Posts Tagged ‘GRU’

Scenes From The Cyberwar In Ukraine

Tuesday, January 9th, 2024

The front lines in Ukraine have been static for the last few months, with Russia grinding away in Avdiivka to little effect and Ukraine having failed to effect further advances. However, there are a few snippets of interest from the ongoing cyberwar, on both sides. I thought it worth taking a look at.

  • First, Russia claimed a successful, long-running penetration of Ukrainian a telecom service.

    Over nearly a decade, the hacker group within Russia’s GRU military intelligence agency known as Sandworm has launched some of the most disruptive cyberattacks in history against Ukraine’s power grids, financial system, media, and government agencies. Signs now point to that same usual suspect being responsible for sabotaging a major mobile provider for the country, cutting off communications for millions and even temporarily sabotaging the air raid warning system in the capital of Kyiv.

    On Tuesday, a cyberattack hit Kyivstar, one of Ukraine’s largest mobile and internet providers. The details of how that attack was carried out remain far from clear. But it “resulted in essential services of the company’s technology network being blocked,” according to a statement posted by Ukraine’s Computer Emergency Response Team, or CERT-UA.

    Kyivstar’s CEO, Oleksandr Komarov, told Ukrainian national television on Tuesday, according to Reuters, that the hacking incident “significantly damaged [Kyivstar’s] infrastructure [and] limited access.”

    “We could not counter it at the virtual level, so we shut down Kyivstar physically to limit the enemy’s access,” he continued. “War is also happening in cyberspace. Unfortunately, we have been hit as a result of this war.”

    The Ukrainian government hasn’t yet publicly attributed the cyberattack to any known hacker group—nor have any cybersecurity companies or researchers. But on Tuesday, a Ukrainian official within its SSSCIP computer security agency, which oversees CERT-UA, pointed out in a message to reporters that a group known as Solntsepek had claimed credit for the attack in a Telegram post, and noted that the group has been linked to the notorious Sandworm unit of Russia’s GRU.

  • But pro-Ukrainian hackers have managed to strike back, by breaching a Russian Internet provider.

    The pro-Ukrainian hacker group Blackjack is claiming that it breached a Moscow internet provider to seek revenge for a Russian cyberattack on Ukraine’s largest telecom company, Kyivstar.

    The attack on M9com was carried out in cooperation with Ukraine’s security forces (SBU), said a source in Ukraine’s law enforcement agency who requested anonymity because he is not authorized to speak publicly about the incident.

    There isn’t much information available about the attack, and the SBU’s role in the operation. Hackers said Monday on their Telegram channel that they will reveal more details soon. So far, the only confirmation of the incident they have provided includes screenshots of the allegedly hacked systems of the internet provider.

    The group also published some of the data obtained during the hack on a darknet site accessible via the Tor browser.

    The time frame of the attack on M9com is unclear, but as of the time of writing, the allegedly hacked website is up and running. There has been no mention of the operator’s shutdown in the Russian media or on its official website. The company has not replied to requests for comment.

    This is not the first time Ukrainian civilian hackers have allegedly cooperated with security services to attack Russian organizations. In an incident publicized in October, two groups of pro-Ukrainian hackers and the SBU claimed to have breached Russia’s largest private bank, Alfa-Bank.

  • Ukrainian hackers also announced that they hacked Russia’s tax systems.

    The Ukrainian government’s military intelligence service says it hacked the Russian Federal Taxation Service (FNS), wiping the agency’s database and backup copies.

    Following this operation, carried out by cyber units within Ukraine’s Defence Intelligence, military intelligence officers breached Russia’s federal taxation service central servers and 2,300 regional servers across Russia and occupied Ukrainian territories.

    The breach led to all compromised FTS servers being infected with malware, as well as the hacking of a Russian IT company that provides FNS with data center services.

    The attack also reportedly resulted in the complete deletion of configuration files crucial for the functionality of Russia’s extensive taxation system, wiping out both the main database and its backup copies

    As Ukraine’s Main Directorate of Intelligence (GUR) says, the repercussions of the cyberattack have been severe, causing a breakdown in communication between Moscow’s central office and the 2,300 territorial departments that also got hacked in the attack.

