No Sooner Warned Than Struck : Russian CyberAttacks
"Canada's
Cyber Centre ... is aware of foreign cyber threat activities, including
by Russian-backed actors, to target Canadian critical infrastructure
network operators, their operational and information technology."
"[Attacks
could arrive in a range of forms from a] widespread ransomware attack
[to a] single, carefully focused [attempt to significantly impact core
infrastructure]."
Cyber Centre Agency, Communications Security Establishment
"The
depth of the information provided by the U.S. and the urgency used
underlines the seriousness of this situation. These government bulletins
do not come without sufficient research and justification."
"While
we can speculate what exactly drove this alert, the more important
message is that the entire world should be watching the heightened
tensions surrounding Russia's intentions toward Ukraine and, especially,
the recent publicly acknowledged cyberattacks."
"A
cuberattack on any of Canada's critical support systems could cause
crippling disruption to the population and the economy. For this reason,
protecting critical infrastructure and the operational technology
behind it is increasingly regarded as a mater of national security."
"Canada
and our allies have experienced a general increase in cyberthreat
activity throughout the last year, including ransomware attacks, supply
chain attacks, and the exploitation of discovered vulnerabilities in
commonly used software."
"Russian-linked groups have been among the drivers of this activity."
"Should
Russia-backed cyber threat activity launch against Canada, we can
expect to see anything from a widespread ransomware attack to a single,
carefully focused but impactful attack on our infrastructure."
"It
may take some time to work out what is going on (or what happened) as
Russia has a long history of distracting opponents from its real
intentions."
David Masson, director, Darktrace cyber-A1 defence company
"Russian
state-sponsored advanced persistent threat actors have used
sophisticated cyber capabilities to target a variety of U.S. and
International critical infrastructure organizations, including those in
the Defense Industrial Base as well as the Healthcare and Public Health,
Energy, Telecommunications, and Government Facilities Sectors."
U.S. Bulletin
Intelligence experts in recent years have been warning about the growing frequency of cyber attacks by foreign states.Photo by Sean Kilpatrick/The Canadian Press/File
Russia
uses all manner of cold-war, 21st Century battlefields delivering
messages to those countries that provoke Moscow's ire of their
displeasure, through their ability to negotiate around cyberspace and
threaten the infrastructure and social order of countries opposed to
Russia's moves on the international scene. In 2007 Estonia, a former
Soviet Union satellite, assaulted Moscow's sensibilities by removing a
memorial to the Soviet Red Army to a loss prominent position, and paid
for its audacity through a devastating series of major cyberattacks that
shut down banks, media outlets and government offices.
Russian speakers rose up on the streets in protest at the statue's move - and cyber attackers followed behind Getty Images
In
more recent years, after the 2014 start of an ethnic-Russian Ukrainian
separatist group in the Donbas and Russia's military incursion, arming
and fighting alongside the separatists against Ukraine, culminating in
Russia's claiming of the Crimea Peninsula as Russian territory, the
standoff between Ukraine and the separatists in Donetsk and Luhansk in
eastern Ukraine while leading to active hostilities and violence also
saw Ukraine suffering cyberattacks threatening its electrical system
power grid in 2015.
And in mid-January Kyiv experienced cyberattacks on government offices, with an eerily sinister message: : "Be afraid and expect the worst."
This, in the buildup to a feared Russian invasion of Ukraine,
reclaiming what Vladimir Putin insists is a historical connection
between the two countries as one. And the 'one' who controls Ukraine
would be Russia. Embodying Mr. Putin's other cherished aspiration, to
appeal to the better sense of its neighbours to return to the good old
days of the USSR, within Russia's loving embrace.
A threatening message appeared on Ukrainian government websites on 14 January, 2022
Detailed
warnings arrived in Canada from the United States and United Kingdom
cybersecurity sections of the imminence of Russian actors imposing
hostile, threatening and damaging cyberattacks within Canada. Both the
U.S. and the U.K. warned that their own cybersecurity communities are in
a "heightened state of awareness, proactively searching out risks to their networks in response to threats from Russia", looming increasingly in the very near future.
