Canada, allies warn of Russian cyberattacks on critical infrastructure due to Ukraine war

Western governments jointly warned on Wednesday about a potential threat of increased malicious cyber activity by Russia against critical infrastructure as a response to sanctions imposed as punishment for its invasion of Ukraine.

The cybersecurity agencies of the United States, Britain, Australia, Canada and New Zealand that together form the Five Eyes intelligence-sharing alliance said the war could expose organizations everywhere to cyber crime.

Share

Companies were slow to remove Russian spies’ malware, so FBI did it for them

How the FBI took down “Cyclops Blink,” a Russia state botnet infecting network firewalls.

The FBI remotely accessed and disinfected US-located devices running a powerful new strain of Russian state botnet malware, federal authorities said Wednesday. Those authorities added that the Kremlin was using the malware to wage stealthy hacks of its adversaries.

The infected devices were primarily made up of firewall appliances from WatchGuard and, to a lesser extent, network devices from Asus. Both manufacturers recently issued advisories providing recommendations for hardening or disinfecting devices infected by the botnet, known as Cyclops Blink. It is the latest botnet malware from Russia’s Sandworm, which is among the world’s most elite and destructive state-sponsored hacking outfits.

Share

Kaspersky antivirus software added to US national security risk list

Antivirus software maker Kaspersky Labs has been added to a federal list of companies that pose “an unacceptable risk to the national security of the United States.”

The Moscow-based cybersecurity firm, which says it has more than 400 million users worldwide, was added to the Federal Communications Commission’s list of restricted entities on Friday alongside two Chinese companies.

Share

How bad could a Russian cyberattack be?

 

Containing the attack is the problem

When I have designed wargames around a NATO-Russia conflict, I often left out cyberattacks for a simple reason: it was just too complicated. Too many unknowns make an accurate simulation impossible.

The number of targets, scale of the attack, damage done, how the attack could be carried out and its ramifications were beyond calculation for a mere simulation on the scale I was running using just consumer-based computer technology.

Honestly, nuclear war seemed easier to think about, and that says a lot.

Share

‘It’s the right thing to do’: the 300,000 volunteer hackers coming together to fight Russia

Ukraine appealed for a global army of IT experts to help in the battle against Putin – and many answered the call.

Kali learned how to use technology by playing with his grandfather’s phone. Now, the Swiss teenager is trying to paralyse the digital presence of the Russian government and the Belarussian railway.

Kali – and many others who contributed to this article – declined to share his real name because some of the action he is taking is illegal and because he fears Russian retaliation. He is one of about 300,000 people who have signed up to a group on the chat app Telegram called “IT Army of Ukraine”, through which participants are assigned tasks designed to take the fight to Vladimir Putin. In so doing, they are trying to level the playing field between one of the world’s superpowers and Ukraine as it faces bombardment and invasion.

Share

Canadian intelligence agency calls for ramped-up cyber defences after Russia invades Ukraine

Canada’s cyber spy agency is warning organizations, including power companies and banks, to shore up their defences against Russia-based cyber threat activity as the Western world responds to Moscow’s invasion of Ukraine.

In a statement Thursday, the Communications Security Establishment said that “in light of Russia’s ongoing, unjustified military offensive in Ukraine,” it “strongly encourages all Canadian organizations to take immediate action and bolster their online cyber defences.”

Share

North Korea Hacked Him. So He Took Down Its Internet

FOR THE PAST two weeks, observers of North Korea’s strange and tightly restricted corner of the internet began to notice that the country seemed to be dealing with some serious connectivity problems. On several different days, practically all of its websites—the notoriously isolated nation only has a few dozen—intermittently dropped offline en masse, from the booking site for its Air Koryo airline to Naenara, a page that serves as the official portal for dictator Kim Jong-un’s government. At least one of the central routers that allow access to the country’s networks appeared at one point to be paralyzed, crippling the Hermit Kingdom’s digital connections to the outside world. 

Share

Canada’s cyberspy agency warns of Russian cyberattacks on critical infrastructure

Canada’s cyberspy agency is warning of Moscow-backed cyberattacks on Canadian critical infrastructure as Western countries prepare economic sanctions in the growing expectation that Russia will invade Ukraine.

