Russian spies ‘launched major cyber attack on Ukraine’ prior to naval incident

Strait of KerchRussia “paved the way” for last November’s seizure of Ukrainian Navy ships by launching a major cyber attack and disinformation campaign aimed at Ukraine, according to a cyber security firm and the European Union. In what has become known as the Kerch Strait incident of November 25, border service coast guard vessels belonging to the Russian Federal Security Service (FSB) opened fire on three Ukrainian Navy ships that were attempting to enter the Sea of Azov through the Kerch Strait. All three Ukrainian vessels, along with crews totaling 24 sailors, were captured by the Russian force and remain in detention. Ukraine condemned Russia’s action as an act of war and declared martial law in its eastern and southern provinces. But Moscow said the incident had been caused by a provocation by the Ukrainian government, in a desperate effort to increase its popularity at home. Meanwhile, the three Ukrainian ships and their crews remain in Russia.

But now a private cyber security firm has said that Moscow launched a series of cyber attacks on Ukrainian government servers, which were aimed at gathering intelligence that could be used for the ships’ capture. In a separate development, the European Union’s security commissioner has alleged that the Kremlin launched an elaborate “disinformation campaign” aiming to “soften up public opinion” before seizing the Ukrainian ships.

The American-based cyber security firm Stealthcare said this week that the cyber attacks were carried out by Carbanak and the Gamaredon Group, two hacker entities that are believed to be sponsored by the Russian intelligence services. The first wave of attacks, which occurred in October of this year, centered on a phishing campaign that targeted government agencies in Ukraine and other Eastern European countries. Victims of these attacks had “important functions” of their computers taken over by remote actors who stole and exfiltrated data, according to Stealthcare. Another attack installed back doors on computer servers belonging to Ukrainian government agencies in November, just days prior to the Kerch Strait crisis. The two attacks, said the company, provided the hackers with “information that would have been very […] relevant in planning” the November 25 naval crisis, said Stealthcare. The company added that there was “no doubt that this was a Kremlin-led reconnaissance effort to prepare for the Kerch Strait crisis”.

Meanwhile on Monday Julian King, a British diplomat who is currently the European Commissioner for the Security Union, said that Russia “paved the way for the Kerch Strait crisis” through a systematic fake news campaign that “lasted for more than a year”. The campaign, said King, included the use of social media to spread false rumors, such as claims that the Ukrainian government had infected the Black Sea with bacteria that cause cholera. Another report by Russian media allegedly claimed that Kiev had tried to secretly transport a nuclear device to Russian-annexed Crimea through the Kerch Strait. The EU security commissioner added that social media platforms and online search engines like Google had a responsibility “to identify and close down fake accounts that were spreading disinformation”.

► Author: Joseph Fitsanakis | Date: 12 December 2018 | Research credit: D.V. | Permalink

Jailed Russian who spied for CIA writes letter to Trump, asking to be freed

Russian Ministry of Internal AffairsA Russian former police officer, who is serving a prison sentence in Russia for having spied for the United States Central Intelligence Agency, has written an open letter to President Donald Trump, asking to be freed. Yevgeny A. Chistov was arrested by the Russian Federal Security Service (FSB) in 2014 on charges of spying for Washington. During his trial, he admitted having been recruited by the CIA when he worked as an officer in the police, Russia’s federal law-enforcement agency, which operates under the Ministry of Internal Affairs. Russian state prosecutors accused him of having established contact with the CIA in 2011. In 2015, he was sentenced to 13 years in prison, which he is currently serving at a labor camp in the Nizhny Novgorod town of Bor, located in central European Russia.

On Saturday, British newspaper The Guardian published a letter that was allegedly written by Chistov. In the letter, the jailed spy admits that he passed Russian state secrets to the CIA for three years, after deciding “to help the US as a friend”. He claims that he did it out of love for his country, and in order to help “overthrow […] the regime” of Russian President Vladimir Putin. Chistov goes on to accuse “Putin and his cronies” of having plundered Russia and of oppressing its people through “corruption and extortion”. He blames the Kremlin for Russia’s current economic state: “we have a resource-rich country yet our people are poor”, he says. The jailed spy adds that he told the CIA about the “secret plans” of the Ministry of Internal Affairs, that he provided “names of some people from the FSB”, and that he “revealed some objectives of Russia’s Ministry of Defense”. He does not provide details. He then claims that, even though he was paid by the CIA for his services, he did not act out of self-interest.

Chistov says that the conditions of his imprisonment are inhumane and that he and his family “are in great danger in Russia”. He also claims that his wife visited the US embassy in Ukraine in an attempt to secure a travel visa, but that her application was rejected and she was forced to return to Russia. The jailed spy adds that he “wrote two letters to the CIA asking them to help and received no response”. He then pleads with President Trump to help him, in two ways. First, by granting asylum in the US to his wife and mother. Second, by swapping him with someone “who worked for Russia” and is serving time in a US prison. “I want to appeal to the president to conduct the exchange”, he concludes.

