Russia Posturing to Own Space, then China?

The U.S. military will soon be using lasers to shoot down ...

photo

Right now, miles above your head, there are fleets of robotic, weaponized satellites poised to do battle as the world’s superpowers await the opening salvo in a very real cosmic chess match.

When it comes to Russia, the real cause for concern surrounds a mysterious object known cryptically as 2014-28E. The object first appeared in space soon after the launch of three Russian military communication satellites. Initially, many believed 2014-28E was just another piece of debris left over from the launch. Not long afterward, however, this hunk of space junk began to swiftly change orbit, demonstrating an onboard propulsion system. What exactly 2014-28E is is still unknown, as the Russians have remained tight-lipped on the matter. Many experts fear that these actions signal that the Russians have revived their allegedly-defunct operation known as Istrebitel Sputnik (meaning “Satellite Fighter”), a covert Soviet-era ASAT program.

Russian and Chinese officials have continuously accused the United States of spying on the Chinese Space Station with a top-secret space toy known officially as X-37B. This craft is essentially an unmanned version of the Space Shuttle with a payload bay that’s roughly the size of a pickup truck bed. However, what exactly will be carried and what has been carried on its previous three missions is classified. So too is the entire X-37B budget. Many aeronautic experts dispute claims that the U.S. is using this craft to spy on the Chinese Space Station — but, the complete lack of transparency from U.S. officials hasn’t helped thaw frigid relations between the involved parties.

And the X-37B definitely isn’t the only trick the U.S. has up its proverbial sleeve. Some of America’s most sophisticated ASAT technology is in development as we speak. DARPA, the research and development wing of the U.S. Department of Defense, is now quickly moving along with its Phoenix initiative. The program is based around the concept of a series of robotic craft with the ability to repair damaged satellites from the scraps parts of other defunct satellites already in orbit. Again, from a foreign military perspective, if a satellite has the ability to build something, that satellite also has the intrinsic ability to dismantle something — say, an enemy satellite. More here from Digital Trends.

Russia Will Fight to Be World’s Top Space Power, Agency Chief Says

Russia is ready to do “serious battle” for the title of leading space power in the world, the head of the country’s state space agency has said.

Moscow’s Roscosmos has become the subject of some ridicule, following budget cuts and high-profile setbacks, including a recent botched launch that resulted in the loss of a multimillion dollar silo of satellites. The agency still regards itself as heir to Russia’s Soviet legacy of space exploration and Russian President Vladimir Putin has repeatedly urged officials to recapture that status in the world, telling agency employees last month that Roscosmos needed “breakthrough successes” to do so.

Roscosmos Director Dmitry Rogozin gave a defiant message on the agency’s ambitions.

“We are not looking to surrender leadership in space to anyone,” Rogozin said at the opening of a satellite equipment manufacturing plant in Yaroslavl region. The director, who served as Russia’s deputy prime minister until May, admitted that the agency had “fallen behind from the leading positions” in recent years.

08_06_Rogozin Moscow Mayor Sergei Sobyanin (front left) gestures at Russian President Vladimir Putin (front center) and others as they visit a space exhibition in Moscow, on April 12. Maxim Shipenkov/AFP/Getty Images

Roscosmos unveiled a brand new spaceport in eastern Russia in 2016, although Putin reportedly reprimanded senior officials in private after the launching ceremony, which he had gone to watch, suffered a 24-hour delay. More here.

Just two years ago:

So why is there so much global interest in space at the moment, including in Australia, and what are countries around the world doing up there right now?

Space remains ‘hugely contested’ in 2018

Modern militaries rely on satellites that feed them vital intelligence.

As a result, “counterspace” weapons have become a rising area of interest, and earlier this year, US intelligence agencies warned that China and Russia were both working on “destructive counterspace weapons” for use in a future conflict.

The potential weapons US intelligence agencies were concerned about included both ground-launched missiles capable of taking out enemy satellites, as well as “directed-energy weapons” that could blind or damage the sensors on satellite instruments.

