Fake URL shortening service was part of British online spy operation

Iran protestsAn internet website that offered free URL shortening services appears to have been a front created by British intelligence in order to spread messages and monitor activists involved in protests in Iran and the Arab world. The website was used heavily during the Iranian presidential election protests of 2009, which became known as the Iranian Green Movement. After a brief hiatus, the website was used again in 2011, as the Arab Spring revolts in North Africa and the Middle East were intensifying. The information pointing to the use of the website comes from documents leaked by Edward Snowden, the American former intelligence employee who has been granted political asylum in Russia.

According to the leaked documents, the website, lurl.me, was devised by a specialist until of the Government Communications Headquarters (GCHQ), Britain’s intelligence agency that collects signals intelligence. The unit, called Joint Threat Research Intelligence Group (JTRIG), devised the website as part of an operation codenamed DEADPOOL. The leaked documents state that the purpose of the website was to operate as a “shaping and honeypot” tool, by helping disseminate messages in support of the protests while at the same time allowing the GCHQ to monitor the protesters’ online activities. Lurl.me first appeared in June 2009 as a self-described “free URL shortening service”, using the slogan: “we help you get links to your friends and family fast”. It was used repeatedly on Twitter and other social media platforms to spread messages against the government of Iran. But the vast majority of social media accounts that made use of the website, like @2009iranfree, were operational only for a short period of time, had few followers, and ceased all activity at the end of the Iranian Green Movement. By that time, hardly anyone was using lurl.me. But the website made its appearance again on social media in April of 2011, with messages against the government of Syria. According to Vice’s Motherboard website, Tweets using the lurl.me service appeared to be active only between 9 a.m. and 5 p.m. UK time, and only on weekdays.

Both in 2009 and 2011-2013, lurl.me was used to instruct anti-government activists on how to avoid being monitored by the authorities. Some links contained instructions on how to access the Internet via satellite. Others provided directions on using proxies to access websites that were blocked by the authorities. At the same time, however, the documents leaked by Snowden show that the GCHQ also used the service to track the activities of anti-government activists who clicked on the lurl.me links, and even to ‘deanonymize’ (=to establish the real identity) of these users.

IntelNews first reported on JTRIG in February 2014, when its existence was first revealed by Snowden. The specialist unit has been associated with targeting self-described ‘hacktivist’ groups like Anonymous or LulzSec, using malware, social engineering, and other techniques. JTRIG also appears to have conducted online intelligence operations against the government of Argentina.

Motherboard reports that lurl.me was last used in November 2013, shortly after Snowden began leaking files from his secret hiding place in Russia. Motherboard said it contacted GCHQ for a reaction to the lurl.me allegations, but the agency said it would “not comment on intelligence matters”.

Author: Joseph Fitsanakis | Date: 02 August 2016 | Permalink

CIA warned Tunisian officials about murder of opposition politician

Brahmi supporters in TunisBy JOSEPH FITSANAKIS | intelNews.org
The Tunisian government has admitted that it received advance warning by “an external intelligence source” of an assassination operation against a popular opposition figure. The politician, Mohammed Brahmi, a widely respected member of the country’s National Constituent Assembly, was gunned down 11 days after the alleged warning was received. His death, in July of this year, plunged the country into political chaos, which continues to dominate Tunisian politics today. Speaking to lawmakers on Thursday, Tunisia’s Minister of the Interior, Lotfi Ben Jeddou, said the warning had been received on July 15, 2013. He refused to identify the source of the warning, but Tunisian media speculated that it was most likely the United States Central Intelligence Agency (CIA). The warning was included in a memorandum, which stated that Brahmi was likely to be targeted by “Salafist elements” because of his secular and liberal political beliefs. The minister said that the warning contained no “further clarification”, but added that the absence of details in the memorandum did not justify the failure of the Tunisian security establishment to adequately respond to it. Brahmi, died on July 25 after being shot over a dozen times at close range outside his house in the al-Gazala neighborhood of Tunisian capital Tunis. On Saturday, two days after Minister Ben Jeddou’s revelation, Tunisian newspaper Al Maghreb published a leaked memorandum that contains a summary of the warning about Brahmi’s killing. The leaked summary, which is signed by Tunisia’s Director General of National Security, Mustafa Ben Amor, appears to be dated July 15, 2013, exactly 11 days before Brahmi’s assassination. It describes a warning issued by a CIA official, concerning credible threats to Brahmi’s life. Read more of this post

News you may have missed #835 (Americas edition)