The United States has participated in very few spy swaps in the post-Cold War era. In 2010, Washington and Moscow conducted one of history’s largest spy exchanges, as ten deep-cover Russian agents captured in the US earlier that year were swapped for four Russian citizens imprisoned by Moscow for spying for the US and Britain. Four years later, a Cuban intelligence officer who spied for the CIA was released as part of a wider exchange between Washington and Havana of persons held in each other’s prisons on espionage charges. The White House has not commented on Chistov’s letter.

► Author: Joseph Fitsanakis | Date: 10 December 2018 | Permalink

Czechs accuse Moscow of ‘most serious wave of cyberespionage’ in years

Czech Security Information ServiceThe main domestic intelligence agency of the Czech Republic has accused Russia of “the most serious wave of cyberespionage” to target the country in recent years. The claim was made on Monday in Prague by the Security Information Service (BIS), the primary domestic national intelligence agency of the Czech Republic. Details of the alleged cyberespionage plot are included in the BIS’ annual report, a declassified version of which was released this week.

According to the document, the cyberespionage attacks were carried out by a hacker group known as APT28 or Fancy Bear, which is believed to operate under the command of Russian intelligence. The hacker group allegedly targeted the Czech Ministry of Defense, the Ministry of Foreign Affairs and the headquarters of the country’s Armed Forces. As a result, the electronic communication system of the Ministry of Foreign Affairs was compromised “at least since early 2016”, said the report (.pdf). More than 150 electronic mailboxes of ministry employees —including diplomats— were accessed, and a significant number of emails and attachments were copied by the hackers. The compromise was terminated a year later, when BIS security personnel detected the penetration. The BIS report goes on to say that a separate cyberespionage attack was carried out by a Russian-sponsored hacker group in December of 2016. An investigation into the attacks concluded that the hackers were not able to steal classified information, says the report. It adds, however, that they were able to access personal information about Czech government employees, which “may be used to launch subsequent attacks [or to] facilitate further illegitimate activities” by the hackers.

The BIS report concludes that the hacker campaign was part of “the most serious wave of cyberespionage” to target the Czech Republic in recent years. Its perpetrators appear to have targeted individuals in “virtually all the important institutions of the state” and will probably continue to do so in future attacks, it says. Moreover, other European countries probably faced similar cyberespionage breaches during the same period, though some of them may not be aware of it, according to the BIS. Czech Prime Minister Andrej Babis told parliament on Tuesday that his cabinet will discuss the BIS report findings and recommendations early in the new year.

► Author: Joseph Fitsanakis | Date: 05 December 2018 | Permalink

Nerve agent used in Skripal attack ‘could have killed thousands’ say experts

GRUThe amount of poison smuggled into Britain for a near-fatal attack on Russian former spy Sergei Skripal was powerful enough to kill “thousands of people”, according those leading the investigation into the incident. Skripal, a former military intelligence officer, was resettled in the English town of Salisbury in 2010, after spending several years in a Russian prison for spying for Britain. But he and his daughter Yulia almost died in March of this year, after being poisoned by a powerful nerve agent that nearly killed them. The attack has been widely blamed on the Russian government, though the Kremlin denies that it had a role in it.

Investigators from Britain and other Western countries have identified the poison used in the attack on the Skripals as novichok. The term (meaning ‘newbie’ in Russian) was given by Western scientists to a series of rarely used nerve agents that were developed the Soviet Union and Russia between 1971 and the early 1990s. It is believed that the poison was smuggled into the United Kingdom hidden inside an imitation perfume bottle, which had been fitted with a custom-made pump used to apply the poison. British authorities have determined that the assailants sprayed the poison on the doorway —including the handle— of the Skripals’ house in Salisbury. They then discarded the perfume bottle, containing the leftover novichok, in a garbage can before leaving the country in a hurry. The bottle was eventually recovered by Salisbury resident Charlie Rowley. His partner, Dawn Sturgess, died of poisoning after she applied some of the contents of the bottle on her wrists. British government scientists have since been examining the contents of the perfume bottle found inside Sturgess’ home.

