What did Google Know, When did The Know it?

Image result for google russian hacking Techviral

A Glimpse Into How Much Google Knows About Russian Government Hackers

A 2014 leaked private report from Google shows how much the internet giant knows about government hacking groups.

Motherboard: In October of 2014 an American security company revealed that a group of hackers affiliated with the Russian government, dubbed APT28, had targeted Georgia and other Eastern European countries in a wide-ranging espionage campaign. Two and a half years later, APT28—also known as “Fancy Bear” or “Sofacy”—is a household name not just in the cybersecurity industry, but in the mainstream too, thanks to its attack on the US Democratic party and the ensuing leaks of documents and emails.

Before that report by FireEye, APT28 was a well-kept secret within the cybersecurity industry. At the time, several companies were willing to share information about the hacking group. Even Google investigated the group, and penned a 40-page technical report on the hacking group that has never been published before.

This sort of document, which Motherboard obtained from two independent sources, may be a common sight in the threat intelligence industry, but the public rarely gets to see what such a report from Google looks like. The report draws from one of Google’s most interesting sources of data when it comes to malware and cybersecurity threats: VirusTotal, a public malware repository that the internet giant acquired in 2012.

Sofacy and X-Agent, the report read, referring to the malware used by APT28, “are used by a sophisticated state-sponsored group targeting primarily former Soviet republics, NATO members, and other Western European countries.”

“It looks like Google researchers were well aware of Sofacy before it was publicly disclosed.”

While Google security researchers don’t dwell into who’s really behind these operations, they do hint that they agree with the now widespread belief that APT28 works for the Russian government in a clever, indirect, way—in the very title of the report: “Peering into the Aquarium.”

While that might seem like an obscure title, for those who follow Russian espionage activities, it’s a clear reference to the headquarters of the military intelligence agency known as GRU or Glavnoye Razvedyvatel’noye Upravleniye, which are popularly known as “The Aquarium.”

“It looks like Google researchers were well aware of Sofacy before it was publicly disclosed,” Matt Suiche, a security researcher and the founder of Comae Technologies and the OPCDE  conference, told Motherboard in an online chat after reviewing the report. “And also attributed Sofacy and X-Agent to Russia before it was publicly done by FireEye, ESET or CrowdStrike.”

In its report Google security researcher note that APT28 attacks a large number of targets with its first-stage malware Sofacy, but only uses the more tailored and sophisticated X-Agent, which was recently used against Ukraine’s military units, for “high-priority targets.”

“Sofacy was three times more common than X-Agent in the wild, with over 600 distinct samples,” Google’s report stated.

Asked for comment, a Google spokesperson said via email that the company’s “security teams are constantly monitoring potential threats to internet users, and regularly publish information to better protect them.”

The report noted that Georgia had the highest ratio of submissions of Sofacy malware, followed by Romania, Russia and Denmark.

While this report is now a bit dated, it shows that for all its sophistication, APT28 has been often caught in the act of hacking politically interesting targets, betraying the origin of the hackers behind the dry nickname. It also reveals how much a company like Google, which doesn’t have software installed on thousands of customers computers like other antivirus and security vendors that is designed to specifically detect malware, can still learn a lot about government hacking groups thanks to the other data it has access to.

*** Related reading:

State-sponsored hackers targeting prominent journalists, Google warns

Politico: Google has warned a number of prominent journalists that state-sponsored hackers are attempting to steal their passwords and break into their inboxes, the journalists tell POLITICO.

Jonathan Chait of New York Magazine said he received several messages from Google warning him about an attack from a government-backed hacker starting shortly after the election. He said the most recent warning came two to three weeks ago.

Julia Ioffe, who recently started at The Atlantic and has covered Russia for years, said she got warnings as recently as two weeks ago. (See one of the warnings: http://bit.ly/2kMUyRb)

Some journalists getting the warnings say they suspect the hackers could be Russians looking to find incriminating emails they could leak to embarrass journalists, either by revealing alleged liberal bias or to expose the sausage-making of D.C. journalism.

