Categories
Tweets

Michael Novakhov retweeted: Senate revs up work on $2 trillion spending proposal, aiming to complete vote on Biden-backed bill before Christmas wapo.st/3Dnpzlm

Michael Novakhov retweeted:

Senate revs up work on $2 trillion spending proposal, aiming to complete vote on Biden-backed bill before Christmas wapo.st/3Dnpzlm

Categories
Tweets

Michael Novakhov retweeted: Biden turns to spy chief for tricky diplomatic missions ft.com/content/6a04d1…

Michael Novakhov retweeted:

Biden turns to spy chief for tricky diplomatic missions ft.com/content/6a04d1…

Categories
Tweets

Michael Novakhov retweeted: The sale came after a bidding war between three parties. dlvr.it/SDs56J

Michael Novakhov retweeted:

The sale came after a bidding war between three parties. dlvr.it/SDs56J

Categories
Michael Novakhov - SharedNewsLinks℠

Criminal hackers are now going after phone lines, too


Michael_Novakhov
shared this story
.

b’

Criminal groups have been sending threatening messages in the past couple of months to companies that manage broadband phone services all over the world, promising they’ll flood the digital phone lines with traffic and take them offline unless victims pay a ransom.

What those extortionists have discovered is that the number of phone calls that take place at least partially over the internet has quietly and dramatically increased over recent years xe2x80x94 and there’s a lot at stake when major providers go down.

Like landline providers, companies that manage digital phone calls, also known as voice over internet protocol (VoIP) services, are required to transmit audio in real time, facilitating personal, business and even emergency calls.

It’s probably a bigger part of our lives than many people realize. It’s much cheaper and often more accessible and scalable, a staple of working from home during the coronavirus pandemic. Small companies and people living overseas might have been using purely digital phone lines for years to reach customers, friends and family abroad. Large carriers and telecommunication companies often use VoIP to handle calls or connections between providers, while smaller carriers are routing tens of thousands of simultaneous calls over the internet. Call center companies handle over 1 million digital calls a day.

But if those companies that manage digital phone lines come under attack by a tsunami of fake callers, the behind-the-scenes mechanisms for beaming voices online begins to crumble fairly quickly.

“The challenge is that when you put all of the phone system on the internet, it exposes it to all of the other things that can go wrong on the internet,” says Matthew Prince, CEO and co-founder of Cloudflare, a company that provides protection against the kinds of attacks currently hitting internet phone providers.

The digital telecommunications industry is scrambling to gird against attacks

Prince and other security providers who focus on digital communications started noticing an uptick in attacks on VoIP services this fall. Specialists on forums for network operators started posting about the attacks, discussing what to do.

“In layman’s terms, people are freaking out,” says Fred Posner, a VoIP security specialist.

While providers’ themselves are mostly keeping quiet about these attacks, issuing terse email updates and sometimes social media posts to inform their customers about repeated outages, the security experts working with them are noticing a collective shift in mindset. Several of the experts interviewed by NPR agreed that the digital telecommunications industry was unprepared for this latest onslaught and has been forced to rethink their defensive strategy in a hurry. It’s not just the big banks or major corporations in the sights of criminal hackers xe2x80x94 it’s everyone and anyone who can and will pay to get their businesses back online.

“I think the point that we’re at right now is what we see is that there’s a sort of huge spectrum in terms of preparedness: from organizations that don’t know about the problem and are prepared, to organizations that know about the problem but aren’t able to invest or are willing to invest because they don’t think it relates to them,” says Jen Ellis, vice president of community and public affairs for cybersecurity firm Rapid7 and who also served on the Ransomware Task Force, a public-private sector collaboration.

These extortionists don’t actually have to hack victims to be a threat

That collective panic kickstarted when the digital communications provider <a href=”http://Bandwidth.com” rel=”nofollow”>Bandwidth.com</a> got hit by a digital extortion campaign in late September, Posner says. Previous attacks had targeted smaller providers, but Bandwidth was the biggest company yet to suffer a DDoS, or “distributed denial of service,” attack. While companies like Bandwidth expect a certain amount of legitimate traffic from users trying to make calls and send text messages, a DDoS attack involves bad actors directing a gargantuan number of illegitimate digital requests to its servers, overwhelming their ability to respond.

“I spent my career building big chunks of internet infrastructure, and I’m here to tell you that the internet really is just a series of tubes and those tubes have a certain amount of capacity,” says Prince of Cloudflare.

The criminals involved in these recent VoIP attacks are financially motivated. But unlike when major companies like Colonial Pipeline were hacked and held ransom, these attackers don’t actually have to hack into their victims to hold their services hostage. Merely weaponizing digital traffic is enough to at least temporarily disrupt a company’s ability to operate.