On Thursday, BBC Television’s Panorama investigative program aired an episode entitled “Salisbury Nerve Agent Attack: The Inside Story”. Among those interviewed was Dean Haydon, a British Deputy Assistant Commissioner who is leading the ongoing investigation into the Salisbury attack. He told Panorama that “a significant amount” of novichok was left behind by the assailants inside the discarded perfume bottle. The amount of poison in the discarded bottle could have been used to kill “thousands”, he said, adding that the way it was applied to the Skripals’ home was “completely reckless”. The BBC program’s producers also spoke to a British government chemical weapons scientist, identified only as “Tim”, who is credited with having identified the substance used on the Skripals. He told the program that less than 100g of novichok was used against the Skripals, leaving the vast majority of the nerve agent inside the bottle. Given that novichok is “one of the deadliest substances known”, which has a “unique ability to poison individuals at very low concentrations”, the scientist said he was shocked by the amount of poison that was smuggled into Britain by the assailants.

The assailants have been identified by British intelligence as Dr. Alexander Yevgenyevich Mishkin (cover name “Alexander Petrov”) and Colonel Anatoliy Chepiga (cover name “Ruslan Boshirov”). Both men are said to be employees of the Russian military intelligence agency known as the Main Directorate of the General Staff of the Armed Forces, commonly referred to as the GRU. Moscow denies that it had any role in the attack on the Skripals.

► Author: Joseph Fitsanakis | Date: 22 November 2018 | Permalink

Austria arrests second spy for Russia in a week: media reports

BVT AustriaAuthorities in Austria have arrested a second alleged spy for Russia in a week, according to media reports. Several Austrian news outlets reported on Monday that police had arrested an Austrian counterintelligence officer on suspicion of passing classified information to Russian intelligence. The news follows reports late last week of the arrest of an unnamed retired colonel in the Austrian Army, who is believed to have spied for Russia since 1988. As intelNews reported on Monday, the unnamed man worked at the Austrian Armed Forces’ headquarters in Salzburg. He is believed to have been in regular contact with his Russian handler, known to him only as “Yuri”, who trained him in the use of “sophisticated equipment” for passing secret information to Moscow. He is thought to have given Russia information on a range of weapons systems used by the Austrian Army and Air Force, as well as the personal details of high-ranking officers in the Austrian Armed Forces.

On Monday, the Vienna-based newspaper Kronen Zeitung, said that a second Austrian man had been arrested on suspicion of carrying out espionage for Moscow. The man was identified in Austrian news reports only as “O.”, due to strict restrictions imposed on media in the country. But the Kronen Zeitung said that the Vienna Public Prosecutor’s Office and the Austrian Ministry of Foreign Affairs had confirmed the reports of the arrest of the second alleged spy. According to the Vienna Public Prosecutor’s Office, the second individual was an employee of the Austrian Office for Protection of the Constitution and Counterterrorism, known as BVT. He had been investigated on suspicion of espionage for more than a year prior to his arrest this week. The man’s arrest took place alongside simultaneous raids at two residential addresses associated with him, according to reports. No further details about this latest case have been made available.

No information is available about the kind of information that the suspect is believed to have shared with Moscow. Furthermore, statements from Austrian officials do not mention any connection between the arrest of “O.” and the arrest of the retired Army colonel that took place last week. The Kronen Zeitung notes that, if found guilty of espionage, “O.” will face a sentence of up to 10 years behind bars. The embassy of Russia in Vienna refused to respond to questions about the arrest of “O.” on Monday night.

► Author: Joseph Fitsanakis | Date: 13 November 2018 | Permalink

Austria summons Russian ambassador over arrest of alleged army spy

Sebastian Kurz Mario KunasekThe Austrian Ministry of Foreign Affairs summoned the Russian ambassador to Vienna on Friday, following the arrest of a retired Austrian Army colonel who allegedly spied for Moscow for more than two decades. The news was announced on Friday by Austrian Chancellor Sebastian Kurz at an emergency news conference in Vienna. He did not reveal the alleged spy’s identity, but said that he had been taken into custody as Austrian counterintelligence were investigating the extent of the security breach he caused.

However, according to the Kronen Zeitung, Austria’s highest-circulation newspaper, the suspect is a 70-year-old Army colonel who recently retired after a long military career. He reportedly worked at one of the Austrian Armed Forces’ two headquarters, located in the western city of Salzburg. The unnamed man is believed to have spied for Russia from the early 1990s until his arrest last week. The Kronen Zeitung said that the retired Army colonel was in regular contact with his Russian handler, known to him only as “Yuri”. The Russian handler reportedly trained him in the use of “sophisticated equipment”, which he used to communicate information to Moscow. He is thought to have given Russia information on a range of weapons systems used by the Austrian Army and Air Force, as well as the personal details of high-ranking officers in the Austrian Armed Forces. Austrian media reported that the alleged spy was paid nearly $350,000 for his services to Moscow. According to Austria’s Minister of Defense Mario Kunasek, the arrest came after a tip given to the Austrian government “a few weeks ago” by an unnamed European intelligence agency. He also said that Austrian security services were looking into the possibility that the suspect may have been part of a larger spy ring working for Moscow.

