Posts Tagged ‘hacking’

A Few More Thoughts On Operation Grim Beeper

Sunday, September 22nd, 2024

A third but brief post on Israel’s exploding pager attack against Hezbollah. Several people have expressed incredulity that Israel would go to the trouble of setting up “their own factory” to manufacture the exploding pages against Hezbollah. I suspect people are envisioning something the size of a Foxconn iPhone line, but for smaller runs of less cutting-edge products, modern contract manufacturing can usually do things in much smaller footprints. Pagers are old 1980s tech, most probably use off-the-shelf commodity parts you can find anywhere, and I suspect Israel set up something much smaller.

You don’t need a line of assembly workers, you need a pick-and-place machine to attach the surface-mount components to your circuit board. Pick-and-place machines are also old technology that have gone through many iterations, but you can literally run a circuit board a assembly line in your garage. Here’s a guy that uses a very old pick-and-place machine to make amusement park controllers using equipment in his own shed.

Note that his boards are roughly the same size as a pager (probably slightly bigger). His is a low-tech approach that allows him to do all the steps himself and requires hand-soldering for some components. With a few more machines and a few more people, I suspect Israel could easily have run their exploding pager line out of a space of 1,000 square feet or less. Everything save the explosive batteries probably used commodity pager parts, and even the special command sequence to trigger the explosion was probably programmed into a commodity controller chip.

Israel also has a modern, sophisticated electronics sector, so it’s possible they contract with one of their existing military electronics contractors to do a run, but I’m not sure anyone had an assembly line suitable for turning out old-tech pagers, as you wouldn’t want to alert Hezbollah agents with a circuit board that looked too modern.

There were a lot of sophisticated aspects to Israel’s supply chain attack, especially how they used human intelligence to insinuate themselves into Hezbollah’s procurement system to be in a position to provide the pagers. And producing batteries that actually held explosives was not a trivial task. But setting up an assembly line for the pagers once they had done all the upfront espionage work to get in a position to provide them was probably among the least difficult aspects of the operation.

Israel’s Supply Chain Hack: Manufactured, Not Altered

Thursday, September 19th, 2024

More information about Israel’s pager etc. attack against Hezbollah has come to light, and it appears Israel didn’t intercept and adulterate the supply chain, it was the supply chain.

Israel has injured thousands across Lebanon, with hundreds in critical condition and dozens more dead, this week in two waves of simultaneous explosions of electronic communications equipment targeting Iranian-backed Hezbollah terrorists.

The blasts — which may have killed 19 and wounded 150 of Iran’s Islamic Revolutionary Guard Corps (IRGC) members — started on Tuesday afternoon around 3:30 p.m. local time when pagers used by Hezbollah started beeping with a message from their leadership.

After a few beeps, the pagers simultaneously exploded across the country, blinding hundreds, tearing off limbs, and leaving gaping holes in bodies.

The messages that the devices received were not from Hezbollah leadership; they were from Israel’s intelligence and military apparatus, and they were part of a multi-year plan.

There was initial confusion as to what happened when the explosions were reported. Various news reports said that malware had potentially been uploaded to the devices, causing the batteries to overheat and explode. Then reports surfaced claiming a small amount of highly explosive material had been placed into each device after Israel intercepted the devices after they were manufactured by a Taiwanese company.

However, none of those reports were accurate, according to a New York Times report that revealed that Israel never intercepted the pagers — it made them.

Hezbollah has forced tens of thousands of Israelis to evacuate their homes in northern Israel since October 7 as the terrorist group fires drones, rockets, and missiles on a regular basis — having fired many thousands in nearly 12 months.

Israel has responded with precision strikes, killing more than 300 top Hezbollah commanders and numerous lower-level terrorists.

Hezbollah Secretary General Hassan Nasrallah pushed for the terrorists to abandon their phones and switch to low-tech pagers to avoid being tracked by Israel. Nasrallah had bragged that his strategy would “blind” Israel.

However, unbeknownst to Hezbollah, Israel had been secretly manufacturing the pagers that Hezbollah was buying for years.

The Taiwanese company Gold Apollo had contracted with a company called B.A.C. Consulting in Hungary to manufacture the pagers. B.A.C. Consulting was one of three shell companies that Israel created to mask the true manufacturer of the communications equipment: Israeli intelligence.

B.A.C. Consulting created real pagers for numerous customers to create the perception of a legitimate company in order to get picked up for the contract to produce the pagers for Hezbollah.

The pagers manufactured for Hezbollah were separate from those made for other clients, the report said. The pagers that Hezbollah received “contained batteries laced with the explosive PETN” and began shipping in 2022, the report said.

One of my objections to the “planted explosives” idea was that there was no way for explosives in the battery compartment to access the antenna circuitry to receive the detonation signal, but if Israel designed the pagers from the ground up to go boom then obviously that’s not a problem.

After the first round of explosions on Tuesday, Israel struck again on Wednesday, detonating Hezbollah’s backup communications equipment: walkie-talkies.

The explosions from the walkie-talkies were significantly larger than the explosions from the pagers because the devices were larger, meaning they could be packed with more explosive material. Videos posted online showed entire apartment units blown out and numerous cars engulfed in flames.

My other objection was that Israel would be better off gathering intel from the pagers than making them go boom, but if they manufactured them, they probably have all the intel they need on locations of leadership, warehouses, weapons, etc. It looks like Israel was the one that blinded Hezbollah, not the reverse.

It may also explain why Israel hasn’t assassinated Nasrallah yet: Because he’s evidently an idiot.

There’s been much speculation that with Hezbollah’s communications so compromised, Israel will now move decisively against them. And indeed, right now Israel is pounding the snot out of locations in southern Lebanon.

Plus Israeli F-15s are evidently flying over Beirut with evident impunity. (Lebanon couldn’t take down Israeli aircraft during the Lebanon War in 2006 either, mainly because they’re using old Soviet crap.)

A lot of MSM commentators have shrieked over and over again during the Israel-Hamas War that Israel was in trouble because they would face a two-front war when Hezbollah really got involved. That didn’t happen. Instead, Israel settled Hamas’ hash in Gaza (where it’s now mopping up), then hit a whole lot of militant factions on the West Bank (an under-reported story), all the while withstanding pinprick strikes from the Mullahs and their proxies while carrying out varied strikes in Syria and Iran.

Having accomplished all that, Israel seems to be moving decisively against Hezbollah. Now Israel is poised to enter a two-front war, but only on its own terms, not Hezbollah’s. It’s almost like Israel had its own Schlieffen Plan to defeat each of its enemies in turn before turning to the next, only competently executed. But with Hezbollah so disorganized, it may not even feel the need to launch a ground incursion into Lebanon.

The end result of the war Hamas’ terrorist atrocity started will be that Israel will be stronger and its borders more secure, all Israel’s terrorist enemies will be destroyed or weaker, and Iran will be shown, yet again, as a very weak horse using incompetent proxies.

Now, as a bonus, here’s a Habitual Linecrosser video on the subject.

Edited to add: “Hezbollah Starting To Think They Shouldn’t Have Gotten Pagers From Levi Goldbraumstein’s Pager Emporium.”

The Hezbollah Pager Attack: How?

Wednesday, September 18th, 2024

By now I’m sure you’ve heard about the epic, ingenious pager attack that Israel carried out against Hezbollah:

At least nine people were killed and about 2,750 people were injured in Lebanon on Tuesday during the mass explosion of pagers belonging to members of Hezbollah, according to the country’s health ministry.