“The fact that all this started right after the election suggests to me that journalists are the next wave to be targeted by state-sponsored hackers in the way that Democrats were during it,” said one journalist who got the warning. “I worry that the outcome is going to be the same: Someone, somewhere, is going to get hacked, and then the contents of their gmail will be weaponized against them — and by extension all media.”

The Russian embassy did not respond to a request for comment.

Image result for russian embassy washington dc Russian embassy Washington DC

Google cautioned that the warnings did not mean the accounts had been compromised already and were sent due to “an abundance of caution.”

“Since 2012, we’ve notified users when we believe their Google accounts are being targeted by government-backed attackers,” said a Google spokesperson in a statement. “We send these warnings out of an abundance of caution — they do not indicate that a user’s account has already been compromised or that a more widespread attack is occurring when they receive the notice.”

Ezra Klein, the founder of Vox, said he had received the warning as recently as a few days back. CNN senior media reporter Brian Stelter said he has been getting the alerts for the past few months.

Other journalists who confirmed they’ve recently gotten the warnings include New York Times national security correspondent David Sanger, Times columnist Paul Krugman and Yahoo Washington bureau chief Garance Franke-Ruta.

GQ special contributor Keith Olbermann said the warnings started a few weeks after the election, and he received the most recent alert earlier this week, a “big bright red bar” across the top of his Gmail. Some of the reporters say they are tightening up their email security to try to prevent the hackers from getting in.

Chait also said he was “contacted over email by a stranger who offered to help me by giving me an encryption key to protect me from hackers. He would not give me his name, meet me or talk on the phone, despite repeated requests.”

The stranger also emailed The Atlantic’s David Frum, James Fallows and Adam Serwer, Andrew Sullivan and Ars Technica’s Dan Goodin.

Stanford professor Michael McFaul, the former U.S. ambassador to Russia, said he also received hacking warnings from Google. He added: “Given my background, one would have to guess that it’s the Russians.”

Trump’s Aggressive Immigration Plan Released

When it comes to asylum seekers, a person under the Obama administration only needed to say they were seeking asylum. Trump’s plan raises the bar where conditions for being granted asylum must be proven.

Image result for trump immigration plan Image result for trump immigration detention centers

In part from Reuters:

WHAT IS “CREDIBLE FEAR”?

Under the Immigration and Nationality Act, an applicant must generally demonstrate “a well-founded fear of persecution on account of race, religion, nationality, membership in a particular social group, or political opinion.”

Immigration lawyers say any applicants who appear to meet that criteria in their initial interviews should be allowed to make their cases in court. They oppose encouraging asylum officers to take a stricter stance on questioning claims and rejecting applications.

Interviews to assess credible fear are conducted almost immediately after an asylum request is made, often at the border or in detention facilities by immigration agents or asylum officers, and most applicants easily clear that hurdle. Between July and September of 2016, U.S. asylum officers accepted nearly 88 percent of the claims of credible fear, according to U.S. Citizenship and Immigration Services data.

Asylum seekers who fail the credible fear test can be quickly deported unless they file an appeal. Currently, those who pass the test are eventually released and allowed to remain in the United States awaiting hearings, which are often scheduled years into the future because of a backlog of more than 500,000 cases in immigration courts.

Between October 2015 and April 2016, nearly 50,000 migrants claimed credible fear, 78 percent of whom were from Honduras, El Salvador, Guatemala or Mexico, according to statistics from USCIS.

The number of migrants from those three countries who passed credible fear and went to court to make their case for asylum rose sharply between 2011 and 2015, from 13,970 claims to 34,125, according to data from the Justice Department. More here from Reuters.

 

Implementing the President’s Border Security and Immigration Enforcement Improvements Policies by USA TODAY on Scribd

FNC: Homeland Security Secretary John Kelly moved Tuesday to implement a host of immigration enforcement changes ordered by President Trump, directing agency heads to hire thousands more officers, end so-called “catch-and-release” policies and begin work on the president’s promised U.S.-Mexico border wall.