The incident has strained relations between Austria and Russia. In the past decade, Austria —which is not a member of the North Atlantic Treaty Organization— has been seen by observers as a rare ally of Moscow inside the European Union. Unlike the vast majority of European Union countries, Austria chose not to expel Russian diplomats following the poisoning of former Russian double spy Sergei Skripal in March of this year. In August, Russian President Vladimir Putin attended the wedding of his personal friend, Austria’s Foreign Minister Karin Kneissl. But Mrs. Kneissl has now canceled a planned visit to Moscow in December in response to last week’s spy scandal. Speaking in Moscow on Saturday, Russian Foreign Minister Sergei Lavrov dismissed Austria’s accusations as “unfounded” and “unacceptable”.

► Author: Joseph Fitsanakis | Date: 12 November 2018 | Permalink

New book names ex-KGB defector who outed FBI agent Robert Hanssen as Russian spy

Robert HanssenA new book reveals for the first time the name of a former intelligence officer of the Soviet KGB who helped American authorities arrest Robert Hanssen, an American spy for the Soviet Union and Russia. The son of a Chicago police officer, Hanssen joined the Federal Bureau of Investigation in 1976 and was eventually transferred to the Bureau’s Soviet analytical unit, where he held senior counterintelligence posts. It wasn’t until 2000, however, that the FBI realized Hanssen had spied for Moscow since 1979. Following Hanssen’s arrest in 2001, it emerged that he had betrayed the names of 50 FBI and CIA assets or informants, many of whom perished in the hands of the Russian intelligence services.

In 2002, the US Department of Justice opined that Hanssen had caused “possibly the worst intelligence disaster in US history”. He is currently serving 15 consecutive life terms without the possibility of parole. But despite numerous articles, reports and books on the Hanssen spy case, the story of the FBI investigation that led to his arrest remains at best fragmentary. A major question concerns the identity of the mysterious person that helped FBI counterintelligence investigators zero in on Hanssen after years of fruitless efforts to confirm suspicions of the existence of a Russian mole. It is known that the FBI paid the sum of $7 million to a former KGB officer, who delivered the contents of Hanssen’s Russian intelligence file. But the identity of that informant has not been revealed.

That may have changed as of last month, however, thanks to The Seven Million Dollar Spy, a book written by the late David Wise, a journalist and best-selling intelligence author who died on October 8, aged 88. Wise’s book, published posthumously on October 23 in audio book format, received little media attention. But Newsweek intelligence correspondent Jeff Stein said last week that the book might bring us a step closer to uncovering the identity of the individual who led to Hanssen’s capture. Stein explains that the mysterious informant had previously developed a business relationship with Jack Platt, a retired CIA case officer who after the end of the Cold War co-founded an international security consultancy with ex-KGB operative Gennady Vasilenko. The two men staffed their company with several American and Russian former spies. Among them was Anatoly Stepanov, a former case officer in the KGB. Stein reports that, according to Wise’s posthumous book, Stepanov is in fact the pseudonym of former KGB officer Aleksandr Shcherbakov. It was he who delivered Hanssen’s file to the FBI, thus facilitating his eventual capture. It is believed that Shcherbakov defected to the United States in 2010 where he continues to live today under an assumed identity.

► Author: Joseph Fitsanakis | Date: 06 November 2018 | Permalink

Suicide bomber who attacked Russian spy agency identified as ‘anarchist-communist’

Mikhail ZhlobitskyA teenager who killed himself with an improvised explosive device in the lobby of a regional office of Russia’s domestic intelligence agency appears to have identified himself as an “anarchist-communist” on social media. At 8:52 am local time on Wednesday, the 17-year-old entered the regional office of Russia’s Federal Security Service (FSB) in the city of Archangelsk, located 800 miles north of Moscow. On CCTV footage released by the Russian security services, he is seen reaching into his backpack and taking out an object, which soon exploded, killing him and wounding three others.

The bomber was later identified in the Russian media as Mikhail Zhlobitsky, a student at a local technical college. Within hours, reports pointed to posts made on social media platforms by Zhlobitsky, who used several online aliases, including that of “Sergey Nechayev”, one of Russia’s leading 19th-century anarchists, who died in prison for advocating terrorism as a means of revolution. Shortly before the attack, someone using the alias “Valeryan Panov” commented on the social messaging application Telegram that he was about to bomb the FSB in Archangelsk. In the comment, which was posted on an anarchist forum, the user said that he had decided to act “because the FSB falsifies cases and tortures people”. The user added that he would probably die in the attack because he had to manually detonate the improvised explosive device he was carrying with him. He concluded his message with the words: “I wish you a glorious future of anarchist communism!”.

