What did Google Know, When did The Know it?

Image result for google russian hacking Techviral

A Glimpse Into How Much Google Knows About Russian Government Hackers

A 2014 leaked private report from Google shows how much the internet giant knows about government hacking groups.

Motherboard: In October of 2014 an American security company revealed that a group of hackers affiliated with the Russian government, dubbed APT28, had targeted Georgia and other Eastern European countries in a wide-ranging espionage campaign. Two and a half years later, APT28—also known as “Fancy Bear” or “Sofacy”—is a household name not just in the cybersecurity industry, but in the mainstream too, thanks to its attack on the US Democratic party and the ensuing leaks of documents and emails.

Before that report by FireEye, APT28 was a well-kept secret within the cybersecurity industry. At the time, several companies were willing to share information about the hacking group. Even Google investigated the group, and penned a 40-page technical report on the hacking group that has never been published before.

This sort of document, which Motherboard obtained from two independent sources, may be a common sight in the threat intelligence industry, but the public rarely gets to see what such a report from Google looks like. The report draws from one of Google’s most interesting sources of data when it comes to malware and cybersecurity threats: VirusTotal, a public malware repository that the internet giant acquired in 2012.

Sofacy and X-Agent, the report read, referring to the malware used by APT28, “are used by a sophisticated state-sponsored group targeting primarily former Soviet republics, NATO members, and other Western European countries.”

“It looks like Google researchers were well aware of Sofacy before it was publicly disclosed.”

While Google security researchers don’t dwell into who’s really behind these operations, they do hint that they agree with the now widespread belief that APT28 works for the Russian government in a clever, indirect, way—in the very title of the report: “Peering into the Aquarium.”

While that might seem like an obscure title, for those who follow Russian espionage activities, it’s a clear reference to the headquarters of the military intelligence agency known as GRU or Glavnoye Razvedyvatel’noye Upravleniye, which are popularly known as “The Aquarium.”

“It looks like Google researchers were well aware of Sofacy before it was publicly disclosed,” Matt Suiche, a security researcher and the founder of Comae Technologies and the OPCDE  conference, told Motherboard in an online chat after reviewing the report. “And also attributed Sofacy and X-Agent to Russia before it was publicly done by FireEye, ESET or CrowdStrike.”

In its report Google security researcher note that APT28 attacks a large number of targets with its first-stage malware Sofacy, but only uses the more tailored and sophisticated X-Agent, which was recently used against Ukraine’s military units, for “high-priority targets.”

“Sofacy was three times more common than X-Agent in the wild, with over 600 distinct samples,” Google’s report stated.

Asked for comment, a Google spokesperson said via email that the company’s “security teams are constantly monitoring potential threats to internet users, and regularly publish information to better protect them.”

The report noted that Georgia had the highest ratio of submissions of Sofacy malware, followed by Romania, Russia and Denmark.

While this report is now a bit dated, it shows that for all its sophistication, APT28 has been often caught in the act of hacking politically interesting targets, betraying the origin of the hackers behind the dry nickname. It also reveals how much a company like Google, which doesn’t have software installed on thousands of customers computers like other antivirus and security vendors that is designed to specifically detect malware, can still learn a lot about government hacking groups thanks to the other data it has access to.

*** Related reading:

State-sponsored hackers targeting prominent journalists, Google warns

Politico: Google has warned a number of prominent journalists that state-sponsored hackers are attempting to steal their passwords and break into their inboxes, the journalists tell POLITICO.

Jonathan Chait of New York Magazine said he received several messages from Google warning him about an attack from a government-backed hacker starting shortly after the election. He said the most recent warning came two to three weeks ago.

Julia Ioffe, who recently started at The Atlantic and has covered Russia for years, said she got warnings as recently as two weeks ago. (See one of the warnings: http://bit.ly/2kMUyRb)

Some journalists getting the warnings say they suspect the hackers could be Russians looking to find incriminating emails they could leak to embarrass journalists, either by revealing alleged liberal bias or to expose the sausage-making of D.C. journalism.