A Hezbollah official described the event as the “biggest security breach” the group has suffered since the start of the Israel-Gaza war nearly one year ago, according to a Reuters report. The Shiite terror group claimed that lithium batteries inside the pagers apparently detonated.

Some members allegedly felt the pagers “heating up” before abandoning them, according to an unnamed Hezbollah official speaking to the Wall Street Journal. Hezbollah officials have speculated that Israeli malware could be behind the infiltration.

Sky News Arabia, however, quoted sources insisting that Mossad, Israel’s primary intelligence agency, physically planted explosive materials inside the pagers before they were delivered to Lebanon.

According to the Times of Israel, Hezbollah Secretary-General Hassan Nasrallah turned to pagers after he directed members to stop using cell phones in February, fearing they could be tracked by Israeli intelligence. A Lebanese security source claimed the devices were imported five months ago, according to Al Jazeera.

Seven individuals were similarly killed in Syria around Damascus, according to Iran’s IRGC-affiliated Saberin News. This signals a coordinated effort to reach the group in multiple locations across different countries.

Everyone and their dog has posted this story, so I wasn’t going to note it outside the LinkSwarm, except I think some commenters are making erroneous assumptions about how the attack was carried out. I see three possibilities:

  1. The Sky News Arabia suggestion (also floated in this Washington Post article) that the attack was carried out via a supply chain attack planting explosive in each pager, seems clever and has a certain surface plausibility. But I think it very unlikely, mainly because, if you already have that level of access to their communication network hardware, planting explosives is probably the least rewarding attack you could carry out. No, the real play for a supply chain attack is to compromise the security of the devices themselves so you can use Hezbollah’s own devices to spy on their entire communications network. That’s a whole lot more valuable than a handful of deaths and a larger number of maimings. I also find the idea that they intercepted the batteries and loaded them with Pentaerythritol tetranitrate (PETN) even less likely. Just how would these batteries receive the detonate signal if they’re not directly in the circuit to access the antenna to receive the signal?
  2. My guess is that Israel discovered the type of battery and charging firmware Hezbollah’s pagers used, and used a remote exploit to trigger overcharging in the batteries. This also aligns with reports that several Hezbollah terrorists felt the pager getting hot before they exploded. That isn’t the way explosives work, but it is the way Lithium Ion batteries respond to overcharging. Further supporting this hypothesis is that Israel’s previous Stuxnet worm targeting Iran’s nuclear program used a broadly similar attack (a combination software/firmware exploit that caused physical destruction of the targeted system). Such attacks are by no means easy, but dozens of broadly similar hardware hacking exploits are revealed at DEFCON every year.
  3. A third theory I’ve seen proposed by various commenters: Israel was able to explode the pagers because Hezbollah equipped all of them with explosives from the git-go, either to use as improvised explosives or for data security if captured. The first is unlikely because we all know Hezbollah has access to a wide range of explosives to build bombs and IEDs with, and it doesn’t make sense to use something as small as a pager for any significant target. The second strikes me as deeply unlikely from a cost/benefit analysis.

(If someone can think of another theory than those three, let me know in the comments below.)

The heady onrush of the technological revolution has allowed non-state actors like Hezbollah to punch well above their weight by using commercial off-the-shelf technology to strike vulnerable targets (civilians and infrastructure) of larger state actors like Israel. But the downside of not controlling your own supply chain is that a technologically sophisticated state actor like Israel has the knowledge and resources to hack your consumer-grade equipment.

I just read that Hezbollah radios are now exploding as well, so I’m going to go ahead and post this before Israel manages to remote detonate still more of Hezbollah’s tech.

Hezbollah, of course, is talking about launching a full-scale war against Israel. Given the destruction of their communication networks, one wonders how long it will take them to learn semaphore to coordinate attacks…

LinkSwarm for June 21, 2024

Friday, June 21st, 2024

More evidence of the Biden Recession, California’s welfare state goes extra crazy, Chicago has to spend mad money to produce illiterate children, an Assistant DA resigns, a cyberattack hits car dealers nationwide, a Brazilian thief gets ventilated, and God unites the entire world in hatred of the New York Yankees. It’s the Friday LinkSwarm!

  • Statistics show that the economy is contracting. Just like we already knew. Thanks, Joe Biden.
  • California’s tax dollars and welfare state at work:

    Taxpayers are funding a new high-rise building in Los Angeles where homeless people will enjoy skyline views, a cafe, a gym, and an art studio, not to mention the free rent.

    The fancy new building is 19 stories high and has 278 units, each costing about $600,000. The total cost was $165 million, according to the Los Angeles Times. It is the first of three new high-rise buildings that will soon house homeless people.

    Snip.

    This modern tower for the homeless includes a TV in each apartment, a gym, an art room, a soundproofed music room, a computer room with a library, a TV lounge, a courtyard, and a cafe that will host movie nights. There are also six common balconies, four of which have dog runs.

    Where are politicians getting all the money for this project? The buildings are funded by the city’s supportive housing loan program, Proposition HHH, which was approved by city voters in 2016, as well as state housing funds and $56 million in state tax credits.

    The three apartment buildings will be located around the headquarters of the Weingart Center, a nonprofit that assists homeless people. Kevin Murray, a former California state senator, is the man behind the project. He serves as the chief executive of the nonprofit.

    I’m sure all the Homeless Industrial Complex members involved got generously paid for their efforts. Once again, the message of the Democratic Party is: You’re suckers for working for a living.

  • “Chicago Doubles Education Spending, Tragedy Ensues.”

    Illinois Policy just issued a report showing that while CPS has doubled spending per student since 2012, grades are down by 60-80%, depending on the subject. “Just 1-in-4 CPS students can read or perform math at grade level,” the report says. “The percent of students enrolling in college after high school graduation is decreasing. And for those who do enroll, another study found many are struggling to finish college in four years – just 30% get their bachelor’s in four years compared to 47% nationally.”

    By every other measure… there’s no other way to put this… CPS is falling apart.

    • In 2023, 26% of students in grades 3 through 8 across all of CPS could read at grade level and about 18% could do math proficiently. For 11th grade CPS students, only 22% could read at grade level and 19% do math proficiently.
    • CPS’ failure to engage students shows in the chronic absenteeism rate. Chronic absenteeism has skyrocketed.
    • According to ISBE data, 86.3% of teachers in CPS were rated as proficient or excellent in 2023, down from 91.4% in 2019. Yet many students in CPS are struggling to reach proficiency in core subjects.

    There’s much more at the link, all of it tragic. An entire generation of Chicago students is failing — and being failed by their schools and, let’s be brutally honest, by their families.

    If you’re thinking that CPS must be seriously underfunded to achieve such dismal results, you must have been living in a cave for the last 40 or 50 years. CPS will spend a jaw-dropping $29,028 per student this year. My family lives in a lovely exurb of Colorado Springs and our district spends roughly one-third of what CPS does — $10,214 per student — and we get much better results. It isn’t about the money. It rarely is.

  • Turtle tank captured.
  • Another week, another series of Ukrainian strikes on Russia oil depots. First in Platanovka, Tambov region, some 500km from Ukraine…
  • …then the Lukoil Depot in Krasnodar, where fuel trucks were apparently targeted…
  • …and an oil export depot in Rostov-on-Don.
  • MS-13 Gang Leader Arrested in Texas. Cesar Humberto Lopez-Larios will be handed over to a New York court to face terrorism charges.”
  • Loper Bright Enterprises V. Raimondo offers the Supreme Court a way to roll back the Administrative State.