The activities of militant Russian anarchists and anarcho-communists date back to the mid-19th century; anarchist militants are responsible for numerous assassinations of senior Russian officials, including Emperor Alexander II, who was killed by a Russian anarchist in 1881. But the movement was ruthlessly suppressed by the Soviet state and today the FSB and other Russian security services are actively monitoring the remnants of the Russian anarchist movement. These include the Confederation of Revolutionary Anarcho-Syndicalists, the group Autonomous Action, and the Siberian Confederation of Labor. Large sections of these groups have now moved underground, as the government of Russian President Vladimir Putin has named anarchists as primary enemies of order and security in the Russian Federation. Earlier this month, another Russian teenager, Vladislav Roslyakov, killed himself after shooting 19 students and teachers at a technical college in Kerch, a Black Sea port city in Russian-annexed Crimea. No political motive for the attack has been reported.

► Author: Joseph Fitsanakis | Date: 01 November 2018 | Research credit: S.F. | Permalink

Russian espionage reaching ‘intolerable levels’ say Swiss officials

Jean-Philippe GaudinRussian espionage activities in Switzerland are increasing and are crossing long-established “red lines”, according to senior Swiss defense and intelligence officials who spoke at a news conference last week. The claims were made by Guy Parmelin, head of Switzerland’s Federal Department of Defense, and Jean-Philippe Gaudin, director of the Swiss Federal Intelligence Service (NDB). The two men spoke on Friday before reporters in Bern. Following the news conference, Gaudin spoke with reporters from the Reuters news agency.

Gaudin, who assumed the post of NDB director three months ago, told Reuters that Russian espionage activities in Switzerland have been increasing steadily in recent years. He refused to provide details, but said that “it is clear we have more activities than before”. Additionally, Moscow had more active spies in Switzerland than in previous years, said Gaudin. He refused to provide numbers, saying that he would “share that with [his] colleagues elsewhere and not with the media”. The NDB chief noted that Switzerland had always been a target of Soviet and Russian espionage because it hosts the headquarters of a large number of international and non-governmental organizations. However, what is different today, he said, is that Moscow is targeting Switzerland’s “sensitive infrastructure”, which is “a red line”. He did not provide further information. Speaking alongside Gaudin, Defense Minister Parmelin said that Russian espionage activities against Swiss national infrastructure “has reached intolerable levels”.

These allegations by senior Swiss government officials come a little more than a month after reports that Swiss and other Western intelligence agencies thwarted a plot by two Russians who tried to hack the computer systems of a Swiss government laboratory that investigates nuclear, biological and chemical weapons. The laboratory, located in the western Swiss city of Spiez, had been commissioned by the Organization for the Prohibition of Chemical Weapons to carry out investigations related to the poisoning of Russian double agent //Sergei Skripal// and his daughter Yulia in March of this year. It has also carried out probes on the alleged use of chemical weapons by the Russian-backed government of President Bashar al-Assad in Syria.

The Russian embassy in Bern rejected the accusations of espionage and called the allegations made by Gaudin, and Parmelin “absurd”.

► Author: Joseph Fitsanakis | Date: 23 October 2018 | Permalink

Russia claims ‘misunderstanding’ led to arrests of four spies in Holland

Sergei LavrovRussia’s minister of foreign affairs has downplayed the arrest and expulsion of four Russian military intelligence officers in Holland last April, saying that the incident was caused by a “misunderstanding”. Last Thursday, the US government named and indicted seven officers of the Main Directorate of the General Staff of Russia’s Armed Forces, known as GRU. The seven are alleged to have participated in cyber-attacks on international agencies, private companies and government computer networks in at least half a dozen countries around the world since 2015. Four of the men named last week were reportedly detained in April of this year while trying to hack into the computer network of the Organization for the Prohibition of Chemical Weapons (OPCW). Headquartered in The Hague, the OPCW oversees efforts by its 193 member states to detect and eliminate chemical weapons stockpiles around the world. In the past year, the OPCW has been probing the failed attempt to poison the Russian former double spy Sergei Skripal in England, which the British government has blamed on Moscow.

On Monday, Russia’s Minister of Foreign Affairs Sergei Lavrov dismissed Washington’s accusations against the GRU and said that the Dutch authorities had overreacted in detaining the four Russian officers in April. Following a meeting in Moscow with his Italian counterpart Enzo Moavero Milanesi, Lavrov said that the visit of the four GRU officers in Holland had been “customary”, adding that “there was nothing clandestine in it”. The GRU specialists were in Holland in order to secure computer servers used at the Russian embassy there. “They were not trying to hide from anyone once they arrived at the airport”, said Lavrov. They then “checked into a hotel and paid a visit to our embassy”, he added. Had they been engaged in espionage, the men would have taken strict precautions, said the Russian foreign affairs minister. They were eventually “detained by Dutch police without any reason or explanations, and were not allowed to contact our embassy”, said Lavrov. Eventually they were “asked to leave the country”, but it was “all because of a misunderstanding”, he concluded.