The US intelligence agencies said in their report that both China and Russia would probably have operational weapons within a few years.

China last month launched a communications satellite named Magpie Bridge that is currently sitting in a special orbit near the moon, giving it a view of both the Earth and the so-far-unexplored dark side of the Moon.

That feat was praised in official Chinese state media Xinhua as a “world first”.

The plan is for the satellite to beam continuous images of the dark side of the moon, with China looking set to become the first country to land a rover there later this year.

China is also planning on setting up a permanent robotic base on the lunar surface in the next 10 years, and is hoping for a manned mission in the 2030s.

Iran’s Boiling Point, About to Get Worse

For 6 days in a row, demonstrators against the Iran regime are demanding regime change. There is hardly any gas for 6000 bus drivers in Tehran. There are curfews, people being shot while others are being arrested. The country currency, the rial has continued to plunge in value and food is being rationed.

After passing a 90-day mark on Aug. 6, the following sanctions will snap back on Iran, according to the Treasury Department:

  • Sanctions on Iran buying or acquiring U.S. dollars
  • Sanctions on Iran trading gold and other precious metals
  • Sanctions on Iran’s sale, supply or trade of metals such as aluminum and steel, as well as graphite, coal and certain software for “integrating industrial processes”
  • Sanctions on “significant” sales or purchases of Iranian rials, or the maintenance of significant funds or accounts outside the country using Iranian rials
  • Sanctions on issuing Iranian debt
  • Iranian auto sanctions

The U.S. will also revoke certain permissions, granted to Iran under the deal, on Aug. 6. These include halting Iran’s ability to export its carpets and foods into the U.S., as well as ending certain licensing-related transactions.

At the end of the 180-day interval on Nov. 4, another set of sanctions will once again be clamped down on Iran:

  • Sanctions on Iran’s ports, as well as the country’s shipping and shipping sectors
  • Sanctions on buying petroleum and petrochemical products with a number of Iranian oil companies
  • Sanctions on foreign financial institutions transacting with the Central Bank of Iran and other Iranian financial institutions
  • Sanctions on the provision of certain financial messaging services to Iran’s central bank and other Iranian financial institutions
  • Sanctions on the provision of underwriting services, insurance, or reinsurance
  • Sanctions on Iran’s energy sector

The following day, on Nov. 5, the Trump administration will disallow U.S.-owned foreign entities from being allowed to engage in certain transactions with Iran. Sanctions on certain Iranian individuals will also be re-imposed on Nov. 5.

Read the Treasury’s full guide to the re-imposition of Iran nuclear deal sanctions here.

Meanwhile:

LONDON/ANKARA(Reuters) – An English court has cleared the way to consider whether it will allow the families of some of those killed in the Sept. 11, 2001 attacks on the United States to make a claim on Iranian assets in Britain.

The relatives want the English High Court to enforce a 2012 decision by a U.S. court which found there was evidence to show that Iran provided “material support and resources to al Qaeda for acts of terrorism”. The militant group carried out the attacks.

The New York court awarded the plaintiffs damages of over $7 billion. Iran denies any links to Al Qaeda or any involvement in the 9/11 attacks.

If the English court agrees to enforce the ruling, it could clear the way for assets in England and Wales to be frozen or seized. Iranian assets in England include a central London building and funds held by two subsidiaries of state-owned banks. This could add to Tehran’s troubles as it tries to stave off a financial crisis.

The June 8 ruling by a judge after a hearing in the English High Court removed an obstacle that was holding up the process.

The law requires the UK’s Foreign Office (FCO) to formally serve the legal papers to Iran’s Ministry of Foreign Affairs (MFA) before the enforcement proceedings can begin. A British official said it was routinely difficult to deliver papers to the MFA, according to FCO correspondence seen by Reuters. An FCO official declined to comment.

The judge ruled it was sufficient to try to notify them through other communication such as email or post.

That decision has unblocked the process. The plaintiffs will now ask a judge at the High Court in the next few months to consider whether the New York ruling can be entered as a judgment in English law, said their lawyer Natasha Harrison, a partner at the London office of Boies Schiller Flexner. The judgment could then be enforced, she said. This would mean assets could be frozen or seized.

