WannaCry Hacking Bad, but This is Terrifying

WASHINGTON — CIA Director Mike Pompeo says he thinks disclosure of America’s secret intelligence is on the rise, fueled partly by the “worship” of leakers like Edward Snowden.

“In some ways, I do think it’s accelerated,” Pompeo told MSNBC in an interview that aired Saturday. “I think there is a phenomenon, the worship of Edward Snowden, and those who steal American secrets for the purpose of self-aggrandizement or money or for whatever their motivation may be, does seem to be on the increase.”

Pompeo said the United States needs to redouble its efforts to stem leaks of classified information. More here.

***

A Cyberattack ‘the World Isn’t Ready For’

Golan Ben-Oni, of the IDT Corporation, which was attacked in April with two cyberweapons stolen from the National Security Agency.  Justin T. Gellerson for The New York Times

NEWARK — There have been times over the last two months when Golan Ben-Oni has felt like a voice in the wilderness.

On April 29, someone hit his employer, IDT Corporation, with two cyberweapons that had been stolen from the National Security Agency. Mr. Ben-Oni, the global chief information officer at IDT, was able to fend them off, but the attack left him distraught.

In 22 years of dealing with hackers of every sort, he had never seen anything like it. Who was behind it? How did they evade all of his defenses? How many others had been attacked but did not know it?

Since then, Mr. Ben-Oni has been sounding alarm bells, calling anyone who will listen at the White House, the Federal Bureau of Investigation, the New Jersey attorney general’s office and the top cybersecurity companies in the country to warn them about an attack that may still be invisibly striking victims undetected around the world.

And he is determined to track down whoever did it.

“I don’t pursue every attacker, just the ones that piss me off,” Mr. Ben-Oni told me recently over lentils in his office, which was strewn with empty Red Bull cans. “This pissed me off and, more importantly, it pissed my wife off, which is the real litmus test.”

Two weeks after IDT was hit, the cyberattack known as WannaCry ravaged computers at hospitals in England, universities in China, rail systems in Germany, even auto plants in Japan. No doubt it was destructive. But what Mr. Ben-Oni had witnessed was much worse, and with all eyes on the WannaCry destruction, few seemed to be paying attention to the attack on IDT’s systems — and most likely others around the world.

The strike on IDT, a conglomerate with headquarters in a nondescript gray building here with views of the Manhattan skyline 15 miles away, was similar to WannaCry in one way: Hackers locked up IDT data and demanded a ransom to unlock it.

But the ransom demand was just a smoke screen for a far more invasive attack that stole employee credentials. With those credentials in hand, hackers could have run free through the company’s computer network, taking confidential information or destroying machines.

Worse, the assault, which has never been reported before, was not spotted by some of the nation’s leading cybersecurity products, the top security engineers at its biggest tech companies, government intelligence analysts or the F.B.I., which remains consumed with the WannaCry attack.

Were it not for a digital black box that recorded everything on IDT’s network, along with Mr. Ben-Oni’s tenacity, the attack might have gone unnoticed.

Scans for the two hacking tools used against IDT indicate that the company is not alone. In fact, tens of thousands of computer systems all over the world have been “backdoored” by the same N.S.A. weapons. Mr. Ben-Oni and other security researchers worry that many of those other infected computers are connected to transportation networks, hospitals, water treatment plants and other utilities.

An attack on those systems, they warn, could put lives at risk. And Mr. Ben-Oni, fortified with adrenaline, Red Bull and the house beats of Deadmau5, the Canadian record producer, said he would not stop until the attacks had been shut down and those responsible were behind bars.

“The world is burning about WannaCry, but this is a nuclear bomb compared to WannaCry,” Mr. Ben-Oni said. “This is different. It’s a lot worse. It steals credentials. You can’t catch it, and it’s happening right under our noses.”

And, he added, “The world isn’t ready for this.”

Targeting the Nerve Center

Mr. Ben-Oni, 43, a Hasidic Jew, is a slight man with smiling eyes, a thick beard and a hacker’s penchant for mischief. He grew up in the hills of Berkeley, Calif., the son of Israeli immigrants.

Even as a toddler, Mr. Ben-Oni’s mother said, he was not interested in toys. She had to take him to the local junkyard to scour for typewriters that he would eventually dismantle on the living room floor. As a teenager, he aspired to become a rabbi but spent most of his free time hacking computers at the University of California, Berkeley, where his exploits once accidentally took down Belgium’s entire phone system for 15 minutes.

To his parents’ horror, he dropped out of college to pursue his love of hacking full time, starting a security company to help the city of Berkeley and two nearby communities, Alameda and Novato, set up secure computer networks.

He had a knack for the technical work, but not the marketing, and found it difficult to get new clients. So at age 19, he crossed the country and took a job at IDT, back when the company was a low-profile long-distance service provider.

As IDT started acquiring and spinning off an eclectic list of ventures, Mr. Ben-Oni found himself responsible for securing shale oil projects in Mongolia and the Golan Heights, a “Star Trek” comic books company, a project to cure cancer, a yeshiva university that trains underprivileged students in cybersecurity, and a small mobile company that Verizon recently acquired for $3.1 billion.