“It is in the national interest of the United States to prevent criminals and criminal organizations from destabilizing border security,” Kelly wrote in one of two memos released Tuesday by the department.

The memos follow up on Trump’s related executive actions from January and, at their heart, aim to toughen immigration enforcement.

The changes would spare so-called “dreamers.” On a conference call with reporters, a DHS official stressed that the directives would not affect Obama-era protections for illegal immigrants who came to the U.S. as children and others given a reprieve in 2014. But outside those exemptions, Kelly wrote that DHS “no longer will exempt classes or categories of removable aliens from potential enforcement.”

A DHS official said the agencies are “going back to our traditional roots” on enforcement.

The memos cover a sprawling set of initiatives including:

  • Prioritizing criminal illegal immigrants and others for deportation, updating guidance from previous administration
  • Expanding the 287(g) program, which allows participating local officers to act as immigration agents – and had been rolled back under the Obama administration
  • Starting the planning, design and construction of a U.S.-Mexico border wall
  • Hiring 10,000 Immigration and Customs Enforcement agents and officers
  • Hiring 5,000 Border Patrol agents
  • Ending “catch-and-release” policies under which illegal immigrants subject to deportation potentially are allowed to “abscond” and fail to appear at removal hearings

It’s unclear what timelines the secretary is setting for some of these objectives, and what budgetary and other constraints the department and its myriad agencies will face. In pursuing an end to “catch-and-release,” one memo called for a plan with the Justice Department to “surge” immigration judges and asylum officers to handle additional cases.

While congressional Republicans have vowed to work with Trump to fund the front-end costs associated with his promised border wall, the same memo also hints at future efforts to potentially use money otherwise meant for Mexico – following on Trump’s repeated campaign vow to make Mexico pay for the wall. The secretary called for “identifying and quantifying” sources of aid to Mexico, without saying in the memo how that information might be used.

Mexican officials repeatedly have said they will not pay for a border barrier. DHS said it has identified initial locations to build a wall where current fencing is not effective, near El Paso, Texas; Tucson, Ariz.; and El Centro, Calif.

The DHS directives come as the Trump White House continues to work on rewriting its controversial executive order suspending the U.S. refugee program as well as travel from seven mostly Muslim countries. The order was put on hold by a federal court, and Trump’s team is said to be working on a new measure.

The directives also come as the Trump administration faces criticism from Democratic lawmakers and immigration advocacy groups for recent ICE raids of illegal immigrants.

DHS officials on Tuesday’s conference call stressed that they are operating under existing law and once again shot down an apparently erroneous news report from last week claiming National Guard troops could be utilized to round up illegal immigrants. That will not happen, an official said.

“We’re going to treat everyone humanely and with dignity, but we are going to execute the laws of the United States,” a DHS official said on the conference call.

The JPOA, Billions Given by Obama to Iran Results in Huge Profits

Remember, Barack Obama and John Kerry gave billions to Iran, which is to say to the Supreme Leader Ali Khamenei. Two companies owned and controlled by the Supreme leader are Setad and Bonyad Mostazafan.

  For the full summary investigation performed by Reuters, go here.

Image result for iran supreme leader wealth

Iran Irony: IRGC And State Firms Are Benefiting From JCPOA

Mr. Alavi is an Iranian activist focusing on human rights, social crackdown, the regime’s support for terrorism, and its nuclear program.

Forbes: Those who raised the Iran deal flag, mainly in the United States and Europe, claimed the Joint Comprehensive Plan of Action (JCPOA) would boost trade and encourage foreign investment, enhancing Iran’s private sector and eventually downgrading the regime’s tight grip on the economy.

This was back in 2015 when the P5+1 agreed to lift sanctions in return for having Iran’s nuclear program curbed. Now in early 2017, however, signs indicate the main winners in Iran are none other than state-owned companies. This means Iranian Supreme Leader Ali Khamenei and the terrorist-supporting Revolutionary Guards are enjoying JCPOA benefits.

