Wednesday, January 26, 2022

No Sooner Warned Than Struck : Russian CyberAttacks


"Canada's Cyber Centre ... is aware of foreign cyber threat activities, including by Russian-backed actors, to target Canadian critical infrastructure network operators, their operational and information technology."
"[Attacks could arrive in a range of forms from a] widespread ransomware attack [to a] single, carefully focused [attempt to significantly impact core infrastructure]."
Cyber Centre Agency, Communications Security Establishment
 
"The depth of the information provided by the U.S. and the urgency used underlines the seriousness of this situation. These government bulletins do not come without sufficient research and justification."
"While we can speculate what exactly drove this alert, the more important message is that the entire world should be watching the heightened tensions surrounding Russia's intentions toward Ukraine and, especially, the recent publicly acknowledged cyberattacks."
"A cuberattack on any of Canada's critical support systems could cause crippling disruption to the population and the economy. For this reason, protecting critical infrastructure and the operational technology behind it is increasingly regarded as a mater of national security."
"Canada and our allies have experienced a general increase in cyberthreat activity throughout the last year, including ransomware attacks, supply chain attacks, and the exploitation of discovered vulnerabilities in commonly used software."
"Russian-linked groups have been among the drivers of this activity."
"Should Russia-backed cyber threat activity launch against Canada, we can expect to see anything from a widespread ransomware attack to a single, carefully focused but impactful attack on our infrastructure."
"It may take some time to work out what is going on (or what happened) as Russia has a long history of distracting opponents from its real intentions."
David Masson, director, Darktrace cyber-A1 defence company 

"Russian state-sponsored advanced persistent threat actors have used sophisticated cyber capabilities to target a variety of U.S. and International critical infrastructure organizations, including those in the Defense Industrial Base as well as the Healthcare and Public Health, Energy, Telecommunications, and Government Facilities Sectors."
U.S. Bulletin
Intelligence experts in recent years have been warning about the growing frequency of cyber attacks by foreign states.
Intelligence experts in recent years have been warning about the growing frequency of cyber attacks by foreign states. Photo by Sean Kilpatrick/The Canadian Press/File

Russia uses all manner of cold-war, 21st Century battlefields delivering messages to those countries that provoke Moscow's ire of their displeasure, through their ability to negotiate around cyberspace and threaten the infrastructure and social order of countries opposed to Russia's moves on the international scene. In 2007 Estonia, a former Soviet Union satellite, assaulted Moscow's sensibilities by removing a memorial to the Soviet Red Army to a loss prominent position, and paid for its audacity through a devastating series of major cyberattacks that shut down banks, media outlets and government offices.
 
Police face demonstrators 27 April 2007 in Tallin, during a protest against plans to move the Bronze Soldier statue, a Soviet World War II memorial
Russian speakers rose up on the streets in protest at the statue's move - and cyber attackers followed behind   Getty Images

 In more recent years, after the 2014 start of an ethnic-Russian Ukrainian separatist group in the Donbas and Russia's military incursion, arming and fighting alongside the separatists against Ukraine, culminating in Russia's claiming of the Crimea Peninsula as Russian territory, the standoff between Ukraine and the separatists in Donetsk and Luhansk in eastern Ukraine while leading to active hostilities and violence also saw Ukraine suffering cyberattacks threatening its electrical system power grid in 2015. 
 
And in mid-January Kyiv experienced cyberattacks on government offices, with an eerily sinister message: : "Be afraid and expect the worst." This, in the buildup to a feared Russian invasion of Ukraine, reclaiming what Vladimir Putin insists is a historical connection between the two countries as one. And the 'one' who controls Ukraine would be Russia. Embodying Mr. Putin's other cherished aspiration, to appeal to the better sense of its neighbours to return to the good old days of the USSR, within Russia's loving embrace.

Threatening message which appeared on Ukrainian government websites
A threatening message appeared on Ukrainian government websites on 14 January, 2022

Detailed warnings arrived in Canada from the United States and United Kingdom cybersecurity sections of the imminence of Russian actors imposing hostile, threatening and damaging cyberattacks within Canada. Both the U.S. and the U.K. warned that their own cybersecurity communities are in a "heightened state of awareness, proactively searching out risks to their networks in response to threats from Russia", looming increasingly in the very near future.