Two
years earlier Canada's CSE warned that state-sponsored threat actors
like Russia were "very likely" trying to develop tools to allow them to
disrupt critical infrastructure "such as the supply of electricity", concluding that the attackers were not likely to want to disrupt critical infrastructure in Canada to cause "major damage or loss of life". But for the major caveat "in the absence of international hostilities".
Well, those international hostilities have eventuated with Russia's
massing of a 100,000 troops on the Ukraine border and deliberate
additional provocations enlisting Belarus and Kazakhstan bordering
Ukraine, in its assault plans.
Belarusian
peacekeepers leave a Russian military plane at an airfield in
Kazakhstan, Saturday, Jan. 8, 2022. As Kazakhstan struggles to cope with
a violent uprising this week, it has turned for help to a Russian-led
security bloc, the Collective Security Treaty Organization.The Associated Press
"Critical
services for Canadians through Global Affairs Canada (Department of
Foreign Affairs) are currently functioning. Some access to internet and
internet-based services are not currently available as part of the
mitigation measures and work is underway to restore them."
"At this time, there is no indication that any other government departments have been impacted by this incident."
"The
Government of Canada deals with ongoing and persistent cyber risks and
threats every day. Cyber threats can result from system or application
vulnerabilities, or from deliberate, persistent, targeted attacks by
outside actors to gain access to information."
Treasury Board of Canada Secretariat
(RedPixel/stock.adobe.com)
So
there it is. No sooner said than done. Cyberattacks against Canadian
government departments are not new, they have been occurring with some
regularity of recent times. And the suspects are usually China or
Russia. This latest attack that occurred on the very day that Canada's
cyberdefence agency warned of Russian-backed threats, was a significant
attack, a cyber incident causing disruption to a group of departmental
systems. The Canadian Centre for Cyber Security, which had warned of
such an attack's likelihood is now investigating what it had predicted.
Civilian participants in a Kyiv Territorial Defence unit train in a forest on January 22, 2022, in Kyiv, Ukraine. (Sean Gallup/Getty Images)
"As a result of a massive cyber attack, the websites of the Ministry of
Foreign Affairs and a number of other government agencies are
temporarily down."
"Our specialists have
already started restoring the work of IT systems, and the cyber police
has opened an investigation."
"Ukrainians! All your personal data was uploaded to the public network.
All data on the computer is destroyed, it is impossible to restore it."
"All information about you has become public, be afraid and expect the worst. This is for your past, present and future."
Cyber message, posted in Ukrainian, Russian, and Polish
"All subjects of cyber security were aware of such possible provocations
by the Russian Federation."
"Therefore the response to these incidents is
carried out as usual."
Ukrainian security official
A
laptop screen displaying a warning message in Ukrainian, Russian and
Polish, on the official website of the Ukrainian Foreign Ministry on
January 14, 2022. REUTERS/Valentyn Ogirenko/Illustration
"As
part of its plans, Russia is laying the groundwork to have the option
of fabricating a pretext for invasion, including through sabotage
activities and information operations, by accusing Ukraine of preparing
an imminent attack against Russian forces in eastern Ukraine."
Jen Psaki, White House press secretary
According
to the United States, Russia appears to be making preparations for a
pretext to enable their response in invading Ukraine. This, should
diplomacy fail to achieve the results Moscow is gambling on; presenting
ultimatums to both the United States and NATO, to completely withdraw
from Greater Russia's near-abroad, its Baltic neighbours, and to deny
entry to NATO to any other of its former satellites, including Ukraine.
The massive cyberattack just experienced by Ukraine across its government websites leaving a warning: "be afraid and expect the worse",
standing out as an attempt to provoke Ukraine into a retaliatory move
that would serve as a need for Russia to protect its interests by
invading its former satellite whose territory it regards as
traditionally Russian and which it is determined to reclaim.