Which is to say he has encountered hundreds of thousands of hackers of every stripe, motivation and skill level. He eventually started a security business, IOSecurity, under IDT, to share some of the technical tools he had developed to keep IDT’s many businesses secure. By Mr. Ben-Oni’s estimate, IDT experiences hundreds of attacks a day on its businesses, but perhaps only four each year give him pause.

Nothing compared to the attack that struck in April. Like the WannaCry attack in May, the assault on IDT relied on cyberweapons developed by the N.S.A. that were leaked online in April by a mysterious group of hackers calling themselves the Shadow Brokers — alternately believed to be Russia-backed cybercriminals, an N.S.A. mole, or both.

The WannaCry attack — which the N.S.A. and security researchers have tied to North Korea — employed one N.S.A. cyberweapon; the IDT assault used two.

Both WannaCry and the IDT attack used a hacking tool the agency had code-named EternalBlue. The tool took advantage of unpatched Microsoft servers to automatically spread malware from one server to another, so that within 24 hours North Korea’s hackers had spread their ransomware to more than 200,000 servers around the globe.

The attack on IDT went a step further with another stolen N.S.A. cyberweapon, called DoublePulsar. The N.S.A. used DoublePulsar to penetrate computer systems without tripping security alarms. It allowed N.S.A. spies to inject their tools into the nerve center of a target’s computer system, called the kernel, which manages communications between a computer’s hardware and its software.

In the pecking order of a computer system, the kernel is at the very top, allowing anyone with secret access to it to take full control of a machine. It is also a dangerous blind spot for most security software, allowing attackers to do what they want and go unnoticed. In IDT’s case, attackers used DoublePulsar to steal an IDT contractor’s credentials. Then they deployed ransomware in what appears to be a cover for their real motive: broader access to IDT’s businesses.

Mr. Ben-Oni learned of the attack only when a contractor, working from home, switched on her computer to find that all her data had been encrypted and that attackers were demanding a ransom to unlock it. He might have assumed that this was a simple case of ransomware.

But the attack struck Mr. Ben-Oni as unique. For one thing, it was timed perfectly to the Sabbath. Attackers entered IDT’s network at 6 p.m. on Saturday on the dot, two and a half hours before the Sabbath would end and when most of IDT’s employees — 40 percent of whom identify as Orthodox Jews — would be off the clock. For another, the attackers compromised the contractor’s computer through her home modem — strange.

The black box of sorts, a network recording device made by the Israeli security company Secdo, shows that the ransomware was installed after the attackers had made off with the contractor’s credentials. And they managed to bypass every major security detection mechanism along the way. Finally, before they left, they encrypted her computer with ransomware, demanding $130 to unlock it, to cover up the more invasive attack on her computer.

Mr. Ben-Oni estimates that he has spoken to 107 security experts and researchers about the attack, including the chief executives of nearly every major security company and the heads of threat intelligence at Google, Microsoft and Amazon.

With the exception of Amazon, which found that some of its customers’ computers had been scanned by the same computer that hit IDT, no one had seen any trace of the attack before Mr. Ben-Oni notified them. The New York Times confirmed Mr. Ben-Oni’s account via written summaries provided by Palo Alto Networks, Intel’s McAfee and other security firms he used and asked to investigate the attack.

“I started to get the sense that we were the canary,” he said. “But we recorded it.”

Since IDT was hit, Mr. Ben-Oni has contacted everyone in his Rolodex to warn them of an attack that could still be worming its way, undetected, through victims’ systems.

“Time is burning,” Mr. Ben-Oni said. “Understand, this is really a war — with offense on one side, and institutions, organizations and schools on the other, defending against an unknown adversary.”

‘No One Is Running Point’

Since the Shadow Brokers leaked dozens of coveted attack tools in April, hospitals, schools, cities, police departments and companies around the world have largely been left to fend for themselves against weapons developed by the world’s most sophisticated attacker: the N.S.A.

A month earlier, Microsoft had issued a software patch to defend against the N.S.A. hacking tools — suggesting that the agency tipped the company off to what was coming. Microsoft regularly credits those who point out vulnerabilities in its products, but in this case the company made no mention of the tipster. Later, when the WannaCry attack hit hundreds of thousands of Microsoft customers, Microsoft’s president, Brad Smith, slammed the government in a blog post for hoarding and stockpiling security vulnerabilities.

For his part, Mr. Ben-Oni said he had rolled out Microsoft’s patches as soon as they became available, but attackers still managed to get in through the IDT contractor’s home modem.

Six years ago, Mr. Ben-Oni had a chance meeting with an N.S.A. employee at a conference and asked him how to defend against modern-day cyberthreats. The N.S.A. employee advised him to “run three of everything”: three firewalls, three antivirus solutions, three intrusion detection systems. And so he did.

But in this case, modern-day detection systems created by Cylance, McAfee and Microsoft and patching systems by Tanium did not catch the attack on IDT. Nor did any of the 128 publicly available threat intelligence feeds that IDT subscribes to. Even the 10 threat intelligence feeds that his organization spends a half-million dollars on annually for urgent information failed to report it. He has since threatened to return their products.

