Sophisticated spy malware found on Russian government computers
August 1, 2016 1 Comment
According to the predominant media narrative, the United States is constantly defending itself against cyber-attacks from countries like China and Russia. But, as intelNews has argued for years, this narrative is misleading. Recent intelligence disclosures clearly show that the US cyber-security posture is as offensive as that of its major adversaries. Additionally, China and Russia have to defend their computer networks as much as America does. Last weekend’s report from Moscow helps restore some of the balance that is missing from media reporting on cyber-security. According to the Russian Federal Security Service (FSB), a meticulously coded and sophisticated virus has been found on the computer networks of at least 20 major Russian agencies and organizations. The targets appear to have been carefully selected by the malware’s authors. They include government bodies, weapons laboratories and defense contractors located throughout Russia.
The FSB said that once installed, the virus gave its handler control of the infected computer system. It permitted an outside hacker to turn on a computer’s microphone or camera, and capture screenshots. It also stealthily installed keylogging software, thus allowing an outside party to monitor keyboard strokes on an infected system. Based on its functions, the malicious software seems to be designed to conduct deep surveillance on infected computers and their physical surroundings. The FSB would not attribute the malware to a specific hacking group or nation. But it said it believed that the malware attack was “coordinated”, “planned and planned professionally”. It also said that the coding of the virus “required considerable expertise”. In a brief statement released Saturday, the FSB said that aspects of the coding of the virus, as well as other identifying information, resembled those detected in preceding hacking attacks on computer servers in Russia and other countries. The statement did not elaborate, however.
The news about hacked Russian computers comes less than two weeks after it was claimed that Russian government-backed hackers stole electronic data belonging to the Democratic National Convention (DNC) in the United States. The Democratic Party’s presidential candidate, Hillary Clinton, publicly accused the Russian government of orchestrating the hacking of the DNC computer systems in an attempt to damage her campaign.
► Author: Ian Allen | Date: 01 August 2016 | Permalink
Unprecedented quantities of weapons and ammunition worth in nearly $1.5 billion have been procured from Eastern Europe and sent to Syria to arm nearly every side in the ongoing civil war, a study has found. The weapons are transported through the Balkans and sold legally to countries bordering Syria, including Jordan, Saudi Arabia and Turkey. Once there, they are secretly transported to Syria for use in the bloody five-year civil war, which has so far killed or displaced millions. The
American officials have strongly denied accusations in the Turkish press that Washington was behind the failed July 15 coup in Turkey. On July 25, Yeni Şafak, a popular Turkish daily, alleged that the failed coup had been funded and organized by the United States government. The newspaper, which is headquartered in Istanbul, is known for its conservative political stance and close links to the AKP, the party of Turkish President Recep Tayyip Erdoğan. Its editorials typically reflect the AKP’s position on the political affairs of the day.
Police in Ireland say they have arrested two individuals in connection with the 2006 killing of a senior member of the Irish Republican Army, who had previously been outed as a spy for the British state. Denis Donaldson joined the Provisional IRA as a volunteer in mid-1960s, before the outbreak of the Troubles, which rocked Northern Ireland from the late 1960s until 1998. He was trained in paramilitary operations in Lebanon and participated in many IRA actions. He served time at the Long Kesh Detention Centre along with IRA volunteer and Member of Parliament Bobby Sands, who died in the famed 1981 Irish hunger strike. After Sands’ death, Donaldson stood as a general election candidate in Belfast East for Sinn Féin, the IRA’s political wing. In the process, he became a close associate of Sinn Féin President Gerry Adams. In 2000, shortly after the end of the IRA’s 30-year military campaign, Sinn Féin appointed Donaldson as the administrator of its parliamentary group in Stormont, the devolved Northern Irish parliament.
For the first time in history, India has refused to extend temporary residency visas for three senior Chinese media correspondents, effectively expelling them from the country, allegedly for espionage activities. All three reporters are employees of China’s state-run Xinhua news agency. They include Xinhua’s bureau chief in the Indian capital, New Delhi, Wu Xiang, and the agency’s Mumbai bureau chief, Lu Tang. A third journalist, She Yonggang, also based in Mumbai, has been asked to leave India by no later than July 31.
Russian and Turkish authorities will not confirm or deny reports that the Kremlin warned Turkey’s intelligence services about an impending coup on July 15, several hours before tanks appeared on the streets of major Turkish cities. On Wednesday, several
The death of three French Special Forces soldiers in Libya has prompted the first public acknowledgement by France that its troops are involved in “dangerous intelligence operations” in the North African country. The acknowledgement was made on Wednesday in an official statement issued by Jean-Yves Le Drian, France’s Minister of Defense. In the statement, Le Drian said he “regretted the loss of three French officers who expired while on mission in Libya”. The
In a development that is reminiscent of the Cold War, a radio station in North Korea appears to have resumed broadcasts of encrypted messages that are typically used to give instructions to spies stationed abroad. The station in question is the Voice of Korea, known in past years as Radio Pyongyang. It is operated by the North Korean government and airs daily programming consisting of music, current affairs and instructional propaganda in various languages, including Arabic, Chinese, Spanish, French, English, and Russian. Last week however, the station interrupted its normal programming to air a series of numbers that were clearly intended to be decoded by a few select listeners abroad.
