In the Year 2889 (also known as Year 2889) is a 1967 American made-for-television horror science fiction film from American International Pictures about the aftermath of a future nuclear war.[1] The film stars Paul Petersen, Quinn O'Hara, Charla Doherty, Neil Fletcher and Hugh Feagin. AIP commissioned low-budget cult film auteur Larry Buchanan to produce and direct this film as a color remake of Roger Corman's 1956 film Day the World Ended.[2]
Although not set in the year 2889, In the Year 2889's title is borrowed from a short story of the same title by Jules Verne and his son, Michael Verne. (The film however did not follow the Jules Verne story at all.) The screenplay was written for Buchanan by Harold Hoffman.[3][4]
A nuclear war has wiped out most of Earth's population. The film follows a group of survivors who are holed up in a secluded valley and must protect themselves from rising radiation levels, mutants, and in some cases, each other.[5]
AIP gave Buchanan the script of the 1955 Corman film Day the World Ended, originally written by Lou Rusoff, to use for this film, resulting in an almost line-for-line, scene-for-scene remake.[citation needed]
This was Buchanan's fifth Azalea Productions film.[citation needed] It was made by AIP six years after the success of their 1961 Jules Verne adaptation Master of the World.[citation needed] Because this was an even lower budget remake of the earlier low budget Corman film, it needed a new title; AIP already had a registered title available (for a previously unmade Verne project), so it was used on the Buchanan film.[citation needed]
AIP's 1950s special effects technician Paul Blaisdell, who handled the effects in the original AIP film Day the World Ended, happened to come across the film while channel surfing on a Saturday afternoon. He hadn't been told that all of his old AIP films had been remade in Color. He said "I recognized some of the dialogue coming out of the actors' mouths because it was a direct steal from Day the World Ended. I sat there...staring at it, and i just couldn't believe it. I was absolutely spellbound....It's just absolutely unbelievable that they (remade) those.... I don't want to know a damn thing about them. I hope I never see them. One was more than enough!"[6]
Paul Gaita from Allmovie called the film "threadbare and blandly executed", but also noted that the film's pacing, and performances were more professional than the director's previous efforts. Finishing his review, Gaita wrote, "No one will mistake this for a classic of the genre, or even one of Corman's titles, but for Buchanan completists and late movie devotees, it's a harmless and agreeable time-killer."[8]
The 25 fake LinkedIn accounts identified by CTU researchers fall into two categories: fully developed personas (Leader) and supporting personas (Supporter). The table in the Appendix lists details associated with the accounts. The level of detail in the profiles suggests that the threat actors invested substantial time and effort into creating and maintaining these personas. The photos used in the fake accounts are likely of innocent individuals who have no connection to TG-2889 activity.
Profiles for Leader personas include full educational history, current and previous job descriptions, and, sometimes, vocational qualifications and LinkedIn group memberships. Of the eight Leader personas identified by CTU researchers, six have more than 500 connections (see Figure 1).
Five of the Leader personas purport to work for Teledyne, an American industrial conglomerate. In addition, one claims to work for Doosan (an industrial conglomerate based in South Korea), one for Northrop Grumman (a U.S. aerospace and defense company), and one for Petrochemical Industries Co., (a Kuwaiti petrochemical manufacturing company).
Profiles for Supporter personas are far less developed than for Leader personas. They all use the same basic template with one simple job description, and they all have five connections (see Figure 4). Profile photographs for three of the Supporter personas appear elsewhere on the Internet, where they are associated with different, seemingly legitimate, identities. As with the Leader profiles, open-source research indicates that the Supporter profiles are also fake.
The purpose of the Supporter personas appears to be to provide LinkedIn skills endorsements for Leader personas, likely to add legitimacy to the Leader personas. As shown in Figure 5, most of the Supporter accounts identified by CTU researchers have endorsed skills listed on the profiles of the Leader personas. Although unable to view Leader personas' LinkedIn connections, CTU researchers suspect the threat actors use the Supporter accounts to provide the Leader profiles with an established network, which also enhances credibility.