    The case began in November 2022, when Loper Bright Enterprises, a fishery based out of Cape May, New Jersey, appealed a district court opinion to the Supreme Court. The conflict between Loper Bright and the National Marine Fisheries Service (NMFS) started after the agency decided to require private fisheries like Loper Bright to pay their regulatory inspectors for their time observing fishery practices.

    While the law doesn’t explicitly allow this practice, the Fishery Service cites the Chevron Deference, a precedent set by a 1984 Supreme Court case, which states that an ambiguous law can be interpreted by government agencies as they see fit. In short, the Fishery Service wants private companies to pay their salaries and found a legal loophole to justify it.

    While this may seem like an isolated incident, it is just one example of a long history of government agencies infringing on individual liberty. The outcome of this case holds supreme importance for the future of our republic and the preservation of our financial and civil freedoms.

    Since 1950, the federal government has steadily grown in size. Today, it has over 2.9 million civilian employees, more than Walmart has worldwide. This growth has paved the way for the creation of a governmental pseudo-branch denoted the “administrative state.” The administrative state contains government employees who have a significant impact on people’s everyday lives but yet aren’t held accountable to citizens in the form of elections. These unelected bureaucrats undermine the central ethos of a republic, where elected officials are supposed to seek the good of their constituents or risk not being re-elected.

    The problem with this system was made evident during the pandemic. During the COVID shutdown, hundreds of millions of Americans were sentenced to lockdowns, impacting their schools, churches, and families. Many of the people behind this policy were members of the CDC, one of the government agencies that comprise the administrative state. The decisions they made were not subject to the traditional checks and balances which typically constrain the US government. Instead, America found itself under a tyranny of the unelected.

    This overreach extends beyond individual liberty into private business. When businesses can be encroached upon at a whim by unelected authorities, long-term investment becomes a much riskier endeavor. When the COVID shutdown occurred, many small businesses, with their small profit margins and high overhead, were unable to weather the storm. For the companies that survived, the blatant government intervention and the severe consequences that followed left a sour taste in their mouth for future capital investments. You’re not going to build a new business if a bureaucrat can shut it down the next day. All of these factors contribute to government agencies having a negative impact on financial markets and investor portfolios.

    The Chevron Deference precedent, which is at the center of Loper Bright Enterprises v. Raimondo, gives even more power to these governmental agencies. When ambiguity exists, this precedent allows courts to simply defer to agencies’ interpretations, even if those interpretations favor the agencies’ own interests. It also allows courts to seek out ambiguity in order to give near-unbridled power to these agencies.

    If the Supreme Court upholds Chevron, it will further entrench the power of unelected bureaucrats and make it increasingly difficult for individuals and businesses to challenge agency overreach. However, if the Court rules against Chevron, it would represent a shift toward increased restraint of the administrative state, leading to a reevaluation of the scope and authority of federal agencies.

  • Israeli arms exports hit record sales. Funny how having products that actually work stimulates sales. I’m betting Russia is enjoying the opposite right now…
  • Baseball game announcer: We will not be singing the national anthem. Crowd: The hell we won’t! Patriotism ensues.
  • Soros-backed Manhattan DA Alvin Braggs drops all charges against the pro-Hamas protestors who smashed up offices at Columbia. Because of course he did.
  • Speaking of DA’s behaving badly, a followup: Assistant Travis County DA Joseph Frederick, who was charged with aggravated assault, has resigned before he could be fired, his lawyer saying this was to maintain his health benefits, because he has Parkinson’s. Which is strange, because COBRA covers involuntary termination as well.
  • Argentine President Javier Milei has a glorious rant about how you can’t negotiate with leftists.
  • Brazilian thief pulls a gun in a phone store, instantly gets lit up like the 4th of July.
  • No surprise: San Francisco named America’s worst run city.
  • This week’s California restaurant chain closing due to the minimum wage hike: Arby’s. (Hat tip: Dwight.)
  • “CDK Global, a major software provider to auto dealerships in the U.S., has been hacked, forcing the company to shut down most of its systems temporarily. This cyberattack effectively halted sales operations at approximately 15,000 car dealerships, including those under General Motors, Group 1 Automotive, and Holman.” Without this software, there’s essential dead in the water. (More details.)
  • Man finds a GPS tracker his Toyota dealership installed in his car without telling him, despite him declining that option and despite not financing the car.
  • “MacKenzie Scott Gives Millions to Philly Nonprofit Tied to Anti-Israel Penn Encampment.” Scott is the woman who divorced Jeff Bezos.
  • Another week, another catch and release illegal alien child rapist.
  • Black San Francisco firefighter attacks Asian firefighter with a wrench. So San Francisco fires the Asian guy who was attacked.
  • CNN drops down to 396,000 Total Viewers. Why would any company still buy advertising on such a small platform? (Hat tip: Stephen Green at Instapundit.)
  • Speaking of money-losing MSM outlets, the incoming editor of the Washington Post says thanks but no thanks after the staff there preemptively published a hit piece on him. How’s that letting the inmates run the asylum working out for you, Jeff Bezos?
  • Ecomorons spread paint on Stonehenge.

  • George R. Nethercutt Jr., the Republican who ousted Democratic Speaker Thomas S. Foley in the Newt Gingrich Contract with America wave of 1994, dead at 79 (Hat tip: Dwight.)
  • Because tranny pandering is more important than actually healing people, Oregon moves to make reporting microaggressions mandatory for doctors.
  • Tubi, which is free, drew in more viewers than Disney+.
  • Morgan Freeman hates black history month. “My history is American history.”
  • Employees at small Philadelphia chain of three coffee shops unionize, and the owner immediately shuts them down because they’re no longer profitable.
  • Is olive oil good for your brain? I hope so, since it’s an Atkins-compliant dressing for my salad, so I generally get more than the recommended teaspoon a day.
  • Himmler’s top 10 pistols. Some went for pretty breathtaking sums at auction.
  • Another Metal Ball Studios monster height comparison video, but this one is first person.
  • “New Debate Rule Allows Moderators To Zap Trump With Giant Cattle Prods Anytime They Feel Like It.”
  • “Tropical Storm Alberto Crosses Into Texas, Immediately Registered To Vote As A Democrat.”
  • “God Confirms Heaven Will Bring All Nations, Tribes, And Tongues Together In Hatred Of The New York Yankees.”
  • Mine!

    (Hat tip: Ace of Spades HQ.)

  • Still between jobs, so hit the tip jar if you’re so inclined.





    NYTimes Hacked, Source Code Stolen

    Sunday, June 9th, 2024

    This seems like a story that should be getting a lot more coverage: The New York Times was evidently hacked and hundred of gigabytes of their source code released.

    An anonymous hacker has claimed to have leaked 270 GB of internal data and source code from The New York Times (NYT) on the controversial image board 4chan.

    The leak, reportedly containing over 5,000 repositories and 3.6 million files, was published on June 6, 2024. It has since raised widespread concern and speculation about the potential implications for the historic news organization.

    The hacker, who has not been identified, posted a magnet link to the files on 4chan, encouraging users to download and share the data. According to the hacker, the leaked collection comprises uncompressed tar files with fewer than 30 encrypted repositories.

    The leaked data reportedly contains a variety of source code, including the blueprints of well-known games like Wordle, email marketing campaigns, and ad reports. The hacker’s message was signed “With love from /aicg/,” a nod to a 4chan community.

    While the leak’s legitimacy has not been independently verified, cybersecurity experts and media outlets have expressed serious concerns. The Register reported that it had seen a list of files in the purported leak but had not confirmed their authenticity.

