Documents show ISIS plans sleeper cell attacks in Middle East, Europe

Islamic State - IADocuments acquired from retreating Islamic State fighters in Syria appear to show that the militant group is planning a series of high-profile attacks in Europe and the Middle East, using newly formed sleeper cell units. The information was revealed over the weekend by the British newspaper The Sunday Times. The London-based broadsheet said that the information was found last month in flash drive, which was left behind by retreating Islamic State forces in Syria, and acquired by Kurdish militia forces. The flash drive was found to contain dozens of internal documents belonging the militant group, which is also known as Islamic State of Iraq and Syria (ISIS).

Among them, said The Times, are several memoranda authored by an ISIS leader and operations planner known as Abu Taher al-Tajiki. In his memoranda, al-Tajiki informs the group’s senior leadership that he commands numerous fighters who are willing and able to carry out strikes “far away” from the Islamic State’s strongholds in the Middle East and Africa. He states that he is in regular communication with them and that they are awaiting instructions to “undertake the operations”. Al-Tajiki then calls for the creation of a Foreign Relations Office under the Islamic State’s Department of Operations, which would be tasked with launching attacks throughout Europe. He adds that the new Office can also count on the assistance of computer hackers and other technically literate Islamic State members. In another memorandum, al-Tajiki suggests the creation of what he calls “crocodile cells” in Syria and Iraq. These cells will “lurk beneath the surface” and “attack at the right moment to assassinate the enemies of Allah”, says al-Tajiki.

The Times report comes as experts warn that the Islamic State retains significant financial power, despite the loss of its territories in the Middle East. In a well-informed article in The Atlantic, David Kenner reports from Beirut that the Islamic State without its territories is a double-edged sword. On the one hand, the group cannot rely on taxation and oil revenues that used to enrich its coffers by $1 million per day during the height of its power. On the other hand, argues Kenner, the loss of its territory has freed the Islamic State from the costs associated with state-running and allows it to devote its financial resources “exclusively to terrorist activity”. These resources —cash and other assets— are formidable, says Kenner. In the words of Howard Shatz, senior economist at the Rand Corporation and an expert on ISIS’ finances, we “don’t know where it all went” after ISIS lost its territory. We do know that much of it has been invested in “legitimate commercial enterprises”, says Shatz, with the help of profit-oriented middlemen with access to markets that are as far away as Southeast Asia and the Caribbean. A lot of it is hidden in suitcases and boxes throughout Iraq, Syria and Turkey. All of it is intended to be used to fund terrorist attacks, warns Kenner.

► Author: Ian Allen | Date: 25 March 2019 | Permalink

East German Stasi spies questioned for evidence on Lockerbie bombing

Lockerbie air disasterFive former officers of East Germany’s State Security Service, known commonly as the Stasi, have been questioned in Berlin over the Lockerbie air disaster at the request of British prosecutors. A total of 270 people died on December 21, 1988, when Pan Am flight 103, flying from Frankfurt to Detroit, exploded in mid-air over the Scottish village of Lockerbie. In 2001, a British court sitting in the Netherlands ruled that the bombing was carried out by Abdelbaset al-Megrahi, former head of security for Libyan Arab Airlines. Al-Megrahi was also believed to have been an officer of Intelligence of the Jamahiriya —Libya’s main intelligence service. He claimed he was innocent of the crime until his death in 2012 from cancer.

But Scotland’s independent public prosecution agency, the Crown Office and Procurator Fiscal Service, has always claimed that several other Libyan intelligence operatives helped Megrahi bring down Pan Am flight 103. Last December, the Crown Office said that it was continuing to pursue a criminal inquiry into several individuals —other than Megrahi— who were “involved in the conspiracy” to bomb Pan Am flight 103. As part of the inquiry, Crown Office prosecutors have interviewed potential suspects and witnesses, including Abdullah Senussi, former head of Libyan intelligence.

On Thursday, the German news agency DPA said that five former officers of the East German Stasi —all of them in their 70s and 80s— had been interviewed in connection to the Lockerbie bombing. The news agency said that the interviews had been conducted by German intelligence officers at the request of Crown Office prosecutors in Britain. Later on Thursday, the Berlin office of the German state prosecutor confirmed that the unnamed five individuals had been interviewed “as witnesses, not as suspects” throughout the past nine months. It gave no further information, saying that “it would be inappropriate to comment on a developing criminal investigation”.