According to Allan Liska, an intelligence analyst at threat intelligence firm Recorded Future, this method of combining ransom threats with DDoS attacks, has been around since at least 2019. Back then, the extortionists often didn’t follow through on their threats to pummel victims with illegitimate traffic, because it was tough to reach the volume of signals required. “They weren’t actually backed up,” he says. But in recent months, some of these criminals have realized it doesn’t actually take that much traffic to disrupt the specialized protocols involved in transmitting audio in real time.

The internet wasn’t initially designed to be a conduit for real-time voice, text and video communication, according to the security experts. That’s because, in order to have a seamless conversation, each bit of audio has to arrive at exactly the right time or else the conversation won’t make sense xe2x80x94 whereas a website’s contents can load in any order. When you speak into the receiver to make a digital call, the audio is translated into tiny packets of digital information and then transformed back on the receiver.

Sandro Gauci, a security expert who helps communications companies patch flaws in their systems, says a digital call requires approximately one packet of data to be sent around every 20 milliseconds for a phone call to function properly.

“As soon as you have a little bit of downtime, the system stops working right … and since it’s meant to be real time, this is a huge problem,” Gauci says. “Our clients, if they are service providers, they are really concerned about denial of service because it makes them lose money every second their system is down.”

That’s exactly what the attackers have figured out how to do.

“It’s continuing to escalate,” says Liska. “And you know, one of the things about cybercriminals is they’re copycats. If you see something that works very quickly, other groups are going to copy it.”

Cybercriminals are claiming to be part of infamous hacking groups like Fancy Bear

Based on interviews with experts responding to these attacks, as well as a ransom note provided to NPR, attackers have falsely claimed to be part of well-known hacking groups such as Russia’s Fancy Bear, which was tied by security firms to 2016 U.S. election interference activities, and REvil, a now infamous criminal ransomware group. Liska notes this is a popular tactic to convince victims that their tormentors are legitimate and make them more likely to pay.

“They are adopting names of well-known threat groups in the hopes of inspiring more fear,” he says.

While providers have not shared information about whether or not they have considered paying ransoms to the attackers, many have had at least temporary success recovering from the attacks. But that doesn’t mean the disruptions haven’t had real impacts already.

Chet Wisniewski, principal research scientist at the security firm Sophos, moved to Vancouver, Canada, years ago and decided to switch to using VoIP full time in order to connect with friends and family in a more affordable way. Over the past couple weeks, he’s seen an error screen on his handset, sometimes for hours at a time.

“Like everyone else, you know, we all rely on our mobile phones,” Wisniewski says. “And I can’t imagine the disruption, you know, to a business that relies on this service if their phones are unreliable for their sales teams and tech support and things like that. It’d be a real disaster.”

The worst impact of a major telecommunications disruption would be the inability to call emergency services. Security experts tell NPR that at least some of the disruptions to major broadband providers have had a limited impact on 911 calls. The communications sector is listed by the Department of Homeland Security’s cyberagency, CISA, as a part of critical infrastructure because it serves an “enabling function” to connect businesses, individuals, emergency services and governments, particularly in a crisis.

“Gosh, if there were going to be a kinetic war with an adversary xe2x80x94 Russia, North Korea, Iran, whatever xe2x80x94 look how fragile this is that some probably teenage kids with a botnet are able to take out major communication providers and demand ransoms from them,” Wisniewski says. “What if it was a sophisticated, well equipped adversary like a nation state could wipe out our communication in minutes?”

The FBI was given the authority in recent years to disrupt botnets, which are essentially zombie armies of compromised devices that attackers use to flood their victims with traffic. It’s possible those kinds of authorities would be helpful in going after these criminal groups. Reportedly, AT&T announced it has “taken steps to mitigate” a botnet that targeted thousands of VoIP servers within its network, though it’s unclear whether that botnet was designed to launch denial of service attacks or for another purpose.

However, finding the extortionists is a real challenge. Most of the criminal groups demanding ransoms from broadband providers want payment in the digital currency Bitcoin to help cloak their identities.

Posner, the VoIP expert, says he’s been thinking a lot over the past month about what needs to be done to defend the communications sector. “First of all, clearly there needs to be some law enforcement,” he says. “These attacks are clearly violating existing laws, and there are few, if any, arrests or repercussions from these attacks. So it would be great if there could be some dedicated resources to help protect our infrastructure.”

On the other side, companies are going to have to come up with a response plan. “From my end, it seems that more preparation is necessary,” says Gauci, the security expert.