    Bryan Lunduke of The Lunduke Journal (who’s covered leaked/hacked material like this before) downloaded the files. He says they’re 334GB worth of files (maybe the size discrepancy is zipped vs unzipped) and thinks they’re real.

  • This dropped June 6.
  • “We are talking about a 334 gigabyte archive containing supposedly 3.6 million and some change files, individual source code files. Massive. Off-the-charts massive.”
  • He though it might just be every New York Times story ever published, but it doesn’t appear to be. Nor does it look like an email server dump.
  • “This is massive. It almost is making my brain hurt simply going through all of this.”
  • “I went through it. I read a bunch of it in depth. When I say a bunch of it, I mean I spent a long time on it and barely made a dent.”
  • “It truly does look to be over 3 something million source code files.”
  • “The first things I looked through were tremendously boring. It was just stupid JavaScript files dealing with Markdown.” JavaScript is a front-end programming language used for performing a huge variety of tasks in your browser. Markdown is an HTML-like text markup language used as a basis for rendering documents in a variety of different formats (standard web page, phone webpage, PDF, online help, etc.).
  • A lot of it appears to be internal website documents.
  • “It’s from a wide variety of stuff. I mean it’s all over the map. We’re talking onboarding documents and technical documents, hiring documents, switchboard documents, user attribute documents, a huge amount of documentation.”
  • Plus actual source code for iOS and Android applications.
  • Lunduke explains legal doctrine on leaked materials and reporting, saying he didn’t commit any crime to obtain the material, which should legally put him in the clear for talking about material therein relevant to the public interest. Normally I’d point out “Hacking is wrong, mkay,” but New York Times has itself published hacked/leaked/stolen material itself at least as far back as The Pentagon Papers, so this is a case of biter bit.
  • “There a reasonable assumption that publishing some of this leaked material would be of the public interest…There are a number of policies and other interesting things in place documented within this material that could be of the public interest.”
  • “This does appear to be real. I cannot fathom how all of this could have been created if it wasn’t real.” I am inclined to agree. But! It’s important to note that a real archive can be salted with false information for a variety of nefarious purposes, so caveat lector.
  • “It is an absolutely monstrous amount. Simply searching through it and scanning it is insane. There are over 5,000 individual mini-archives within this link each one appears to represent an individual source code repository, or at least a folder or subfolder within source code repositories.” He says it appears to be just the latest snapshot, and not all the versions you would find in a source code repository like GitHub.

  • The time stamps on the files look recent.
  • “Man, there’s some funky things going on here.”
  • I am most interested in how internal policies codify/enforce woke social justice priorities, if there are any special instructions for covering Donald Trump (or other Republicans), racial preferences in hiring policies, etc.

    I’m hoping for some juicy revelations…

    Does Malicious Backdoor Compromise SSH?

    Monday, April 1st, 2024

    A newly discovered backdoor found in the xz liblzma library of XZ Utils, the XZ format compression utilities included in most Linux distributions, targets the RSA implementation of OpenSSH.

    For those outside of tech, that sentence was an unreadable jumble of acronyms. For those inside tech, a chill probably ran down their spine, as those technologies are everywhere. Anytime anyone buys something online, they’re going to be using SSH to create a secure channel to pass transaction information. [As a commenter noted, SSH is a command tool rather than Secure Socket Layer (SSL), which is used for encrypted transactions. Mental typo. My bad. – LP.] Depending on how many distros are using that library, the consequence range from “bad” to “really, really bad.”

    Details:

    A vulnerability (CVE-2024-3094) in XZ Utils, the XZ format compression utilities included in most Linux distributions, may “enable a malicious actor to break sshd authentication and gain unauthorized access to the entire system remotely,” Red Hat warns.

    The cause of the vulnerability is actually malicious code present in versions 5.6.0 (released in late February) and 5.6.1 (released on March 9) of the xz libraries, which was accidentally found by Andres Freund, a PostgreSQL developer and software engineer at Microsoft.

    “After observing a few odd symptoms around liblzma (part of the xz package) on Debian sid installations over the last weeks (logins with ssh taking a lot of CPU, valgrind errors) I figured out the answer: The upstream xz repository and the xz tarballs have been backdoored,” he shared via the oss-security mailing list.

    According to Red Hat, the malicious injection in the vulnerable versions of the libraries is obfuscated and only included in full in the download package.

    “The Git distribution lacks the M4 macro that triggers the build of the malicious code. The second-stage artifacts are present in the Git repository for the injection during the build time, in case the malicious M4 macro is present,” they added.

    “The resulting malicious build interferes with authentication in sshd via systemd.”

    I’m just going to note for the record that a whole lot of longtime Linux programmers absolutely hated the introduction of systemd. I don’t have deep enough Linux chops to take a side in this controversy, or know whether systemd was a significant factor in allowing the exploit to work.

    Moving on:

    The malicious script in the tarballs is obfuscated, as are the files containing the bulk of the exploit, so this is likely no accident.

    “Given the activity over several weeks, the committer is either directly involved or there was some quite severe compromise of their system. Unfortunately the latter looks like the less likely explanation, given they communicated on various lists about the “fixes” [for errors caused by the injected code in v5.6.0],” Freund commented.

    One silver lining is that the problem doesn’t look to be as widespread as it could be.

    “Luckily xz 5.6.0 and 5.6.1 have not yet widely been integrated by Linux distributions, and where they have, mostly in pre-release versions.”

    Red Hat says that the vulnerable packages are present in Fedora 41 and Fedora Rawhide, and have urged users of those distros to immediately stop using them.

    “If you are using an affected distribution in a business setting, we encourage you to contact your information security team for next steps,” they said, and added that no versions of Red Hat Enterprise Linux (RHEL) are affected.

    Since Red Hat is usually the default for big E-commerce platforms, it looks like this exploit is merely “bad” rather than “really, really bad,” which means its not nearly as bad as, say, Log4J was. Your Amazons and eBays are probably safe from the exploit.

    The people who are likely going to be hurt by this exploit are mom and pop E-commerce sites using their webhost’s “build an E-commerce site using these easy tools” feature. The smaller the site, the more likely they’re using a free distro, some of which may have this vulnerability.

    Whatever the site, they should run an updated software composition analysis tool on stacks and build-chains to see if they’re vulnerable.

    Did Facebook Run A Man-in-The-Middle Hack Against Competitors?

    Thursday, March 28th, 2024

    Newly unsealed court documents accuse Facebook of running a man-in-the-middle attack against several competitors.

    At the request of CEO Mark Zuckerberg, Facebook officials developed a program called In-App Action Panel (IAAP) that they deployed in 2016 and which was in use through mid-2019, according to the documents, which include internal emails.

    The program utilized cyberattacks to intercept information from Snapchat, YouTube, and Amazon. The program then decrypted the information.

    “Facebook’s IAAP Program used nation-state-level hacking technology developed by the company’s Onavo team, in which Facebook paid contractors (including teens) to designate Facebook a trusted ‘root’ certificate authority on their mobile devices, then generated fake digital certificates to redirect secure Snapchat analytics traffic (and later, analytics from YouTube and Amazon) from Snapchat’s servers to Onavo’s; decrypted these analytics and used them for competitive gain, including to inform Facebook’s product strategy; reencrypted them; and sent them up to Snapchat’s servers as though it came straight from Snapchat’s app, with Facebook’s Social Advertising competitor none the wiser,” lawyers said in one of the documents.

    This is a clever attack in several ways. If you can create and get a program/device to accept a false signing certificate, you bypass having to break a company’s encryption altogether. The program trusts your fake certificate and creates a secure connection to your backend, using your encryption, thinking it’s transmitting information back to the targeted company. Also, analytics data doesn’t have to be sent and received in real time, so a significant delay in gather and receive times may not tip off the targeted company to the attack.

