Showing posts with label political hacking. Show all posts
Showing posts with label political hacking. Show all posts

Thursday, October 01, 2009

Russian FSB Arrests for Dagestan Intrusions

Axis Information and Analysis provided a short report on the arrest by Russian FSB (Federal Security Services) of an individual for politically motivated intrusions into the systems of various Russian republics:
"In the course of investigation the FSB employees managed to find cyber-criminals of the Ansar group of insurgents who had been engaged in hacker attacks with an aim of distribution of their ideas through the world-wide web, and the 27 y.o. hacker Albert Saayev. The FSB established his participation in breaking of some of the state information resources, including sites of authorities of the Chechen Republic, Dagestan and Ingushetia."
The article alleges that Mr. Saayev had previously been arrested and convicted of similar crimes.

Dagestan hackers suspected of cyber-extremism detained by Federal Security Service in Moscow

Tuesday, March 10, 2009

"Political Hacking" Is a Growing Trend

International Relations and Security Network (ISN) published an article on the increasing nature of politically motivated computer crime and hacktivism:
"A growing trend of politicized hacking or "hacktivism" is emerging. The incidents in Estonia and Georgia were most likely carried out by state-encouraged Russian nationalist youth groups and criminal organizations, as well as at-large volunteers. One German youth claimed on a web forum that, with instruction from a Russian website, he was initiating fully functional denial-of-service attacks against targets in Georgia in a manner of hours. In reaction to a Danish newspaper cartoon of the Prophet Mohammad, loose groups of hackers in Turkey and other Muslim countries cyberattacked that publication's website."

The report summarizes some of the related recent activity.

The State of the Data War

Friday, February 27, 2009

Political Motivation Still Top Motive for Web Defacement

Breach Security, Inc has released its annual report analyzing web page defacement. The study found that although financial motivation for web attacks is increasing, political and ideological motivations are still the primary drivers:
"On the other end of the spectrum, the ideologists use the Internet to convey their message using Web hacking. Their main vehicle is defacing web sites."
...
"When further analyzing defacement incidents, we found that the majority were of a political nature, targeting political parties, candidates and government departments, often with a very specific message related to a campaign. Others have a cultural aspect, mainly Islamic hackers defacing western web sites."

The report also looks at who is targeted most often for web defacements:
"Government is a prime target due to ideological reasons, while universities are more open than other organizations. These statistics, however, are biased, to a degree, as the public disclosure requirements of government and other public organizations are much broader than those of commercial organizations..."

"On the commercial side, Internet-related organizations top the list. This group includes retail shops, comprising mostly e-commerce sites, media companies and pure internet services such as search engines and service providers."

THE WEB HACKING INCIDENTS DATABASE 2008

Tuesday, February 10, 2009

More 'Political Hacking' in India

CyberMedia India Online (CIOL) looks at politically motivated computer crime in an article with the subtitle "Imagine if computer hackers, the daredevils of the networked world, turn into principled political activists".

The article mostly reviews incidents around the world, not all with political motivation. However, it does discuss some recent activity in India related to attacks that are alleged to have originated in Pakistan or are in support of Islamic causes:
"In a virtual act of mocking the cyber crime department of the police the official website of the Andhra Pradesh Crime Investigation Department (CID), www.cidap.gov.in, was hacked and defaced recently. Though no one has publicly claimed responsibility for the act, the abusive message posted on the website points to some Islamic fundamentalist group.

"The group had hacked nearly five India's site, including that of the ONGC, in a 'retaliatory' action against the hacking of the site of Pakistan's OGRA (Oil and Gas Regulatory Authority)

"Amidst reports from all over the world regarding hacking celebrity sites and other websites, the community site of the former President of India, Dr. APJ Kalam, in Orkut World, was recently targeted by Pakistani hackers."

Is hacking a war tool?

Friday, October 10, 2008

Saudi Owned Television News Website Attacked

The defacement of Al Arabiya's website, a Dubai based, Saudi-owned television station, was in apparent retaliation for recent attacks on Shiite websites:



The number of web site defacements continues to escalate between opposing Sunni and Shiite groups:
"Last month, prominent Sunni religious commentator Sheikh Yusuf al-Qaradawi charged that Shiites are "invading" Sunni societies. Also, a tit-for-tat cyber war disabled 900 websites, belonging to both sects, as Shiite and Sunni hackers infiltrated religious websites and uploaded their own messages."