“Our industry likes to work on known problems,” Mr. Ben-Oni said. “This is an unknown problem. We’re not ready for this.”

No one he has spoken to knows whether they have been hit, but just this month, restaurants across the United States reported being hit with similar attacks that were undetected by antivirus systems. There are now YouTube videos showing criminals how to attack systems using the very same N.S.A. tools used against IDT, and Metasploit, an automated hacking tool, now allows anyone to carry out these attacks with the click of a button.

Worse still, Mr. Ben-Oni said, “No one is running point on this.”

Last month, he personally briefed the F.B.I. analyst in charge of investigating the WannaCry attack. He was told that the agency had been specifically tasked with WannaCry, and that even though the attack on his company was more invasive and sophisticated, it was still technically something else, and therefore the F.B.I. could not take on his case.

The F.B.I. did not respond to requests for comment.

So Mr. Ben-Oni has largely pursued the case himself. His team at IDT was able to trace part of the attack to a personal Android phone in Russia and has been feeding its findings to Europol, the European law enforcement agency based in The Hague.

The chances that IDT was the only victim of this attack are slim. Sean Dillon, a senior analyst at RiskSense, a New Mexico security company, was among the first security researchers to scan the internet for the N.S.A.’s DoublePulsar tool. He found tens of thousands of host computers are infected with the tool, which attackers can use at will.

“Once DoublePulsar is on the machine, there’s nothing stopping anyone else from coming along and using the back door,” Mr. Dillon said.

More distressing, Mr. Dillon tested all the major antivirus products against the DoublePulsar infection and a demoralizing 99 percent failed to detect it.

“We’ve seen the same computers infected with DoublePulsar for two months and there is no telling how much malware is on those systems,” Mr. Dillon said. “Right now we have no idea what’s gotten into these organizations.”

In the worst case, Mr. Dillon said, attackers could use those back doors to unleash destructive malware into critical infrastructure, tying up rail systems, shutting down hospitals or even paralyzing electrical utilities.

Could that attack be coming? The Shadow Brokers resurfaced last month, promising a fresh load of N.S.A. attack tools, even offering to supply them for monthly paying subscribers — like a wine-of-the-month club for cyberweapon enthusiasts.

In a hint that the industry is taking the group’s threats seriously, Microsoft issued a new set of patches to defend against such attacks. The company noted in an ominously worded message that the patches were critical, citing an “elevated risk for destructive cyberattacks.”

Mr. Ben-Oni is convinced that IDT is not the only victim, and that these tools can and will be used to do far worse.

“I look at this as a life-or-death situation,” he said. “Today it’s us, but tomorrow it might be someone else.”

Taliban Lindh out in Two Years, Then What

Image result for john walker lindh pink house Clarion

Related reading: John Walker Lindh Sues For Prison Prayer Group

Related reading: Remembering Johnny Michael Spann

Image result for john walker lindh in prison TheBlaze

FP: On Nov. 25, 2001, two CIA officers discovered a bearded 19-year-old English speaker among a group of captured Taliban fighters in Afghanistan.

The bedraggled teen stood out. “Irish? Ireland?” a CIA officer asked the prisoner, who gave no reply.

He turned out to be an American. And hours later, one of his CIA interrogators was killed when the captured Taliban prisoners staged an uprising.

Photographed naked and bound, California-born John Walker Lindh became detainee #001 in the global war on terrorism and dubbed the “American Taliban.” Branded a traitor and terrorist back home, he was convicted of supporting the Taliban and sentenced to 20 years in prison in a media firestorm that captured the zeitgeist of the post-9/11 era.

Now 36 years old, Lindh is set to be released in less than two years. And he’ll leave prison with Irish citizenship and a stubborn refusal to renounce violent ideology, according to the U.S. government. Foreign Policy obtained two government documents that express concerns about Lindh: One details the communications of Lindh and other federal prisoners convicted of terrorism-related charges, and the second, written by the National Counterterrorism Center, addresses the intelligence community’s larger concerns over these inmates, once released.

“As of May 2016, John Walker Lindh (USPER) — who is scheduled to be released in May 2019 after being convicted of supporting the Taliban — continued to advocate for global jihad and to write and translate violent extremist texts,” reads the National Counterterrorism Center document prepared earlier this year.

The report, marked “For Official Use Only” and dated Jan. 24, 2017, provides a window into how the intelligence community looks at the prospect of releasing American citizens still considered potential threats. The document indicates that intelligence and law enforcement agencies are already worried that “homegrown violent extremists,” like other criminals, could have high rates of recidivism.

The document, which cites various Federal Bureau of Prisons intelligence summaries, claims that in March of last year, Lindh “told a television news producer that he would continue to spread violent extremist Islam upon his release.”

The television news producer is not identified, no specific statements are quoted, and there is no public record that Lindh has participated in media interviews.

While Lindh’s case is the most prominent among these prisoners, it’s not unique. U.S. authorities are monitoring dozens of other inmates who they deem to be “homegrown violent extremists” and who will be released within the next several years.