“More testing security testing is important,” he says, “because you want to know where you stand and if your security protection mechanisms are actually working and if they are introducing new problems for you or not, and how you are able to recover.” [Copyright 2021 NPR]

Categories
Michael Novakhov - SharedNewsLinks℠

Who Is Ilya Sachkov, Russian Cyber CEO Linked to 2016 Election Fancy Bear Leaks?


Michael_Novakhov
shared this story
.

b’

At a business awards ceremony in February 2019 at the Kremlin, a young cybersecurity entrepreneur named Ilya Sachkov chatted with Russian President Vladimir Putin. As cameras rolled, Sachkov invited Putin to visit the Moscow offices of his company, Group-IB, to see its powerful antihacking technologies firsthand. xe2x80x9cYouxe2x80x99ll definitely be astonished,xe2x80x9d he said.

It was the height of Sachkovxe2x80x99s success. Hexe2x80x99d started Group-IB as a college student and built it from a tiny consulting firm into one of Russiaxe2x80x99s most prominent security businesses. The company had hundreds of employees and was trying to expand into the U.S., Europe, the Middle East, and Asia. Sachkov traveled the world, cutting a glamorous figure in smartly tailored suits.

In a dramatic reversal of fortunes, the once-globetrotting executive is now languishing behind bars after being arrested in September and accused of treason. Sachkov, 35, denies the charges. He faces up to 20 years in a labor camp.

Details of the crimes Sachkov is accused of are shrouded in official secrecy. (Russian authorities donxe2x80x99t disclose specific charges in treason cases.) But interviews with a half-dozen people close to the case reveal that the surprise detention of Sachkov has links to one of the governmentxe2x80x99s most notorious hacking operations.

One of his alleged transgressions is that he gave information to the U.S. government regarding a hacking team in Russiaxe2x80x99s GRU military intelligence servicexe2x80x94dubbed xe2x80x9cFancy Bearxe2x80x9d by U.S. cybersecurity companiesxe2x80x94and its efforts to influence the 2016 U.S. presidential election, four of the people tell Bloomberg. The information Sachkov disclosed helped the U.S. government identify GRU agents involved in the hacking, three of the people say. The FBI declined to comment.

Bloomberg couldnxe2x80x99t determine whether those alleged acts are part of the official charges against Sachkov. Russian media has reported that the charges relate to a separate incident from 2014.

Interviews with people familiar with his casexe2x80x94including close associates, former Group-IB employees, and ex-Russian security officials who maintain close ties to the governmentxe2x80x94reveal that Sachkov worked in recent years to ingratiate himself with Western intelligence and law enforcement agencies. He sought to reduce his dependence on Group-IBxe2x80x99s Russian state contracts and to enter international markets, a risky game that made him a target of suspicion for both the U.S. and Russia.

Group-IB tells Bloomberg its work in fighting cybercrime has relied only on official agreements or requests from law enforcement agencies, not informal relationships. Sergei Afanasyev, Sachkovxe2x80x99s lawyer, declined to comment on any aspects of his case.

xe2x80x9cIn Putinxe2x80x99s eyes, the most serious problem is traitors,xe2x80x9d says Tatiana Stanovaya, founder of the political consulting firm R.Politik and a nonresident scholar at the Carnegie Moscow Center. xe2x80x9cHe is full of hatred toward people who leak information.xe2x80x9d

U.S. President Joe Biden is seeking greater help from Moscow to curb ransomware attacks and hunt cybercrime gangs operating from Russia. The prosecution of Sachkov doesnxe2x80x99t bode well for those efforts, says Christopher Painter, a former top U.S. cybersecurity official: xe2x80x9cThis sends a bad signal about cooperation with the U.S.xe2x80x9d

Group-IB performs digital forensics and hacking investigations, among other services, and builds technologies that look for breaches deep within computer networks. Some of its most consistent clients have been state-controlled corporations in Russia, including the countryxe2x80x99s top two banks, Sberbank and VTB, and Russian government bodies such as the space agency, the central bank, the interior ministry, and the investigative committee (Russiaxe2x80x99s equivalent of the FBI). The company obtained a license to work with secret government information, according to two former Russian security officials and an ex-employee. Group-IB denies having such a license.

Dmitry Volkov, a co-founder and now chief executive officer of Group-IB, told Bloomberg in October that Russia accounted for more than half the companyxe2x80x99s revenue last year and that he expected that to fall to 40% by the end of 2021. Despite Sachkovxe2x80x99s imprisonment, Volkov said, the company is still looking for a strategic foreign investor and is continuing with plans for an initial public offering on an international market.