Two years earlier Canada's CSE warned that state-sponsored threat actors like Russia were "very likely" trying to develop tools to allow them to disrupt critical infrastructure "such as the supply of electricity", concluding that the attackers were not likely to want to disrupt critical infrastructure in Canada to cause "major damage or loss of life". But for the major caveat "in the absence of international hostilities". Well, those international hostilities have eventuated with Russia's massing of a 100,000 troops on the Ukraine border and deliberate additional provocations enlisting Belarus and Kazakhstan bordering Ukraine, in its assault plans.

Belarusian peacekeepers leave a Russian military plane at an airfield in Kazakhstan, Saturday, Jan. 8, 2022. As Kazakhstan struggles to cope with a violent uprising this week, it has turned for help to a Russian-led security bloc, the Collective Security Treaty Organization.The Associated Press

"Critical services for Canadians through Global Affairs Canada (Department of Foreign Affairs) are currently functioning. Some access to internet and internet-based services are not currently available as part of the mitigation measures and work is underway to restore them."
"At this time, there is no indication that any other government departments have been impacted by this incident."
"The Government of Canada deals with ongoing and persistent cyber risks and threats every day. Cyber threats can result from system or application vulnerabilities, or from deliberate, persistent, targeted attacks by outside actors to gain access to information."
Treasury Board of Canada Secretariat
(RedPixel/stock.adobe.com)
So there it is. No sooner said than done. Cyberattacks against Canadian government departments are not new, they have been occurring with some regularity of recent times. And the suspects are usually China or Russia. This latest attack that occurred on the very day that Canada's cyberdefence agency warned of Russian-backed threats, was a significant attack, a cyber incident  causing disruption to a group of departmental systems. The Canadian Centre for Cyber Security, which had warned of such an attack's likelihood is now investigating what it had predicted.

Civilian participants in a Kyiv Territorial Defence unit train in a forest on January 22, 2022, in Kyiv, Ukraine. (Sean Gallup/Getty Images)


Labels: , , , , , , , ,

Sunday, January 16, 2022

Moscow's Diplomacy : Withdrawal Ultimatums

"As a result of a massive cyber attack, the websites of the Ministry of Foreign Affairs and a number of other government agencies are temporarily down."
"Our specialists have already started restoring the work of IT systems, and the cyber police has opened an investigation."
Ukrainian foreign ministry spokesman Oleg Nikolenko
 
"Ukrainians! All your personal data was uploaded to the public network. All data on the computer is destroyed, it is impossible to restore it."
"All information about you has become public, be afraid and expect the worst. This is for your past, present and future."
Cyber message, posted in Ukrainian, Russian, and Polish
 
"All subjects of cyber security were aware of such possible provocations by the Russian Federation."
"Therefore the response to these incidents is carried out as usual."
Ukrainian security official
A laptop screen displays a warning message in Ukrainian, Russian and Polish, that appeared on the official website of the Ukrainian Foreign Ministry after a massive cyberattack, in this illustration taken January 14, 2022. REUTERS/Valentyn Ogirenko/Illustration
A laptop screen displaying a warning message in Ukrainian, Russian and Polish, on the official website of the Ukrainian Foreign Ministry on January 14, 2022.
REUTERS/Valentyn Ogirenko/Illustration

"As part of its plans, Russia is laying the groundwork to have the option of fabricating a pretext for invasion, including through sabotage activities and information operations, by accusing Ukraine of preparing an imminent attack against Russian forces in eastern Ukraine."
Jen Psaki, White House press secretary
According to the United States, Russia appears to be making preparations for a pretext to enable their response in invading Ukraine. This, should diplomacy fail to achieve the results Moscow is gambling on; presenting ultimatums to both the United States and NATO, to completely withdraw from Greater Russia's near-abroad, its Baltic neighbours, and to deny entry to NATO to any other of its former satellites, including Ukraine.

The massive cyberattack just experienced by Ukraine across its government websites leaving a warning: "be afraid and expect the worse", standing out as an attempt to provoke Ukraine into a retaliatory move that would serve as a need for Russia to protect its interests by invading its former satellite whose territory it regards as traditionally Russian and which it is determined to reclaim.
 
