Sophisticated cyberespionage operation focused on high-profile targets

Rocra malware programming codeBy JOSEPH FITSANAKIS | intelNews.org |
After Stuxnet and Flame, two computer programs believed to have made cyberespionage history, another super-sophisticated malware has been uncovered, this time targeting classified computer systems of diplomatic missions, energy and nuclear groups. The existence of the malware was publicly announced by Russian-based multi-national computer security firm Kaspersky Lab, which said its researchers had identified it as part of a cyberespionage operation called Rocra, short for Red October in Russian. The company’s report, published on Monday on Securelist, a computer security portal run by Kaspersky Lab, said that the malware has been active for at least six years. During that time, it spread slowly but steadily through infected emails sent to carefully targeted and vetted computer users. The purpose of the virus, which Kaspersky Lab said rivals Flame in complexity, is to extract “geopolitical data which can be used by nation states”. Most of the nearly 300 computers that have so far been found to have been infected belong to government installations, diplomatic missions, research organizations, trade groups, as well as nuclear, energy and aerospace agencies and companies. Interestingly, the majority of these targets appear to be located in Eastern Europe and former Soviet republics in Central Asia. On infected computers located in North America and Western Europe, the Rocra virus specifically targeted Acid Cryptofiler, an encryption program originally developed by the French military, which enjoys widespread use by European Union institutions, as well by executive organs belonging to the North Atlantic Treaty Organization. Read more of this post

Closed-door trial of Soviet/Russian sleeper agents starts in Germany

The Anschlags' house in MeckenheimBy JOSEPH FITSANAKIS | intelNews.org |
A married couple accused of spying on Germany on behalf of the Soviet Union and Russia for over two decades has gone on trial in Stuttgart. Andreas Anschlag, 54, and his wife, Heidrun, 48, were arrested in October 2011 by GSG-9, the elite counter-terrorism and special operations unit of the German Federal Police. They were later charged with having spied since at least 1990 for the Soviet KGB’s First Chief Directorate and its post-Soviet successor organization, the SVR. German federal prosecutors also accuse the couple of document forgery, since their Austrian passports, which they used to enter West Germany from Mexico in 1988 (Andreas) and 1990 (Heidrun) are believed to be counterfeit. There is also speculation that the couple’s surname may in fact be an alias given to them by their intelligence handlers. Upon entering West Germany in 1988 and 1990, the Anschlags initially settled in Aachen, on the German-Belgian border, before moving to Meckenheim, a small town with a population of less than 30,000 located a few miles southwest of Bonn. They concentrated on blending into German society, while raising their son daughter and leading what their neighbors describe as a “discreet life”. Over the years, they managed to recruit a number of informants, including a Dutch diplomat identified by authorities in Holland only as ‘Raymond P’. The diplomat, who was arrested last June, is believed to have given the Anschlags nearly 500 classified documents originating from the German armed forces, the North Atlantic Treaty Organization and the European Union. Read more of this post

US providing intelligence support to French forces in Mali

Mali and the Independent State of AzawadBy IAN ALLEN | intelNews.org |
The United States is providing intelligence support to hundreds of French troops that entered the West African nation of Mali last week, according to American and French officials. On January 11, at least 400 French soldiers entered Mali from French military bases in neighboring Burkina Faso and Chad, in what the French Ministry of National Defense has codenamed Opération SERVAL. The French intervention was sparked by the conflict in northern Mali, which erupted in 2012. In January of that year, Tuareg tribesmen formerly employed by the late Libyan leader Muammar al-Gaddafi teamed up with a host of local Islamist groups, including the Movement for Oneness and Jihad in West Africa (MUJWA) and Ansar Dine (Defenders of the Faith). Guided by members of the al-Qaeda Organization in the Islamic Maghreb (AQIM), these groups rapidly seized Mali’s massive northern region (which they call ‘the Independent State of Azawad’), where they are said to have imposed a strict version of Islamic sharia law. Last week’s intervention by the French military came to many as a surprise, though not to intelNews leaders, who have known for a while that Paris had been lobbying Western officials to help it launch a military intervention in the West African country. It now appears that Western countries are indeed helping France’s military operations in Mali. Outgoing US Defense Secretary Leon Panetta told reporters on Monday that the Pentagon is gathering intelligence for the benefit of French forces. The US, said Panetta, has “a responsibility to go after al-Qaida wherever they are” and ensure that its members do not “establish a base of operations” in West Africa. He added that Washington is considering widening its support to Paris by providing “logistics, surveillance and airlift capability”. Read more of this post