All five former Stasi officers are believed to have provided evidence at the trial in the Netherlands that resulted in Megrahi’s conviction. Among other things, they told the court that the Libyans had contracted a Swiss businessman who manufactured the timer that detonated the Lockerbie bomb. Moreover, the 2014 documentary My Brother’s Bomber, directed by the American filmmaker Ken Dornstein, whose brother died in the Lockerbie bombing, claimed that the Stasi had closely monitored the activities of Libyan intelligence in West Germany in the years leading up to the downing of Pan Am flight 103. Some believe that the Stasi had evidence of a conspiracy by several Libyan intelligence officers to carry out the bombing.

► Author: Joseph Fitsanakis | Date: 22 March 2019 | Permalink

Putin’s ex-adviser found dead in Washington had broken neck, say medical examiners

Mikhail LesinA former senior adviser to Russian President Vladimir Putin, who died allegedly by falling while intoxicated in a luxury hotel room in Washington, may in fact have been strangled to death, according to a newly released medical examination. The body of Mikhail Yuriyevich Lesin, a well-known Russian media mogul, was found in the luxury Dupont Circle Hotel on November 5, 2015. He became famous in Russia soon after the collapse of the communist system, when he founded Video International, an advertising and public-relations agency that was hired by Russian President Boris Yeltsin to run his reelection campaign in 1995.

Yeltsin’s electoral success was partly attributed to the well-tailored media message projected by Lesin’s company. The media magnate was rewarded by Yeltsin, who offered him influential government posts, including that of director of Russia’s state-owned news agency Novosti. Meanwhile, Lesin became a media personality and frequently gave interviews espousing a free-enterprise model for the Russian media industry. But soon after Vladimir Putin’s ascendance to the presidency, Lesin saw the writing on the wall and began advocating for increased government regulation of media and telecommunications conglomerates. In 1999, Putin made him Minister of Press, Broadcasting and Mass Communications, a post he held for nearly six years, until 2004. In 2006, Lesin was awarded the Order for Merit to the Fatherland, one of the most prestigious civilian decorations in Russia.

But in late 2009, Putin abruptly fired Lesin from his post in the Kremlin’s Media Advisory Commission, allegedly because the media mogul had developed close contacts with Russian organized crime. Lesin’s ties with Putin’s inner circle were further strained in 2014, when he resigned from his position as head of Gazprom Media, after he clashed with pro-Putin executives on the board. When Lesin’s body was found in his hotel room by a member of the hotel staff, some suggested that he may have been killed by the Kremlin. Read more of this post

Heavily armed gang attacks nuclear fuel convoy in Brazil

Angra Nuclear Power PlantA convoy of trucks carrying nuclear fuel to one of Brazil’s nuclear plants was attacked by a heavily armed gang on Tuesday, according to police reports. The convoy was carrying uranium fuel from Resende, an industrial city in the municipality of Rio de Janeiro in southeastern Brazil. Its destination was the Angra Nuclear Power Plant in the coastal city of Angra dos Reis, which is located 100 miles south of Resende. Angra is Brazil’s sole nuclear power plant. It consists of two pressurized water reactors, Angra I and Angra II. It is owned by Eletrobras, Brazil’s state-owned power utility firm, which is also the world’s tenth largest electric utilities company.

According to Brazil’s O Globo newspaper, the nuclear fuel convoy came under heavy attack by gunmen as it reached the outskirts of Angra dos Reis, just a few miles north of the power plant. The Brazilian Federal Highway Police said in a statement that its vehicles that were escorting the nuclear fuel convoy were shot at and returned fire. It added that the attackers fled the scene without anyone getting hurt, and that no arrests were made. The convoy then reached the power plant without further incident 20 minutes following the shootout. The police statement was followed by a public announcement by Eletronuclear, Eletrobras’ nuclear utility arm. The announcement argued that national security was not compromised by the attack, as the fuel carried by the trucks consisted of “uranium in its natural state”. It would therefore have to be weaponized with the use of advanced mechanical instruments before it could be truly harmful.