By the end of 2016, according to the National Counterterrorism Center, there were 300 terrorism offenders in prison, including 80 arrested in the past two years. “We assess that at least some of the more than 90 homegrown violent extremists incarcerated in the US who are due to be released in the next five years will probably reengage in terrorist activity,” the report says, “possibly including attack plotting, because they either remain radicalized or are susceptible to re-radicalization as has already been demonstrated overseas.”

Back in 2002, Lindh’s case posed difficult challenges for a government just starting to grapple with how to prosecute the war on terrorism on the battlefield and in the courts. Fifteen years later, as Lindh approaches his release from prison, the federal government will again be venturing into unchartered waters as sentences for other convicted extremists expire.

Now it will be up to President Donald Trump to decide one of the trickiest legacies of the war on terrorism: how to treat so-called homegrown terrorists after they’ve served their time.

Several attorneys who worked on terrorism cases told FP the government doesn’t have any specific conditions in place for extremists once they’re released. Most of the emphasis is on the prosecution up front, and not what happens after they leave prison, they say.

Most sentences for terror-related cases involving U.S. citizens in the post-9/11 era “are ripening into release just now,” said Joshua Dratel, a lawyer who has defended suspected terrorists in federal court. “The government is just starting to run into the dilemma of what to do with them.”

Lindh’s journey from a liberal suburb in Marin County, California to northern Afghanistan began as an adolescent, when he watched the film Malcolm X. He told FBI interrogators that the movie inspired him to convert to Islam. In 1998, at just 17 years old, he dropped out of school and went to Yemen to learn Arabic, with his parents’ support.

From there, he traveled to Pakistan, where he spent time with a paramilitary group fighting for Kashmir’s independence from India. Then he made his way to Afghanistan, prior to the Sept. 11 attacks, to fight with the Taliban, which controlled much of the country and was waging a war with the Northern Alliance. It was then that he lost contact with his family, who wouldn’t hear from him again until after his capture.

Lindh spent seven weeks at a training camp near Kandahar, which was used to prepare Taliban militants for combat and al Qaeda volunteers for terrorist attacks. He met Osama bin Laden at least once and spoke briefly with the al Qaeda leader, who thanked the American and other foreign fighters for taking part in the jihad, according to the FBI’s account of his interrogation.

In November 2001, U.S. forces found Lindh among a group of Taliban fighters whose commander had surrendered to the Northern Alliance near Mazar-i-Sharif. Hours after Lindh was interrogated, his fellow prisoners staged a revolt in which some 500 were killed, including a CIA operations officer, Johnny Michael Spann. Lindh was shot in the leg during the fighting. He was one of only 86 who survived the uprising.

Lindh’s parents only learned of his whereabouts when CNN aired an interview with him shortly after his capture.

During more than 50 days of detention, U.S. authorities sometimes had Lindh blindfolded, naked and bound to a stretcher with duct tape. Although his family had retained a defense lawyer and told U.S. authorities about it, Lindh knew nothing about his attorney for a month.

Left: 14-year-old John Walker Lindh (Photo credit: Courtesy Frank Lindh); Right: The home of Frank Lindh on Dec. 3, 2001 in San Rafael, California. (Photo credit: JUSTIN SULLIVAN/Getty Images)

Brought back to the United States, Lindh found himself facing charges of terrorism, even though there was no evidence he plotted against Americans. In the frenzied aftermath of the Sept. 11 attacks on New York and Washington, then-Attorney General John Ashcroft described Lindh as an al Qaeda-trained terrorist who “chose to embrace fanatics.”

In the first legal case of the “war on terror,” Lindh was charged with providing material support for terrorism. The government’s case eventually collapsed over questions about Lindh’s treatment and confession while he was held by the U.S. military in Afghanistan and on U.S. naval ships.

With the defense team ready to shine an embarrassing light on Lindh’s treatment, federal prosecutors — at the urging of the Defense Department — dropped nine of the ten counts, including charges he tried to kill a CIA officer or support terrorism. Lindh ultimately pleaded guilty to violating an executive order prohibiting aid to the Taliban, and for carrying weapons in Afghanistan, and he agreed to drop any claims that he was abused by the U.S. military.

At his sentencing, Lindh, then 21, denounced Osama bin Laden, expressed regret over joining the Taliban, and renounced terrorism. “I condemn terrorism on every level — unequivocally,” he said in a prepared statement. “My beliefs about jihad are those of mainstream Muslims around the world.”

More than 15 years after he was captured on the battlefield in Afghanistan, Lindh’s case remains the subject of debate and intense speculation. Is he a dangerous traitor or the victim of an angry nation lashing out after a terrorist attack?

“We’ll never know what actually happened to John Walker Lindh,” said Wells Dixon of the Center for Constitutional Rights. “John Walker Lindh, in many respects, was a victim of the time. It was the aftermath of 9/11.”

Marc Sageman, a former CIA operations officer and a terrorism expert, said Lindh’s rise to public infamy and lengthy prison term was an “overreaction” to the new threat of terrorism in the aftermath of the 9/11 attacks. “Of course he pled guilty to some kinds of charges. Because the country was ready to lynch him,” Sageman said.

For Sageman, Lindh was more of a foot soldier fighting for a U.S. adversary rather than a terrorist plotting attacks. “People bandy about the word terrorism when they describe him,” he added. “I don’t see him as a terrorist.”