Iran secretly sold ‘untold quantities’ of ammo to African warring groups

Two of the 'mystery cartridges'By JOSEPH FITSANAKIS | intelNews.org |
An independent report has concluded that some of Africa’s most brutal conflicts are currently being fuelled by “untold quantities” of Iranian-manufactured small-arms ammunition. The ire of weapons-trafficking researchers is usually directed at the ‘heavyweights’ of the global arms-trade, including Russia, China, the United States, and France, among other countries. It appears, however, that Iran’s state-owned weapons manufacturer has been selling ammunition throughout Africa since at least 2006 via a secret network of distributors. According to The New York Times, a group of arms-trafficking experts from the United Nations, Amnesty International, the Federation of American Scientists, and other bodies, has found that Iran began selling ammunition to African clients in 2006 or earlier. On that year, a new brand of ammunition rounds for Kalashnikov assault rifles started appearing in armed clashes in Kenya, Uganda, and Darfur (now South Sudan). By 2010, the same type of cartridges had been found in Guinea, Ivory Coast and the Democratic Republic of Congo. More recently, says The Times, similar cartridges were discovered in the hands of groups in Niger connected with Al-Qaeda in the Islamic Maghreb. Suspiciously, the cartridges bore no factory code and their packaging had been deliberately constructed to obscure the identity of the manufacturer. However, according to the expert study, it is now considered “beyond dispute” that the Ammunition and Metallurgy Industries Group, a subsidiary of Iran’s state-owned and operated Defense Industries Organization, is the source of the mysterious cartridges. It is worth pointing out that many of the governments or militias that have been found to use Iranian ammunition are officially subject to UN resolutions that bar arms transfers to the countries or territories in which they operate. Read more of this post

Turkey peace talks halted as Kurdish activists are assassinated in Paris

Sakine Cansiz with Abdullah Öcalan in 1995By JOSEPH FITSANAKIS | intelNews.org |
The future of peace talks between the Turkish government and the country’s Kurdish minority appeared uncertain yesterday, after three female Kurdish activists were found murdered execution-style in downtown Paris, France. The murders marked the first-ever killings in Europe of senior members of the Kurdistan Workers’ Party (PKK), which operates as the primary political and paramilitary agent of Turkey’s Kurdish population. According to reports from France, a gun fitted with a silencer was used to kill two of the women in the back of the neck and the third one in the stomach.

One of the dead, Leyla Sönmez, was a Kurdish activist responsible for Kurdish diplomatic relations in France. Another, Fidan Doğan, who was also a French citizen, was the Paris representative of the Kurdistan National Congress (KNK), which operates as Kurdistan’s government-in-exile based in Brussels, Belgium. But the most prominent victim of the triple murder is Sakine Cansiz, co-founder of the PKK, who is described as a “legend” among party activists. Cansiz who was present at PKK’s founding in 1978, was imprisoned by the Turkish government in the 1980s and given political asylum in France in 1998. Read more of this post

Iran official in secret visit to Egypt to discuss ‘new spy agency’