After the failure of the recent military coup d’état in Turkey, much attention has been given to the country’s armed forces, the police, even the judiciary. In contrast, little to no information has surfaced about Turkey’s intelligence establishment, which is led by MİT, the National Intelligence Organization. Did it anticipate the plot, and how did it fare as the crisis unfolded in the early hours of July 16?
The head of Italian intelligence paid a secret visit to Syria earlier this month, a week after his Syrian counterpart visited Rome, according to reports from the Middle East. The Dubai-based newspaper Gulf News, which first reported the alleged behind-the-scenes exchange, said the visits focused on counter-terrorism cooperation between Syria and the European Union. The paper said that the initial contact was made in late June by Major General Deeb Zeitoun, head of Syria’s General Intelligence Directorate, who paid a secret visit to Rome. General Zeitoun’s visit was allegedly in response to an official invitation issued by the Italian government. The general is believed to have stayed in a secluded private villa, which was provided by the Italian External Intelligence and Security Agency, known as AISE. He subsequently met with several Italian intelligence officials, including AISE Director, General Alberto Manenti.
Recent satellite images reveal that the headquarters of the Russian Federation’s external intelligence agency has doubled, and possibly tripled, in size in the past nine years. The Russian Foreign Intelligence Service, known as SVR, is one of the successor agencies of the Soviet-era KGB. During the Soviet times, the present-day SVR was known as the First Chief Directorate or First Main Directorate of the KGB. Despite its name change, however, its mission remains the same, namely to collect secrets from targets outside the Russian Federation —often through the use of espionage— and to disseminate intelligence to the president. In the Soviet days, along with most of the KGB, the First Chief Directorate was headquartered in the imposing Lubyanka building, which is located in Moscow’s Meshchansky District. But in the early 1970s, the entire First Chief Directorate began a decade-long process of moving to a new, state-of-the-art complex in the southern suburbs of the Russian capital. The complex, which is located in Yasenevo, today houses the entire apparatus of the SVR, including its espionage wing, and is informally known as les (the forest) or kontora (the office).
American Scientists’ Secrecy News blog, has
An ambitious new personnel exchange program between intelligence agencies in Australia and Indonesia aims to combat the unprecedented rise of militant Islamism in Southeast Asia, which is fueled by the Islamic State. The program, which is already underway, aims to strengthen intelligence cooperation between two traditionally adversarial regional powers.
A major parliamentary inquiry into the operations of Germany’s main intelligence agency has concluded that it spied on nearly 3,500 foreign targets in recent years, most of which belonged to allied countries. The inquiry was initiated by the German government in response to a number of recent public controversies involving the Bundesnachrichtendienst, Germany’s Federal Intelligence Service, known as BND.






Fake URL shortening service was part of British online spy operation
August 2, 2016 by Joseph Fitsanakis 2 Comments
According to the leaked documents, the website, lurl.me, was devised by a specialist until of the Government Communications Headquarters (GCHQ), Britain’s intelligence agency that collects signals intelligence. The unit, called Joint Threat Research Intelligence Group (JTRIG), devised the website as part of an operation codenamed DEADPOOL. The leaked documents state that the purpose of the website was to operate as a “shaping and honeypot” tool, by helping disseminate messages in support of the protests while at the same time allowing the GCHQ to monitor the protesters’ online activities. Lurl.me first appeared in June 2009 as a self-described “free URL shortening service”, using the slogan: “we help you get links to your friends and family fast”. It was used repeatedly on Twitter and other social media platforms to spread messages against the government of Iran. But the vast majority of social media accounts that made use of the website, like @2009iranfree, were operational only for a short period of time, had few followers, and ceased all activity at the end of the Iranian Green Movement. By that time, hardly anyone was using lurl.me. But the website made its appearance again on social media in April of 2011, with messages against the government of Syria. According to Vice’s Motherboard website, Tweets using the lurl.me service appeared to be active only between 9 a.m. and 5 p.m. UK time, and only on weekdays.
Both in 2009 and 2011-2013, lurl.me was used to instruct anti-government activists on how to avoid being monitored by the authorities. Some links contained instructions on how to access the Internet via satellite. Others provided directions on using proxies to access websites that were blocked by the authorities. At the same time, however, the documents leaked by Snowden show that the GCHQ also used the service to track the activities of anti-government activists who clicked on the lurl.me links, and even to ‘deanonymize’ (=to establish the real identity) of these users.
IntelNews first reported on JTRIG in February 2014, when its existence was first revealed by Snowden. The specialist unit has been associated with targeting self-described ‘hacktivist’ groups like Anonymous or LulzSec, using malware, social engineering, and other techniques. JTRIG also appears to have conducted online intelligence operations against the government of Argentina.
Motherboard reports that lurl.me was last used in November 2013, shortly after Snowden began leaking files from his secret hiding place in Russia. Motherboard said it contacted GCHQ for a reaction to the lurl.me allegations, but the agency said it would “not comment on intelligence matters”.
► Author: Joseph Fitsanakis | Date: 02 August 2016 | Permalink
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with 2009 Iranian presidential election protests, Arab Spring, GCHQ, GCHQ Joint Threat Research Intelligence Group, Iran, News, operation DEADPOOL, Twitter, UK