    None of this is a walk in the park, but it’s something like ten orders of magnitude easier than breaking the targeted company’s encryption stream on a live session to seamlessly hack it in real time, which is the sort of God-level hacking limited to those with NSA-level computing power, or fictional characters.

    The lawyers, representing plaintiffs in a lawsuit that accuses Facebook of anti-competitive behavior, were describing emails they obtained through discovery.

    In one email, Mr. Zuckerberg wrote that there was a need to receive information about Snapchat but that their traffic was encrypted. “Given how quickly they’re growing, it seems important to figure out a new way to get reliable analytics about them. Perhaps we need to do panels or write custom software. You should figure out how to do this,” he wrote.

    After Facebook employees started working on figuring it out, Facebook Chief Operating Officer Javier Olivan wrote that the program could pay users to “let us install a really heavy piece of software (that could even do man in the middle, etc.).”

    Man in the middle refers to a type of cyberattack where attackers secretly intercept information.

    More specifically, it’s where a third party successfully inserts itself into the communication stream between two other parties, relaying (and possibly altering) both ends of the communication without either party knowing.

    “We are going to figure out a plan for a lockdown effort during June to bring a step change to our Snapchat visibility. This is an opportunity for our team to shine,” Guy Rosen, founder of Onavo, later wrote. Onavo was started in Israel and bought by Facebook in 2013.

    In a presentation on the program when it was being finalized, it was stated that there would be “’kits” that can be installed on iOS and Android that intercept traffic for specific sub-domains, allowing us to read what would otherwise be encrypted traffic so we can measure in-app usage.”

    Documents and testimony obtained in the case showed the program was launched in June 2016 and continued being used through 2019.

    The program initially targeted Snapchat but was later expanded to Google’s YouTube and Amazon, according to the documents.

    A few quick points:

    1. This is all from Snapchat’s court documents, so you have to put an “allegedly” on all this.
    2. If all the allegations are true, Facebook has just broken all sorts of federal anti-hacking laws, including the Computer Fraud and Abuse Act (CFAA), the Electronic Communications Privacy Act (ECPA), the Identity Theft and Assumption Deterrence Act, and probably half a dozen more I haven’t even thought of.
    3. That Zuckerberg himself is (allegedly) directly implicated in deliberately breaking federal law is pretty breathtaking. He could be looking at serious jail time. Or would be, if he weren’t such a big Democratic Party Donor. (We’ll see how much time Sam Bankman-Fried catches today.)
    4. Snapchat is one thing, but targeting fellow tech behemoths Google (which owns YouTube) and Amazon with this sort of attack would seem to be…unwise. (Maybe Google’s forgiveness was covered in the secret deal the two companies allegedly signed with each other.)
    5. The timeframe is important here. Back in 2016-2019, the handling of digital signing certificates was a lot more loosey-goosey than it is now. A whole lot of things have been tightened up. I wouldn’t say it’s impossible to carry out such an attack now, but it would be harder.

    We’ll see if the whole thing jumps from litigation land to the feds actually going after Facebook, but at a time when Facebook is being sued by all manner of plaintiffs (including Texas and other state attorney generals) over privacy violations and anti-competitive practices, the Snapchat revelations could certainly provide more fuel for the fire…

    Scenes From The Cyberwar In Ukraine

    Tuesday, January 9th, 2024

    The front lines in Ukraine have been static for the last few months, with Russia grinding away in Avdiivka to little effect and Ukraine having failed to effect further advances. However, there are a few snippets of interest from the ongoing cyberwar, on both sides. I thought it worth taking a look at.

  • First, Russia claimed a successful, long-running penetration of Ukrainian a telecom service.

    Over nearly a decade, the hacker group within Russia’s GRU military intelligence agency known as Sandworm has launched some of the most disruptive cyberattacks in history against Ukraine’s power grids, financial system, media, and government agencies. Signs now point to that same usual suspect being responsible for sabotaging a major mobile provider for the country, cutting off communications for millions and even temporarily sabotaging the air raid warning system in the capital of Kyiv.

    On Tuesday, a cyberattack hit Kyivstar, one of Ukraine’s largest mobile and internet providers. The details of how that attack was carried out remain far from clear. But it “resulted in essential services of the company’s technology network being blocked,” according to a statement posted by Ukraine’s Computer Emergency Response Team, or CERT-UA.

    Kyivstar’s CEO, Oleksandr Komarov, told Ukrainian national television on Tuesday, according to Reuters, that the hacking incident “significantly damaged [Kyivstar’s] infrastructure [and] limited access.”

    “We could not counter it at the virtual level, so we shut down Kyivstar physically to limit the enemy’s access,” he continued. “War is also happening in cyberspace. Unfortunately, we have been hit as a result of this war.”

    The Ukrainian government hasn’t yet publicly attributed the cyberattack to any known hacker group—nor have any cybersecurity companies or researchers. But on Tuesday, a Ukrainian official within its SSSCIP computer security agency, which oversees CERT-UA, pointed out in a message to reporters that a group known as Solntsepek had claimed credit for the attack in a Telegram post, and noted that the group has been linked to the notorious Sandworm unit of Russia’s GRU.

  • But pro-Ukrainian hackers have managed to strike back, by breaching a Russian Internet provider.

    The pro-Ukrainian hacker group Blackjack is claiming that it breached a Moscow internet provider to seek revenge for a Russian cyberattack on Ukraine’s largest telecom company, Kyivstar.

    The attack on M9com was carried out in cooperation with Ukraine’s security forces (SBU), said a source in Ukraine’s law enforcement agency who requested anonymity because he is not authorized to speak publicly about the incident.

    There isn’t much information available about the attack, and the SBU’s role in the operation. Hackers said Monday on their Telegram channel that they will reveal more details soon. So far, the only confirmation of the incident they have provided includes screenshots of the allegedly hacked systems of the internet provider.

    The group also published some of the data obtained during the hack on a darknet site accessible via the Tor browser.

    The time frame of the attack on M9com is unclear, but as of the time of writing, the allegedly hacked website is up and running. There has been no mention of the operator’s shutdown in the Russian media or on its official website. The company has not replied to requests for comment.

    This is not the first time Ukrainian civilian hackers have allegedly cooperated with security services to attack Russian organizations. In an incident publicized in October, two groups of pro-Ukrainian hackers and the SBU claimed to have breached Russia’s largest private bank, Alfa-Bank.

  • Ukrainian hackers also announced that they hacked Russia’s tax systems.

    The Ukrainian government’s military intelligence service says it hacked the Russian Federal Taxation Service (FNS), wiping the agency’s database and backup copies.

    Following this operation, carried out by cyber units within Ukraine’s Defence Intelligence, military intelligence officers breached Russia’s federal taxation service central servers and 2,300 regional servers across Russia and occupied Ukrainian territories.

    The breach led to all compromised FTS servers being infected with malware, as well as the hacking of a Russian IT company that provides FNS with data center services.

    The attack also reportedly resulted in the complete deletion of configuration files crucial for the functionality of Russia’s extensive taxation system, wiping out both the main database and its backup copies

    As Ukraine’s Main Directorate of Intelligence (GUR) says, the repercussions of the cyberattack have been severe, causing a breakdown in communication between Moscow’s central office and the 2,300 territorial departments that also got hacked in the attack.