John Walker Lindh knows he won’t walk out of prison as just another ex-convict, and will likely face a hostile American public. While in prison, he came up with the plan of possibly moving to Ireland, according to a Bureau of Prisons intelligence summary. The document, prepared by the Federal Bureau of Prisons Counter Terrorism Unit, summarizes communications of prisoners convicted of terrorism-related crimes, and includes excerpted emails in which Lindh discuss his desire to leave the United States after his release.

Lindh secured Irish citizenship in 2013, according to the intelligence summary. Sources familiar with the matter confirmed his Irish citizenship to FP, and said it was obtained thanks to his paternal grandmother, Kathleen Maguire, an Irish citizen from Donegal born in 1929.

His father, Frank Lindh, hopes that his son could build a new life in Ireland after his release. But under Irish law, even with his new citizenship, the Irish government could refuse to issue a passport on grounds that Lindh posed a threat to national security. The U.S. government also could bar him from traveling abroad for at least three years, under the terms of his “supervised release” from prison, and even after that, legal experts say.

When asked about Lindh’s case, the Irish Embassy in Washington said it “does not comment on individual cases.” U.S. authorities also declined to comment.

In his initial years in prison at Terre Haute, Indiana, John Walker Lindh was kept under what are known as “special administrative measures,” which heavily restricted his communications with the outside world. Those measures were lifted in 2009, though the Bureau of Prisons declined to say if any specific restrictions are currently applied to Lindh.

Whether by choice or government constraint, Lindh has communicated little about his life in Terre Haute, though some details can be gleaned from his lawsuits against the Bureau of Prisons. In 2013, he won the right for communal prayer, and in December 2014, Lindh joined another legal battle, this time arguing for the right to wear his pants above his ankle, in line with Muslim tenets.

The Bureau of Prisons intelligence summary obtained by FP indicates that Lindh does have email contact with his father and an advocacy group working on his behalf.

“Regarding the Ireland issue, I really don’t know what to expect from the Irish government. I know virtually nothing about them. I think the only reasonable way to present my case to them is to explain my unique circumstances that make my survival in the US practically impossible,” Lindh wrote to CAGE, a nongovernmental organization that advocates on behalf of prisoners and detainees caught up in the war on terrorism. “Essentially I am seeking asylum from one country where I am a citizen in another country where I am also a citizen. The worst they can do is to decline my request. I figure it is worth at least trying,” Lindh wrote.

Go here to access documents.

In an email to his son in December 2016, Frank Lindh recounted his “hope-inducing conversation” with CAGE about emigrating. But first, CAGE required the assistance of an American defense lawyer to communicate with U.S. government officials, Frank Lindh informed his son.

There was one hitch: The renowned attorney who represented Lindh in his 2002 trial, James Brosnahan, had “dropped” his client, according to the intelligence summary. (Brosnahan did not respond to a request for comment.)

Frank urged his son “to mend fences with Jim,” referring to his former lawyer, adding that Brosnahan would likely demand that Lindh explicitly reject violence.

“We can discuss this in our next phone call, but one thing I anticipate Jim will absolutely demand is that you be willing to condemn, in all sincerity, publicly if needed, and without any reservation whatsoever, depravity of any kind, whoever commits it,” he wrote.

“You can visualize yourself what the list of depraved acts might consist of. I believe such a request should be easy for you, to fulfill as a devout Muslim and person of conscience.”

But John Walker Lindh refused. Replying to his father, he wrote: “I am not interested in renouncing my beliefs or issuing condemnations in order to please Brosnahan or anybody else.”

The Bureau of Prisons document says that “inmate Walker Lindh made pro ISIS statements to various reporters and was subsequently dropped by counsel.” It does not indicate which counsel, nor does it cite any specific statements.

CAGE has been at the center of its own controversy in recent years; proponents praise its work with detainees while critics accuse of it apologizing for terrorists. Amnesty International dropped its partnership with CAGE in 2015 and still refuses to share a public platform with the group, according to an Amnesty spokesperson. Despite the political baggage, it appears Frank Lindh is pinning his hopes on this organization.

Over the years, John Walker Lindh’s father has campaigned to win a possible commutation of his son’s sentence. In 2009, he participated in an interview with GQ in which he said, “I’m proud of my son.”

Lindh’s father has sought to portray his son as a spiritual, well-intentioned young man unjustly labeled as a terrorist. “Like Ernest Hemingway during the Spanish Civil War, John had volunteered for the army of a foreign government battling an insurgency,” he wrote in a 2011 New York Times op-ed. “His decision was rash and blindly idealistic, but not sinister or traitorous.”

Frank Lindh declined several requests for comment. A letter sent to John Walker Lindh at Terre Haute went unanswered. The Bureau of Prisons said that John Walker Lindh declined a request to comment for this article.

In October 2016, in the waning days of the Barack Obama’s presidency, the writer Paul Theroux published an op-ed in the New York Times asking that Lindh’s sentence be commuted, arguing that what Lindh did was comparable to his own youthful experience supporting rebels in Malawi in the 1960s. Theroux said that Lindh was “taking risks to help people perceived as oppressed; and like me, he did not fully understand the bigger picture, was in over his head, and was overtaken by events.”