At least 90 of the nearly 110 agreements, totaling nearly $80 billion, involve such state-controlled companies. This includes the National Iranian Oil Company, parallel to others run by regime pension funds and massive conglomerates of semi-public nature.

Despite a long slate of harsh remarks made by Iran’s hardliners against the JCPOA, a recent Reuters study shows those businesses answering directly to Khamenei are benefiting most from the JCPOA.

Many deals, spanning the energy, infrastructure, pharmaceuticals and other sectors, remain in the preliminary stage. Iran’s foreign partners mainly include France, Germany, Italy, Russia and South Korea.

Iran’s “Setad Ejraiye Farman-e Hazrat-e Emam,” also known as the Headquarters for Executing the Order of the Imam and best known as Khamenei’s personal empire, has been the main benefactor of the highly flawed nuclear pact. This entity has stakes in and control over nearly all of Iran’s economy and benefits significantly through the JCPOA.

A 2013 Reuters probe shed light on Setad’s $95 billion empire, established through illegally seizing thousands of properties owned by business people, Iranians living abroad and religious minorities.

“A major network of front companies controlled by Iran’s leadership” is how the U.S. Treasury Department described Setad as it sanctioned the massive entity. Through the JCPOA, however, this conglomerate has enjoyed doing business with foreign companies.

One of the three such deals signed with foreign companies involves a $10 billion oil refinery construction plan. While Khamenei may not personally own these companies, his shadow—described as supervision—is essentially routing all invested finances.

In the past 18 months Khamenei-controlled companies, including the IRGC conglomerate, have sealed deals with foreign companies valued at over $11 billion.

It is a known fact that Tehran maintains a heavy hand over the economy, providing circumstances allowing state-controlled firms to acquire most business deals made possible after sanctions were lifted. The private sector makes up a mere 20% of Iran’s economy, according to official estimates.

To this end, private companies have received a dismal 17 deals, including a hotel management contract sealed most probably because of the French partner’s chief executive being the brother of Eshaq Jahangiri, Iran’s vice president.

The first slate of investments inked for Iran is most likely to strengthen state power, meaning Khamenei, counter to any hopes raised prematurely by JCPOA supporters. The supreme leader enjoys vast control, especially in the IRGC, through which he pursues his Syria, Iraq, Yemen, Bahrain and Lebanon policies.

Conglomerates, or foundations, whose chiefs are appointed directly by Khamenei, were the recipients of five of the 90 deals. Several of these entities enjoy widespread business transactions and not being obligated to pay full taxes. This includes Astan Qods Razavi, a vast religious institution controlling at least 36 subsidiary companies and entities.

One such firm is the Razavi Oil & Gas Development Company that sealed a preliminary agreement with Italy’s Saipem, also an oil and gas company.

The IRGC, known for its domestic crackdown and dispatching tens of thousands of Shiite militia members and arms throughout the region, is also considered a major destination point of JCPOA benefits.

The IRGC controls or has large stakes in four of the 90 deals sealed with the Iranian regime. And of course, Khamenei enjoys full hegemony over the IRGC. Despite remaining U.S. sanctions banning any “significant” business transactions with the IRGC, many of its front companies are free of any blacklisting.

Three of the four mentioned deals are signed with companies with strong ties to the IRGC and yet are not sanctioned. And to add insult to injury, the fourth company is on sanctions and yet enjoys involvement in a foreign deal through indirect routes.

Loopholes remain in the sanction regime imposed against Iran, all resulting from an appeasement/engagement approach adopted by former president Barack Obama. This is a gap in need of closing at a policy level.

