allegedly, French citizens of Moroccan descent, charges against three of the five 'tourists' were dropped by Bexar County Magistrate Judge Amalia 'Molly' Cavazos" The decision puzzled the Bexar County Sheriff's office and the county district attorney's office.

The incident at the Bexar County Court House also worries U.S. Representative Henry Cuellar, a member of the House Homeland Security Committee. Cuellar KSAT-TV in San Antonio that the night before the "French" nationals broke into the court house, a Turkish national was detained for suspiciously taking photographs of the old main post office building, which is next to the Alamo. Like the French nationals, the Turkish national was said to be a tourist.

Sources believe the presence of the "French" nationals in the court house was related to the nearby
GEOINT Symposium, billed as the nation's largest annual intelligence event, at the Henry B. Gonzalez Convention Center was related to the operations of the team at the court house.

The word is that law enforcement and U.S. intelligence are prohibited from arresting and bringing charges against Israeli intelligence agents in the United States, even if the agents are found to be involved in operations that impact on U.S. national security and threaten the safety of American citizens. To pursue Israeli intelligence operations, against an unwritten prohibition, is for an FBI or CIA agent to sign his or her own professional death sentence, with a charge of "anti-Semitism" sealing the fate of anyone who dares challenge the "hands-off" policy on Israeli agents.

We received the following from a veteran U.S. intelligence source in Texas:

"Too many unanswered questions. The charges against the three were dropped by a Magistrate Judge even before the search of the RV was completed. I can't help but wonder if they installed some type of listening devices inside of the Court House? Also, if it is the Court House that I am thinking of, there is a direct line of sight to the Henry B. Gonzalez Convention Center. If it is that specific Court House then they could have easily installed a micro-transmitter capable of intercepting signals intelligence from the National Geospatial Intelligence Convention somewhere in the Court House, which has yet to be discovered. Their computers would have the requisite receivers and they could have lingered in the area and picked up intelligence from the convention center. I also find it interesting that the charges were dropped by a Magistrate Judge before the RV was searched and before the computers could have been gone through. The five are probably on their way to whatever their next destination is.
It is a long drive from NY JFK to Miami to pick up one person. Where did they stop on the way? Why did they drive to Miami instead of one person getting a flight from MIA to JFK? How long did it take the four to get to Miami from JFK? When did they make their reservations for the RV in New Jersey? Why did the Feds back off and leave the case to the Bexar County Prosecutor? The Feds could have put a "hold" on the 5 or at a minimum the three. The only conclusion that one can reach is that there are multiple unanswered questions that even a minor league Intel officer would pursue. Did the FBI put GPS tracking on their RV? If not, why not? Nothing about this case stands up to any scrutiny. If three regular people were caught breaking into the exact same Court House they would face charges of 'Breaking and entering,' 'Burglary' or 'Criminal Mischief,' but they would not have all charges dropped. I would be interested if they are being tracked via GPS that could yield a lot of information and prove what they are really up to. No reason not to track them in the first instance."

Israel appears to have learned its lesson from past intelligence exposures on U.S. soil. By using nationals of France and Turkey, both of which have an ample number of sayanim, Jewish collaborators for Israeli intelligence, Israeli consular officials can avoid the diplomatic and public relations fallout, such as what arose after arrests across the country of Israeli "art students," "movers," and mall kiosk vendors. Instead of Israeli diplomats with egg on their faces, that fell to French and Turkish consular officers in Texas. There was also the odd report that the French consulate in Dallas was contacted to handle the matter of the five burglars at the San Antonio Court House. However, the French are represented in Dallas by an Honorary Consul, hardly the sort of individual who would get involved in a potential criminal matter involving French nationals. France maintains a full consulate in Houston.

The five French nationals arrested claimed not to be conversant in English, however, they were all proficient in English. Israelis, when arrested, often claim to not understand English, which results in a delay in interrogations until Israeli diplomatic officials can bail them out.

We also received the following item of interest from intelligence sources in Texas: "This district for U.S. District Courts [Hipolito F. Garcia Federal Building and U.S. Courthouse, Southern District of Texas] has more CIA operatives in it than anywhere else in Texas outside of Houston. I am told that. St. Mary's Law School in San Antonio is a major player in security and terror. In reading this story, couple the highest ranking Mossad spy in Texas with that program at St. Mary's."




....
November , 2011 -- More on "innocent" pranksters/MOSSAD in San Antonio....

Bexar court invasion far from a prank.....

The case involving a night time break-in of the Bexar County court house in San Antonio is developing into a much more sinister operation as more details become known.

On October 25, 2011, WMR reported: "Retired CIA sources in Texas tell WMR that the recent break-in of the Bexar County Court House in San Antonio was not the work of a few drunk French nationals, said to be of Moroccan descent, but part of a larger intelligence operation directed against the United States by a foreign intelligence service, reportedly that of Israel . . . Sources believe the presence of the "French" nationals in the court house was related to the nearby
GEOINT Symposium, billed as the nation's largest annual intelligence event, at the Henry B. Gonzalez Convention Center was related to the operations of the team at the court house."

WMR has now been informed by law enforcement sources in Texas of the following concerning the break-in: "[A]
further analysis of the photo of the two men walking down the hall in the Bexar County Courthouse: At the top left it indicates:
CH32.10.11.11.1:14AM. As I interpret that data, it is Camera 32 and the photo was taken at 1:14 AM which is consistent with the alleged entry at or about 0100, which means that the photo released to the media is only one of many others and was, by the reports, taken 14 minutes after the alarm on the fire escape went off. Both men are carrying boxes and the front man has what appears to be a pouch hanging from his belt on his right side.
. . . blowing up the photo to 400 percent and tracing the lines on the left arm of the last man and just above the wrist joint, it flares out. He was wearing gloves. The same for the front person. If you look at the position of the arms on the man in front he had his arms in the same position as the man in the back and was carrying a box also. Two men, two Boxes, two sets of gloves, two Sombreros, 14 minutes after entry."


T
wo of the five "drunk Frenchmen" seen on court house security cameras.

The conclusion of law enforcement in Texas who are not trained. i.e., brainwashed,| by the Israelis is that there was something in the boxes being carried by the "drunk Frenchmen" and it is reminiscent of suspicious Israeli "art student" and "mover" behavior around federal and state buildings prior to 9/11. However, considering that the FBI, Drug Enforcement Administration, and the military were ordered to "stand down" on pursuing criminal investigations of pre-9/11 Israeli intelligence activities, it is unlikely that further proof that the Bexar court house break-in will go anywhere since San Antonio judges and law enforcement officials appear to be taking their orders from elsewhere on the "drunk Frenchmen...."