An Iranian official said: “Iran will take all the necessary measures to stop it.”

An Iranian foreign ministry official said the June ruling was “fabricated” and “politically motivated”.

U.S. is on the Offensive, Espionage and Cyber

In the last few weeks, there was the Aspen Security Forum, a 3 day event. Then there was a DNI report. Then came 2 separate nationwide conference calls hosted by CERT, the cyber division of DHS.

A remarkable White House press briefing included the heads of intelligence agencies explaining the condition of cyber/espionage and the countermeasures against Russia.

Then there is the military side, a division frankly not well known, the Defense Security Services.

 

See the whole 2 page release here.

 

 

 

 

 

 

 

 

 

 

And there is more:

FBI Releases Article on Securing the Internet of Things

The Federal Bureau of Investigation (FBI) has released an article on the risks associated with internet-connected devices, commonly referred to as the Internet of Things (IoT). FBI warns that cyber threat actors can use unsecured IoT devices as proxies to anonymously pursue malicious cyber activities.

As our reliance on IoT becomes an important part of everyday life, being aware of the associated risks is a key part of keeping your information and devices secure. NCCIC encourages users and administrators to review the FBI article for more information and refer to the NCCIC Tip Securing the Internet of Things.

*** IOT?

The internet of things, at its simplest level, is a network of smart devices – from refrigerators that warn you when you’re out of milk to industrial sensors – that are connected to the internet so they can share data, but IoT is far from a simple challenge for IT departments.

Related reading: Five IoT Predictions For 2019

For many companies, it represents a vast influx of new devices, many of which are difficult to secure and manage. It’s comparable to the advent of BYOD, except the new gizmos are potentially more difficult to secure, aren’t all running one of three or four basic operating systems, and there are already more of them.

A lot more, in fact – IDC research says that there are around 13 billion connected devices in use worldwide already, and that that number could expand to 30 billion within the next three years. (There were less than 4 billion smartphone subscriptions active around the world in Ericsson’s most recent Mobility Report.)

With a huge number of companies “doing IoT” – most big-name tech companies, including Google, Microsoft, Apple, Cisco, Intel, and IBM have various types of IoT play – all working to bring as many users as possible into their respective ecosystems, motivation to make sure IoT systems and devices from different companies all work with each other is sometimes lacking.

Internet of Things photo

The problem, of course, is that nobody’s willing to give up on the idea of their own ecosystem becoming a widely accepted standard – think of the benefits to the company whose system wins out! – and so the biggest players in the space focus on their own systems and development of more open technologies lags behind. More here.

Hey Jim Acosta, this Could be Why Media is an Enemy

Traveling over the CNN’s Jim Acosta’s Twitter account, this is his pinned tweet:

Then yesterday, he re-tweeted this:

And he retweeted this:

At the White House press briefing, Sarah Sanders called on @Acosta and he asked Sarah if she or the Trump White House would denounce that the media is an enemy of the people. She did not denounce that but went on to describe the media and progressive abuse the Trump administration endures, listing many nasty encounters.

What did @Acosta do?

He tweeted again:

As a conservative radio host, I watched that WH exchange between them and sent a tweet to @Acosta inviting him to an interview with me. ……crickets….

But there is more. It goes beyond CNN actually. Media and the left are simply branding all things law enforcement as racists including those in government, Republican voters and even some at Fox News. So we are in a posture war here that is undeniable. So….no sooner was all that over, here comes the New York Times.

***

Meet Sarah Jeong. She’s the newest member of the New York Times editorial board. She also has a history of saying pretty vile, racist things on Twitter.

Saved tweets from Sarah Jeong, the newest member of the New York Times editorial board. (source: Twitter)

Heck, just read more here, if you can stomach the vile branding of her and where the NYT’s is going in the future.

Eligible Receiver 97, Red Team Being Applied Today for Cyber Hacks?