Qassem SuleimaniBy JOSEPH FITSANAKIS | intelNews.org |
A senior Iranian intelligence official paid a secret visit to Egypt earlier this month, allegedly to discuss the establishment of a new intelligence service controlled by the Muslim Brotherhood. Several Egyptian newspapers, including the quality broadsheet Al-Masry Al-Youm, said that the Iranian official was Qassem Suleimani, commander of Quds Force, a unit inside the Islamic Revolutionary Guard Corps, which is specifically tasked with exporting the Iranian Revolution abroad. The Quds Force has traditionally constituted the primary channel of communication between the government of Iran and a host of international groups allied to it, including Hezbollah in Lebanon and Hamas in Palestine. Suleimani is said to have traveled incognito to Cairo at the personal invitation of Egyptian President Mohammed Mursi, who is also a leading member of the Muslim Brotherhood. The group, which was legalized in Egypt after the 2011 revolution, is the Egyptian branch of a Pan-Islamic political and social movement that assumed control of the government after the ousting two years ago of Egyptian longtime dictator Hosni Mubarak. According to reports from Egypt, Suleimani met with “senior officials” in the Egyptian capital, including President Mursi’s chief adviser on foreign affairs, Issam al-Haddad, as well as prominent members of the Muslim Brotherhood. Al-Masry Al-Youm said the Iranian commander discussed plans to develop a new civilian intelligence service in post-Mubarak Egypt, which will be answerable to the government of the country. The apparent plan of the Muslim Brotherhood is to create a brand new spy service that will operate outside the control of Egypt’s military, which currently commands the bulk of the country’s intelligence community. Read more of this post

How did the US know that Syria was about to use chemical weapons?

Regional map of SyriaBy IAN ALLEN | intelNews.org |
Early last December, United States President Barack Obama issued a surprise warning to the government of Syria, saying that if it made “the tragic mistake” of using chemical weapons against rebel forces, there would be “immediate consequences”. Most observers took this as a clear indication that the US was prepared to intervene militarily in the ongoing Syrian civil war. Today, a month after Obama’s December ultimatum, one question is still in need of an official answer: namely, how did the United States come to suspect that the Syrians were contemplating using chemical weapons? An article by The New York Times‘ Eric Schmitt and Dave Sanger suggests that Washington was alarmed in late November by a tip-off from Israeli intelligence. According to The Times, the Israelis shared with officials at the US Department of Defense a series of satellite images showing Syrian government troops transporting tank-loads of chemicals to at least two storage sites along the country’s border with Jordan. The paper, which says it confirmed this information by speaking to “half a dozen military, intelligence and diplomatic officials”, claims that Syrian troops were ordered to load sarin nerve gas onto dozens of 500-pound bombs. The plan was for the bombs to be secretly transported by land to military air bases and from there onto planes, pending final approval by Syrian President Bashar al-Assad. According to the Israelis, the bombs could be airborne less than two hours after Assad’s order. By the time the information from the Israelis reached President Obama, American military commanders realized they had been caught by surprise, as there was no time to act in the two hours that it would take the Syrians to deploy the bombs. Read more of this post

Obama’s National Security Nominations: Nothing to See Here

Chuck Hagel, Barack Obama, John BrennanBy I. ALLEN and J. FITSANAKIS | intelNews.org |
The deluge of reports that are flooding the news media about the national security nominations of United States President Barack Obama is both natural and understandable. The Departments of State and Defense, as well as the Central Intelligence Agency, are among the critical components of the American government, especially in matters of foreign policy. Yet much of the commentary on the nominations of John Kerry for State, Chuck Hagel for the Pentagon, and John Brennan for the CIA, is unduly over-dramatizing what is essentially a routine story. To begin with, it is clear that, in selecting Kerry, Hagel and Brennan for the nominations, the President’s priority was to surround himself with people he knows and trusts. Knowledgeable observers point out that all three nominees come from Obama’s most trusted circle of friends and —if appointed— will allow the President to stay well “within his comfort zone” as he begins his second term in office. In this sense, Obama selected the three candidates, not with some major policy shift in mind, but in order to ensure continuity and permanence in his foreign policy.

