Dutch intelligence disrupt large-scale botnet belonging to Russian spy agency
March 7, 2022 Leave a comment
ON MARCH 3, 2022, Dutch newspaper Volkskrant reported that the Dutch Military Intelligence and Security Service (MIVD) took action in response to abuse of SOHO-grade network devices in the Netherlands. The attacks are believed to have been perpetrated by the Main Intelligence Directorate of the General Staff of the Russian Armed Forces (GRU) Unit 74455. The unit, which is also known as Sandworm or BlackEnergy, is linked to numerous instances of influence operations and sabotage around the world.
The devices had reportedly been compromised and made part of a large-scale botnet consisting of thousands of devices around the globe, which the GRU has been using to carry out digital attacks. The MIVD traced affected devices in the Netherlands and informed their owners, MIVD chief Jan Swillens told Volkskrant. The MIVD’s discovery came after American and British [pdf] services warned in late February that Russian operatives were using a formerly undisclosed kind of malware, dubbed Cyclops Blink. According to authorities, the botnet in which the compromised devices were incorporated has been active since at least June 2019.
Cyclops Blink leverages a vulnerability in WatchGuard Firebox appliances that can be exploited if the device is configured to allow unrestricted remote management. This feature is disabled by default. The malware has persistence, in that it can survive device reboots and firmware updates. The United Kingdom’s National Cyber Security Centre describes Cyclops Blink as a “highly sophisticated piece of malware”.
Some owners of affected devices in the Netherlands were asked by the MIVD to (voluntarily) hand over infected devices. They were advised to replace the router, and in a few cases given a “coupon” for an alternative router, according to the Volkskrant. The precise number of devices compromised in the Netherlands is unclear, but is reportedly in the order of dozens. Swillens said the public disclosure is aimed at raising public awareness. “The threat is sometimes closer than you think. We want to make citizens aware of this. Consumer and SOHO devices, used by the grocery around the corner, so to speak, are leveraged by foreign state actors”, he added.
The disclosure can also be said to fit in the strategy of public attribution that was first mentioned in the Netherlands’ Defense Cyber Strategy of 2018. Published shortly after the disclosure of the disruption by MIVD of an attempted GRU attack against the computer network of the OPCW, the new strategy included the development of attribution capabilities, as well as the development of offensive capabilities in support of attribution. It advocates the view that state actors “that are [publicly] held accountable for their actions will make a different assessment than attackers who can operate in complete anonymity”.
► Author: Matthijs Koot | Date: 07 March 2022 | Permalink
LAST WEEK, THE DUTCH General Intelligence and Security Service (AIVD) launched an awareness campaign dubbed ‘Check before connecting’. The purpose of the campaign is to inform the Dutch public about risks of foreign actors using fake accounts on social media, in efforts to acquire sensitive business information. According to the AIVD, such online campaigns frequently target and recruit employees of Dutch private sector companies. The
Since 2008, when intelNews was launched, it has been our
Since 2008, when intelNews was launched, it has been our
Since 2008, when intelNews was launched, it has been our 
IN HIS NEW BOOK, We Never Expected That: A Comparative Study of Failures in National and Business Intelligence (Lexington Books), Dr. Avner Barnea has coined two new terms in the field of strategic surprise. One is diffused surprise and the other is concentrated surprise, two terms that help us to better understand why intelligence failures occur. In a diffused surprise there is difficulty in identifying the intelligence target and therefore the chance of a surprise increases; while in a concentrated surprise the intelligence target is usually a recognized organization. At the same time, the mistake lies in the assessment of the target’s abilities and intentions.



surprised observers with its range of weapons, such as long-range missiles with a reach that is in excess of 150 miles. This constitutes a strategic surprise for Israel. So far (May 13, 2021), Hamas has fired about 1,500 missiles at Israel, most of which have been intercepted by Israel’s air defense system called the Iron Dome.
LAST MONTH I WROTE an
THE FEDERAL BUREAU OF Investigation and the New York Police Department gave Capitol Police officials specific warnings that supporters of United States President Donald Trump were determined to engage in serious violence on January 6, according to federal officials. The FBI even made contact with known far-right radicals across the United States in early January, and warned them not to travel to Washington for the pro-Trump rally that resulted in the bloody attack on the US Capitol,
IF WEDNESDAY’S ATTACK ON the United States Capitol Complex was part of a coup d’état, then the American political system should be considered safe for the time being. The mob that ransacked the Capitol was disordered, leaderless, and appeared to have no coordination, or even direction. However, the broader militant movement that it represents is evolving very rapidly. If left unchecked, it will be able to turn its weaknesses into strengths and spell major trouble ahead for the already stormy waters of American politics. The nation’s law enforcement and security agencies must therefore prepare for a period of widespread insurrection, some of which will be armed and lethal in nature. Insurrectionist acts are likely to occur across the nation, and may last for months, if not longer.







Several EU member states expel dozens of Russian diplomats for suspected espionage
April 4, 2022 1 Comment
The Czech Republic, which in 2021 called on the European Union (EU) and the North Atlantic Treaty Organization (NATO) to expel Russian diplomats in solidarity against Moscow, announced the expulsion of one diplomat from the Russian embassy in Prague, on a 72-hour notice. In a tweet, the Czech ministry of foreign affairs stated that “Together with our Allies, we are reducing the Russian intelligence presence in the EU”.
Belgium has order the expulsion of 21 diplomats from the Russian embassy in Brussels and consulate in Antwerp. Minister Sophie Wilmès said the measure was taken to protect national security and was unrelated to the war in Ukraine. “Diplomatic channels with Russia remain open, the Russian embassy can continue to operate and we continue to advocate dialogue”, Wilmès said.
The Netherlands will be expelling 17 diplomats from the Russian embassy in The Hague. According to minister Wopke Hoekstra, the diplomats were secretly active as intelligence officers. Hoekstra based this on information from the Dutch secret services AIVD and MIVD. The Russian embassy in The Hague has 75 registered diplomats, of which 58 will remain. Hoekstra says the decision was taken with “a number of like-minded countries”, based on grounds of national security. Like his Belgian colleague, Woekstra adds he wants diplomatic channels with Russia to remain open.
Ireland will be expelling four “senior officials” from the Russian embassy in Dublin, for engaging in activities “not […] in accordance with international standards of diplomatic behaviour”. They were suspected of being undercover military officers of the GRU and were already on the radar of Garda Síochána, the Irish national police and security service, for some time.
Read more of this post
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with Belgium, Czech Republic, diplomatic expulsions, Ireland, Netherlands, News, Russia, Slovakia