The next month, Donald Trump, who has railed against the threat of Islamic extremism, was elected president, potentially snuffing out any chance of a commutation. It is now unclear how the government will deal with Lindh or others convicted of terrorism-related charges upon release.

It’s difficult to create a one-size-fits-all rehabilitation program for extremists because there are so few of these cases and each one is unique, said a former U.S. attorney who prosecuted numerous high-profile terrorists. “In this area of trying to rehabilitate extremists, it is really all over the map,” said the former U.S. attorney, who requested to remain anonymous. “The threshold question is what’s effective?

The National Counterterrorism Center suggested one option would be to widen government programs designed to counter violent extremism to include probation and parole officers, and to track convicted terrorists upon release. There’s a precedent with Megan’s Law, the document notes, which requires sex offenders to register their home address and check in frequently with law enforcement.

Lindh, for his part, does not appear to be optimistic. He tells his father in a December 2016 email quoted in the intelligence summary that he likely will have to “abandon this project” to move to Ireland. He says an earlier request to be released to Puerto Rico had not been answered, and that he anticipates having to endure threats and hostility on the U.S. mainland.

“I will just have to stay here for a while and deal with the lynch mobs as best as I can,” he writes. “It is a daunting predicament that I’m in, but many people around the world are in even more difficult situations and find ways to manage, so I am not worried.”

Cyber Spy Weapons Software Used Against Activists and Journalists

Mexico ranks 9th in journalists deaths. Find the list here by country.

Related reading: iPhone security flaw discovered, used by cyber weapons dealer

 Geek.com

Mexican Government was spying on Journalists and Activists with Pegasus Surveillance software

Journalists and activists in Mexico accused the government of spying on them with the powerful surveillance software Pegasus developed by the NSO Group.

Journalists and activists in Mexico accused the government of spying on them with a powerful surveillance software. According to the journalists, the authorities used an Israeli spyware to hack their mobile devices. The surveillance software is the questionable Pegasus that is developed by the Israeli surveillance NSO Group and sold exclusively to the governments and law enforcement agencies.

NSO Group is owned by US private equity firm Francisco Partners Management. it made the headlines after the investigation conducted by The New York Times.

People familiar with the NSO Group confirmed that the company has an internal ethics committee that monitors the sales and potential customers verifying that the software will not be abused to violate human rights.

Officially the sale of surveillance software is limited to authorized governments to support investigation of agencies on criminal organizations and terrorist groups.

Unfortunately, its software is known to have been abused to spy on journalists and human rights activists.

“There’s no check on this,” said Bill Marczak, a senior fellow at the Citizen Lab at the University of Toronto’s Munk School of Global Affairs. “Once NSO’s systems are sold, governments can essentially use them however they want. NSO can say they’re trying to make the world a safer place, but they are also making the world a more surveilled place.”

The discovery is the result of an investigation conducted by Mexican NGOs and the CitizenLab organization.

R3D, SocialTic, Article 19 and CitizenLab published a report that details the surveillance illegally operated by the Mexican government through the spyware.

Authorities have been sending malicious links to individuals’ phones, in order to trick victims into opening the messages they were specifically crafted and in some cases, the attack involved also family members if the victims were not compromised.

“The targets received SMS messages that included links to NSO exploits paired with troubling personal and sexual taunts, messages impersonating official communications by the Embassy of the United States in Mexico, fake AMBER Alerts, warnings of kidnappings, and other threats.” states the report. “The operation also included more mundane tactics, such as messages sending fake bills for phone services and sex-lines. Some targets only received a handful of texts, while others were barraged with dozens of messages over more than one and a half years. A majority of the infection attempts, however, took place during two periods: August 2015 and April-July 2016″.

Mexican Govenment surveillance

The Pegasus spyware leverages zero-day exploits to compromise both iOS and Android devices.

The government targeted individuals that exposed evidence on government corruption and activists who revealed human rights violations by the Mexican Government.

The researchers observed at least two periods of intense targeting:

  • Period 1 (August 2015) when the Mexican President was officially exonerated for his role in the “Casa Blanca” scandal on which Carmen Aristegui, a well-known reporter, had first reported, and Carlos Loret de Mola was questioning the government’s role in extrajudicial killings. Aristegui revealed that President Enrique Pena Nieto’s wife had bought a $7 million Mexico City mansion from a government contractor.
  • Period 2 (April- July 2016) when revelations of government involvement in human rights abuses and extra-judicial killings were made public.

Mexican Government spyware

According to the New York Times report, at least three Mexican federal agencies have purchased some $80 million of spyware from NSO Group since 2011.

Companies like the NSO Group operate in the dark, in a sort of “legal gray area,” despite the Israeli government exercises strict control of the export of such kind of software, surveillance applications could be abused by threat actors and authoritarian regimes worldwide.

Let me close with Key Findings of the report

  • Over 76 messages with links to NSO Group’s exploit framework were sent to Mexican journalists, lawyers, and a minor child (NSO Group is a self-described “cyber warfare” company that sells government-exclusive spyware).
  • The targets were working on a range of issues that include investigations of corruption by the Mexican President, and the participation of Mexico’s Federal authorities in human rights abuses.
  • Some of the messages impersonated the Embassy of the United States of America to Mexico, others masqueraded as emergency AMBER Alerts about abducted children.
  • At least one target, the minor child of a target, was sent infection attempts, including a communication impersonating the United States Government, while physically located in the United States.