The Ukrainian Foreign Ministry building in Kyiv. The country's Foreign Ministry website was one of a
number of government sites brought down temporarily in a hacking attack
Friday. (Ukrainian Foreign Ministry Press Service/The Associated Press)
Kyiv's
state security service is certain, given signs of Russian involvement,
that the cyberattack had been pre-planned, arising mere hours after
diplomacy in security talks were convened on Thursday where no
breakthrough agreements resulted between Moscow and Western allies.
Andriy Yernak, President Volodymyr Zelensky's chief of staff, spoke of
the "life and death" of Ukraine hanging in the balance.
The "false-flag operation"
in eastern Ukraine saw Russia positioning operatives in preparation for
an impending invasion, an event that Russia continues to deny it has
planned. Stating, on the other hand, it may, under certain circumstances
take unspecified military action should its demands -- a promise by the
NATO alliance among them -- never to admit Kyiv are met.
"We
categorically will not accept the appearance of NATO right on our
borders, especially so given the current course of the Ukrainian
leadership."
"Measures
to deploy military hardware, that is obvious. When we take decisions
with military hardware we understand what we mean and what we are
preparing for".
Russian Foreign Minister Sergei Lavrov
NATO's
response was to announce it was prepared to sign a new agreement within
days with Kyiv on closer co-operation in cyber defence, including
Ukraine being given access to the Western military alliance's system for
sharing information on malicious software. Cyber experts from NATO were
working with Ukrainian authorities to respond to the attack.
Armoured vehicles and allied military hardware was shown in footage released by RIA
news agency, being loaded on to trains in Russia's far east.
Representing what Moscow spoke of as an inspection drill to practise
long-range deployments. The footage came courtesy of the Russian Defence
Ministry. "This is likely cover for the units being moved toward Ukraine", observed Rob Lee, military analyst, fellow at the Foreign Policy Research Institute based in the U.S.
A Ukrainian Military Forces member walks in a trench on the
frontline with Russia-backed separatists in the Donetsk region on
Tuesday. (Anatolii Stepanov/AFP/Getty Images)
"Let's call out bad behaviour, reinforce a shared and common understanding of rules-based norms and deter malicious foreign cyber actors from targeting our country." Canadian Defence Minister Harjit Sajjan
"[Canada can be assured of Britain's solidarity with Canada and the United States] against the reckless actions of Russia's intelligence services, who we have exposed today for committing cyber attacks [against those working on a COVID-19 vaccine." British Foreign Secretary Dominic Raab
Dominic Raab
@DominicRaab
against the reckless actions of Russia’s intelligence services, who we have exposed today for committing cyber attacks against those working on a #Covid19 vaccine - undermining vital cooperation to defeat this pandemic
UK condemns Russian Intelligence Services over vaccine cyber attacks
The Foreign Secretary has called out Russia’s unacceptable cyber attacks against COVID-19 vaccine developers.
gov.uk
"The group uses a variety of tools and techniques to predominantly target governmental, diplomatic, think-tank, health-care and energy targets for intelligence gains." "APT29 is likely to continue to target organizations involved in COVID-19 vaccine research and development." Center for Cyber Security, Communications Security Establishment
Security services in Canada, Britain and the U.S. have identified hackers believed to be working for Russian intelligence, attempting to purloin research from organizations in all three countries and around the world, focusing on COVID-19 vaccine research.Malicious cyber activities, according to Canada's Communications Security Establishment, were likely to have been undertaken to grab data and intellectual property regarding development and testing of vaccines for the novel coronavirus.
According to the CSE's Centre for Cyber Security a group known as APT29, known as well as "the Dukes" or "Cozy Bear" was responsible, and without doubt operate as a branch of Russian intelligence services. Partners at Britain's Government communications Headquarters National Cyber Security Centre, along with the U.S. National Security Agency and the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency are all aligned in their assessment of the situation.
"These malicious cyber activities were very likely undertaken
to steal information and intellectual property relating to the
development and testing of COVID-19 vaccines, and serve to hinder
response efforts at a time when health care experts and medical
researchers need every available resource to help fight the pandemic." "[APT29] is likely to continue to target
organizations involved in COVID-19 vaccine research and development, as
they seek to answer additional intelligence questions relating to the
pandemic." Joint assessment, CSE, the United Kingdom's
National Cyber Security Centre and the National Security Agency in the
U.S.