    It has led to a virtual collapse of one of Russia’s vital governmental agencies with a significant loss of tax-related data, according to GUR, as well as tax data-related internet traffic across Russia falling into the hands of Ukraine’s military hackers, as The Record first reported.

    If this is true, it will take quite some time to get tax collections up and running again. And the inability to collect taxes will severely hamper Russia’s ability to finance the war.

  • Speaking of the Alfa-Bank hack, just recently Ukrainian hackers announced that they made all their data available online.

    The Ukrainian hacker group Kiborg has made the entire client base of the Russian Alfa Bank publicly available.

    Kiborg hackers, acting in collaboration with NLB hackers, gained access to the customer database in October 2023 and exposed information about 44,000 customers.

    The database contains information on the names, dates of birth, phone numbers, cards and accounts of 38 million unique individuals and legal entities.

    The Vazhnyye Istorii (Important Stories) website clarified that this includes over 24 million customer accounts and over 13 million more data on legal entities.

  • Both sides have struck cyberblows against the other, but Ukraine seems to have done more damage to Russia than vice-versa this week.

    Russo-Ukranian War Update for June 22, 2022

    Wednesday, June 22nd, 2022

    The general course of the Russio-Ukrainian War seems the same (Russia grinding out slow gains in the Severodonetsk front, while Ukraine gains back territory on the wings near Kharkiv and Kherson), but there are a lot of interesting stories out on the periphery of the conflict.

    First, the requisite map snap:

    (These snapshots are not the end-all and be-all of the situation, but back when I was covering the war against the Islamic State, I found that they were helpful in jogging my memory reviewing the course of the war at later dates.)

    Now some links:

  • ISW’s assessment.

    Members of the Russian military community continue to comment on the shortcomings of Russian force generation capabilities, which are having tangible impacts on the morale and discipline of Russians fighting in Ukraine. Russian milblogger Yuri Kotyenok claimed that Russian troops lack the numbers and strength for success in combat in Ukraine. Kotyenok accused Russian leadership of deploying new and under-trained recruits and called for replenishment of forces with well-trained recruits with ground infantry experience—though the Russian military is unlikely to be able to quickly generate such a force, as ISW has previously assessed. Despite growing calls for increased recruitment from nationalist figures, Russian leadership continues to carry out coercive partial mobilization efforts that are only producing limited numbers of replacements while negatively impacting the morale and discipline of forcibly mobilized personnel. Ukraine’s Security Service (SBU) claimed that Russian authorities in Luhansk are arranging gas leaks in apartment buildings to force men who are hiding from mobilization into the streets. The Ukrainian Main Intelligence Directorate (GUR) additionally reported that Russian soldiers in occupied Tokmak, Zaporizhia Oblast, are appealing to local Ukrainian doctors to issue them certificates alleging medical inability to continue military service.

    Ukrainian forces conducted a drone strike (likely with a loitering munition, though this cannot be confirmed) on a Russian oil refinery in Novoshakhtinsk, Rostov Oblast, on June 22. Russian Telegram channel Voenyi Osvedomitel claimed that the strike, which targeted Russian infrastructure within 15 km of the Ukrainian border, originated from Donetsk Oblast. Ukrainian forces have not targeted Russian infrastructure for several weeks, and this strike is likely an attempt to disrupt Russian logistics and fuel supply to Russian operations in eastern Ukraine.

    Though they also note that Russia has been using its anti-air capabilities to better deal with Ukrainian drones.

  • Ukraine attacked long-occupied gas platforms off the coast of Crimea. It also reportedly hit occupied Snake Island, though there seems to be some dispute over this.
  • Did a Russian cyberattack trigger the Freeport LNG explosion on June 8?

    Well, a June 14 press release from Freeport LNG notes that “the incident occurred in pipe racks that support the transfer of LNG from the facility’s LNG storage tank area to the terminal’s dock facilities. … Preliminary observations suggest that the incident resulted from the overpressure and rupture of a segment of an LNG transfer line, leading to the rapid flashing of LNG and the release and ignition of the natural gas vapor cloud. Additional investigation is underway to determine the underlying precipitating events that enabled the overpressure conditions in the LNG piping.” The statement added that federal authorities were assisting with its investigation.

    However, what was not explained is how a critical overpressure event could have occurred without safety systems kicking into action. Two LNG pipeline experts I talked to, who both asked to remain anonymous due to potential retaliatory damage to their business interests, say that pipeline corrosion and other material failures can cause critical incidents. Still, the FBI’s investigative involvement, the specific nature of this explosion, and the scale of damage incurred do raise major questions. The experts suggested that piping from a storage tank to a terminal, as in this explosion, should have extensive safeguards to prevent overpressure events. One expert was highly confident that control of pipeline flows would be undertaken from a networked control facility.

    That brings us to the Russian cyber unit involved in the targeting reconnaissance against Freeport LNG.

    Named XENOTIME by researchers, the unit has utilized boutique TRITON/TRISIS malware developed by the Russian Ministry of Defense’s Central Scientific Research Institute of Chemistry and Mechanics. That malware is designed for the seizure of industrial control systems and the defeat of associated safety systems. In 2017, GCHQ (Britain’s NSA-equivalent signals intelligence service) outlined the need for network compartmentalization to protect safety systems against this malware better. In March 2022, the FBI warned that TRISIS malware remained a threat.

    XENOTIME is assessed by the U.S. and British governments as a critical infrastructure-focused, advanced persistent threat actor. The unit’s modus operandi involves targeting industrial control systems and supervisory control systems in order to effect unilateral control of a network. XENOTIME has caused specific concern in Western security circles for its targeting of safety systems that would otherwise mitigate threats to life during a cyberattack. XENOTIME’s activity has escalated in 2022. Evincing as much, an April 13 U.S. government cybersecurity warning noted, “By compromising and maintaining full system access to [industrial control system]/[safety] devices, [threat] actors could elevate privileges … and disrupt critical devices or functions.”

    Snip.

    While the Freeport LNG explosion remains under investigation, multiple sources told me they were struck by the overpressure event along a key pipeline transit route and the evident failure of safety systems to engage. This fits with XENOTIME’s modus operandi.

    That’s an “interesting but unproven” in my book… (Hat tip: Jim Geraghty at NRO.)

  • Switzerland Imports Russian Gold for First Time Since War.”

    More than 3 tons of gold was shipped to Switzerland from Russia in May, according to data from the Swiss Federal Customs Administration. That’s the first shipment between the countries since February.

    The shipments represent about 2% of gold imports into the key refining hub last month. It may also mark a change in perception of Russian bullion, which became taboo following the invasion. Most refiners swore off accepting new gold from Russia after the London Bullion Market Association removed the country’s own fabricators from its accredited list.

    While that was viewed as a de facto ban on fresh Russian gold from the London market, one of the world’s biggest, the rules don’t prohibit Russian metal from being processed by other refiners. Switzerland is home to four major gold refineries, which together handle two-thirds of the world’s gold.

    Almost all of the gold was registered by customs as being for refining or other processing, indicating one of the country’s refineries took it. The four largest — MKS PAMP SA, Metalor Technologies SA, Argor-Heraeus SA and Valcambi SA — said they did not take the metal.

    In March, at least two major gold refineries refused to remelt Russian bars even though market rules permit them to do so. Others, such Argor-Heraeus, said they would accept products refined in Russia prior to 2022, so long as there were documents proving that the gold had not been exported from Russia after beginning of the war, and that accepting them would not benefit Russia, a Russian person or entity anywhere in the world.