“The fact that all this started right after the election suggests to me that journalists are the next wave to be targeted by state-sponsored hackers in the way that Democrats were during it,” said one journalist who got the warning. “I worry that the outcome is going to be the same: Someone, somewhere, is going to get hacked, and then the contents of their gmail will be weaponized against them — and by extension all media.”

The Russian embassy did not respond to a request for comment.

Image result for russian embassy washington dc Russian embassy Washington DC

Google cautioned that the warnings did not mean the accounts had been compromised already and were sent due to “an abundance of caution.”

“Since 2012, we’ve notified users when we believe their Google accounts are being targeted by government-backed attackers,” said a Google spokesperson in a statement. “We send these warnings out of an abundance of caution — they do not indicate that a user’s account has already been compromised or that a more widespread attack is occurring when they receive the notice.”

Ezra Klein, the founder of Vox, said he had received the warning as recently as a few days back. CNN senior media reporter Brian Stelter said he has been getting the alerts for the past few months.

Other journalists who confirmed they’ve recently gotten the warnings include New York Times national security correspondent David Sanger, Times columnist Paul Krugman and Yahoo Washington bureau chief Garance Franke-Ruta.

GQ special contributor Keith Olbermann said the warnings started a few weeks after the election, and he received the most recent alert earlier this week, a “big bright red bar” across the top of his Gmail. Some of the reporters say they are tightening up their email security to try to prevent the hackers from getting in.

Chait also said he was “contacted over email by a stranger who offered to help me by giving me an encryption key to protect me from hackers. He would not give me his name, meet me or talk on the phone, despite repeated requests.”

The stranger also emailed The Atlantic’s David Frum, James Fallows and Adam Serwer, Andrew Sullivan and Ars Technica’s Dan Goodin.

Stanford professor Michael McFaul, the former U.S. ambassador to Russia, said he also received hacking warnings from Google. He added: “Given my background, one would have to guess that it’s the Russians.”

Trump’s Aggressive Immigration Plan Released

When it comes to asylum seekers, a person under the Obama administration only needed to say they were seeking asylum. Trump’s plan raises the bar where conditions for being granted asylum must be proven.

Image result for trump immigration plan Image result for trump immigration detention centers

In part from Reuters:

WHAT IS “CREDIBLE FEAR”?

Under the Immigration and Nationality Act, an applicant must generally demonstrate “a well-founded fear of persecution on account of race, religion, nationality, membership in a particular social group, or political opinion.”

Immigration lawyers say any applicants who appear to meet that criteria in their initial interviews should be allowed to make their cases in court. They oppose encouraging asylum officers to take a stricter stance on questioning claims and rejecting applications.

Interviews to assess credible fear are conducted almost immediately after an asylum request is made, often at the border or in detention facilities by immigration agents or asylum officers, and most applicants easily clear that hurdle. Between July and September of 2016, U.S. asylum officers accepted nearly 88 percent of the claims of credible fear, according to U.S. Citizenship and Immigration Services data.

Asylum seekers who fail the credible fear test can be quickly deported unless they file an appeal. Currently, those who pass the test are eventually released and allowed to remain in the United States awaiting hearings, which are often scheduled years into the future because of a backlog of more than 500,000 cases in immigration courts.

Between October 2015 and April 2016, nearly 50,000 migrants claimed credible fear, 78 percent of whom were from Honduras, El Salvador, Guatemala or Mexico, according to statistics from USCIS.

The number of migrants from those three countries who passed credible fear and went to court to make their case for asylum rose sharply between 2011 and 2015, from 13,970 claims to 34,125, according to data from the Justice Department. More here from Reuters.

 

Implementing the President’s Border Security and Immigration Enforcement Improvements Policies by USA TODAY on Scribd

FNC: Homeland Security Secretary John Kelly moved Tuesday to implement a host of immigration enforcement changes ordered by President Trump, directing agency heads to hire thousands more officers, end so-called “catch-and-release” policies and begin work on the president’s promised U.S.-Mexico border wall.

“It is in the national interest of the United States to prevent criminals and criminal organizations from destabilizing border security,” Kelly wrote in one of two memos released Tuesday by the department.