Rene GonzalezBy IAN ALLEN | intelNews.org |
►►‘Cuban Five’ spy member renounces US citizenship. Cuban intelligence officer Rene Gonzalez, who was a member of the “Cuban Five” spy group in South Florida, was released from a US prison in 2011, after serving 10 years for espionage. He was required to serve three years’ probation in the US. But on Friday US District Judge Joan Lenard ruled that Gonzalez, who had already been allowed to temporarily return to Cuba for his father’s funeral, could stay there if he renounced his US citizenship. Gonzalez is the first of the Cuban Five to return to the island. The other four men continue to serve lengthy sentences in US federal prisons.
►►US Defense Intelligence Agency contemplates austerity. Since 2001, intelligence agencies have had just about all money they wanted, but not anymore, as the cuts mandated by the Budget Control Act are hitting even previously inviolable spook accounts. In a reflection of this new reality, the Defense Intelligence Agency plans a conference with industry at its headquarters on June 27, 2013. Agency leaders will focus on “current and emerging challenges in the context of an increasingly austere fiscal posture”.
►►Report says Canada spies caught off guard by Arab Spring. The 2011 Arab Spring uprising in the Middle East came as a surprise to the Canadian government, which risks getting caught off-guard again without a new approach to gathering intelligence. This is according to a new report by Canada’s Intelligence Assessment Secretariat, a unit of the Privy Council’s Office, the bureaucratic arm of the Office of the Canadian Prime Minister. On the other hand, the report states, “there is no reason to believe that [Canadian intelligence agencies] did any worse than other allied agencies in its analysis of the Arab Spring, and in a few areas it appears to have done somewhat better”.

US spy agencies turn to Israel, Turkey, for help in Syria war

Regional map of SyriaBy JOSEPH FITSANAKIS | intelNews.org |
Just days after a senior United States defense official admitted Pentagon intelligence analysts missed early signs of the Arab Spring, a new report claims that Washington is still “struggling to understand” the Syrian situation, sixteen months into the uprising. Citing “interviews with US and foreign intelligence officials”, The Washington Post says that the US Intelligence Community has yet to develop a clear understanding of the intentions of the regime of Syrian President Bashar al-Assad. Nor have American analysts been able to draw a lucid picture of the fragmented opposition forces in the country. The paper says that, even though US spy agencies have intensified their intelligence-gathering efforts targeting all sides of the civil war, they have been unable to establish a physical presence inside Syria. This, according to The Post, is partly due to Washington’s decision, back in February of this year, to shut down the US embassy in Damascus, which has traditionally served as staging ground for Central Intelligence Agency operations inside Syria. This latest article confirms previous reports in The New York Times and elsewhere, of a small CIA team operating along the Syrian-Turkish border, with the task of overseeing a multinational effort to secretly deliver weapons, communications equipment and medical supplies to Syrian opposition forces. But this is about as close as the CIA has managed to get to Syria; for the most part, like its partner agencies in the US Intelligence Community, the Agency is “still largely confined to monitoring intercepted communications and observing the conflict from a distance”, says The Washington Post. As a result, US intelligence agencies are becoming increasingly dependent on their counterparts in Turkey, Jordan, and —most of all— Israel for reliable ground intelligence from inside Syria. Read more of this post

News you may have missed #766 (Arab world edition)

David SheddBy IAN ALLEN | intelNews.org |
►►Yemen busts alleged Iranian spy ring. Yemeni president Abd-Rabbu Mansour Hadi called on Tehran to stay out of Yemen’s internal affairs last week, after security officials in Sana’a, Yemen’s capital, announced they had uncovered an Iranian spy ring there. Yemen’s government-run SABA news agency said the spy cell, which was allegedly led by a former commander of Iran’s Islamic Revolutionary Guard corps, had operated in Yemen as well as in the Horn of Africa,  and that it had kept an operations center in Sana’a. An interior ministry official said all those detained were Yemenis.
►►CIA sued for killing US citizens in Yemen. Survivors of three Americans killed by targeted drone attacks in Yemen last year have sued top-ranking members of the United States government, alleging they illegally killed the three, including a 16 year-old boy, in violation of international human rights law and the US Constitution. The suit (.pdf), the first of its kind, alleges the United States was not engaged in an armed conflict with or within Yemen, prohibiting the use of lethal force unless “at the time it is applied, lethal force is a last resort to protect against a concrete, specific, and imminent threat of death or serious physical injury”. The case directly challenges the government’s decision to kill Americans without judicial scrutiny.
►►US intel official acknowledges missed Arab Spring signs. David Shedd, deputy director of the US Defense Intelligence Agency, the Pentagon’s intelligence arm, said analysts failed to note signs of the unrest across the Middle East and North Africa that exploded into the Arab Spring. Shedd’s comments were posted Thursday by the American Forces Press Service, a Pentagon information wire. They constitute a rare public acknowledgment of the US intelligence failure regarding the turmoil that has redrawn the Middle East’s political landscape, toppling autocratic rulers in Tunisia, Egypt, Yemen and Libya and now engulfing Syria.