Take John Brennan, for instance: an Arabic-speaking career officer in the CIA, who has served the Agency in various positions for over 25 years. It is undeniable that, since 2008, Brennan has been instrumental in shaping the thinking behind the Obama administration’s targeted killings program using unmanned drones. According to some analysts, he has been the White House’s “most important adviser for shaping the campaign of drone strikes”. As intelNews explained recently, Washington’s unmanned drone program will continue and most likely expand, but this has little to do with Brennan. As an excellent analysis of Brennan’s nomination (by the Council on Foreign Relations’ Micah Zenko) points out, the CIA’s targeted killing program “has become institutionalized” with a momentum of its own, which ensures its sustainability, “making it far bigger than any one person —even John Brennan”.

Read more of this post

Analysis: Will 2013 Be the Year of the Unmanned Drone?

Predator droneBy JOSEPH FITSANAKIS | intelNews.org |
As United States President Barack Obama prepares to enter his fifth year in office, one may be excused for thinking that his administration’s response to insurgency warfare essentially boils down to one thing: the joystick. This is the means by which Washington’s unmanned aerial vehicle (UAV) fleet is remotely guided, usually from the safety of ground control stations located thousands of miles away from selected targets. Even prior to last November’s Presidential election, Obama administration officials declared in every possible way that the drone campaign would remain a permanent feature of the White House’s counterinsurgency campaign. Not only that, but it seems increasingly apparent that when, on November 19, 2012, Defense Secretary Leon Panetta announced that America’s UAV fleet would expand, he meant it both in terms of raw numbers and geographical reach. Africa appears now to be high on the list of UAV targets. The US is currently busy establishing a large network of small air bases located in strategic locations throughout the continent, in what US observers have termed a “massive expansion” of US covert operations in Africa. Read more of this post

Revealed: German neo-Nazi who helped Palestinians was CIA agent

Willi Pohl, a.k.a. Willi VossBy JOSEPH FITSANAKIS | intelNews.org |
A German far-right militant, whose animosity against Jews led him to aid Palestinians kill Israeli athletes in the 1972 Munich massacre, says he was later recruited by the United States Central Intelligence Agency. Willi Pohl, also known as Willi Voss, 68, was arrested by German authorities a few weeks after Palestinian terrorist group Black September stormed the Olympic village in Munich and took hostage 11 Israeli athletes. All of them were eventually killed by their captors during a botched escape attempt at the nearby Fürstenfeldbruck airport. Voss, who was a known neo-Nazi activist at the time, was charged with possession of weapons and providing logistical support to the Black September militants. However, after his sentence was suspended, Voss managed to secretly emigrate to Beirut, Lebanon, where he was recruited as an agent of Jihaz el-Razd, the intelligence service of the Fatah, the main group in the Palestine Liberation Organization. But in 1975, while on a PLO mission in Belgrade, Yugoslavia, he decided to switch sides. He made the decision after discovering that the car he and his girlfriend were transporting on behalf of the PLO from Beirut to Belgrade contained weapons and highly unstable explosives. He says that the PLO had apparently failed to mention the existence of the hidden items when they asked him to transport the car to Europe. According to Voss’ new book, which has just been published in Germany under the title UnterGrund (Underground), the guns and explosives were discovered by customs officers in Romania (then Rumania); but because at that time the communist country was an ally of the PLO, Voss and his girlfriend were allowed to travel to Belgrade, minus the car and the weapons. Read more of this post

Year in Review: The 10 Biggest Spy-Related Stories of 2012

Happy New YearBy J. FITSANAKIS and I. ALLEN | intelNews.org |
Ever since we launched this website in 2008, we have been monitoring daily developments in the highly secretive world of intelligence and espionage, striving to provide an expert viewpoint removed from sensationalism and conspiratorial undertones. In the past year, we witnessed our fair share of significant intelligence-related stories, some of which made mainstream headlines, while others failed inexplicably to attract the attention of the news media industry. In anticipation of what 2013 may bring, we decided to take a look back to the year that just ended by compiling a list of what we think are the ten most important security- and intelligence-related developments of the past 12 months. The stories below are listed in reverse order of importance. Do you agree with our choices? Have we missed something important? Share your thoughts.