  • Though this piece is two weeks old, Frederick Kagan is not impressed with Russia’s Severodonetsk offensive.

    he fight for Severodonetsk is a Russian information operation in the form of a battle. One of its main purposes for Moscow is to create the impression that Russia has regained its strength and will now overwhelm Ukraine. That impression is false. The Russian military in Ukraine is increasingly a spent force that cannot achieve a decisive victory if Ukrainians hold on.

    Russian President Vladimir Putin is therefore trying to turn his invasion of Ukraine into a brutal contest of wills. He’s betting his army on breaking Ukrainians’ collective will to fight on in their country. His own won’t likely break. Fortunately, Ukraine doesn’t need it to. If Ukrainians can weather the current Russian storm and then counterattack the exhausted Russian forces they still have every chance to free their people and all their land.

    Putin amassed the wreckage of Russian combat forces into a lethal amalgam around the cities of Severodonetsk and Lysychansk in Ukraine’s eastern Luhansk Oblast. That amalgam is crawling forward using massive artillery barrages to obliterate everything in its path allowing Russia’s demoralized and frightened soldiers to walk into the rubble.

    The Ukrainian defenders are wisely withdrawing in the face of this reckless barbarism, but at a high price to their own morale and their will to continue the fight. Ukrainian soldiers and citizens are criticizing their government for not supporting the troops on the front lines. Ukrainians are starting to doubt that they can prevail for the first time since they won the Battle of Kyiv. Delays in the provision of Western aid and refusals by the U.S. and other countries to provide certain needed weapons systems are helping to fuel those doubts. And now voices are rising in the West calling on Ukraine to offer concessions.

    All of which is exactly what Putin needs. He cannot defeat Ukraine militarily as long as Ukrainians retain the will to fight and the West the will to back them. So he attacks the will of both by forcing his own troops into the most vicious and brutal offensive of this war, hoping to persuade everyone that he’s finally harnessed the mass and power of Russia that Stalin wielded to defeat Hitler—and thus that resistance to his demands is futile. Putin also holds hostage critical export supplies of Ukrainian food and fuel, hoping to impose high enough costs on the West to persuade it to abandon Ukraine.

    Neither Ukrainians nor their friends around the world must give in to Putin or be deluded by the current mirage of Russian success and power he is presenting in the Battle of Severodonetsk. For mirage it is. Russia’s drive in Luhansk is the desperate gamble of a dictator staking the last of the offensive combat power he can scrape together in hopes of breaking his enemies’ will to continue the fight. and let him claim that he’s taken all of Luhansk Oblast. It is a historical rhyme with Hitler’s determination to seize Stalingrad in 1942 or to hold Kharkov in defiance of his commander’s advice. There are no Russian large reserves coming behind this force to carry its successes forward. On the contrary, Putin has created it only by denuding other key axes of the forces they need to defend against Ukrainian counterattacks. This offensive will likely culminate soon because even this slow, grinding advance will exhaust the forces conducting it. Putin will then be unable to launch another for quite some time.

  • I thought this would be a longer update, but I’m running out of day…

    Russo-Ukrainian War Update for March 8, 2022

    Tuesday, March 8th, 2022

    At this point, there seems to be no indication that Russian forces are measurably closer to their goal of controlling all of Ukraine.

    Here’s a LiveMap snapshot.

    From a pure strategic viewpoint, those Russian tendrils snaking toward Kiev from the northeast look like a bad idea, since there’s no way to protect their supply lines.

    (Always remember that the map is not the territory, and that both sides are working hard to put out propaganda, though the Russians seem to be manifestly incompetent at it.)

  • Here’s a fascinating thread reportedly leaked from an active Russian FSB (successor to the KGB) analyst about how badly everything is screwed up.

    I assume that’s Ramzan Kadyrov, corrupt head of the Chechen Republic, former resistance fighter against Russia who defected in 1999 and was appointed by Putin in 2007. Bit of a jihadist scumbag to boot, and just a generally nasty piece of work. I assume by “Kadyrov’s squad” they mean the Kadyrovtsy, the militia forces under his direct control.

    Some tweets about who could they even get post-Zelensky to sign a treaty (Medvechuk? Tsaryova? Yanukovich?) snipped.

    I don’t agree with every conclusion (I doubt the war will produce worldwide famine), but it’s still worth reading the whole thread.

  • Cheap Chinese tires blamed for Russian convoy unable to reach Kyiv.”

    Cheap Chinese tires have been blamed for a Russian convoy of armoured vehicles being unable to reach Kyiv.

    Yesterday, the Ministry of Defence issued an update revealing that a convoy of Russian tanks advancing on the capital of Ukraine remained 30km from the centre of the city having made little progress over the previous three days because of “Ukranian resistance, mechanical breakdown and congestion.”

    Karl Muth, an academic based at the University of Chicago and a self-described tire expert, took to Twitter to set out a theory blaming cheap Chinese tires for the slow advance of Russian vehicles.

    “Those aren’t Soviet-era heavy truck radials,” Muth said, commenting on a photo of a Russian army vehicle with ripped tires.

    Instead Muth believes the trucks use “Chinese military tires, and I believe specifically the Yellow Sea YS20.”

    “This is a tire I first encountered in Somalia and Sudan. it’s a bad Chinese copy of the excellent Michelin XZL military tire design,” he continued.

    Former pentagon staff member Trent Telenko also got stuck into the debate and said “poor Russian army truck maintenance practices” has created a risk of equipment failure.

    “When you leave military truck tires in one place for months on end. The side walls get rotted/brittle such that using low tire pressure setting for any appreciable distance will cause the tires to fail catastrophically via rips,” Telenko said.

  • Morgan Stanley analyst says that Russia is heading toward debt default as soon as April 15. Those are dollar-denominated bonds, which means they can’t be paid with devalued rubles.
  • Hundreds Of Thousands Of Global Hackers Are Banding Together To Disrupt Russian Military, Banking And Communication Networks.

    There are reportedly more than 400,000 “volunteer hackers” helping Ukraine fight its cyberwar against Russia.

    Victor Zhora, deputy chief of Ukraine’s information protection service, told Bloomberg last week that Ukraine was putting up a “cyber resistance” against its invasion that would work to try and weaken Russia.

    Zhora said: “Our friends, Ukrainians all over globe, [are] united to defend our country in cyberspace. [Ukraine is working to do] everything possible to protect our land in cyberspace, our networks, and to make the aggressor feel uncomfortable with their actions.”

    He also said that volunteers were helping Ukraine obtain intelligence in order to fight back at Russian military systems.

    They are also trying to get the message out to Russian citizens, who have been Fed a starkly different narrative from their government than the rest of the world has seen play out. Volunteers are working to “address Russian people directly by phone calls, by emails, by messages” and “by putting texts on their services and showing real pictures of war.”

    There aren’t 400,000 real hackers around the world. But 10,000 hackers and 390,000 script kiddies can sill do a lot of damage…

  • What breaks first?

    The Russian invasion of Ukraine will end when one or more of four things breaks:

    • the Russian supply lines;
    • the Ukrainian ability to effectively resist;
    • the Russian economy;
    • the patience of some armed individuals around Putin.

    We’re already seeing a lot of the first and third…

  • Is the Russian air force incapable of complex operations?

    More than a week into the Russian invasion of Ukraine, the Russian Air Force has yet to commence large-scale operations. Inactivity in the first few days could be ascribed to various factors, but the continued absence of major air operations now raises serious capability questions.