The memos follow up on Trump’s related executive actions from January and, at their heart, aim to toughen immigration enforcement.

The changes would spare so-called “dreamers.” On a conference call with reporters, a DHS official stressed that the directives would not affect Obama-era protections for illegal immigrants who came to the U.S. as children and others given a reprieve in 2014. But outside those exemptions, Kelly wrote that DHS “no longer will exempt classes or categories of removable aliens from potential enforcement.”

A DHS official said the agencies are “going back to our traditional roots” on enforcement.

The memos cover a sprawling set of initiatives including:

  • Prioritizing criminal illegal immigrants and others for deportation, updating guidance from previous administration
  • Expanding the 287(g) program, which allows participating local officers to act as immigration agents – and had been rolled back under the Obama administration
  • Starting the planning, design and construction of a U.S.-Mexico border wall
  • Hiring 10,000 Immigration and Customs Enforcement agents and officers
  • Hiring 5,000 Border Patrol agents
  • Ending “catch-and-release” policies under which illegal immigrants subject to deportation potentially are allowed to “abscond” and fail to appear at removal hearings

It’s unclear what timelines the secretary is setting for some of these objectives, and what budgetary and other constraints the department and its myriad agencies will face. In pursuing an end to “catch-and-release,” one memo called for a plan with the Justice Department to “surge” immigration judges and asylum officers to handle additional cases.

While congressional Republicans have vowed to work with Trump to fund the front-end costs associated with his promised border wall, the same memo also hints at future efforts to potentially use money otherwise meant for Mexico – following on Trump’s repeated campaign vow to make Mexico pay for the wall. The secretary called for “identifying and quantifying” sources of aid to Mexico, without saying in the memo how that information might be used.

Mexican officials repeatedly have said they will not pay for a border barrier. DHS said it has identified initial locations to build a wall where current fencing is not effective, near El Paso, Texas; Tucson, Ariz.; and El Centro, Calif.

The DHS directives come as the Trump White House continues to work on rewriting its controversial executive order suspending the U.S. refugee program as well as travel from seven mostly Muslim countries. The order was put on hold by a federal court, and Trump’s team is said to be working on a new measure.

The directives also come as the Trump administration faces criticism from Democratic lawmakers and immigration advocacy groups for recent ICE raids of illegal immigrants.

DHS officials on Tuesday’s conference call stressed that they are operating under existing law and once again shot down an apparently erroneous news report from last week claiming National Guard troops could be utilized to round up illegal immigrants. That will not happen, an official said.

“We’re going to treat everyone humanely and with dignity, but we are going to execute the laws of the United States,” a DHS official said on the conference call.

Russian Spy Operations History in the U.S.

In 2015:

The FBI announced on Monday that it had busted a Russian spy ring that was allegedly focused on obtaining economic information including details about US markets and sanctions on Russian banks.

According to a federal complaint filed by FBI special agent Gregory Monaghan in a Manhattan federal court on Friday, an alleged spy, Evgeny Buryakov, posed as a banker in the New York office of an unnamed Russian bank.

Buryakov is reportedly being arraigned in the Southern District of New York.

Monaghan said Buryakov (aka”Zhenya”) was on “deep cover” and working for Russia’s Foreign Intelligence Service (SVR) to gather intelligence and transmit it back to Moscow. The SVR used multiple forms of cover.

The complaint includes several stunning revelations, including claims that staffers at an unidentified Russian news organization in the US are engaged in spying; and indications that American law enforcement bugged the New York office of the Foreign Intelligence Service.

According to the complaint, Buryakov worked with two other men who were involved in intelligence-gathering activities for the SVR: Victor Podobnyy and Igor Sporyshev. The complaint said Sporyshev served as a trade representative to the Russian Federation in New York. Podobnyy was allegedly an attaché to the permanent mission of the Russian Federation to the United Nations. More here from BusinessInsider.