10. South African spy officials faked threats to increase budget. The historical tendency of spy agencies to overstate security threats in order to secure governmental funds is hardly novel. But officials in the South African Secret Service appear to have gone a step further: they allegedly paid some of their informants to make bogus threats against the government, in order to prompt an increase in counterterrorist funding. The bogus threats were allegedly aimed at creating “a false impression of imminent, unprecedented attacks on black people and African National Congress (ANC) members”. Incredibly, or perhaps predictably, nobody from the Secret Service has been fired in connection with this scandal.

Read more of this post

News you may have missed #821 (civil liberties edition)

Bernard SquarciniBy IAN ALLEN | intelNews.org |
►►French domestic spy chief cleared of snooping charges. Back in October of 2011, intelNews reported that Bernard Squarcini, who then headed France’s domestic intelligence agency, the DCRI, had been charged with spying on a journalist with the daily Le Monde. The accusation was part of a wider case of domestic snooping, in which Squarcini was believed to have been trying to detect the source of government leaks to the press, allegedly on orders by then-President Nicolas Sarkozy. Earlier this month, however, an appeals court in Paris rejected two of three charges against the former DCRI chief. Squarcini could face up to five years in prison if convicted of the remaining charge.
►►FBI documents termed Occupy movement as ‘terrorism’. A number of heavily redacted US government documents, released following a Freedom of Information Act request, reveal that the FBI organized a nationwide law enforcement investigation and monitoring of the Occupy Wall Street movement beginning in August of 2011. In some documents, the FBI refers to the Occupy Wall Street protests as a “criminal activity” and “domestic terrorism”.
►►Wiretapping by Russian spy agencies doubled in five years. Wiretapping by Russia’s intelligence agencies has nearly doubled over the past five years, according to The Moscow Times. In Western countries, intelligence agencies were given wider powers after the 9/11 terrorist attacks. But in Russia, the exponential growth of wiretapping began after 2007, when terrorism by Islamic-inspired separatists was already on the decline. A federal law passed in 2010 expanded the legal grounds for wiretapping Russian citizens. Now, intelligence officers can wiretap someone’s phones or monitor their Internet activity simply because they allegedly received reports that an individual is preparing to commit a crime.

News you may have missed #820

H. Keith MeltonBy IAN ALLEN | intelNews.org |
►►World’s best known spy collector displays his home. And now for something completely different. Most intelNews readers will be aware of H. Keith Melton, the author of more than 25 nonfiction works on espionage (including The Ultimate Spy Book) and the world’s largest private collector of spy memorabilia. The question is, where does he keep all this stuff? The 68-year-old author invited Forbes magazine to his Boca Raton house, which includes his two-story private spy museum. The article is here, a photo gallery here, and a video of the house (but not the museum) is here.
►►Acting CIA director criticizes ‘Zero Dark Thirty’. IntelNews has ignored the commentary that has flooded the Web about Zero Dark Thirty, the feature film fictional account of the assassination of al-Qaeda founder Osama bin Laden. But when the Director of CIA, the agency behind the real-life operation to kill bin Laden, publicly comments, it is time to pay attention. Michael J. Morell, who took over as CIA Director from General David Petraeus last month, has criticized the film, saying it exaggerates the role of coercive interrogations in producing clues to bin Laden’s whereabouts.
►►British police says MI6 expert ‘killed himself’. British police say MI6 cryptology expert Gareth Williams, who was found dead inside a sports bag in August 2010, probably locked himself into the sports bag, where his naked body was found, and was not the victim of a hit by the security services. Williams, 31, worked for Britain’s secret eavesdropping service GCHQ but was attached to MI6 when his remains were found inside the bag in a bathtub at his London apartment.