The Russian official did not address the information provided a series of photographs released by Holland’s Ministry of Defense, which show a car used by the four Russians at the time of their arrest in April. The photographs show that the car was equipped with WiFi antennas and transformers. A wireless server and batteries can also be seen in the photographs. Lavrov said that the allegations against the GRU were meant to draw attention to Russia and distract Western citizens from “widening divisions that exist between Western nations”.

► Author: Joseph Fitsanakis | Date: 09 October 2018 | Research credit: S.F. | Permalink

Britain sees Russian government hackers behind Islamic State cyber group

Cyber CaliphateA new report by the British government alleges that the so-called ‘Cyber Caliphate’, the online hacker wing of the Islamic State, is one of several supposedly non-state groups that are in fact operated by the Russian state. The group calling itself Cyber Caliphate first appeared in early 2014, purporting to operate as the online wing of the Islamic State of Iraq and Syria (ISIS), which was later renamed Islamic State. Today the Cyber Caliphate boasts a virtual army of hackers from dozens of countries, who are ostensibly operating as the online arm of the Islamic State. Their known activities include a strong and often concentrated social media presence, as well as computer hacking, primarily in the form of cyber espionage and cyber sabotage.

But an increasing number of reports, primarily by Western government agencies, have claimed in recent years that the Cyber Caliphate is in fact part of a Russian state-sponsored operation, ingeniously conceived to permit Moscow to hack Western targets without retaliation. On Wednesday, a new report by Britain’s National Cyber Security Centre (NCSC) described the Cyber Caliphate and other similar hacker groups as “flags of convenience” for the Kremlin. The report was authored by the NCSC in association with several British and European intelligence agencies. American spy agencies, including the National Security Agency and the Federal Bureau of Investigation, also helped compile the report, according to the NCSC. The report names several hacker groups that have been implicated in high-profile attacks in recent years, including Sofacy, Pawnstorm, Sednit, Cyber Berkut, Voodoo Bear, BlackEnergy Actors, Strontium, Tsar Team, and Sandworm. Each of these, claims the NCSC report, is “an alias of the Main Directorate of the General Staff of Russia’s Armed Forces”, more commonly known as the GRU. The report concludes that Cyber Caliphate is the same hacker group as APT 28, Fancy Bear, and Pawn Storm, three cyber espionage outfits that are believed to be online arms of the GRU.

The NCSC report echoes the conclusion of a German government report that was leaked to the media in June of 2016, which argued that the Cyber Caliphate was a fictitious front group created by Russia. In 2015, a security report by the US State Department concluded that despite the Cyber Caliphate’s proclamations of connections to the Islamic State, there were “no indications —technical or otherwise— that the groups are tied”. In a statement issued alongside the NCSC report on Wednesday, Britain’s Secretary of State for Foreign and Commonwealth Affairs, Jeremy Hunt, described the GRU as Moscow’s “chosen clandestine weapon in pursuing its geopolitical goals”. The Russian government has denied these allegations.

► Author: Ian Allen | Date: 05 October 2018 | Permalink

Swiss police saw Russian oligarch Abramovich as threat to security, files reveal

Roman AbramovichPolice in Switzerland cautioned that allowing the Russian billionaire Roman Abramovich to live there would threaten public security and damage the country’s reputation, according to files released this week. The Soviet-born Abramovich took advantage of Russia’s privatization laws in the early 1990s to gain considerable financial and political influence there. His friendship with Russia’s first post-Soviet President, Boris Yeltsin, was instrumental in his business career, and eventually placed him in close proximity to Russia’s current President, Vladimir Putin. Unlike many other oligarchs, Abramovich is believed to have remained close to Putin, despite living mostly in the United Kingdom in the past decade. The Russian oligarch has been staying in a mansion valued at close to $120 million in London’s exclusive suburb of Kensington. His lawyers have been renewing his British residence visa every six months.

However, the attempted assassination of Russian former spy Sergei Skripal earlier this year prompted the British government to intensify its scrutiny of Britain’s sizeable Russian expatriate community. London introduced tighter regulations that require Russian citizens applying to live in the UK to declare the source of their income in a far greater detail than previously. Soon after the new regulations were put in place, Abramovich’s lawyers withdrew his application to renew his British residency visa. Then, in May of this year, the Russian oligarch acquired Israeli citizenship. He has made it clear, however, that he does not intend to live in Israel. Instead, his legal team focused on an application for Swiss residency, which Abramovich first filed in the summer of 2016. In the application papers, Abramovich wrote that he intended to reside full time in Verbier, an Alpine village in the canton of Valais that is a popular holiday destination for celebrities and royalty.