"Canada remains both a target for malicious cyber activities, and a platform from which these hostile actors conduct CNO [Computer Network Operations] against entities in other countries." Annual Report, Canadian Security Intelligence Service
"It would come as no surprise that terrorism and violent extremism remained the most immediate threat to Canada's national security during the period covered by this report, and represented our top priority." "The number of terrorism-related threats, the speed at which they evolve, and the use of technology and social media, has created some very real and complicated challenges for the service." CSIS Director Michel Coulombe
"I think it is true that area [Internet-connected vital infrastructure] is relatively poorly defended." "Many of those things that you would think would run on separate
systems are actually connected to the Internet." "Pipelines, power supplies, water treatment and things of that sort.
We have had one example of a pipeline in Turkey that appears to have
been exploded by remote control, by some kind of hack. So anyone who
runs a pipeline is worried about things like that." "It's certain that we are not where we want to be or where we should be." David Skillicorn, computer studies professor, Queen's
University/Royal Military College, Kingston, Ontario
Getty Images
"The fact they've been able to conduct pretty sophisticated terrorist
operations tells me that they have the ability to fly 'under the radar." "The fact that they're able to do this successfully tells me that
their cyber capabilities are very significant," "ISIS has two ways of doing it. One, people who are signed up to
ISIS. And [two] perhaps people who are going to be paid a lot of money
by ISIS to bring their talents to ISIS. I mean money is not a problem
for these guys. Neither is their desire, their capability and their
reach." Amos Guiora, law professor,
counterterrorism specialist, University of Utah.
"The stakes could hardly be higher. If our electricity supply, or our air traffic control, or our hospitals
were successfully attacked on line, the impact could be measured not
just in terms of economic damage but of lives lost." "They have not been able to use it to kill people yet by attacking
our infrastructure through cyberattack. They do not yet
have that capability. But we know they want it, and are doing their best
to build it." Britain's Chancellor of the Exchequer George Osborne
There are no countries around the globe, particularly those in the Western orbit, that are not alert to the very real potential of a disastrous cyber attack in our interconnected, online world where virtually all infrastructure, public and private, government and industrial, is connected to the Internet. There are those experts in computer warfare who view the possibility and eventuality of malicious attacks against state entities and their private partners as a cherished goal to be achieved for the breakdown of a nation's stability, security and public order.
Great Britain has just announced a £1.9 billion ($3.6 billion) commitment in new funding for its electronic spy agency, GCHQ. The purpose is urgent and twofold; for the development of tools in the United Kingdom's defence against cyberattacks and as well, to facilitate the structure and operation of offensive operations against extremist threats, conducted over the Internet. The Internet, both a boon to modern life and an open forum out of which the aspiration to do great harm in a new kind of modern warfare appeals to oppositional state actors and terrorist groups alike.
In the domestic setting the targeting of hospitals, airports and power plants would effectively shut down the civil operational capacities of any country, sending it into a desperate spiral of survival and imperilling its vulnerable civilian population while panicked government and defence departments would be reacting in less than spectacular fashion, its critical tools of communication, transportation and machinery impacted, leaving it helpless to mount a salvage operation after the fact.
Canada's Communications Security Establishment (CSE) has been developing tools to fight back, including cyberweapons to disrupt online chat groups, to shut down websites and even destroy computer networks. The response to such a devastating cyberattack whatever form it might take, would be to see a nation attacked by a state-sponsoring cybernetwork or terrorist group, attempting to restore functionality and fend off further attacks with its defensive arsenal down and out.
The goal is to keep one step ahead of those planning these doomsday scenarios.
This represents a general opinion site for its author. It also offers a space for the author to record her experiences and perceptions,both personal and public. This is rendered obvious by the content contained in the blog, but the space is here inviting me to write. And so I do.