The Ukrainian Foreign Ministry building in Kyiv. The country's Foreign Ministry website was one of a number of government sites brought down temporarily in a hacking attack Friday. (Ukrainian Foreign Ministry Press Service/The Associated Press)
 
Kyiv's state security service is certain, given signs of Russian involvement, that the cyberattack had been pre-planned, arising mere hours after diplomacy in security talks were convened on Thursday where no breakthrough agreements resulted between Moscow and Western  allies. Andriy Yernak, President Volodymyr Zelensky's chief of staff, spoke of the "life and death" of Ukraine hanging in the balance.

The "false-flag operation" in eastern Ukraine saw Russia positioning operatives in preparation for an impending invasion, an event that Russia continues to deny it has planned. Stating, on the other hand, it may, under certain circumstances take unspecified military action should its demands -- a promise by the NATO alliance among them -- never to admit Kyiv are met.
"We categorically will not accept the appearance of NATO right on our borders, especially so given the current course of the Ukrainian leadership."
"Measures to deploy military hardware, that is obvious. When we take decisions with military hardware we understand what we mean and what we are preparing for".
Russian Foreign Minister Sergei Lavrov
NATO's response was to announce it was prepared to sign a new agreement within days with Kyiv on closer co-operation in cyber defence, including Ukraine being given access to the Western military alliance's system for sharing information on malicious software. Cyber experts from NATO were working with Ukrainian authorities to respond to the attack.

Armoured vehicles and allied military hardware was shown in footage released by RIA news agency, being loaded on to trains in Russia's far east. Representing what Moscow spoke of as an inspection drill to practise long-range deployments. The footage came courtesy of the Russian Defence Ministry. "This is likely cover for the units being moved toward Ukraine", observed Rob Lee, military analyst, fellow at the Foreign Policy Research Institute based in the U.S.

A Ukrainian Military Forces member walks in a trench on the frontline with Russia-backed separatists in the Donetsk region on Tuesday. (Anatolii Stepanov/AFP/Getty Images)

 

Labels: , , , , ,

Saturday, July 18, 2020

Calling Out Russia

"Let's call out bad behaviour, reinforce a shared and common understanding of rules-based norms and deter malicious foreign cyber actors from targeting our country."
Canadian Defence Minister Harjit Sajjan

"[Canada can be assured of Britain's solidarity with Canada and the United States] against the reckless actions of Russia's intelligence services, who we have exposed today for committing cyber attacks [against those working on a COVID-19 vaccine."
British Foreign Secretary Dominic Raab
Profile photo, opens profile page on Twitter in a new tab

Dominic Raab

@DominicRaab
🇬🇧 against the reckless actions of Russia’s intelligence services, who we have exposed today for committing cyber attacks against those working on a #Covid19 vaccine - undermining vital cooperation to defeat this pandemic

UK condemns Russian Intelligence Services over vaccine cyber attacks
The Foreign Secretary has called out Russia’s unacceptable cyber attacks against COVID-19 vaccine developers.
gov.uk
"The group uses a variety of tools and techniques to predominantly target governmental, diplomatic, think-tank, health-care and energy targets for intelligence gains."
"APT29 is likely to continue to target organizations involved in COVID-19 vaccine research and development."
Center for Cyber Security, Communications Security Establishment
🇺🇸Security services in Canada, Britain and the U.S. have identified hackers believed to be working for Russian intelligence, attempting to purloin research from organizations in all three countries and around the world, focusing on COVID-19 vaccine research.Malicious cyber activities, according to Canada's Communications Security Establishment, were likely to have been undertaken to grab data and intellectual property regarding development and testing of vaccines for the novel coronavirus.

