Categories
Audio Sources - Full Text Articles

Wall St set to open higher after two-day selloff

2022-11-18T13:55:31Z

Traders work on the floor of the New York Stock Exchange (NYSE) in New York City, U.S., November 15, 2022. REUTERS/Brenda McDermid/File Photo

Wall Street’s main indexes were set to open higher on Friday, as investors looked past hawkish comments from a top Federal Reserve official that had fanned fears of aggressive interest rate hikes from the central bank.

St. Louis Fed President James Bullard said on Thursday the U.S. central bank needed to keep raising interest rates given that its tightening so far “had only limited effects on observed inflation”.

The comments, coming on the heels of strong retail sales data, dampened hopes of the Fed toning down its hawkish approach following softer-than-expected inflation reports.

“Initially when that (Bullard commentary) came out, you saw the market sell off and then there was some discussion about was he being over-reactive?” said Kenny Polcari, managing partner at Kace Capital Advisors in Boca Raton, Florida.

All the three major U.S. indexes, which fell for a second straight session on Thursday, appear set to log weekly declines after notching solid gains last week.

“The rate increases that we’ve had over the last six months haven’t really had time to completely filter through the system and we’re going to see more of it filter over the next couple of months,” Polcari said.

Traders still largely expect the central bank to hike interest rates by 50 basis points in December and see rates peaking at 5.02% in May next year. .

“Markets are getting a little bit more comfortable with the fact that (a Fed pivot) is not likely. They are getting more comfortable with a generally higher interest rate regime,” said Paul Nolte, portfolio manager at Kingsview Asset Management in Chicago.

The benchmark S&P 500 (.SPX) and the Nasdaq (.IXIC) have lost 17% and nearly 29%, respectively, so far this year on worries that the Fed’s aggressive rate hikes aimed at curbing inflation could push the economy into a recession.

At 8:31 a.m. ET, Dow e-minis were up 224 points, or 0.67%, S&P 500 e-minis were up 35.5 points, or 0.9%, and Nasdaq 100 e-minis were up 118.25 points, or 1.01%.

Gap Inc (GPS.N) jumped 8.4% in premarket trade after the retailer surpassed quarterly sales and profit estimates, helped by steady demand despite a surge in inflation.

U.S.-listed shares of JD.com Inc advanced 2.7% after the e-commerce firm posted better-than-expected third-quarter revenue, as COVID-19 lockdowns in China led more consumers to shop online.

Applied Materials Inc (AMAT.O) gained 4.0% after the chip tools maker forecast first-quarter revenue above estimates, on hopes of easing supply chain constraints. read more

Categories
Audio Sources - Full Text Articles

Russia“s war on Ukraine latest news: 10 million Ukrainians reported to be without power

2022-11-18T14:02:37Z

Russian drones hit Dnipro early on Wednesday (November 9), damaging a warehouse and wounding four workers, according to Ukraine officials.

Russian forces kept up a barrage of shell and missile attacks on various regions of Ukraine, many hitting power infrastructure, while heavy fighting persisted in the Luhansk and Donetsk regions in the east of the country.

* Russia’s defence ministry said its strikes in Ukraine on Thursday were aimed at military and energy infrastructure, Russian news agencies reported.

* About 10 million people are without power, President Volodymyr Zelenskiy said in a Thursday evening video address, in a country with a pre-war population of about 44 million. He said authorities in some areas ordered forced emergency blackouts.

* A Reuters witness heard explosions in the centre of Kherson city on Friday morning and saw black smoke rising from behind buildings.

* Ukraine’s military said Russian forces had fired artillery on the towns of Bakhmut and nearby Soledar in the Donetsk region. Russian fire had also hit Balakliya in northeastern Kharkiv region, which Ukraine recaptured in September, and Nikopol, a city on the opposite bank of the Kakhovka reservoir from the Zaporizhzhia nuclear power station, it said.

Reuters could not immediately verify the battlefield reports.