The Canadian Centre for Cyber Security joined its counterparts in the United States and United Kingdom on Thursday in urging Canadian companies, such as electrical utilities and energy firms, to watch out for cyberattacks from Russia.

I bet the Russians will be pissed to find the ChiComs got there first.

Share

Fears grow that cyber chaos will spark wars as hack attacks become more aggressive

The nightmare of America under cyberattack is happening now and it is not going to stop anytime soon. Foreign adversaries and criminal gangsters alike are hammering all aspects of society from hospitals to schools to government offices.

In December alone, a ransomware attack on human resources software disrupted operations for some hospitals operated by Ascension Healthcare, the timekeeping system of New York City’s Metropolitan Transit Authority, and the government of Prince George’s County in Maryland, among others.

Share

The “most serious” security breach ever is unfolding right now

The fact that log4j is such a ubiquitous piece of software is what makes this such a big deal. Imagine if a common type of lock used by millions of people to keep their doors shut was suddenly discovered to be ineffective. Switching a single lock for a new one is easy, but finding all the millions of buildings that have that defective lock would take time and an immense amount of work.

Share

Evil Corp: ‘My hunt for the world’s most wanted hackers’

Many of the people on the FBI’s cyber most wanted list are Russian. While some allegedly work for the government earning a normal salary, others are accused of making a fortune from ransomware attacks and online theft. If they left Russia they’d be arrested – but at home they appear to be given free rein.

“We’re wasting our time,” I thought, as I watched a cat licking the carcass of a discarded takeaway chicken.

Surely there would no longer be any trace of an alleged multi-millionaire cyber-criminal on this dilapidated estate in a run-down town 700km (400 miles) east of Moscow.

Share

Experts say China’s low-level cyberwar is becoming severe threat

Chinese state-sponsored hacking is at record levels, western experts say, accusing Beijing of engaging in a form of low-level warfare that is escalating despite US, British and other political efforts to bring it to a halt.

There are accusations too that the clandestine activity, which has a focus on stealing intellectual property, has become more overt and more reckless, although Beijing consistently denies sponsoring hacking and accuses critics of hypocrisy.

Jamie Collier, a consultant with Mandiant, a cybersecurity firm whose work is often cited by intelligence agencies, said the level of hacking emerging from China in 2021 was “a more kind of severe threat than we previously anticipated”.


Hackers breached computer network at key US port but did not disrupt operations

Suspected foreign government-backed hackers last month breached a computer network at one of the largest ports on the US Gulf Coast, but early detection of the incident meant the intruders weren’t in a position to disrupt shipping operations, according to a Coast Guard analysis of the incident obtained by CNN and a public statement from a senior US cybersecurity official.

The incident at the Port of Houston is an example of the interest that foreign spies have in surveilling key US maritime ports, and it comes as US officials are trying to fortify critical infrastructure from such intrusions.

Share

Cyberwar, Part Two: “Flipping Switches”

Discussing Russian hacking capabilities in a video discussion for the Heritage Foundation recently, Prof. Scott Jasper of the Naval Postgraduate School recalled a hack in 2018 in which the attackers succeeded in penetrating electrical power companies in the U.S., as they did in Ukraine

“We had evidence from CISA (Cybersecurity and Infrastructure Security Agency) that Russian actors had penetrated up to 20 to 24 utilities by compromising vendors that had trusted relationships,” Jasper said. “They had taken control to the point where they could have thrown switches. They did this in Ukraine and flipped the switches of substations. So, this is a real threat.”

Share

Cyberwar – Part One

Cybercrime often merges with cyberwarfare. The techniques of both are similar, even if their intentions are not. Yet, unlike their “real-world” counterparts, we cannot afford to treat the former as merely a law enforcement problem and the latter as a military problem. Today’s gnat is tomorrow’s nuclear-tipped missile.

In a recent article, former U.S. National Security Adviser John Bolton highlighted the cyberwarfare being waged on the West every day by Russia, China, Iran and North Korea. The assault is an accelerating proxy war, a coordinated terrorism campaign conducted by both hired criminals and military intelligence agencies, capable of great economic and societal damage. At the same time, even at lower intensity, it is a subtler attack on Western morale.

Share