Brazilian Federal Highway Police officials told reporters that they did not believe that the gunmen had planned to attack the nuclear fuel convoy. They claimed that the convoy happened to be passing from the scene of the attack as a shootout was taking place between members of rival drug gangs, which are known to control the outskirts of Angra dos Reis. Some of the gang members began shooting at the police vehicles escorting the convoy, apparently without realizing that the trucks they were shooting at were carrying nuclear fuel.

The incident underscores the steady rise and increasing aggressiveness of organized criminal gangs in Brazil, which, according to some observers, are beginning to resemble Mexico’s drug cartels. Angra dos Reis’ Mayor Fernando Jordão told O Globo that the residents of his city felt unprotected by the federal government. “Regional security must be improved”, he added, especially since “there are nuclear plants here. This region is very sensitive”, he said.

► Author: Joseph Fitsanakis | Date: 20 March 2019 | Permalink

Analysis: Who was behind the raid on the North Korean embassy in Madrid?

North Korea SpainAn obscure North Korean dissident group was most likely behind a violent raid on North Korea’s embassy in Madrid on February 22, which some reports have pinned on Western spy agencies, including the Central Intelligence Agency. The group, known as the Cheollima Civil Defense, is believed to be the first North Korean resistance organization to declare war on the government of Supreme Leader Kim Jong-un.

THE ATTACK

The attack took place at 3:00 in the afternoon local time in Aravaca, a leafy residential district of northern Madrid, where the embassy of North Korea is located. Ten assailants, all Southeast Asian-looking men, entered the three-story building from the main gate, brandishing guns, which were later found to be fake. They tied up and gagged the embassy’s staff, as well as three North Korean architects who were visiting the facility at the time. But one staff member hid at the embassy. She eventually managed to escape from a second-floor window and reach an adjacent building that houses a nursing home. Nursing home staff called the police, who arrived at the scene but had no jurisdiction to enter the embassy grounds, since the premises are technically North Korean soil. When police officers rang the embassy’s doorbell, an Asian-looking man appeared at the door and Q Quote 1said in English that all was fine inside the embassy. But a few minutes later, two luxury cars belonging to the North Korean embassy sped away from the building with the ten assailants inside, including the man who had earlier appeared at the front door.

Once they entered the embassy, Spanish police found eight men and women tied up, with bags over their heads. Several had been severely beaten and at least two had to be hospitalized. The victims told police that the assailants were all Korean, spoke Korean fluently, and had kept them hostage for nearly four hours. But they refused to file formal police complaints. The two diplomatic cars were later found abandoned at a nearby street. No money was taken by the assailants, nor did they seem interested in valuables of any kind. But they reportedly took with them an unknown number of computer hard drives and cell phones belonging to the embassy staff. They also stole an unknown quantity of diplomatic documents, according to reports.

POSSIBLE FOREIGN CULPRITS

Within a few hours, Spanish police had reportedly ruled out the possibility that the assailants were common thieves, arguing that the attack had been meticulously planned and executed. Also, common thieves would have looked for valuables and would not have stayed inside the embassy for four hours. Within a week, several Spanish newspapers, including the highly respected Madrid daily El País and the Barcelona-based El Periodico, pinned the raid on Western intelligence services. They cited unnamed police sources who claimed that at least two of the assailants had been identified and found to have links with the CIA. The reports also cited claims by embassy employees that the attackers interrogated them extensively about Soh Yun-sok, North Korea’s former ambassador to Madrid. Soh became Pyongyang’s chief nuclear negotiator after he was expelled by the Spanish government in 2017 in protest against North Korea’s nuclear missile tests. Read more of this post

Bosnia accuses Croatian spy services of arming Islamists

Dragan MekticAuthorities in Bosnia and Herzegovina have accused the government of Croatia of deliberately arming militant Islamists in order to damage Bosnia’s reputation and sabotage its campaign to join the European Union. The claims were aired by a Bosnian government minister on Thursday, a day after allegations of a weapons-smuggling plot by Croatia were made in the Bosnian media. On Wednesday, Zurnal, a Bosnian investigative website, alleged that the Croatian intelligence services had recruited a Bosnian national and used him to smuggle weapons and explosives into the majority Muslim country.