Soviets used civilian airliners to gather intelligence, documents show

Soviet Aeroflot airlinerBy JOSEPH FITSANAKIS | intelNews.org |
Soviet spy agencies routinely used civilian airplanes to collect aerial intelligence over Western military installations, according to newly declassified documents. The revelation is contained in British government files from 1982 that were declassified on Friday, following the expiration of the United Kingdom’s 30-year classification rule. According to Bloomberg’s Robet Hutton and Thomas Penny, who accessed the files, they include a detailed memorandum addressed to Conservative Party politician Margaret Thatcher, who was serving as Britain’s Prime Minister at the time. The memorandum, which was authored by then Secretary of State for Defence, John Nott, informed Mrs. Thatcher that the airborne behavior of airliners belonging to Aeroflot, the Soviet Union’s state-owned civilian air carrier, appeared suspicious. Secretary Nott wrote in the memo that Britain’s Royal Air Force had “established that some [Soviet] aircraft deviated from their flight-plan routes” when flying over Western military bases. He goes on to describe an “incident of particular interest”, in which an Aeroflot Ilyushin IL62 airplane descended without authorization from 35,000 feet to 10,000 feet right above the village of Boulmer. Located in Northumberland, England, Boulmer is adjacent to a Royal Air Force base, which at the time featured a newly modernized radar system. The same Aeroflot airplane behaved in similar fashion while flying over a United States Navy base in Groton, Connecticut, which at the time hosted the first US submarine equipped with Trident Ballistic Missiles. The memorandum states that the circumstances surrounding the flight patterns of Aeroflot airliners had led the Royal Air Force to assume that the Soviet airplanes “were gathering intelligence” on Western military targets. Read more of this post

Who wiretapped Turkish Prime Minister’s office, home?

Recep Tayyip ErdoğanBy JOSEPH FITSANAKIS | intelNews.org |
During a televised interview on December 21, Turkish Prime Minister Recep Tayyip Erdoğan revealed that four unauthorized wiretapping devices had been detected in his parliamentary office and government car. A subsequent report from the Office of the Prime Minister on December 25 said that one more device had been found in Mr. Erdoğan’s home-office at this residence in Turkish capital Ankara. Who is behind the operation? In his December 21 interview, the Prime Minister told a nationwide audience that the bugs had been planted by “elements of a deeper state” within Turkey. “A deeper state exists in nearly every country”, he said, adding: “we try a lot but unfortunately it is impossible to [completely] eradicate the deeper state”. The term ‘deep’ or ‘deeper state’, which is used frequently in Turkey, is meant to signify a covert collaboration of convenience between organized crime and members of the country’s intelligence services.

One example of the Turkish ‘deep state’ that comes to mind is Ergenekon, a clandestine ultra-nationalist organization with secularist and anti-Western objectives. Its membership, which is reportedly drawn primarily from Turkey’s military and security establishments, is involved in both criminal and political activities aiming to preserve the political power of Turkey’s armed forces, while subverting the rise of Islamism and keeping Turkey out of the European Union. The existence of this mysterious organization was revealed in 2001 by Tuncay Güney, an operative of Turkey’s National Intelligence Organization (MİT), who was arrested for petty fraud. In 2009, an investigation into Ergenekon uncovered a clandestine network of safe houses in Ankara, as well as in the Turkish-occupied northern Cyprus, for the sole purpose of wiretapping the communications of targeted individuals and organizations. The safe houses were reportedly equipped with wiretapping systems purchased in Israel, some of which were portable and were thus moved to various cities and towns in Turkey, in accordance with Ergenekon’s mission directives. But are Ergenekon’s tentacles powerful enough to reach into the Turkish Prime Minister’s residence? Read more of this post