    It has led to a virtual collapse of one of Russia’s vital governmental agencies with a significant loss of tax-related data, according to GUR, as well as tax data-related internet traffic across Russia falling into the hands of Ukraine’s military hackers, as The Record first reported.

    If this is true, it will take quite some time to get tax collections up and running again. And the inability to collect taxes will severely hamper Russia’s ability to finance the war.

  • Speaking of the Alfa-Bank hack, just recently Ukrainian hackers announced that they made all their data available online.

    The Ukrainian hacker group Kiborg has made the entire client base of the Russian Alfa Bank publicly available.

    Kiborg hackers, acting in collaboration with NLB hackers, gained access to the customer database in October 2023 and exposed information about 44,000 customers.

    The database contains information on the names, dates of birth, phone numbers, cards and accounts of 38 million unique individuals and legal entities.

    The Vazhnyye Istorii (Important Stories) website clarified that this includes over 24 million customer accounts and over 13 million more data on legal entities.

  • Both sides have struck cyberblows against the other, but Ukraine seems to have done more damage to Russia than vice-versa this week.

    Clinton Corruption Update for April 24, 2019

    Wednesday, April 24th, 2019

    No one expects the unexpected return of the Clinton Corruption Update! Surprise is one of our chief weapons…

    With the Mueller document clearing away the cobwebs of the Russian collusion fantasy, we can finally focus on the other half of the scandularity. There’s news on the Clinton Corruption front, namely the recovery of still more Hillary emails:

    Judicial Watch announced today that a senior FBI official admitted, in writing and under oath, that the agency found Clinton email records in the Obama White House, specifically, the Executive Office of the President. The FBI also admitted nearly 49,000 Clinton server emails were reviewed as result of a search warrant for her material on the laptop of Anthony Weiner.

    E.W. (Bill) Priestap, assistant director of the FBI Counterintelligence Division, made the disclosure to Judicial Watch as part of court-ordered discovery into the Clinton email issue.

    U.S District Court Judge Royce Lamberth ordered Obama administration senior State Department officials, lawyers, and Clinton aides, as well as Priestap, to be deposed or answer writer questions under oath. The court ruled that the Clinton email system was “one of the gravest modern offenses to government transparency.”

    Priestap was asked by Judicial Watch to identify representatives of Hillary Clinton, her former staff, and government agencies from which “email repositories were obtained.” Priestap responded with the following non-exhaustive list:

    • Bryan Pagliano
    • Cheryl Mills
    • Executive Office of the President [Emphasis added]
    • Heather Samuelson
    • Jacob Sullivan
    • Justin Cooper
    • United States Department of State
    • United States Secret Service
    • Williams & Connolly LLP

    Who knew that so many people enjoyed Hillary’s recipes and yoga tips?

    Priestap, is serving as assistant director of the FBI’s counterintelligence division and helped oversee both the Clinton email and the 2016 presidential campaign investigations. Priestap testified in a separate lawsuit that Clinton was the subject of a grand jury investigation related to her BlackBerry email accounts.

    “This astonishing confirmation, made under oath by the FBI, shows that the Obama FBI had to go to President Obama’s White House office to find emails that Hillary Clinton tried to destroy or hide from the American people.” said Judicial Watch President Tom Fitton. “No wonder Hillary Clinton has thus far skated – Barack Obama is implicated in her email scheme.”

    The complete text of Priestap’s response is here.

    Now some other Clinton Corruption news that’s been cooking on the back burner for a while:

  • “FEC Records Indicate Hillary Campaign Illegally Laundered $84 Million.” That’s the DNC scheme we’ve covered before. Also, a familiar name shows up in the story:

    Dan Backer, a campaign-finance lawyer and attorney-of-record in the lawsuit, explained the underlying law in an article for Investor’s Business Daily: Under federal law, “an individual donor can contribute $2,700 to any candidate, $10,000 to any state party committee, and (during the 2016 cycle) $33,400 to a national party’s main account. These groups can all get together and take a single check from a donor for the sum of those contribution limits—it’s legal because the donor cannot exceed the base limit for any one recipient. And state parties can make unlimited transfer to their national party.”