According to Zurnal, the Bosnian man was “intercepted” by Croatian intelligence while driving through Croatia on his way to Bosnia. He was traveling to Bosnia from an unnamed “European Union country”, where he allegedly lives. The Zurnal report alleges that officers of Croatia’s Security and Intelligence Agency (SOA) had evidence that the Bosnian man was a supporter of the Islamic State and threatened to notify the authorities in his country of residence. They then allegedly used this threat in order to pressure the Bosnian man to smuggle weapons and explosives into Bosnia and hide them in a mosque in Zenica, a city of about 100,000 residents in central Bosnia.

On Thursday, Bosnia and Herzegovina’s Minister of Security, Dragan Mektic (pictured), accused the SOA of plotting the weapons-smuggling operation in an attempt to damage Bosnia’s reputation. The goal of the operation, said Mektic, was to paint Bosnia as a center of Islamic State activity in Europe and sabotage the country’s efforts to join the European Union —of which Croatia is already a member. Also on Thursday, the office of Bosnia’s state prosecutor announced that an investigation had been launched into whether Croatian intelligence agencies had attempted to recruit other Bosnian citizens with known extremist views.

Since 2014, Croatian and Serbian security agencies have repeatedly warned that hundreds of Bosnian Muslims traveled to Syria and Iraq to join the Islamic State, and that many of them have since returned to the Balkans. But the Bosnian government argues that extremist Islam has no place in the country, whose predominantly Muslim population follows moderate versions of the religion. Late on Thursday, the Croatian government dismissed Mektic’s claims as “groundless” and said that they were aimed at harming relations between Bosnia and Croatia. No information has been released about the identity of the Bosnian arms smuggler, his current whereabouts or the fate of the alleged operation.

► Author: Joseph Fitsanakis | Date: 15 March 2019 | Permalink

Russians use front-company to access US federal employees’ contact info, says report

EFIS EstoniaRussian spy agencies use front companies to purchase directorates that contain the contact details of United States government employees, according to a new intelligence report. The contact details are contained in multi-page directories of Congressional staff members and employees of US federal agencies. They are published every January by a specialist vendor called Leadership Connect with the cooperation of a Washington, DC-based provider of publishing services. The directories contain the names, job titles, professional addresses and telephone numbers of US government employees.

But according to the Estonian Foreign Intelligence Service (EFIS), copies of the directorate are purchased every year by the Russian intelligence services, such as the Federal Security Service (FSB) and the Foreign Intelligence Service (SVR). The two Russian spy agencies allegedly use a front company in order to purchase copies of the directory. In reality, however, the purchases are made on behalf of Russian intelligence units, such as Military Unit 71330 of the FSB. This allegation is contained in the 2019 security environment assessment, which was published this week by the EFIS. Titled International Security and Estonia, the report is an overview of the main threats to Estonia’s internal security and a description of how these threats relate to international developments.

The directories, says EFIS, are not classified. On the contrary, they contain information that is publicly available in the US. However, the job descriptions and contact information of US federal employees are difficult to access in a collected format. The directories are therefore useful to Russian intelligence, which routinely tries to access large quantities of open-source information from foreign countries. Russian spy agencies are known to incorporate this open-source information into recruitment or surveillance plans that target specific individuals or foreign government agencies. They also use them to fill gaps in intelligence collection about specific agencies or parts of agencies, according to Robert Dannenberg, a former CIA officer who spoke to Yahoo News about the EFIS report.

► Author: Ian Allen | Date: 14 March 2019 | Permalink

US to shut down its embassy in Venezuela as national blackout enters 6th day

US embassy in Caracas VenezuelaThe United States said on Tuesday that it will evacuate its last few diplomats from its embassy in Caracas, as the electricity blackout in Venezuela enters its sixth day, making it the longest energy crisis in the nation’s history. Energy shortages are not new in Venezuela. The oil-rich Latin American country of 31 million people suffered two disastrous nationwide blackouts in 2009 and a third one in 2016. But the current blackout is quickly approaching the one-week mark and is believed to have caused a minimum of 20 deaths, mostly in hospitals around the country. The majority of the population currently lacks access to fuel and banking services, while there are disruptions in critical food and water supply lines. Several instances of mass looting have been reported across the nation since Monday.