More information on these attacks is available at: Sunni-Shiite hacking war disables 900 websites


Al Arabiya hit by Sunni-Shiite hacking war

Friday, September 19, 2008

VP Candidate Sarah Palin's Personal Email Compromised

Sarah Palin, the Republican Vice Presidential candidate's personal Yahoo email account was compromised and emails and family photographs were made public:

"Among the emails posted on the Internet is a message sent from Palin to the vice-governor of Alaska, Sean Parnell, who is currently seeking election to Congress.

"The hacking comes at a time when Palin is suspected of using her personal email account for conducting public affairs in Alaska.

"According to law, all messages relating to the official functions of governor must be archived and not destroyed, but allows for personal messages to be destroyed."


Hackers infiltrate Palin's email account

Thursday, September 04, 2008

Various Articles on Russian Georgian Cyber Attacks

In an attempt to catch up on past articles concerning the Russian Georgian cyber attacks, I'll just post links to several articles that provide at least some factual information - Thanks to S.Y. for the pointers.

July 2008:

Wednesday, September 03, 2008

Researching Politically Motivated Computer Crimes

The Washington Post provides details of two groups researching politically motivated computer crimes. The article provides some information concerning the Georgian Russian online attacks as well as a discussion about online tactics and the effects of attacks:
"It's unclear who is behind the attacks, however. In some cases, the locations of botnet controllers can be traced, but it's impossible to know whether an attacker is working on the behalf of another organization or government."


A New Breed of Hackers Tracks Online Acts of War

Friday, May 09, 2008

The Difficulty in Identifying Source and Motive of Politically Motivated Computer Crimes

In a textbook example of the difficulties in determining the true source and motive behind online attacks, there are several reports coming from Korea concerning the arrest of Chinese and Korean nationals involved in online identify thefts. In this case, the original attacks were attributed to Chinese 'hackers' attacking Korean systems for political reasons. This was because the attacks appeared to originate in China and the software used in the attack had an anti-Korean title.

However, in this case, it appears that Korean criminals involved in online identity thefts were using Chinese 'hackers' to gather the information for fraud:
"...Chinese hackers who claim there is something of a black market for Korean personal information in China. They say Koreans hire Chinese hackers to break into sites to get information, which is then handed over and sold in Korea."

"...the vice head of PR for “Auction” [eBay's Korean subsidiary] said on CBS radio last month that the hacking program employed in the attack was named “Fuck KR,” leading at the time to speculation that the attack was anti-Korean in nature."

This case demonstrated three important issues in analyzing politically motivated computer crimes (or any other computer crime):

1. Most attackers use a chain of connections between themselves and their target. Inexperienced investigators are often misled when they attribute the attack to the most immediate link. (This is not a new phenomena and has been employed for over 20 years by 'hackers'. See "International Intrusions: Patterns and Motives" specifically section 3 Intrusion Patterns and Dynamics for a discussion on how this technique was used in the 1980's and 1990's.)

2. 'Hackers' can be manipulated by more criminal elements thus disguising the actual motive behind the attack.

3. Motive is very difficult to determine in online attacks. There are many cases of politically motived computer crimes disguised as fraud or other types of attacks and also attacks (such as this example) where the motive is disguised as political. Another good example of this is the 'WANK' worm released in 1989:
"...in the internal network of Digital Equipment Corporation and later in the NASA / SPAN networks. This was jokingly named by the Australian authors as “Worms against Nuclear Killers” and has been misreported in several publications as an example of political hacking [See: Denning, Dorothy E., “Activism, Hacktivism, and Cyberterrorism: The Internet as a Tool for Influencing Foreign Policy”].

"However, the authors had no political motive in these attacks and were playing on the British meaning of the word 'wank' [Source: "Hacktivism & Politically Motivated Computer Crime"]."

Too often the source and motives behind attacks are attributed with little information or based on assumptions. This is inadequate when discussing cyberwar and when governments and corporations are considering online retaliation. Investigators and security professionals need better skills in determining actual sources and motives behind computer crimes - political or otherwise.

Also see Analyzing Goggle Attacks - Plenty of Room for Error


Auction Identity Thieves Nabbed

‘Auction’ Hacker Arrested in China?