    One of the greatest surprises from the initial phase of the Russian invasion of Ukraine has been the inability of the Russian Aerospace Forces (VKS) fighter and fighter-bomber fleets to establish air superiority, or to deploy significant combat power in support of the under-performing Russian ground forces. On the first day of the invasion, an anticipated series of large-scale Russian air operations in the aftermath of initial cruise- and ballistic-missile strikes did not materialise. An initial analysis of the possible reasons for this identified potential Russian difficulties with deconfliction between ground-based surface-to-air missile (SAM) batteries, a lack of precision-guided munitions and limited numbers of pilots with the requisite expertise to conduct precise strikes in support of initial ground operations due to low average VKS flying hours. These factors all remain relevant, but are no longer sufficient in themselves to explain the anaemic VKS activity as the ground invasion continues into its second week. Russian fast jets have conducted only limited sorties in Ukrainian airspace, in singles or pairs, always at low altitudes and mostly at night to minimise losses from Ukrainian man-portable air defence systems (MANPADS) and ground fire.

    Snip.

    While the early VKS failure to establish air superiority could be explained by lack of early warning, coordination capacity and sufficient planning time, the continued pattern of activity suggests a more significant conclusion: that the VKS lacks the institutional capacity to plan, brief and fly complex air operations at scale. There is significant circumstantial evidence to support this, admittedly tentative, explanation.

    First, while the VKS has gained significant combat experience in complex air environments over Syria since 2015, it has only operated aircraft in small formations during those operations. Single aircraft, pairs or occasionally four-ships have been the norm. When different types of aircraft have been seen operating together, they have generally only comprised two pairs at most. Aside from prestige events such as Victory Day parade flypasts, the VKS also conducts the vast majority of its training flights in singles or pairs. This means that its operational commanders have very little practical experience of how to plan, brief and coordinate complex air operations involving tens or hundreds of assets in a high-threat air environment. This is a factor that many Western airpower specialists and practitioners often overlook due to the ubiquity of complex air operations – run through combined air operations centres – to Western military operations over Iraq, the Balkans, Libya, Afghanistan and Syria over the past 20 years.

    Second, most VKS pilots get around 100 hours’ (and in many cases less) flying time per year – around half of that flown by most NATO air forces. They also lack comparable modern simulator facilities to train and practise advanced tactics in complex environments. The live flying hours which Russian fighter pilots do get are also significantly less valuable in preparing pilots for complex air operations than those flown by NATO forces. In Western air forces such as the RAF and US Air Force, pilots are rigorously trained to fly complex sorties in appalling weather, at low level and against live and simulated ground and aerial threats. To pass advanced fast jet training they must be able to reliably do this and still hit targets within five to ten seconds of the planned time-on-target. This is a vital skill for frontline missions to allow multiple elements of a complex strike package to sequence their manoeuvres and attacks safely and effectively, even when under fire and in poor visibility. It also takes a long time to train for and regular live flying and simulator time to stay current at. By contrast, most VKS frontline training sorties involve comparatively sterile environments, and simple tasks such as navigation flights, unguided weapon deliveries at open ranges, and target simulation flying in cooperation with the ground-based air-defence system. Russia lacks access to a training and exercise architecture to rival that available to NATO air forces, which routinely train together at well-instrumented ranges in the Mediterranean, North Sea, Canada and the US. Russia also has no equivalent to the large-scale complex air exercises with realistic threat simulation which NATO members hold annually – the most famous of which is Red Flag. As such, it would be unsurprising if most Russian pilots lack the proficiency to operate effectively as part of large, mixed formations executing complex and dynamic missions under fire.

    Third, if the VKS were capable of conducting complex air operations, it should have been comparatively simple for them to have achieved air superiority over Ukraine. The small number of remaining Ukrainian fighters, conducting heroic air-defence efforts over their own cities, are forced to operate at low altitudes due to long-range Russian SAM systems and consequently have comparatively limited situational awareness and endurance. They ought to be relatively easily to overwhelm for the far more numerous, better armed and more advanced VKS fighters arranged around the Ukrainian borders. Ukrainian mobile medium- and short-range SAM systems such as SA-11 and SA-15 have had successes against Russian helicopters and fast jets. However, large Russian strike aircraft packages flying at medium or high altitude with escorting fighters would be able to rapidly find and strike any Ukrainian SAMs which unmasked their position by firing at them. They would lose aircraft in the process, but would be able to attrit the remaining SAMs and rapidly establish air superiority.

    Russia has every incentive to establish air superiority, and on paper should be more than capable of doing so if it commits to combat operations in large, mixed formations to suppress and hunt down Ukrainian fighters and SAM systems. Instead, the VKS continues to only operate in very small numbers and at low level to minimise the threat from the Ukrainian SAMs. Down low, their situational awareness and combat effectiveness is limited, and they are well within range of the MANPADS such as Igla and Stinger which Ukrainian forces already possess. The numbers of MANPADS are also increasing, as numerous Western countries send supplies to beleaguered Ukrainian forces. To avoid additional losses to MANPADS, sorties continue to be primarily flown at night, which further limits the effectiveness of their mostly unguided air-to-ground weapons.

    (Hat tip: Chuck Moss.)

  • How Russian propaganda has sold some of the Russian people on Project Z. But Russian troops are finding things quite a different story. Warning: Bodies, and at about 18 seconds in one, I think strewn body parts:

  • Report that Russian special forces are furious with Putin.

    “Sources have been telling me, sources that are well connected to the Russian Security Services, that the offensive is not going well, that some special forces, the Russian Spetsnaz, are furious because they have been sent into battle without proper support, and many of them have been killed. They say that the national guard forces and the regular army, the national guard forces include those Chechen units, that two of them are not coordinating on the field. And that the overall battle plan is somewhat disjointed in that it’s partly a plan for war and partly a plan for peacekeeping and so-called de-Nazification of this country. And it has led to a lack of cohesion,” Engel reported.

    “A lot of this goes back to the man who’s behind it all, Vladimir Putin, who I’m told is now increasingly isolated, is just taking advice from his inner circle, that there are only about three people who matter right now,” Engel continued. “And that speech, you mentioned it a short while ago, that Putin gave yesterday — bizarre location, speaking at Aeroflot, to a group of flight attendants. He sounded incredibly angry. He sounded detached. He was talking about how the Ukrainians here are machine-gunning people, that they’re driving around in cars packed with explosives, jihadi-style. And he went very deep and repeatedly on this theme that they’re fighting against the Nazis. It was the angriest I’ve ever seen him.”

    This is from a couple of days ago. Have Spetsnaz pissed off at you doesn’t seem like a good long-term survival strategy for a Russian leader. On the other hand, this report probably deserves some skepticism, since it fits too easily into what we would like to hear about the situation, so some salt is in order. (Hat tip: Director Blue.)

  • “Ukraine says it has RE-TAKEN Chuhuiv city and killed two high-ranking Russian commanders during the battle.” (Hat tip: Instapundit.)
  • After nearly two weeks of criticism, the Biden Administration just announced a ban on Russian oil and gas purchases.
  • “A Complete Summary Of All Russia Sanctions And Developments.” Read on for exciting blow-by-blow summaries of foreign exchange surcharges and debt repayment details…
  • Russia may nationalize foreign-owned factories.
  • Aeroflot stops flying to foreign destinations to keep most of their leased airliners from being repossessed.
  • What rolls down stairs/alone and in pairs/and up-armors your Russian truck? Caveat: They call this improvised armor, but it could also be on-hand materials for traction in muddy areas.
  • “Russia-Ukraine war to cripple semiconductor industry globally.” Ukraine supplies a lot of neon, which is used as a carrier gas in certain wavelength DUV lasers in photolithography. (Details here.)
  • Ukraine President Zelenskyy sounds like he may be ready to negotiate.