A year later, following resistance and increasingly persistent questioning from the Swiss government, Abramovich’s legal team withdrew his residency application. Last February, when the Swiss press attempted to investigate the reasons behind the Swiss government’s reluctance, Abramovich’s lawyers secured an injunction forbidding the publication of information regarding his application to live in Switzerland. But the injunction was overturned late last week, and on Tuesday the Swiss media conglomerate Tamedia published some of the relevant documents. They include a letter from the Swiss Federal Police that strongly cautions against allowing the Russian-Israeli oligarch to resettle in Switzerland. The letter remarks that Abramovich has been repeatedly implicated in “suspicion of money laundering” and that the billionaire is “presumed [to have] contacts with criminal organizations”. Additionally, the letter states that Abramovich’s “assets are at least in part of illegal origin”. The letter concludes by strongly cautioning against allowing the oligarch to move to Switzerland, and argues that doing so would pose a “threat to public security” and be detrimental to the country’s international reputation.

The letter has raised eyebrows since its publication, because Switzerland is known for being highly welcoming of foreign billionaires while displaying minimal curiosity about the sources of their fortunes. Moreover, there are no known court rulings against Abramovich for money laundering or connections to organized crime. It is therefore presumed that the Swiss police report is based mostly on confidential informants and other informal sources. On Wednesday, Abramovich’s Swiss lawyer, Daniel Glasl, issued a statement saying that the Russian-Israeli magnate has never been charged with involvement in money laundering. He also reminded readers that his client has a blank criminal record.

► Author: Joseph Fitsanakis | Date: 28 September 2018 | Permalink

Russia planned to smuggle Julian Assange from Ecuador’s embassy in London

Julian AssangeRussia and Ecuador canceled at the last minute a secret plan to smuggle WikiLeaks founder Julian Assange out of the Ecuadorean embassy in London after it was deemed “too risky”, according to a report. The Australian-born founder of the whistleblower website was granted political asylum by the government of Ecuador in June of 2012, after Swedish authorities charged him with rape. He claims that the charges are part of a multinational plot to extradite him to the United States, where he is wanted for having leaked hundreds of thousands of secret government documents. He has thus refused to leave Ecuador’s embassy in the British capital since June 2012.

Last week, the British newspaper The Guardian said that Russian and Ecuadorean officials devised a complex operation to smuggle the WikiLeaks founder out of the Ecuadorean embassy, which is closely monitored by British security agencies. The London-based paper said it spoke to “four separate sources” who confirmed that a small team of Russians and Ecuadoreans met several times to plan the operation. The Ecuadorean side was allegedly represented by Fidel Narváez, a close friend and supporter of Assange, who previously served as Ecuador’s consul in London and continues to live there with his family. The Kremlin was reportedly represented by an unnamed “Russian businessman”, said The Guardian, who served as an intermediary between the Ecuadoreans and Moscow. The plan consisted of several steps, said the paper. The first step was for Assange to receive Ecuadoran citizenship and then be given diplomatic status by the government of Ecuador. That would give the WikiLeaks founder diplomatic immunity and shield him from British laws. A diplomatic vehicle would then secretly transport Assange from the Ecuadorean embassy to an unknown location. From there he would be transported to Ecuador via ship, or to Russia, where he would serve as a member of staff of the Ecuadorean embassy in Moscow. If British security services managed to intercept Assange during the operation, all they could do was expel him from the country. They would not be able to arrest him because of his diplomatic status.

The plan, said The Guardian, was scheduled for December 24, 2017. On December 15, Rommy Vallejo, the head of Ecuador’s national intelligence agency, Secretaría Nacional de Inteligencia (SENAIN), traveled secretly to London to supervise the operation. Two days later, on December 17, Assange was granted Ecuadorian citizenship as part of the plan. But the plan was aborted at the last moment after the British government refused to recognize Assange’s diplomatic status. According to British law, a foreign diplomat does not receive immunity from British law unless the British government officially accepts his or her diplomatic credentials. Although that is typically a formality, the British government reserves the right to refuse a diplomat’s credentials. That was seen by the Russians as a stumbling block and the operation was called off, said the paper.

Narváez spoke with The Guardian and strongly denied that he had any involvement with a joint Russian-Ecuadorean plan to smuggle Assange out of London. The Ecuadorean government did not return messages with questions about the paper’s allegations. The Russian embassy in the British capital tweeted late last week that The Guardian’s claims were “another example of disinformation and fake news from the British media”.