NPR Report Discusses Online Attacks on Activists and Journalists

National Public Radio broadcast a report on attacks involving Chinese systems. The program discusses attacks targeting both Chinese opponents and attacks against pro-Chinese websites:

"Recently, Tibetan advocacy groups and China-based foreign journalists have been hit by a wave of sophisticated computer attacks that steal data, cripple Web sites and even monitor what computer users type on their computers.

"The attacks often come in the form of viruses attached to e-mails skillfully made to look like correspondence from people the recipient knows and trusts."


Cyber Attacks in China Target Activists, Journalists

Monday, May 05, 2008

Indian Government Systems Are Being Mapped and Probed from China

The Times of India is reporting on cyber attacks they believe originate from China. While technical detail is limited, the attacks appear to follow the same pattern as reported in the U.S. and Europe:
"The sustained assault almost coincides with the history of the present political disquiet between the two countries.

"According to senior government officials, these attacks are not isolated incidents of something so generic or basic as "hacking" — they are far more sophisticated and complete — and there is a method behind the madness.

"Publicly, senior government officials, when questioned, take refuge under the argument that "hacking" is a routine activity and happens from many areas around the world. But privately, they acknowledge that the cyber warfare threat from China is more real than from other countries.

"The core of the assault is that the Chinese are constantly scanning and mapping India’s official networks. This gives them a very good idea of not only the content but also of how to disable the networks or distract them during a conflict."

China mounts cyber attacks on Indian sites

Saturday, May 03, 2008

Increase in Hacktivism?

Online protest and hacktivist attacks are gaining more publicity but does this reflect a sudden increase in activity or just more press coverage? A recent blog posting concluding a sudden increase in activity has gained some media attention:

"While incidents of Hacktivism are not new, they are beginning to become a lot more frequent — perhaps due to the availability of tools to conduct hacktivist mischief, but also perhaps due to the ubiquitous social networking mechanisms which can now be used as to build consensus when times of cultural or political unrest present the opportunity.

In any event, Hacktivism is becoming a disturbing trend, and one which can have serious ripple effects that interfere with Internet operational continuity — sometimes in ways which we may have not even thought of yet."

While the availability of social networks and 'hacktivist' tools do contribute to both increasing number of attacks and their effectiveness, most professionals that closely follow politically motivated computer crimes and hacktivism believe there has been a steady increase in activity for several years, with ups and downs following political events in the real world (such as Olympic protests, Israeli-Palestinian conflicts, etc.). What has become more frequent is press coverage of attacks which creates a cycle of more activity followed by more press (see Hacktivism & Politically Motivated Computer Crime for a detailed analysis of the relationship between hacktivism and media coverage).


‘Hacktivism’ Incidents Escalate, Become More Frequent

Wednesday, April 30, 2008

Bank of Israel Website Attacked

The Bank of Israel is reporting that its website has been repeatedly attacked by Islamic 'hackers' using an Algerian server.

From the report, it appears the bank's IT staff had not adequately addressed known security vulnerabilities.
"Governor of the Bank of Israel Prof. Stanley Fischer was taken by surprise by the hacking of the bank's website last week, and in a moment of anger announced that he would fire those responsible."

Fischer incensed at website security breakdown

Radio Free Europe Websites Hit by DoS Attacks

Several websites owned by Radio Free Europe/Radio Liberty (RFE/RL) have been shutdown by denial of service attacks in recent days.

RFE/RL stated the attacks started on the website for Belarus service and spread to other RFE/RL sites and other organizations in Minsk.

RFE/RL believe the attacks are attempts by regional governments to censor news:
"RFE/RL President Jeffrey Gedmin said he is deeply concerned by the attacks. "If free and independent media existed in these countries where we're working and broadcasting, we would have no reason to exist," Gedmin said. "The Belarusians, the Iranians -- they all have basically the same objective. They see free information -- flowing information of ideas and so forth -- as the oxygen of civil society. They'll do anything they can to cut it off. If it means jamming, if it means cyberattacks, that's what they'll do."

US radio websites in Eastern Europe hit by cyberattack: bosses


Other related articles:

Belarus: RFE/RL Cites Online 'Solidarity' in Face of Cyberattack

U.S. Denounces Attack On RFE/RL Websites


Wednesday, April 09, 2008

Estonia Preparing for Further Attacks

The Guardian newspaper has a brief article on Estonian concerns for further cyber attacks on the one year anniversary of the attacks believed to have been motivated by Russian anger over the movement of a Soviet war memorial.
"With the anniversary of the attacks looming, senior officials are preparing for a repeat performance. One official said there had been many smaller attempts to hack into government systems during the last 12 months but they were not as organised or successful as last year's attacks."