News you may have missed #762

Danni YatomBy IAN ALLEN | intelNews.org |
►►Italy postpones court decision on wanted CIA operatives. The Washington Post has published a useful update on Sabrina De Sousa, one of nearly two-dozen CIA operatives who were convicted in Italy in 2007 for the kidnapping four years earlier of Egyptian cleric Hassan Mustafa Osama Nasr. The Americans kidnapped Nasr, known as Abu Omar, from the streets of Milan without the consent of Italian authorities. The Italians, who were themselves carefully monitoring Nasr, responded by convicting all members of the CIA team in absentia, and notifying INTERPOL. But last Friday, the Supreme Court of Cassation in Rome postponed its verdict after a two-day hearing aimed at deciding whether to uphold or overturn the Americans’ convictions.
►►Ex-Mossad chief urges Israel to prepare for military action in Syria. In an interview with British news network Sky News, former Mossad Chief Danni Yatom said last week that Israel must be prepared for the possibility of military attacks on Syria, which may deteriorate into war.  He said his warning stems from the fear that Syria’s hundreds of tons of chemical weapons will fall into the hands of terrorists. “We would have to pre-empt in order to prevent it. We need to be prepared to launch even military attacks […] and military attacks mean maybe a deterioration to war”, said the former Mossad Director.
►►British spy agencies failed to predict Arab Spring. The Intelligence and Security Committee of the British Houses of Parliament has said in its annual report that British spy agencies had been surprised by the spread of unrest during the Arab Spring and failed to predict the dramatic uprisings that swept the region. The report also noted that the Arab Spring had exposed Britain’s decision to scale back intelligence assets in much of the Arab world, in favor of monitoring Iran and al-Qaeda. We at intelNews wrote about this in 2011.

News you may have missed #755

Jeffrey Paul DelisleBy TIMOTHY W. COLEMAN | intelNews.org |
►►MI5 chief says al-Qaeda threatens UK from Arab Spring nations. Brittan’s domestic intelligence agency chief, Jonathan Evans, has stated that al-Qaeda is continuing to gather a foothold in nations that experienced the Arab Spring. In his speech, Evans, who directs the UK’s MI5, warned that al-Qaeda is attempting to reestablish itself in countries that had revolted, and that “a small number of British would-be jihadis [sic] are also making their way to Arab countries to seek training and opportunities for militant activity, as they do in Somalia and Yemen. Some will return to the UK and pose a threat here”. With a suspected 100-200 British born Islamist militants operating in the Middle East and Africa, the MI5 Director General warned that the coming summer Olympics in London made for an attractive target.
►►Russia to conduct airborne surveillance of Canada’s infrastructure. Canada’s National Post newspaper reports that Russian surveillance aircraft will conduct a flyover of Canada’s military and industrial infrastructure in what appears to be an annual Russian air reconnaissance mission. For the past ten years and under the Open Skies treaty, Russia is allowed to conduct flyovers of key Canadian sites. This will be the first flyover since the arrest last January of Jeffrey Paul Delisle (pictured), a Royal Canadian Navy officer, for allegedly spying on Canada on behalf of the Russians.
►►Japanese official who leaked DRPK missile info found dead. A Japanese Foreign Ministry official, who was largely thought to the source of leaked information regarding a Chinese missile technology transfer to North Korea in April, has been found dead. The official, previously under investigation for publicly disclosing national security information, was found hanged in his Chiba prefecture home on June 20. Additional details, including the individual’s name, were not made available, but Japanese government officials did indicate that the death did not appear to be suspicious.