Volkov said in late November that Sachkov built bridges with law enforcement agencies around the world xe2x80x9cas he has always seen the companyxe2x80x99s primary goal in fighting cybercrime worldwide and protecting the companyxe2x80x99s customers.xe2x80x9d Although Group-IB has the knowledge to identify and counter cybercriminals, Volkov said, xe2x80x9citxe2x80x99s only law enforcement agencies that are authorized to carry out justice and ensure that attackers are captured and no longer pose a threat to anyone. This has been Group-IBxe2x80x99s universal strategy in all the regions of our presence.xe2x80x9d

Four months after the awards ceremony at the Kremlin, Group-IB moved its headquarters from Moscow to Singapore, furthering Sachkovxe2x80x99s ambition to build an international powerhouse. He set up offices last year in Amsterdam and Dubai. One way Sachkov sought to establish his credentials internationally was to work with Western law enforcement, four people with knowledge of the matter say.

Sachkovxe2x80x99s mother, Lyudmila Sachkova, described her son as strongly goal-driven and unafraid to take on responsibility, as well as having a head for research and xe2x80x9ca keen sense of justice.xe2x80x9d Her son was inspired to set up his cybersecurity business after reading a book by two former U.S. Air Force cyberagents, Incident Response: Investigating Computer Crime, she told Bloomberg in a written statement through Group-IB.

Under the umbrella of fighting cybercrime, Group-IB promotes on its website collaboration agreements with Interpol, Europol, and other foreign law enforcement agenciesxe2x80x94routine partnerships for Western technology companies. But in courting foreign officials while continuing to do government work in Russia, Sachkov walked a dangerous tightrope.

He became entangled in a byzantine web of powerful Russian technologists and intelligence officials whoxe2x80x99ve now been accused of treason, according to earlier accounts in Russian media and new reporting by Bloomberg.

A central figure is Sergei Mikhailov, 47, a former senior official with the Federal Security Service, or FSBxe2x80x94the main domestic successor to the Soviet-era KGBxe2x80x94who led investigations into cybercriminals in Russia. Mikhailov was arrested in Moscow in December 2016, one month after the U.S. presidential election, and charged with treason. He was convicted in 2019 and sentenced to 22 years in prison after a trial in which Sachkov was a key witness for the prosecution, according to Mikhailovxe2x80x99s defense team, which has accused Sachkov of providing false testimony.

Although the official details of that case havenxe2x80x99t been made public, three people close to Sachkov and Mikhailov say the two men had known and worked with each other for years, including collaborating with foreign governments. Both ultimately provided information to Western officials that helped the U.S. prove Russiaxe2x80x99s role in the election hacking, the people say. Those findings led to the sanctioning by the U.S. of top GRU officials and the indictment of 12 of its alleged agents. The FSB didnxe2x80x99t respond to a request for comment on whether Sachkovxe2x80x99s prosecution is linked to Russiaxe2x80x99s meddling in the 2016 election.

The alleged treachery by Mikhailov and Sachkov had roots, in part, in a long-running conflict between the GRU and the FSB, which compete for resources and prestige in many areas, including foreign hacking operations, according to three people familiar with the matter.

Crowdstrike Holdings Inc., a U.S. cybersecurity company hired in 2016 to investigate the hack of the Democratic National Committee, pinned that breach and the subsequent leak of confidential internal documents on the GRU, in findings endorsed later by U.S. intelligence agencies. Crowdstrike also found that the GRU and FSB had each hacked the DNCxe2x80x99s servers in independent operations in 2015 and 2016, suggesting competition between the agencies.

The hacking of the DNCxe2x80x99s servers resulted in the whistleblowing organization WikiLeaks publishing about 20,000 private emails just before the Democratic National Convention that chose Hillary Clinton as the partyxe2x80x99s nominee for president in July 2016. The documents, which showed efforts by party officials to undermine Clintonxe2x80x99s chief rival for the nomination, Bernie Sanders, forced the resignation of the head of the DNC, Representative Debbie Wasserman Schultz. Clinton has blamed her defeat in the general election by Donald Trump on Russiaxe2x80x99s interference. Putin has repeatedly denied that the Russian state has meddled in U.S. elections.

Three people familiar with Sachkovxe2x80x99s case tell Bloomberg that one reason he may have been targeted is that he provided information to Western agencies about Vladislav Klyushin, the founder of another Russian cybersecurity company with Kremlin ties, who was arrested by Swiss authorities at the request of the U.S. in March, after he stepped off a private jet on his way to a skiing holiday with his family.