***

Related reading: Russian Hacking, We knew Because we had an Inside Operative(s)

SPIES, SPIES EVERYWHERE
A journey through D.C. espionage

WaPo: Mystery and intrigue are running wild in the capital these days. Secret conversations with dangerous diplomats, explosive foreign dossiers on American leaders, handwringing over national security and leaky intelligence. If you dip into our new book “Spy Sites of Washington, D.C.,” you will find that sneaking, lying and skullduggery are as old as the republic itself. And our region is full of the traces: hotels and parks and saloons and embassies and government offices where the deceitful and disloyal got up to their antics. Here is a sampling of sites where our nation’s espionage history has played out.

Presidential Daily Briefing for Trump on Russia

There are rumors flying that the intelligence agencies are holding back on key items that would otherwise be included in the PDB’s, especially items regarding Russia. Okay, we cannot know for sure that is true or not. In fact there are denials this is accurate. While countless media outlets are reporting that some ‘higher-ups’ in some intel agencies are in a war with President Trump, it is all because he is in a war with them. Sheesh….while all this is going on, other allied world leaders are watching all this and are feeling quite uneasy over intelligence collaboration and most especially where all this leads.

Image result for russian spy ship norfolk, virginia

Some one needs to restore order and confidence here and do it fast. At issue is Russia and Iran.

  1. The Russian spy ship doing an ‘in-your-face’ Atlantic coast water adventure and is presently just outside of Norfolk, Virginia and headed back to the Cuba region.
  2. Meanwhile, the new Secretary of State, Rex Tillerson is in Germany meeting with his Russian counterpart Sergey Lavrov.
  3. Another item is General Dunford is in Azerbaijan, meeting with Russian Chief of General Staff of the Armed Forces, Gerasimov.
  4. Qassem Soleimani, head of the Iranian Qods Force is in Moscow. Soleimani has a U.S. and U.N. travel ban and sanctions on him such that he is not allowed to travel. Hah…
  5. Ciaran Martin, head of GCHQ’s new National Cyber Security Centre states that Russia is escalating the rate of hacks against the UK. The United States, Canada, Australia and the UK are the four countries of record that make up GCHQ.
  6. Deputy Defense Secretary Bob Work met with Ukrainian Foreign Affairs Minister Pavlo Klimkin at the Pentagon regarding discussion over the recent escalation of violence by combined Russian separatist forces in eastern Ukraine.
  7. Because of Russian aggression and the lasting threat to the Baltic States, General Mattis has ordered U.S. troops deploy in Bulgaria.
  8. Russian troops attacked Ukrainian positions 139 times using heavy armor in all sectors in Donbas in the past 48 hours.

    Situation in Donbas February 13, 2017 Ukraine conflict map

    9.  Russia tells White House it will not return Crimea to Ukraine.
    10. Russia has secretly deployed a new cruise missile that American officials say violates a landmark arms control treaty, posing a major test for President Trump as his administration is facing a crisis over its ties to Moscow. The missile (Kalibr) is a SSC-8. It is a nuclear capable missile first tested in 2008. While this launch was ground based, it can also be launched from a submarine and is capable of holding 1000 lbs of conventional explosives or a nuclear warhead. There are variants to this weapon, there is also the Iskander and the 9M728. Nonetheless, it is a violation of the INF Treaty.
    Lastly and a very good thing, while Vladimir Putin is calling for full intelligence cooperation with the United States, General Mattis has not, no….not ready. Further, Mattis said that Russia needs to prove itself….tic tic tic…

    11. Soldiers, tanks and M88 recovery vehicles from the 1st Battalion, 8th Infantry Regiment’s “Fighting Eagles” recently arrived at the airbase in Romania in support of Operation Atlantic Resolve. So far, more than 350 U.S. soldiers have arrived this month with another 150 set to arrive before the end of February.

So, should there be some normalizing of relations between the White House and the Kremlin? Nah….has not worked out so well when it comes to Iran or Cuba…

Trump Admin vs. Shadow Operations

Trump and his team were and still are ill-prepared for the opposition hostilities aimed at his people and administration. One must question whether Trump’s operation was ready to take on the legal warfare for his temporary travel suspension. One must question whether Trump is ready for the Russian aggressions. And what about the fights for tax reform and the full repeal of Obamacare?