US resumes controversial weapons sale to Bahrain

Gulf Cooperation Council countriesBy JOSEPH FITSANAKIS | intelNews.org |
The United States has announced that it will resume a controversial weapons deal with the Kingdom of Bahrain, despite its government’s substandard human rights record, which has been internationally criticized in the context of the Arab Spring. The administration of President Barack Obama halted all weapons sales to the oil-rich Gulf state in September of 2011, nearly a year following the eruption of widespread popular protests in the Kingdom. On May 11, however, Washington announced that the weapons sale would go ahead after all, with the exception of some items that could be used against human rights protesters. According to The Christian Science Monitor, one of a handful of American news outlets that covered the story, US officials said that the decision to resume weapons sales to Bahrain was taken “in light of US national security interests”. The paper quotes an unnamed US government official who told reporters that Washington had given the go-ahead to the weapons sale in order to “help Bahrain maintain its external defense capabilities” against Iran. The regime in Bahrain has accused human rights activists of operating under the control of the Iranian government. The Monitor says that the resumption of US military aid to Bahrain has dealt a significant blow to the pro-democracy movement, and appears to have “incensed opposition activists”, who see it “as a signal that that the US supports Bahrain’s repression of opposition protests”. The article quotes one such activist, Mohammed al-Maskati, who describes the weapons deal as a “direct message [from the US] that we support the authorities and we don’t support democracy in Bahrain, we don’t support protesters in Bahrain”. Meanwhile, all eyes are in Saudi Arabia this week, as Arab Gulf leaders are meeting to discuss plans for forming a pan-Arab Gulf union. Read more of this post

News you may have missed #713 (analysis edition)

RAW headquarters, New Delhi, IndiaBy IAN ALLEN | intelNews.org |
►►Israel wary of changes in the Arab world. For decades, Israel had been hoping for change in the Arab world. Yet now that the region is in upheaval, its not just Israeli citizens who are concerned. The government has shown a preference for walling itself in rather than exploring new opportunities. The Jewish state has tried to integrate itself into the Middle East for decades. Now it is trying to cut the cord between itself and the surrounding region, blocking out the changes in its neighborhood.
►►Melting Arctic may redraw global geopolitical map. If, as many scientists predict, currently inaccessible sea lanes across the top of the world become navigable in the coming decades, they could redraw global trading routes —and perhaps geopolitics— forever. This summer will see more human activity in the Arctic than ever before, with oil giant Shell engaged in major exploration and an expected further rise in fishing, tourism and regional shipping. But that, experts warn, brings with it a rising risk of environmental disaster not to mention criminal activity from illegal fishing to smuggling and terrorism.
►►Why Indian intelligence doesn’t work too well in Pakistan. Sources in the RAW, India’s external agency, say India lacks both political will and the capability to carry out a hit inside Pakistan. “We do not have the mandate to do what Mossad does. Our charter does not include the job of getting [or assassinating] people from other countries. If such political will is there, the agency would be able to do it”, says a senior RAW official. Another former officer, who has spent a considerable time studying these outfits, attributes it to the fundamental difference between India and Pakistan in dealing with espionage. “It takes a great deal of money and time to cultivate sources in foreign soil. We don’t have either in plenty, unlike countries in the West. Pakistan’s ISI is better off in this as the state sponsors terrorism”, he says.

Research: Spies increasingly using Facebook, Twitter to gather data

Spying on social networkingBy JOSEPH FITSANAKIS | intelNews.org |
During the past four years, this blog has reported several incidents pointing to the increasing frequency with which spy agencies of various countries are utilizing social networking media as sources of tactical intelligence. But are we at a point where we can speak of a trend? In other words, is the rapid rise of social networking creating the conditions for the emergence of a new domain in tactical intelligence collection? This past week saw the publication of a new research paper (.pdf), which I co-authored with Micah-Sage Bolden, entitled “Social Networking as a Paradigm Shift in Tactical Intelligence Collection”. In it, we argue that recent case studies point to social networking as the new cutting edge in open-source tactical intelligence collection. We explain that Facebook, Twitter, YouTube, and a host of other social networking platforms are increasingly viewed by intelligence agencies as invaluable channels of information acquisition. We base our findings on three recent case studies, which we believe highlight the intelligence function of social networking. The first case study comes out of the Arab Spring, which, according to one report, “prompted the US government to begin developing guidelines for culling intelligence from social media networks”. We also examine NATO’s operations during the 2011 Libyan civil war (Operation UNIFIED PROTECTOR), when Western military forces systematically resorted to social networking media to gather actionable intelligence, by utilizing open sources like Twitter to pinpoint targets for attack. Finally, we examine the sabotage by Israeli security services of the 2011 “Welcome to Palestine Air Flotilla” initiative, a campaign organized by several European groups aiming to draw worldwide attention to the travel restrictions imposed by Israeli authorities on the Occupied Territories. Read more of this post