“Despite a decline in sanctions… the Iranian economy is suffering from recession. The Iranian economy is under the control of the regime’s supreme leader Ali Khamenei and the IRGC. They are the only one who will benefit from trade with Iran and not the Iranian people,” said Iranian opposition leader Maryam Rajavi in a conference. Rajavi is president of the National Council of Resistance of Iran, an umbrella group of Iranian dissident entities, including the People’s Mojahedin Organization of Iran (PMOI/MEK).

Debate over the JCPOA’s future remains a major issue. If kept intact despite all its flaws, the U.S. should fully implement all articles and have each and every loophole sealed. This initiative can be coupled with further sanctions punishing Iran’s lethal meddling across the Middle East, pursuing a dangerous ballistic missile program and atrocious human rights violations.

Russian Spy Operations History in the U.S.

In 2015:

The FBI announced on Monday that it had busted a Russian spy ring that was allegedly focused on obtaining economic information including details about US markets and sanctions on Russian banks.

According to a federal complaint filed by FBI special agent Gregory Monaghan in a Manhattan federal court on Friday, an alleged spy, Evgeny Buryakov, posed as a banker in the New York office of an unnamed Russian bank.

Buryakov is reportedly being arraigned in the Southern District of New York.

Monaghan said Buryakov (aka”Zhenya”) was on “deep cover” and working for Russia’s Foreign Intelligence Service (SVR) to gather intelligence and transmit it back to Moscow. The SVR used multiple forms of cover.

The complaint includes several stunning revelations, including claims that staffers at an unidentified Russian news organization in the US are engaged in spying; and indications that American law enforcement bugged the New York office of the Foreign Intelligence Service.

According to the complaint, Buryakov worked with two other men who were involved in intelligence-gathering activities for the SVR: Victor Podobnyy and Igor Sporyshev. The complaint said Sporyshev served as a trade representative to the Russian Federation in New York. Podobnyy was allegedly an attaché to the permanent mission of the Russian Federation to the United Nations. More here from BusinessInsider.

***

Related reading: Russian Hacking, We knew Because we had an Inside Operative(s)

SPIES, SPIES EVERYWHERE
A journey through D.C. espionage

WaPo: Mystery and intrigue are running wild in the capital these days. Secret conversations with dangerous diplomats, explosive foreign dossiers on American leaders, handwringing over national security and leaky intelligence. If you dip into our new book “Spy Sites of Washington, D.C.,” you will find that sneaking, lying and skullduggery are as old as the republic itself. And our region is full of the traces: hotels and parks and saloons and embassies and government offices where the deceitful and disloyal got up to their antics. Here is a sampling of sites where our nation’s espionage history has played out.

Tillerson Approves North Korea Visit to DC?

Washington prepares to bring North Koreans to U.S. for talks: report

Reuters: Preparations are under way to bring senior North Korean officials to the United States for talks with former U.S. officials, the first such meeting in more than five years, The Washington Post reported on Sunday.

The talks would be the clearest indication yet that North Korean leader Kim Jong Un wants to communicate with the new Trump administration.

Planning for the “Track 1.5 talks” is still in a preparatory stage, the Post reported, citing multiple people with knowledge of the arrangements.

That name, reflecting planned contact between former U.S. officials and current North Korean ones, is a reference to what are known as “Track 2” talks involving former officials on both sides.

The U.S. State Department has not yet approved the North Koreans’ visas for the talks, the newspaper said.

A State Department spokesman commented to Reuters only that Track 2 meetings “routinely” take place on a variety of topics around the world and occur independent of the U.S. government.

A White House official commented that the U.S. government had no plans to meet with North Korea.

North Korea’s testing of an intermediate-range ballistic missile drew international condemnation last week. President Donald Trump told a news conference after the test: Obviously North Korea is a big, big problem and we will deal with that very strongly.”

***

Who is suggested to attend this confab, Bill Richardson? Can the representatives of the United States be in talks with North Korea without including Iran, China or Russia? Not likely. It was not all that long ago that President Trump took a phone call from Taiwan which infuriated China. Trump said he would not be dictated to by China, only to later say he stood for a one China policy. How does China point to policy matters regarding North Korea?