An early classified Defense Department cybersecurity exercise named “Eligible Receiver 97” (ER97) featured a previously unpublicized series of mock terror attacks, hostage seizures, and special operations raids that went well beyond pure cyber activities in order to demonstrate the potential scope of threats to U.S. national security posed by attacks in the cyber domain, according to recently declassified documents and a National Security Agency (NSA) video posted today by the nongovernmental National Security Archive at The George Washington University.

“Joint Exercise Eligible Receiver 97”, run during the Clinton presidency, is frequently pointed to as a critical event in the United States’ appreciation of threats in cyber space. The exercise led directly to the formation of what would eventually become United States Cyber Command (USCYBERCOM) and informed key studies such as the formative Marsh Report on critical infrastructure protection. Despite the significance of ER97, however, very little is publicly known about the exercise itself.

ER97 involved an NSA Red Team playing the role of North Korean, Iranian and Cuban hostile forces whose putative aim was to attack critical infrastructure as well as military command-and-control capabilities to pressure the U.S. government into changing its policies toward those states. An interagency Blue Team was required to provide recommendations to personnel enacting defensive responses. Until now, only two phases out of three (infrastructure and command-and-control) had been publicly known.  The video and documents posted today provide new details about the third phase involving kinetic attacks in the physical domain – i.e. more traditional terrorist assaults on civilian targets – which were built upon intelligence gathered through the Red Team’s successes. Read more here on the declassified files.

*** With all the cyber terror going on today in the United States, are we doing more ‘red team’ exercises? Perhaps some of those tactics are paying off many years later.

3 Carbanak (FIN7) Hackers Charged With Stealing 15 Million ...

Three Members of Notorious International Cybercrime Group “Fin7” in Custody for Role in Attacking Over 100 U.S. Companies

Victim Companies in 47 U.S. States; Used Front Company ‘Combi Security’ to Recruit Hackers to Criminal Enterprise

          SEATTLE – Three high-ranking members of a sophisticated international cybercrime group operating out of Eastern Europe have been arrested and are currently in custody facing charges filed in U.S. District Court in Seattle, announced U.S. Attorney Annette L. Hayes, Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division and Special Agent in Charge Jay S. Tabb Jr. of the FBI’s Seattle Field Office.

According to three federal indictments unsealed today, Ukrainian nationals Dmytro Fedorov, 44, Fedir Hladyr, 33, and Andrii Kolpakov, 30, are members of a prolific hacking group widely known as FIN7 (also referred to as the Carbanak Group and the Navigator Group, among other names).  Since at least 2015, FIN7 members engaged in a highly sophisticated malware campaign to attack more than 100 U.S. companies, predominantly in the restaurant, gaming, and hospitality industries.  As set forth in the indictments, FIN7 hacked into thousands of computer systems and stole millions of customer credit and debit card numbers which were used or sold for profit.

In the United States alone, FIN7 successfully breached the computer networks of businesses in 47 states and the District of Columbia, stealing more than 15 million customer card records from over 6,500 individual point-of-sale terminals at more than 3,600 separate business locations.  Additional intrusions occurred abroad, including in the United Kingdom, Australia, and France.  Companies that have publicly disclosed hacks attributable to FIN7 include such familiar chains as Chipotle Mexican Grill, Chili’s, Arby’s, Red Robin and Jason’s Deli.  Additionally here in Western Washington FIN7 targeted the Emerald Queen Casino (EQC) and other local businesses.  The Emerald Queen Casino was able to stop the intrusion and no customer data was stolen.

“Protecting consumers and companies who use the internet to conduct business – both large chains and small ‘mom and pop’ stores — is a top priority for all of us in the Department of Justice,” said U.S. Attorney Annette L. Hayes.  “Cyber criminals who believe that they can hide in faraway countries and operate from behind keyboards without getting caught are just plain wrong.  We will continue our longstanding work with partners around the world to ensure cyber criminals are identified and held to account for the harm that they do – both to our pocketbooks and our ability to rely on the cyber networks we use.”