    This legal loophole allows “bundlers” to raise large sums of money from wealthy donors—more than $400,000 at a time—filtering the funds to the national committees. Democrats and Republicans alike exploit this tactic. But once the money reaches the national committees, other limits apply.

    Suspecting the DNC had exceeded those limits, a client of Backer’s, the Committee to Defend the President, began reviewing FEC filings to determine whether there was excessive coordination between the DNC and Clinton. What Backer discovered, as he explained in an interview, was much worse. There was “extensive evidence in the Democrats’ own FEC reports, when coupled with their own public statements that demonstrated massive straw man contributions papered through the state parties, to the DNC, and then directly to Clinton’s campaign—in clear violation of federal campaign-finance law.”

    That’s the same Dan Backer who runs a number of scam PACs. Nice to see him doing something useful for a change, but you still shouldn’t contribute to any of his PACs.

  • Break out the tiny violins: “The Clinton Foundation saw contributions dry up approximately 90% over a three-year period between 2014 and 2017.”
  • “Ukraine’s top prosecutor divulged in an interview aired Wednesday on Hill.TV that he has opened an investigation into whether his country’s law enforcement apparatus intentionally leaked financial records during the 2016 U.S. presidential campaign about then-Trump campaign chairman Paul Manafort in an effort to sway the election in favor of Hillary Clinton.”
  • Russia’s GRU military intelligence service used fraudulent emails to gain access to large amounts of sensitive emails and documents that were then disseminated via covert GRU websites during the 2016 presidential election campaign influence operation, according to the report by Special Counsel Robert Mueller.” The GRU evidently used spearphising to penetrate the Clinton campaign and the DNC. The piece details the methods. This section was one of the most heavily redacted in the Mueller report. (Hat tip: Director Blue.)
  • “Reminder: The Russia Collusion Hoax Was Hatched By Hillary Clinton and Her Aides Just Hours After Her Loss, and Fed to a Supportive Media to Explain Away Her Failure — and Theirs.” Including the key role of former CIA director John Brennan in the whole thing.
  • Hillary Clinton spawned the Russia hoax. Christopher Steele is merely its front man.” (Hat tip: Ace of Spades HQ.)
  • It only took two and a half years, but even the New York Times has finally figured out that the Steele Dossier was complete and utter garbage. (Hat tip: The Other McCain.)
  • “U.S. Spends $90 Million to Help a few Dozen Afghan Women Get Jobs.” Guess who was involved?

    The U.S. government has blown almost $90 million on a doomed project to help Afghan women enter the workforce with a big chunk of the money going to a Clinton-aligned “development” company that reaped big bucks from Uncle Sam while Hillary Clinton was secretary of state. The cash flows through the famously corrupt U.S. Agency of International Development (USAID), which is charged with providing global economic, development and humanitarian assistance. In this case USAID allocated $216 million to supposedly help tens of thousands of Afghan women get jobs and gain promotions over five years. Known as “Promoting Gender Equity in National Priority Programs,” the endeavor was launched in 2014 and tens of millions of dollars later it’s proven to be a major failure…Of interesting note is that one of the biggest contracts went to a company, Chemonics International, with close ties to the Clintons.

    (Hat tip: Borepatch.)

  • Hillary Clinton said confirming Brett Kavanaugh to the Supreme Court would bring back slavery.

  • “Easter Worshipers”:

  • Here’s an unlikely bombshell from almost a year ago: “Putin Claims U.S. Intelligence Agents Funneled $400 Million To Clinton Campaign.” Given the source and how little we’ve heard about this claim since, I have to assume there was nothing to it.
  • A new-ish book related to the topic at hand: The Russia Hoax: The Illicit Scheme to Clear Hillary Clinton and Frame Donald Trump