Obama’s advice to Trump: ‘Reality has a way of biting back’

Okay, but there can be only one president at a time and sadly it seems that Obama has a quasi-shadow presidency in full operation and gaining traction to destroy the Trump presidency where Obama can run policy from points all across the country. How so you ask?

Image result for obama trump Vanity Fair

Well we have former CIA Director John Brennan who re-tooled the agency during his last two years as director. Re-tooled it how? Perhaps to carry on policy favoring the Obama doctrine and Iran leaving a few well placed loyal operatives to do the work. But most of all, restructured his spies for the world of cyber. Humm, right?

Then we have Ben Rhodes, the former deputy of the Obama National Security Council. He is working the media channels with wild abandon giving talking points and missions for media to ensure sand stays in the gears of the Trump administration. After all, Rhodes worked those very same channels and the lobby operations during the Iranian nuclear agreement talks. Remember, Ben Rhodes’ brother, David is the president of CBS News.

Then we have Van Jones, the shamed former Obama ‘green czar’ that contributes to CNN. He launched a non-profit called Megaphone Strategies. What is that? It is an operation that promotes demonstrations and rallies all in the name of ‘social justice’. Humm right?

 

 

 

 

 

 

 

 

Okay, so back to Obama….

***

Obama’s Shadow Presidency

Well-funded Organizing for Action promises to crack conservative skulls to halt the Trump agenda.

Vadum: Former President Obama is waging war against the Trump administration through his generously funded agitation outfit, Organizing for Action, to defend his monumentally destructive record of failure and violent polarization.

It is a chilling reminder that the increasingly aggressive, in-your-face Left in this country is on the march.

Acclaimed author Paul Sperry writes in the New York Post:

Obama has an army of agitators — numbering more than 30,000 — who will fight his Republican successor at every turn of his historic presidency. And Obama will command them from a bunker less than two miles from the White House.

In what’s shaping up to be a highly unusual post-presidency, Obama isn’t just staying behind in Washington. He’s working behind the scenes to set up what will effectively be a shadow government to not only protect his threatened legacy, but to sabotage the incoming administration and its popular “America First” agenda.

What is Organizing for Action? It is a less violent version of Mussolini’s black shirts and Hitler’s brown shirts, or of the government-supported goon squads that Venezuela’s Hugo Chavez and Cuba’s Castro brothers used to harass and intimidate their domestic opponents.

OfA isn’t, strictly speaking, a new group. After the 2008 election, the group, then known as Organizing for America, was a phony grassroots campaign run by the Democratic National Committee that sought to replicate the community organizing techniques Obama learned from the teachings of his fellow Chicagoan, Saul Alinsky. OfA was created in large part because the White House could not legally use the 13 million e-mail addresses that the Obama campaign compiled in 2008.

Former U.S. Rep. Bob Edgar (D-Penn.), sounded the alarm about OfA in 2013, suggesting the group was dangerous to democracy. “If President Obama is serious about his often-expressed desire to rein in big money in politics, he should shut down Organizing for Action and disavow any plan to schedule regular meetings with its major donors,” he said as president of the left-wing group Common Cause. “Access to the President should never be for sale.”

“With its reported promise of quarterly presidential meetings for donors and ‘bundlers’ who raise $500,000, Organizing For Action apparently intends to extend and deepen the pay-to-play Washington culture that Barack Obama came to prominence pledging to end,” Edgar said. “The White House’s suggestion this week that this group will somehow be independent is laughable.”

But Edgar’s admonitions were ignored and since then Organizing for Action has thrived and grown rich, just like the Obamas.

As FrontPage previously reported, Obama has rented a $5.3 million, 8,200-square-foot, walled mansion in Washington’s Embassy Row that he is using to command his community organizing cadres. Michelle Obama will join the former president there as will the Obama Foundation. To stay on track, Obama wants his former labor secretary, Tom Perez, to win the chairmanship of the DNC in a party election later this month. “It’s time to organize and fight, said Perez who appears to be gaining on frontrunner and jihadist Rep. Keith Ellison (D-Minn.). “We must stand up to protect President Obama’s accomplishments,” adding, “We’re going to build the strongest grassroots organizing force this country has ever seen.”