The precise cause of the blackout remains unknown, though a number of experts point to a massive outage of the Simón Bolívar Hydroelectric Plant, located in northeastern Venezuela’s Necuima Canyon, as the root of the problem. Known also as the Guri dam, the facility generates more than four fifths of Venezuela’s electricity output, and may be responsible for the nationwide blackout. The continuing crisis has exacerbated the already adversarial relationship between Washington and Caracas, as the Venezuelan government blames the US and the local opposition leader Juan Guaidó for the blackout. The government said on Monday that it would investigate Guaidó in connection with rumors of sabotage of the Guri dam facility. The announcement prompted the White House to warn that “a lot of countries would react very quickly” if Guaidó was incarcerated. On Tuesday, Washington said that the remaining 20 members of staff of its embassy in the Venezuelan capital would be evacuated by Friday. Soon afterwards, the Venezuelan government said that it had ordered the American diplomats to leave the country, so that their presence there would not be used as a pretext by Washington to launch a military invasion of the country.

Meanwhile, the blackout continued as of Tuesday night, with experts warning that the aging infrastructure of Venezuela’s energy network, coupled with the lack of specialists on the ground, made it difficult to overcome the crisis. The US-based Wired magazine explained on Tuesday that restoring the integrity of the energy grid following a large-scale blackout —a process known as a “black start”— will depend on being able to identify the root of the problem. But the absence of spare equipment and up-to-date monitoring software and hardware means that the Venezuelan state operator lacks the ability to visualize the grid and “understand the state of the system in real time”. At the same time, supporters of the Venezuelan government accuse Washington of sabotaging its oil-export sector by refusing to buy Venezuelan oil and threatening to impose sanctions on foreign states that purchase oil from Venezuela. That, they say, has deprived the country of its main source of hard currency and is makes it exceedingly difficult for Caracas to sustain the nation’s energy and food-supply networks.

► Author: Joseph Fitsanakis | Date: 13 March 2019 | Permalink

US warns Germany it will end intelligence sharing if Huawei is given 5G contract

US embassy Berlin GermanyThe United States has warned Germany that intelligence sharing between the two countries will be threatened if the Chinese telecommunications giant Huawei is awarded a contract to build Germany’s 5G network. The company, Huawei Technologies, is a private Chinese venture and one of the world’s leading telecommunications hardware manufacturers. In recent years, however, it has come under scrutiny by some Western intelligence agencies, who view it as being too close to the Communist Party of China. More recently, Washington has intensified an international campaign to limit Huawei’s ability to build the infrastructure for 5G, the world’s next-generation wireless network. Along with Britain, Australia and Canada, the US is concerned that the Chinese telecommunications giant may facilitate global wiretapping on behalf of Beijing’s spy agencies.

But some American allies, including Spain, France and Germany, are not satisfied with Washington’s arguments and claim that the United States is eyeing the financial benefits that would arguably come from its domination of the global digital superhighway. German officials, in particular, have told their American counterparts that Berlin has not seen any evidence that Huawei’s telecommunications hardware come with hidden interception features. Moreover, Germany says that it plans to subject Huawei’s systems to rigorous security tests before using them. On Friday, Washington increased its pressure on Berlin by informing German officials that intelligence cooperation between the two allies would be severely impacted if Chinese telecommunications manufacturers are given the green light to build Germany’s 5G infrastructure.

According to The Wall Street Journal, the warning was included in a letter signed by Ambassador Richard Grenell, America’s top diplomat in Germany. It was allegedly sent to Peter Altmaier, Germany’s Minister of Economic Affairs and Energy. The paper says that Grenell suggests in his letter that Berlin should consider rival bids by companies belonging to American allies, such as the Swedish telecommunications equipment manufacturer Ericsson, Finland’s Nokia Corporation, or the South Korean Samsung Corporation, which is the world’s leading telecommunications hardware manufacturer. The Wall Street Journal did not reveal how it acquired Grenell’s letter, nor did it say whether the German government responded to it.

► Author: Ian Allen | Date: 12 March 2019 | Permalink

India, Pakistan used terrorist groups to attack each other, says Pakistan ex-president

Jaish-e-MohammedThe government of Pakistan employed terrorist groups to attack India, according to Pakistan’s former president, Pervez Musharraf, who also accused India of doing the same. Musharraf, 75, took power in Pakistan in 1999 through a coup d’état supported by the country’s military leadership. The four-star Army general ruled as Pakistan’s 10th president until 2008, when he resigned from power to avoid being impeached. He currently lives in exile in the United Arab Emirates and is wanted in Pakistan for alleged crimes, including high treason. His critics accuse him of arresting several judges in 2007 and suspending the country’s constitution.