► Author: Joseph Fitsanakis | Date: 24 September 2018 | Permalink

Dead Russian oligarch’s links to UK spy agencies must stay secret, judge rules

Aleksandr PerepilichnyA judge has ruled that the British government has the right to withhold information relating to alleged links between British spy agencies and a Russian millionaire who died in mysterious circumstances in England. Aleksandr Perepilichny was a wealthy and influential investment banker living in Moscow. In 2009, however, he fled Russia saying that his life had been threatened following a business disagreement. He resettled in Surrey, south of London, and began cooperating with Swiss authorities who were investigating a multimillion dollar money-laundering scheme involving senior Russian government officials. Described by some as the biggest tax fraud in Russian history, the scheme is said to have defrauded the Russian Treasury of at least $240 million.

On November 10, 2012, having just returned to his luxury Surrey home from a three-day trip to France, Perepilichny went out to jog. He was found dead later that evening, having collapsed in the middle of a side street near his house. He was 44. A postmortem examination concluded that Perepilichny had died of natural causes and pointed to the strong possibility of a heart attack. However, lawyers representing the late businessman’s family told a pre-inquest hearing that Perepilichny stomach was found to have traces of gelsemium, a shrub-like plant that is a “known weapon of assassination [used] by Chinese and Russian contract killers”.

The case is now being revisited following the failed attempt last March, allegedly by the Kremlin, to assassinate Sergei Skripal, a Russian former spy who defected to England in 2010. For the past several months, submissions have been filed for an inquest into Perepilichny’s mysterious death. But the British government said that it would not reveal any information relating to possible contacts between the late Russian businessman and British intelligence. The question was raised in June by lawyers representing Legal and General, Perepilichny’s life insurance company. They argued that if Perepilichny had close dealings with British intelligence, it would have raised significantly the threat that his life was under. But British Home Secretary Sajid Javid argued that releasing documents implicating the intelligence services with the late Russian businessman would endanger national security.

On Monday the judge leading the inquest into Perepilichny’s death ruled in favor of the British government’s position. The judge, Nicholas Hilliard QC, has security clearance and was therefore able to review the relevant evidence behind closed doors, during a secret session. He then ruled that “publicly releasing intelligence information [relating to Perepilichny] would pose a real risk of serious harm to national security”. Critics argue that the Skripal case has heightened public interest in Russian covert activities on British soil and that the public has the right to know whether the death of Perepilichny was in any way connected to the intelligence realm. The inquest continues this week.

► Author: Joseph Fitsanakis | Date: 19 September 2018 | Permalink

US intelligence reevaluates safety of Russian defectors in light of Skripal poisoning

CIAIntelligence officials in the United States are feverishly reassessing the physical safety of dozens of Russian defectors, in light of the case of Russian double spy Sergei Skripal, who was poisoned in England last March. Skripal, a former military intelligence officer who spied for Britain, was resettled in the English town of Salisbury in 2010 by the British Secret Intelligence Service (MI6). But he and his daughter Yulia made international headlines in March, after they were poisoned by a powerful nerve agent that nearly killed them. The attack has been widely blamed on the Russian government, though the Kremlin denies that it had a role in it.

Like MI6, the US Central Intelligence Agency also has a protection program for foreign nationals whose life may be at risk because they spied for the US. The CIA’s protection division, called the National Resettlement Operations Center, helps resettle and sometimes hide and protect dozens of foreign agents, or assets, as they are known in CIA lingo. But following the Skripal case, some CIA resettlement officials have expressed concern that protection levels for some foreign assets may need to be significantly raised. The New York Times, which published the story last week, said that it spoke to “current and former American intelligence officials”, which it did not name. In light of those concerns, US counterintelligence officials have been carrying out what The Times described as “a wide-reaching review” of every Russian asset who has been resettled in the US. The purpose of the review is to assess the ease with which these former assets can be traced through their digital footprint on social media and other publicly available information.

According to the paper, several Russians who defected to the US after working for the CIA and other US intelligence agencies were tracked down by the Kremlin in recent years. In the mid-1990s, says The Times, the CIA actually found an explosive device placed under the car of a Russian defector living in the US. More recently, US intelligence traced the movements of a suspected Russian assassin who visited the neighborhood of a resettled Russian defector in Florida. In the past, Russian CIA assets who have been resettled in the US have voluntarily revealed their whereabouts by reaching out to relatives back in Russia out of homesickness. In some cases, they have left the US in order to meet a lover who may have been planted by the Russian spy services —with sometimes fatal consequences.

In addition to the US, at least one more country has initiated a thorough review of the way it protects former Russian assets living in its territory in light of the Skripal case. As intelNews reported in March, the British secret services tightened the physical security of dozens of Russian defectors living in Britain only a week after the attempted murder of Skripal. Britain’s security services reportedly viewed the attack on Skripal as an intelligence failure and launched a comprehensive review of the risk to British-based Russian double spies and defectors from “unconventional threats”. The latter included attacks with chemical and radiological weapons.

► Author: Joseph Fitsanakis | Date: 18 September 2018 | Permalink