No ex-president has ever done this before, sticking around the nation’s capital to vex and undermine his successor. Of course, Obama is unlike any president the United States has ever had. Even failed, self-righteous presidents like Jimmy Carter, who has occasionally taken shots at his successors, didn’t stay behind in Washington to obstruct and disrupt the new administration.

Organizing for Action, a 501(c)(4) nonprofit that doesn’t have to disclose its donors, is at the head of Obama’s network of left-wing nonprofit groups. OfA, Sperry warns, has “a growing war chest and more than 250 offices across the country.”

On its website, the group claims that there are “5 million Americans who’ve taken action” with OfA, and that those individuals “are part of a long line of people who stand up and take on the big fights for social justice, basic fairness, equal rights, and expanding opportunity.” Among its key issues are “turning up the heat on climate change deniers,” comprehensive immigration reform (which includes mass amnesty), “telling the stories of the millions who are seeing the life-saving benefits of Obamacare,” fighting for “a woman’s health care” which is “a basic right,” and redistributing wealth from those who earned it to those who didn’t.

OfA communications director Jesse Lehrich told Memphis-based WREG that the “grassroots energy that’s out there right now is palpable.” The group is “constantly hearing from volunteers who are excited to report about events they’re organizing around and all of the new people that want to get involved.”

Organizing for Action is drowning in money, by nonprofit standards.

By the end of 2014, OfA, which was formally incorporated only the year before, had taken in $40.4 million, $26 million of which was raised in 2014, according to the organization’s IRS filings. OfA’s big donors are members of the George Soros-founded Democracy Alliance, a donors’ consortium for left-wing billionaires devoted to radical political change. Among the DA members donating to OfA are: Ryan Smith ($476,260); Marcy Carsey ($250,000); Jon Stryker ($200,000); Paul Boskind ($105,000); Paul Egerman ($100,000); and Nick Hanauer ($50,000).

OfA also runs a project called the Community Organizing Institute (COI) which it says partners “with progressive groups and organizations to educate, engage, and collaborate.”

Organizing for Action describes COI in almost lyrical terms:

Building upon the rich history of community organizing in Chicago, the COI is a place to share stories, best practices, and innovations in order to build our community and empower individuals in the fight for change. It is a shared space for organizers, policy makers, advocates, and change-agents to come together for workshops, panel discussions, presentations, trainings, film screenings, and social gatherings—building a strong foundation for partnerships.

Translation: at COI you can learn how to spark riots, get arrested to make a political statement, organize lynch mobs and voter fraud on a massive scale, intimidate and shake down corporations, blackmail lenders, race-bait public officials and businesses into submission, smear and terrorize your opponents, shield illegal aliens from law enforcement, lead squatters to invade foreclosed homes, encourage welfare fraud, and use tax dollars to promote cockamamie social-engineering schemes.

Obama is “intimately involved” in OfA’s operations and issues tweets from the group’s account, Sperry writes. “In fact, he gave marching orders to OFA foot soldiers following Trump’s upset victory.”

“It is fine for everybody to feel stressed, sad, discouraged,” Obama said in a post-election conference call from the White House. “But get over it.” Progressives have to “move forward to protect what we’ve accomplished.”

“Now is the time for some organizing,” he said. “So don’t mope.”

Organizing for Action has been doing anything but moping.

In recent weeks its activists organized marches across the country. Some became riots. After President Trump issued Executive Order 13769 temporarily banning visitors from seven terrorism-plagued Muslim countries, OfA organized “spontaneous” demonstrations at airports.

Obama praised the airport rabble-rousers, saying through a spokesman he was “heartened by the level of engagement taking place in communities around the country.”

“Citizens exercising their Constitutional right to assemble, organize and have their voices heard by the elected officials is exactly what we expect to see when American values are at stake.”

Reinforcements are coming to beef up Organizing for Action’s position, Sperry adds.

OfA will be soon aided by “the National Democratic Redistricting Committee, launched last month by Obama pal Eric Holder to end what he and Obama call GOP ‘gerrymandering’ of congressional districts.”

And more unruly protests, rioting, and violent attacks on Trump supporters will follow.