On Tuesday, Musharraf spoke on the flagship news program of Hum News, a 24-hour news channel headquartered in the Pakistani capital Islamabad. Speaking in Urdu on a phone line from Dubai, Musharraf praised the current Pakistani government of President Imran Khan for launching a crackdown on Jaish-e-Mohammed (JeM) the militant group that is believed to be responsible for killing more than 40 Indian soldiers in Indian-administered Kashmir. The attack sparked a tense standoff between India and Pakistan, as the two countries engaged in aggressive military maneuvers against each other. “This constitutes a step forward”, said Musharraf, referring to the JeM crackdown. “It is a terrorist organization and they tried to assassinate me with a suicide attack”, he added, referring to an attack on his presidential convoy in 2003, which has been blamed on JeM.

In early 2002, Musharraf officially banned the JeM and arrested some of its leaders, after the group participated in two high-profile attacks in Indian Kashmir. But all JeM leaders were eventually freed, after the courts decided that the government had failed to provide sufficient evidence of their participation in terrorism. Musharraf told Hum News that he eventually lost interest in cracking down on JeM. When asked by the reporter why his government did not take further action against the group, Musharraf said that “those were different times”. Instead of stopping groups like JeM, both Pakistan and India used them to carry out a “clandestine struggle” against each other, said Musharraf. Groups like JeM “carried out bombings in each other’s territory”, said the former president, adding that Pakistan’s “intelligence agencies were involved in it”. Both India and Pakistan thus used militant groups, including JeM to carry out “tit-for-tat” operations targeting each other, he concluded. The former Pakistani leader went on to say that he was “very pleased to see the [Pakistani] government adopting a strict policy” against JeM.

► Author: Ian Allen | Date: 08 March 2019 | Permalink

Holland recalls Iran ambassador after Tehran expels Dutch diplomats

Holland embassy IranHolland said on Monday that it had recalled its ambassador from Tehran after Iran expelled two Dutch diplomats, in a deepening dispute involving the assassination of two Dutch citizens by alleged Iranian agents. In July of last year, Holland announced its decision to expel two Iranian diplomats from The Hague, but did not explain the reason for the expulsions. In January of this year, the Dutch Foreign Ministry confirmed that the diplomatic expulsions were in retaliation to the assassination of two Dutch nationals of Iranian background. One of the victims, Mohammad-Reza Kolahi, was shot dead in the head at point-blank range by two assailants in December 2015 in Almere, a coastal town 25 miles east of Amsterdam. Nearly two years later, in November 2017, another man, Ahmad Mola Nissi, was shot in the head in broad daylight in The Hague. Both men were members of Iranian militant anti-government groups that the Iranian state accuses of terrorism and crimes against the state.

On Monday, the Dutch Minister of Foreign Affairs Stef Blok informed the Dutch House of Representatives in The Hague that Tehran had informed his Ministry on February 20 that two Dutch diplomats would be expelled from Holland’s embassy in the Iranian capital. The two diplomats, who have not been named, were ordered to leave the country by Monday, March 4. Later on Monday, Bahram Ghasemi, spokesman for the Iranian Ministry of Foreign Affairs, confirmed that “two of the diplomats of the Netherlands embassy in Tehran were considered undesirable elements in the framework of a retaliatory measure and were asked to leave the country”. The Iranian move was not made public until last Monday. Blok wrote to the House of Representatives that, in response to Tehran’s move, the Dutch government had decided to recall its ambassador to Iran “for consultations” on how to proceed. Blok noted in his letter that Iran’s decision to expel the Dutch diplomats was “unacceptable and damaging to the bilateral relations between the two countries”.

Late on Monday, the Dutch government also summoned the Iranian ambassador in order to protest the expulsions of its diplomats from Tehran. It was also reported in the Dutch media that a series of financial sanctions imposed on Iran by Holland and its European Union partners in June —presumably over the alleged assassinations that took place on Dutch soil— would remain in place. The sanctions are against two individuals associated with Iranian military intelligence.