Klyushin, 41, has been in a Swiss maximum-security detention facility since then, fighting extradition to the U.S. on insider-trading charges. His lawyer, Oliver Ciric, says American authorities want to charge his client with orchestrating the election hacking. He argues that the insider-trading charges were created as a xe2x80x9cpretextxe2x80x9d to get Klyushin to the U.S. to pressure him to provide information about the operation.

Through his lawyer, Klyushin tells Bloomberg that he doesnxe2x80x99t know why he was arrested in March and not before, saying he traveled freely to Europe before then. He says he doesnxe2x80x99t know whether Mikhailov and Sachkov had offered any information about him and doesnxe2x80x99t know about possible cooperation between Group-IB and Western intelligence services.

Klyushin has a wealth of information about Russian interference in the 2016 election, and his extradition to the U.S. would be very damaging for the Kremlin, two people familiar with the matter say. He owns a company in Russia called M13, whose website states it provides media-monitoring services to the Kremlin, the defense ministry, and other Russian institutions. One of Klyushinxe2x80x99s senior employeesxe2x80x94Ivan Yermakovxe2x80x94was among the 12 alleged GRU operatives charged in the U.S. over the election hacking, and he is also a co-defendant in the insider-trading case against Klyushin, according to U.S. judicial documents reviewed by Bloomberg.

For Sachkov, there were danger signs in the final few weeks before his September arrest. He told associates that hexe2x80x99d been warned to not leave the country. According to one person close to him, he feared hexe2x80x99d be arrested. If Russian authorities ever found out the information hexe2x80x99d shared, he allegedly told another person, they would have him killed.

Sachkovxe2x80x99s fate will be decided in a secret trial that his defense team says might not start for 12 to 18 months. Hexe2x80x99s being held in Moscowxe2x80x99s Lefortovo Prison, a notorious ex-KGB detention site with a long history of housing political prisoners, known for its harsh conditions and severe rules restricting inmatesxe2x80x99 communications. A human-rights ombudsman who visited Sachkov in October says he complained that he wasnxe2x80x99t allowed to send or receive letters and was being kept in an information vacuum.

Afanasyev, Sachkovxe2x80x99s lawyer, said on Nov. 22 that the conditions of his imprisonment had improved. Hexe2x80x99s been transferred to a better cell and is now receiving letters, as well as medicine and food meeting his dietary requirementsxe2x80x94though as of Dec. 1, he hadnxe2x80x99t received any family visits, Afanasyev said. He also said Sachkov is xe2x80x9cgiving testimonyxe2x80x9d to investigators from behind bars.

In a letter he passed to his attorney, Sachkovxe2x80x94whose pretrial detention has been extended for an additional three months, to Feb. 28xe2x80x94appealed to Putin to allow him out of prison under home arrest. xe2x80x9cIxe2x80x99m not a traitor or a spy. Ixe2x80x99m a Russian engineer,xe2x80x9d he wrote, according to Afanasyev.
Read next: Cybercriminals Cash Out Ransoms at Moscowxe2x80x99s Tallest Tower

Categories
Tweets

fancy bear – Google Search shar.es/aWkoj7 bloomberg.com/news/features/…

fancy bear – Google Search shar.es/aWkoj7 bloomberg.com/news/features/…
Categories
Tweets

The Brooklyn Times – bklyntimes.com | #TNT – The #News And #Times – thenewsandtimes.blogspot.com | #JOSSICA – JOSSICA – The Journal of the #OpenSource #StrategicIntelligence #Counterintelligence #Analysis | #ODNI fancy bear – Google Search shar.es/aWkoYK

The Brooklyn Times – bklyntimes.com | #TNT – The #News And #Timesthenewsandtimes.blogspot.com | #JOSSICA – JOSSICA – The Journal of the #OpenSource #StrategicIntelligence #Counterintelligence #Analysis | #ODNI

fancy bear – Google Search shar.es/aWkoYK

FF8OjoTXEAYRXzq.png:large

Categories
Tweets

Michael Novakhov retweeted: Экстер А.А. «Вино». 1914 г.

Michael Novakhov retweeted:

Экстер А.А. «Вино». 1914 г.

FF8NuZrXEAQin9u.jpg:large

Categories
Tweets

Bloomberg назвал причину задержания основателя Group-IB Сачкова shar.es/aWkoCs

Bloomberg назвал причину задержания основателя Group-IB Сачкова shar.es/aWkoCs
Categories
Tweets

илья сачков – Google Search shar.es/aWkobi business-vector.info/bloomberg-kak-…

илья сачков – Google Search shar.es/aWkobi

business-vector.info/bloomberg-kak-…
WP Radio
WP Radio
OFFLINE LIVE