***

NewsMax: The U.S. policy of maintaining sanctions and military pressure on North Korea while refusing to talk to the country isn’t working and will only make matters worse, a Chinese official said Saturday, venting Beijing’s impatience with the stalemate over its isolated neighbor.

“China just keeps on telling you this is not working, although we’re going along with you,” Fu Ying, who chairs the Foreign Affairs Committee of China’s legislature and was a vice foreign minister until 2013, said at the Munich Security Conference. “You have to realize — without talking with them, you will only drive them in the wrong direction further.”

Fu was flanked on stage by South Korean Foreign Minister Yun Byung-se and U.S. Senator Dan Sullivan, an Alaska Republican, in a rare public airing of differences between the U.S. and South Korea on the one side, and China on the other. President Donald Trump has repeatedly demanded China do more to rein in its neighbor and force it to abide by United Nations Security Council resolutions aimed at curbing the North’s nuclear ambitions.

Earlier Saturday, China’s Ministry of Commerce said it will halt coal imports from North Korea through the end of the year, stripping Kim Jong-un’s regime of a crucial source of income. No reason was given, although analysts pointed to the murder earlier this week of Kim’s older half-brother, Kim Jong Nam, at a Malaysian airport. He had lived outside North Korea for many years and had close links to China.

Trump’s administration is pushing forward with plans to deploy a missile-defense system known as Thaad in South Korea. Concerns over North Korea’s intentions were only inflamed after the regime carried out a missile test on Feb. 12. More here from NewsMax.

***

There is full and joint collaboration between Iran and North Korea on missile development and testing. Those launched by both countries are coordinated.

Pentagon: Iran Tested a Ballistic Missile With North Korean Origins

Missile tested by Tehran originally came from Pyongyang.

Pentagon identified the July 2016 missile as a locally produced version of the Musudan, a North Korean intermediate-range missile. Also known as the Hwasong-10, the missile is allegedly derived from an obsolete Soviet Cold War missile, the R-27 Zyb.

The Musudan has been adapted from a submarine-launched missile to a road-mobile missile, and is launched from 12-wheeled heavy transporters. The missile has a payload of 2,000 to 2,500 pounds and a theoretical maximum range of 2,500 miles. The range of the missile is open to some debate because so far, despite Pyongyang’s claims to the contrary, it hasn’t been successfully tested. North Korea may have launched as many as eight Musudans in 2016 alone, and not a single launch was considered successful by outside observers. More here.

***

On Sunday, February 12, 2017, North Korea conducted the first test launch of its “Pukguksong-2, solid-fuel missile,” a land-based version of the KN-11 Pukguksong-1 submarine-launched ballistic missile (SLBM), but not from the facility that almost all media sources have reported.[1] The development of the Pukguksong-2 was not unexpected and the system successfully flew a lofted trajectory, reaching an estimated altitude of 575 km and flying approximately 500 km before falling into the East Sea (Sea of Japan).[2]

Almost all initial reporting indicated that the missile was launched from the Panghyon Airbase in North Pyongan Province, located in the northwest. When, however, North Korea released still and video imagery of the test it was clear to North Korea watchers that the test was not conducted from the Panghyon Airbase, but from the Iha-ri Vehicle Testing and Driver Training Facility approximately 9.5 km to the north-northeast.[3] The choice of the Iha-ri facility was undoubtedly due to its proximity (only 5 km) to the No. 95 Factory (Kusong Tank Factory) where it is believed the transporter-erector-launcher (TEL) and its support vehicles were designed and manufactured.[4] It is likely that the Pukguksong-2 pre-test imagery released by North Korea was taken here. Read more here.

An overview image of the Pukguksong-2 launch and Iha-ri Facility. Seen in the background are the preparation shed [C], headquarters and administration buildings [A and B] and the security wall [D]. The propaganda placards [E] and inclined vehicle test hill [G] are visible in the foreground.

(Photo: KCNA)

(Photo: KCNA)