► Author: Joseph Fitsanakis | Date: 06 March 2019 | Permalink

North Korea-linked hackers growing in reach and sophistication, McAfee warns

Computer hackingA computer hacking group with links to the North Korean government has a wider reach and is more sophisticated than was initially believed, according to the computer security firm McAfee. The group, dubbed Lazarus by cybersecurity experts, is believed to be connected with Guardians of Peace, the hacker team that orchestrated the 2014 attacks on Sony Pictures Entertainment. The company drew the ire of the North Korean government for producing The Interview, a black comedy based on a fictional attempt by two Americans to assassinate North Korean leader Kim Jong-un. Known collectively as ‘the Sony Pictures hack’, the attacks included the compromise of internal documents and unreleased copies of films produced by Sony, as well as personal attacks on Sony executives and members of their families. There were also attempts to damage Sony’s digital infrastructure, which cost the company an undisclosed amount in damages, believed to be in the millions of dollars.

In February of last year, the computer security software company McAfee said that Lazarus was behind an ongoing campaign targeting global banks and bitcoin users. On Sunday, the California-based firm said that Lazarus was responsible for what its experts call Operation SHARPSHOOTER, a widespread effort to compromise key industries across several continents. Speaking at the RSA IT security conference in San Francisco, McAfee experts said that SHARPSHOOTER began as early as September of 2017, and that it was first detected in December of 2018. By that time, said McAfee, around 80 firms and organizations had been targeted by Lazarus. But in recent months, it has become clear that SHARPSHOOTER is “more extensive in complexity, scope and duration” than previously thought, according to McAfee experts. They added that they drew this conclusion based on “command-and-control serve code” data that was made available to them by an unnamed “government entity”. This is the type of forensic data that is customarily seized by government agencies and is rarely made available to cybersecurity researchers in the private sector, said the McAfee representatives. This “non-typical access” afforded McAfee technical experts “a rare opportunity” to examine “the inner workings [of Lazarus’] cyberattack infrastructure”, they added.

As a result, the company’s “confidence levels are now much higher” that Lazarus is targeting key agencies and industries, including government organizations involved with national defense, energy and critical infrastructure. Most of Lazarus’ targets are in the United States, Germany and Turkey. But smaller attacks have been detected in Asia and Africa, in countries such as the Philippines and Namibia. Many attacks begin with so-called ‘spearphishing’ attempts, which target particular employees of agencies or firms. These attacks center on emails that are “masked as extremely convincing job recruitments”. The emails contain links to Microsoft Word or Adobe PDF files on popular file-sharing platforms like DropBox, which are infected with malware, said McAfee.

► Author: Joseph Fitsanakis | Date: 05 March 2019 | Permalink

Dutch counterterrorism report sees rise in Islamist recruitment in the West

NCTV HollandHolland’s chief counterterrorism agency has warned that, despite losing its territories in the Middle East, the Islamic State continues to recruit operatives and is ready to launch attacks in the West “at a moment’s notice”. The warning is contained in a report published last week by the Dutch National Coordinator of Counterterrorism and Security (NCTV). Established in 2005 as the Dutch National Coordinator for Counterterrorism, and renamed in 2012, the NCTV works under Holland’s Justice and Security Minister. It is responsible for analyzing terrorism threats and assessing the country’s domestic terrorism threat level.

In its most recent report (.pdf), entitled Terrorist Threat Assessment Netherlands, the NCTV warns that it is not only the Islamic State (known also as Islamic State of Iraq and Syria, or ISIS) that remains highly active, but also al-Qaeda. The two groups are riding a wave of Salafist Muslim extremism that appears to be on the rise throughout Europe, says the report. ISIS, in particular, continues to engage in extensive recruitment drives in the West, which take place mostly through the dissemination of propaganda material online. There is also a proliferation of an underground recruitment movement in conservative Muslim schools and mosques across the West, says the report (.pdf).

But the most serious short-term threat to European and North American security, according to the NCTV document, comes from so-called returnees, citizens of European countries who joined the Islamic State in Syria and Iraq and are now returning —or trying to return— to their home states in the West. The majority of these men and women remain faithful to the idea of the caliphate despite the failure of their efforts in the Middle East. There is a risk that, upon their return to the West, they will connect with existing —and growing— Salafist underground networks there, and remain active in radical circles. The report also notes that both ISIS and al-Qaeda are showing increasing interest in developing chemical and biological weapons for use against civilian and military targets.