***

Then comes former National Security Council advisor for President Trump Michael Flynn.

Cyberweapons Group Sold Spyware Used Against Political Dissidents

He earned nearly $1.5 million last year as a consultant, adviser, board member, or speaker for more than three dozen companies and individuals, according to financial disclosure forms released earlier this year.

Two of those entities are directly linked to NSO Group, a secretive Israeli cyberweapons dealer founded by Omri Lavie and Shalev Hulio, who are rumored to have served in Unit 8200, the Israeli equivalent of the National Security Agency.

Flynn received $40,280 last year as an advisory board member for OSY Technologies, an NSO Group offshoot based in Luxembourg, a favorite tax haven for major corporations. OSY Technologies is part of a corporate structure that runs from Israel, where NSO Group is located, through Luxembourg, the Cayman Islands, the British Virgin Islands, and the U.S.

Flynn also worked as a consultant last year for Francisco Partners, a U.S.-based private equity firm that owns NSO Group, but he did not disclose how much he was paid. At least two Francisco Partners executives have sat on OSY’s board.

Flynn’s financial disclosure forms do not specify the work he did for companies linked to NSO Group, and his lawyer did not respond to requests for comment. Former colleagues at Flynn’s consulting firm declined to discuss Flynn’s work with NSO Group. Executives at Francisco Partners who also sit on the OSY Technologies board did not respond to emails. Lavie, the NSO Group co-founder, told HuffPost he is “not interested in speaking to the press” and referred questions to a spokesman, who did not respond to queries.

Many government and military officials have moved through the revolving door between government agencies and private cybersecurity companies. The major players in the cybersecurity contracting world ― SAIC, Booz Allen Hamilton, CACI Federal and KeyW Corporation ― all have former top government officials in leadership roles or on their boards, or have former top executives working in government.

But it’s less common for former U.S. intelligence officials to work with foreign cybersecurity outfits. “There is a lot of opportunity in the U.S. to do this kind of work,” said Ben Johnson, a former NSA employee and the co-founder of Obsidian Security. “It’s a little bit unexpected going overseas, especially when you combine that with the fact that they’re doing things that might end up in hands of enemies of the U.S. government. It does seem questionable.”

What is clear is that during the time Flynn was working for NSO’s Luxembourg affiliate, one of the company’s main products — a spy software sold exclusively to governments and marketed as a tool for law enforcement officials to monitor suspected criminals and terrorists — was being used to surveil political dissidents, reporters, activists, and government officials. The software, called Pegasus, allowed users to remotely break into a target’s cellular phone if the target responded to a text message.

Last year, several people targeted by the spyware contacted Citizen Lab, a cybersecurity research team based out of the University of Toronto. With the help of experts at the computer security firm Lookout, Citizen Lab researchers were able to trace the spyware hidden in the texts back to NSO Group spyware. After Citizen Lab publicized its findings, Apple introduced patches to fix the vulnerability. It is not known how many activists in other countries were targeted and failed to report it to experts.

NSO Group told Forbes in a statement last year that it complies with strict export control laws and only sells to authorized government agencies. “The company does NOT operate any of its systems; it is strictly a technology company,” NSO Group told Forbes.

But once a sale is complete, foreign governments are free to do what they like with the technology. Read more here.

2016 Internet Crime Report

IC3 Releases Annual Report Highlighting Trends in Internet Crime

Giving someone access to your computer is like giving out a key to your front door. A computer can have your bank account information, family photos, and other private documents and data—information that fraudsters would like to steal. That’s why tech support fraud has become a significant trend in online crime, according to the 2016 Internet Crime Report from the FBI’s Internet Crime Complaint Center (IC3).

In tech support fraud cases, criminals convince unsuspecting victims to provide remote access to their computer by calling and posing as tech support personnel from a legitimate company. The criminal can then simply charge your credit card for a fake anti-virus product, or, in more sinister situations, they can steal your personal information or install malware. More than 10,000 incidents of tech support fraud were reported to the IC3 in 2016, with victims losing nearly $8 million. Though anyone can be a victim, older computer users are the most vulnerable targets.

“They’ll trick you into letting them into your computer,” said IC3 Unit Chief Donna Gregory. “You open the door and allow them in. You may think you’re just watching them install a program to get rid of a virus, but they are really doing a lot of damage behind the scenes.”

In addition to tech support fraud, the other major fraud categories last year were business e-mail compromise, ransomware, and extortion.

The IC3 receives complaints on a variety of Internet scams and crimes, and it has received more than 3.7 million complaints since it was created in 2000. In 2016, the IC3 received a total of 298,728 complaints with reported losses in excess of $1.3 billion. The IC3 uses the information from public complaints to refer cases to the appropriate law enforcement agencies and identify trends. The IC3’s extensive database is also available to law enforcement. Internet users should report any Internet fraud to IC3, no matter the dollar amount. Additional data helps the FBI and law enforcement gain a more accurate picture of Internet crime.