Although CTU researchers identified eight Leader profiles, two appear to be duplicates that have different identities associated with the same account. While CTU researchers were analyzing the profiles, the threat actors altered two of the Leader LinkedIn accounts. The original profile name and photograph were replaced with a new identity, and the current job was updated: in one case replacing Teledyne with Northrup Grumman (see Figure 6) and in the second replacing Teledyne with Airbus Group.
Changing personas associated with existing profiles was a clever exploitation of LinkedIn functionality because the new identities inherit the network and endorsements from the previous identity. These attributes immediately make the new personas appear established and credible, and the transition may prevent the original personas from being overexposed.
Creating a network of seemingly genuine and established LinkedIn personas helps TG-2889 identify and research potential victims. The threat actors can establish a relationship with targets by contacting them directly, or by contacting one of the target's connections. It may be easier to establish a direct relationship if one of the fake personas is already in the target's LinkedIn network.
Five of the Leader personas claim to be recruitment consultants, which would provide a pretext for contacting targets. TG-2889 likely uses spearphishing or malicious websites to compromise victims, and established trust relationships significantly increase the likelihood of these tactics being successful.
Seemingly legitimate LinkedIn users have also endorsed Leader personas. Endorsements are granted by connections, indicating that these legitimate users are part of the Leader personas' networks. Therefore, they are likely TG-2889 targets. Examination of the profiles associated with the endorsements revealed 204 potential TG-2889 targets. As shown in Figure 7, most are based in the Middle East.
A quarter of the targets work in the telecommunications vertical; Middle Eastern and North African mobile telephony suppliers feature heavily. A focus on these types of targets may indicate that TG-2889 is interested in acquiring data held by these organizations or gaining access to the services they operate. A significant minority of identified targets work for Middle Eastern governments and for defense organizations based in the Middle East and South Asia.
Based on strong circumstantial evidence, CTU researchers assess that TG-2889 is linked to the activity that Cylance described in its December 2014 Operation CLEAVER report. The report documented threat actors using malware disguised as a rsum application that appeared to allow rsums to be submitted to the industrial conglomerate Teledyne. Cylance reported the use of the following domains, which reference companies associated with many of the fake LinkedIn profiles identified by CTU researchers:
Cylance attributed the Operation CLEAVER activity to a threat group operating at least in part out of Iran. CTU researchers have not uncovered any intelligence that contradicts this assessment. Furthermore, the strong focus suggested by the endorsement analysis on targets from Arab states in the Middle East and North Africa (MENA) region is in line with the expected targeting behavior of a threat group operating out of Iran.
Updates to profile content such as employment history suggest that TG-2889 regularly maintains these fake profiles. The persona changes and job alterations could suggest preparations for a new campaign, and the decision to reference Northrup Grumman and Airbus Group may indicate that the threat actors plan to target the aerospace vertical.
It is likely that TG-2889 maintains personas that have not yet been identified, and that other threat groups also use this tactic. CTU researchers advise organizations to educate their users of the specific and general risks:
Organizations may want to consider policing abuse of their brand on LinkedIn and other social media sites. If an organization discovers that a LinkedIn persona is fraudulently claiming an association with the company, it should contact LinkedIn. Creating false identities and misrepresenting an association with an organization is a breach of LinkedIn's terms and conditions.
Table 1 lists details associated with Leader and Supporter personas created by TG-2889. The pairs shaded in dark gray are different identities associated with the same LinkedIn account. The only difference in the profile links of the shared accounts is the persona name.
[1] The Dell SecureWorks Counter Threat Unit(TM) (CTU) research team tracks threat groups by assigning them four-digit randomized numbers (2889 in this case), and compiles information from external sources and from first-hand incident response observations.
[Redactor's note: In the Year 2889 was first published in theForum, February, 1889; p. 662. It was published in France the nextyear. Although published under the name of Jules Verne, it is nowbelieved to be chiefly if not entirely the work of Jules' son, MichelVerne. In any event, many of the topics in the article echo Verne'sideas.]
c80f0f1006