“The three Ukrainian nationals indicted today allegedly were part of a prolific hacking group that targeted American companies and citizens by stealing valuable consumer data, including personal credit card information, that they then sold on the Darknet,” said Assistant Attorney General Benczkowski.  “Because hackers are committed to finding new ways to harm the American public and our economy, the Department of Justice remains steadfast in its commitment to working with our law enforcement partners to identify, interdict, and prosecute those responsible for these threats.”

“The naming of these FIN7 leaders marks a major step towards dismantling this sophisticated criminal enterprise,” said Special Agent in Charge Jay S. Tabb Jr., of the FBI’s Seattle Field Office.  “As the lead federal agency for cyber-attack investigations, the FBI will continue to work with its law enforcement partners worldwide to pursue the members of this devious group, and hold them accountable for stealing from American businesses and individuals.”

Each of the three FIN7 conspirators is charged with 26 felony counts alleging conspiracy, wire fraud, computer hacking, access device fraud, and aggravated identity theft.

In January 2018, at the request of U.S. officials, foreign authorities separately arrested Ukrainian Fedir Hladyr and a second FIN7 member, Dmytro Fedorov.  Hladyr was arrested in Dresden, Germany, and is currently detained in Seattle pending trial.  Hladyr allegedly served as FIN7’s systems administrator who, among other things, maintained servers and communication channels used by the organization and held a managerial role by delegating tasks and by providing instruction to other members of the scheme.  Hladyr’s trial is currently scheduled for October 22, 2018.

Fedorov, a high-level hacker and manager who allegedly supervised other hackers tasked with breaching the security of victims’ computer systems, was arrested in Bielsko-Biala, Poland.  Fedorov remains detained in Poland pending his extradition to the United States.

In late June 2018, foreign authorities arrested a third FIN7 member, Ukrainian Andrii Kolpakov in Lepe, Spain.  Kolpakov, also is alleged to be a supervisor of a group of hackers, remains detained in Spain pending the United States’ request for extradition.

According to the indictments, FIN7, through its dozens of members, launched numerous waves of malicious cyberattacks on numerous businesses operating in the United States and abroad.  FIN7 carefully crafted email messages that would appear legitimate to a business’ employee, and accompanied emails with telephone calls intended to further legitimize the email. Once an attached file was opened and activated, FIN7 would use an adapted version of the notorious Carbanak malware in addition to an arsenal of other tools to ultimately access and steal payment card data for the business’ customers. Since 2015, many of the stolen payment card numbers have been offered for sale through online underground marketplaces. (Supplemental document “How FIN7 Attacked and Stole Data” explains the scheme in greater detail.)

FIN7 used a front company, Combi Security, purportedly headquartered in Russia and Israel, to provide a guise of legitimacy and to recruit hackers to join the criminal enterprise.  Combi Security’s website indicated that it provided a number of security services such as penetration testing.  Ironically, the sham company’s website listed multiple U.S. victims among its purported clients.

 

The charges in the indictments are merely allegations, and the defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

The indictments are the result of an investigation conducted by the Seattle Cyber Task Force of the FBI and the U.S. Attorney’s Office for the Western District of Washington, with the assistance of the Justice Department’s Computer Crime and Intellectual Property Section and Office of International Affairs, the National Cyber-Forensics and Training Alliance, numerous computer security firms and financial institutions, FBI offices across the nation and globe, as well as numerous international agencies. Arrests overseas were executed in Poland by the “Shadow Hunters” from CBŚP (Polish Central Bureau of Investigation); in Germany by LKA Sachsen – Dezernat 33, (German State Criminal Police Office) and the Polizeidirektion Dresden (Dresden Police); and in Spain by the Grupo de Seguridad Logica within the Unidad de Investigación Technologica of the Cuerpo Nacional de Policía (Spanish National Police).

This case is being prosecuted by Assistant U.S. Attorneys Francis Franze-Nakamura and Steven Masada of the Western District of Washington, and Trial Attorney Anthony Teelucksingh of the Justice Department’s Computer Crime and Intellectual Property Section.

how_fin7_attacked_and_stole_data.pdf