Estonia prepares for repeat of cyberattacks on anniversary

Monday, March 24, 2008

Similar Tactics Used to Attack Darfor and Tibet Support Groups

Several organizations have recently reported similar attacks against their computer systems. Organizations such as Save Darfur Coalition, the AFP and members of a pro-Tibetan mailing list have all been the victims of email infected attacks using similar methods.

Once again, China is most often named as the source.

F-Secure's weblog "News from the Lab" has a posting which details the specifics of the pro-Tibeten attacks with screen shots of the email message and details of the attached malicious code.

Perhaps most informative, the Washington Post ran an article with some specific details of malicious software that attempts to capture users encryption keys once a system is compromised:

"The specificity of information sought in the targeted attacks also suggests the attackers are searching for intelligence that might be useful or valuable to a group that wants to keep tabs on human rights groups, said Nathan Dorjee, a graduate student who provides technology support to Students for a Free Tibet.

"Dorjee said one recent e-mail attack targeted at the group's members included a virus designed to search victim's computers for encryption keys used to mask online communications. The attackers in this case were searching for PGP keys, a specific technology that group members routinely use to prevent outsiders or eavesdroppers from reading any intercepted messages.

"Dorjee said the attacks have been unsettling but ineffective, as the Students for a Free Tibet network mostly operates on more secure platforms, such as Apple computers and machines powered by open source operating systems."


Targeted Malware Attacks against pro-Tibet Groups

FBI Suspects Chinese Hackers Damaged Darfur Site

Cyber Attacks Target Pro-Tibet Groups

Wednesday, February 13, 2008

Recommended Reading: Combating Enemies Online

The Hawaii Reporter has published an excellent article on politically motivated computer crime. The article discusses the different types (motivations) of activity and reviews responses and recommendations:
"Less attention, however, has been paid to state sponsors of illicit computer activity, which are increasingly using the Internet to conduct espionage, deny services to domestic and foreign audiences, and influence global opinion. In addition, insufficient focus has been given to how terrorists exploit the Internet as a tool for recruiting, fund raising, propa­ganda, and intelligence collection and use it to plan, coordinate, and control terrorist operations. Combat­ing these malicious activities on the Internet will require the cooperation of federal entities, as well as friendly and allied countries and the private sector."
Combating Enemies Online: State-Sponsored and Terrorist Use of the Internet

Thursday, January 31, 2008

Local Government Opposition Website Attacked in Russia

Reuters is reporting an alleged attack against an opposition web site in the southern Russian region of Ingushetia. Opposition leaders accuse local political leaders of attacking the website (no details on how, just that it was "hacked") after the website carried information promoting protests against the local government and details of alleged kidnapings and murders.

"The Web site promoted and helped organize a protest on Saturday in which demonstrators armed with petrol bombs clashed with police and burnt a pro-government newspaper office.

On Thursday the Web site was closed, founder Magomed Evloev said, accusing authorities of hacking into the site to try and silence opposition."



Founder says Russian authorities hack critical Web site

Thursday, January 24, 2008

Conviction in 2007 Estonia Cyber Attack

An Estonian court has convicted the first individual in the 2007 cyber attacks against Estonia.
"Dmitri Galushkevich used his home PC to launched a denial-of-service attack that knocked down the Web site for the political party of Estonia's prime minister for several days..."

He was fined 17,500 kroons (approx. US$ 1,642).

The motive for the attack was to protest the relocation by the Estonian government of a statue to Russian war veterans.

Student Convicted in Attack Against Estonian Web Site

Another article on the conviction is available at:

Estonia convicts first 'cyber-war' hacker: prosecutors

Tuesday, January 22, 2008

Panama's National Assembly Website Vandalised

Intruders vandalised the website of Panama's National Assembly, believed to be in protest for the election of the Assembly's leader who is wanted in the U.S. for allegedly killing a U.S. soldier. The website was replaced with an American flag.
"Officials at the [National] assembly, declining to be quoted by name, said the site, www.asamblea.gob.pa/, has been down since January 9, when a U.S. flag briefly appeared there. One said the cyber attack almost certainly came from the United States."

Hackers bring down Panama assembly's Web site