According to the CSE's Centre for Cyber Security a group known as APT29, known as well as "the Dukes" or "Cozy Bear" was responsible, and without doubt operate as a branch of Russian intelligence services. Partners at Britain's Government communications Headquarters National Cyber Security Centre, along with the U.S. National Security Agency and the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency are all aligned in their assessment of the situation.
"These malicious cyber activities were very likely undertaken to steal information and intellectual property relating to the development and testing of COVID-19 vaccines, and serve to hinder response efforts at a time when health care experts and medical researchers need every available resource to help fight the pandemic."
"[APT29] is likely to continue to target organizations involved in COVID-19 vaccine research and development, as they seek to answer additional intelligence questions relating to the pandemic."
Joint assessment, CSE, the United Kingdom's National Cyber Security Centre and the National Security Agency in the U.S.

Labels: , , , , , , ,

Thursday, March 02, 2017

Planning for the Unthinkable

"Canada remains both a target for malicious cyber activities, and a platform from which these hostile actors conduct CNO [Computer Network Operations] against entities in other countries."
Annual Report, Canadian Security Intelligence Service

"It would come as no surprise that terrorism and violent extremism remained the most immediate threat to Canada's national security during the period covered by this report, and represented our top priority."
"The number of terrorism-related threats, the speed at which they evolve, and the use of technology and social media, has created some very real and complicated challenges for the service."
CSIS Director Michel Coulombe

"I think it is true that area [Internet-connected vital infrastructure] is relatively poorly defended."
"Many of those things that you would think would run on separate systems are actually connected to the Internet."
"Pipelines, power supplies, water treatment and things of that sort. We have had one example of a pipeline in Turkey that appears to have been exploded by remote control, by some kind of hack. So anyone who runs a pipeline is worried about things like that."
"It's certain that we are not where we want to be or where we should be."
David Skillicorn, computer studies professor, Queen's University/Royal Military College, Kingston, Ontario
Getty Images
"The fact they've been able to conduct pretty sophisticated terrorist operations tells me that they have the ability to fly 'under the radar."
"The fact that they're able to do this successfully tells me that their cyber capabilities are very significant,"
"ISIS has two ways of doing it. One, people who are signed up to ISIS. And [two] perhaps people who are going to be paid a lot of money by ISIS to bring their talents to ISIS. I mean money is not a problem for these guys. Neither is their desire, their capability and their reach."
Amos Guiora, law professor, counterterrorism specialist, University of Utah.

"The stakes could hardly be higher. If our electricity supply, or our air traffic control, or our hospitals were successfully attacked on line, the impact could be measured not just in terms of economic damage but of lives lost."
"They have not been able to use it to kill people yet by attacking our infrastructure through cyberattack. They do not yet have that capability. But we know they want it, and are doing their best to build it."
Britain's Chancellor of the Exchequer George Osborne
There are no countries around the globe, particularly those in the Western orbit, that are not alert to the very real potential of a disastrous cyber attack in our interconnected, online world where virtually all infrastructure, public and private, government and industrial, is connected to the Internet. There are those experts in computer warfare who view the possibility and eventuality of malicious attacks against state entities and their private partners as a cherished goal to be achieved for the breakdown of a nation's stability, security and public order.

Great Britain has just announced a £1.9 billion ($3.6 billion) commitment in new funding for its electronic spy agency, GCHQ. The purpose is urgent and twofold; for the development of tools in the United Kingdom's defence against cyberattacks and as well, to facilitate the structure and operation of offensive operations against extremist threats, conducted over the Internet. The Internet, both a boon to modern life and an open forum out of which the aspiration to do great harm in a new kind of modern warfare appeals to oppositional state actors and terrorist groups alike.

In the domestic setting the targeting of hospitals, airports and power plants would effectively shut down the civil operational capacities of any country, sending it into a desperate spiral of survival and imperilling its vulnerable civilian population while panicked government and defence departments would be reacting in less than spectacular fashion, its critical tools of communication, transportation and machinery impacted, leaving it helpless to mount a salvage operation after the fact.

Canada's Communications Security Establishment (CSE) has been developing tools to fight back, including cyberweapons to disrupt online chat groups, to shut down websites and even destroy computer networks. The response to such a devastating cyberattack whatever form it might take, would be to see a nation attacked by a state-sponsoring cybernetwork or terrorist group, attempting to restore functionality and fend off further attacks with its defensive arsenal down and out.

The goal is to keep one step ahead of those planning these doomsday scenarios.

Labels: , , , ,

Follow @rheytah Tweet