► Author: Joseph Fitsanakis | Date: 04 March 2019 | Permalink

Sweden confirms arrest of second person on spying charges

Säpo swedenThe Swedish public prosecutor’s office has confirmed media reports that a second espionage-related arrest took place in Stockholm this week. The latest arrest came just 24 hours after a man was arrested in the Swedish capital on Tuesday, allegedly for spying on behalf of Russia. As intelNews reported yesterday, a man was apprehended on Tuesday while meeting with a foreign diplomat in central Stockholm. The diplomat is allegedly a member of staff at the Russian embassy in Sweden. He is believed to be a Russian intelligence officer operating under official cover. A representative of the Swedish Security Service, known as SÄPO, later said that the man who was meeting with the Russian diplomat had been recruited by Russian intelligence in 2017 or earlier, and had been in regular contact with his Russian handlers. His name has not been revealed to the media, but he is believed to be working for an unnamed technology company in Sweden.

On Thursday, the Stockholm-based newspaper Dagens Nyheter said that it had seen court papers involving the arrest of a second individual on Wednesday, reportedly in connection with espionage for a foreign power. The paper said that the arrest took place in the Swedish capital and the individual in question remained in detention. It added that Hans-Jorgen Hanstrom, of the public prosecutor’s office, had confirmed the arrest and that the main suspect had been charged with spying against Swedish interests for a foreign power. Hanstrom added that the suspect had been found to engage in espionage from April 10 until September 30, 2018. But he did not disclose the person’s name or nationality. SÄPO spokesman Karl Melin also confirmed the espionage-related arrest, but did not comment on whether it was related to Tuesday’s arrest.

Earlier in the week, officials from SÄPO’s counterespionage directorate said that Tuesday’s arrest was the result of a lengthy operation that took “a substantial period of time” and involved “intensive intelligence and investigation work”. The alleged spy was scheduled to be placed in pre-trial detention on Thursday, but his hearing was postponed for Friday. The Russian embassy in Stockholm has not commented on the reports.

► Author: Joseph Fitsanakis | Date: 01 March 2019 | Permalink

Sweden arrests man for spying for Russia; diplomatic expulsions expected soon

Russian Embassy SwedenAuthorities in Sweden have announced the arrest of a man who is accused of spying for Russia. The man was reportedly apprehended while meeting with a Russian diplomat in central Stockholm. The alleged spy, who has not been identified in media reports, is believed to be working for an unnamed technology company in Sweden. A report by Swedish police said that the man is working “in a field that is known to be of interest to the intelligence services of foreign powers”.

The unnamed man is suspected of having been recruited by intelligence officers of Russia in 2017 or earlier. He is believed to have met with his Russian handlers on a regular basis since his recruitment, and to have passed classified information to the Russian government. He was reportedly arrested on Tuesday evening as he was meeting his alleged Russian handler in a downtown area of the Swedish capital. Both he and his alleged handler were detained by officers of the Swedish Security Service, known as SÄPO. The alleged handler was a member of staff of the Russian embassy in Stockholm and has diplomatic immunity. SÄPO said that the Russian embassy officer is believed to be a Russian intelligence officer who works under diplomatic cover. Swedish media said on Tuesday that the diplomat’s expulsion from the country was imminent.

However, SÄPO declined to provide information on the identity of the alleged spy, who is not believed to have diplomatic immunity and is therefore liable to prosecution. Daniel Stenling, head of SÄPO’s counterespionage directorate, said that Tuesday’s arrest was the result of a prolonged probe that took “a substantial period of time” and involved “intensive intelligence and investigation work”. SÄPO spokesman Gabriel Wernstedt said on Wednesday that the agency did not believe that the alleged spy is a member of a ring involving other suspects. He warned, however, that espionage threats against Sweden “are now more far reaching than [they have] been for many years”.

The alleged spy is scheduled to be placed in pre-trial detention on Thursday or Friday at the latest. British newspaper The Daily Telegraph, which reported Tuesday’s arrest, said it reached out to the Russian embassy in Stockholm but received no response.

► Author: Joseph Fitsanakis | Date: 28 February 2019 | Permalink