The IC3 publishes the Internet Crime Report annually to increase public awareness of current trends in Internet crime. For this report, the IC3 has also created a separate state-by-state breakdown that allows users to select their state from a dropdown menu so they can review local trends in Internet crime. The top states for reported dollar amounts lost to Internet fraud in 2016 were California ($255 million), New York ($106 million), and Florida ($89 million).

Though Internet crime is a serious threat, there are ways to help keep yourself safe online. The IC3 recommends computer users update their anti-virus software and operating system. Additionally, the Internet is an especially important place to remember the old adage: If it sounds too good to be true, it probably is.

“Be aware of what you are clicking on and also what you’re posting on social media. Always lock down your social media accounts as much as possible,” Gregory said. “Try to use two factor authentication, and use safe passwords or things more difficult to guess. The tougher the password, the harder it is for someone to crack.”

Global Blackouts, Anywhere in the World, Courtesy Russia

Fitful sleep last night after reading a very long detailed piece on Russian hackers versus Ukraine. Why, well the same tools and language they use have been found on American infrastructure and systems. Last thoughts before sleep were those of life before the internet and how people get emails with attachments that should never be opened. The short summary is just below. The more detailed and terrifying truth follows. It is a long summary, must be read…it is something like a cyber Hitchcock Twilight Zone disaster thriller, but it happened and happened often.

Image result for cyber war russia and us

Further, during a hearing in the House with former DHS Secretary, Jeh Johnson revealed a couple of key facts. One is told that during the election cycle, when the DNC hack, officials on numerous requests refused assistance, cooperation and discussions with DHS and FBI about foreign cyber intrusions. What was the DNC hiding? The other fact is Obama had the full details in intelligence briefings daily leading into November and December and refused to tell the country about Russian interference. He waited until after the elections and into December to take action. Why?

Okay, read on….

Image result for ukraine blackout CommentaryMagazine

Russia’s New Cyber Weapon Can Cause Blackouts Anywhere in the World

Hackers working with the Russian government have developed a cyber weapon that can disrupt power grids, U.S researchers claim. The cyber weapon has the potential to be absolutely disruptive if used on electronic systems necessary for the daily functioning of American cities.

The malicious software was used to shut down one-fifth of the electric power generated in Kiev, Ukraine last December. Called ‘CrashOverride’ the malware only briefly disrupted the power system but its potential was made clear.

With development, the cyber weapon could easily be used against U.S with devastating effects on transmission and distribution systems.

Sergio Caltagirone, director of threat intelligence for Dragos, a cybersecurity firm that examined the malware said, “It’s the culmination of over a decade of theory and attack scenarios, it’s a game changer.”

Dragos has dubbed the group of hackers who created the bug and used it in Ukraine, Electrum. The group and the virus have also been under scrutiny by cyber intelligence firm, FireEye, headed by John Hultquist. Hultquist’s company has nicknamed the group Sandworm and are keeping watch for clues of another attack.

The news of the malware comes in the middle of the ongoing investigation into Russia’s influence on the recent Presidential election. The Russian government is accused of trying to influence the outcome of the election by hacking hundreds of political organizations and leveraging social media.

While there is no hard evidence yet, U.S. officials believe the disruptive power hackers are closely connected to the Russian Government. U.S. based energy sector experts agree the malware is a huge concern and concede they are seeking ways to combat potential attacks.

“U.S utilities have been enhancing their cybersecurity, but attacker tools like this one pose a very real risk to reliable operation of power systems,”said Michael Assante, who worked at Idaho National Labs and is former chief security officer of the North American Electric Reliability Corporation.

CrashOverride

CrashOverride is only the second known instance of malware specifically designed to destroy or disrupt industrial control systems. The U.S. and Israel worked together to create Stuxnet, a bug designed to disrupt Iran’s nuclear enrichment program.

Robert M. Lee, chief executive of Dragos believes CrashOverride could be manipulated to attack other types of industrial control such as gas or water, though there has been no demonstration of that yet. But the sophistication of the entire operation is undeniable. The hackers had the resources to only develop the malware but to test it too.

The malware works by scanning for critical components that operate circuit breakers, then opening these breakers, which stops the flow of electricity. It continues to keep the circuit breakers open, even if a grid operator tries to close them. CrashOverride also cleverly comes with a “wiper” component that erases the existing software on the computer system that controls the circuit breakers. This forces the grid operator to revert to manual operations, which means a longer and more sustained power outage.

Potential outages could last a few hours and probably not more than a couple of days as U.S. power systems are designed to have high manual override capabilities necessary in extreme weather.

As mentioned above, you need to read the full detailed version here and just how the FBI, global cyber experts at the request of Ukraine worked diligently for accurate attribution to a Russian cyber force intruding on power systems. Hat tip to these experts and the story needs to go mainstream, as we are in a cyber war, the depths impossible to fully comprehend. Ukraine is the target and cyber incubation center for Russian cyber terrorists where they test, review, adapts and keep going without consequence.

Image result for ukraine blackout

Okay, read it all here. Hat tip for the detailed summary and the people doing quiet investigative cyber work.