* Russia said it hoped to clinch a prisoner swap with the United States to return convicted Russian arms trafficker Viktor Bout, known as the “Merchant of Death”, in an exchange that would likely include U.S. basketball star Brittney Griner.

* Russia is open to more high-level talks with the United States, a top diplomat said on Friday, but the Kremlin dismissed the idea of a summit between President Vladimir Putin and U.S. President Joe Biden as “out of the question” for now.

* The Dutch government will summon the Russian ambassador in the Netherlands over Russia’s response to the verdict in the trial over the downing of passenger flight MH17, news agency ANP reported. Russia said on Thursday the Dutch court’s decision to convict two former Russian intelligence agents and a Ukrainian separatist leader “neglected impartiality”.

* Ukrainian experts are already working at the site in the border area of southeastern Poland where a missile killed two people, Ukrainian Foreign Minister Dmytro Kuleba said. Warsaw and its Western allies say the blast was likely caused by a Ukrainian air defence missile that went astray in pursuit of a Russian missile. Kyiv says it has evidence of a “Russian trace”.

* A senior U.N. official welcomed the extension by four months of a deal aimed at easing global food shortages by helping Ukraine export its agricultural products from Black Sea ports, but said there was still work to be done.

* Russian President Vladimir Putin discussed the idea of creating a Turkish “gas hub” with Turkish President Tayyip Erdogan during a phone call, the Kremlin said on Friday.

* Russia’s energy exports to China have increased in value by 64% this year, and by 10% in volume as Moscow redirects shipments towards “friendly” nations, Deputy Prime Minister Alexander Novak said on Friday.

The European Union expects to have its regulations completed in time for the introduction of a G7 plan to cap the price of Russian crude oil on Dec. 5 , the EU’s energy policy chief told Reuters.

“The Gulag, created in 1933, and the current prison system(in Russia) are identical except for the name,” Olga Romanova, a representative of the prison rights group Russia Behind Bars, on the conditions Griner can expect in the IK-2 colony in Yavas. Russia’s prison service has not responded to questions from Reuters about conditions in such institutions.

Related Galleries:

Ukrainian servicemen fire a 130 mm towed field gun M-46 on a front line, as Russia’s attack on Ukraine continues, near Soledar, Donetsk region, Ukraine, in this handout image released November 10, 2022. Iryna Rybakova/Press Service of the 93rd Independent Kholodnyi Yar Mechanized Brigade of the Ukrainian Armed Forces/Handout via REUTERS ATTENTION

Toys are placed near the cross in memory of victims of Malaysia Airlines Flight MH17 plane crash in the village of Rozsypne in Donetsk region, Ukraine March 9, 2020. REUTERS/Alexander Ermochenko

A grain ship carrying Ukrainian grain is seen in the Black Sea, amid Russia’s attack on Ukraine, near Ukrainian port of Odesa, Ukraine November 2, 2022. REUTERS/Serhii Smolientsev

A boy waves a national flag as he celebrates after Russia’s retreat from Kherson, in central Kherson, Ukraine November 13, 2022. REUTERS/Valentyn Ogirenko

Police officers stand at a blockade after an explosion in Przewodow, a village in eastern Poland near the border with Ukraine, November 16, 2022. REUTERS/Kacper Pempel

A hearse drives past a police blockade after explosions in Przewodow, a village in eastern Poland near the border with Ukraine, November 16, 2022. REUTERS/Kacper Pempel

Ukrainian servicemen ride a 2S7 Pion self-propelled gun, as Russia’s attack on Ukraine continues, near a frontline in Kherson region, Ukraine November 9, 2022. REUTERS/Viacheslav Ratynskyi

A view shows a building of a local school destroyed during a Russian missile attack in the village of Novooleksandrivka, in Kherson region, Ukraine November 9, 2022. REUTERS/Valentyn Ogirenko

Ukrainian servicemen fire a 2S7 Pion self-propelled gun at a position, as Russia’s attack on Ukraine continues, on a frontline in Kherson region, Ukraine November 9, 2022. REUTERS/Viacheslav Ratynskyi

Ukraine’s President Volodymyr Zelenskiy speaks during a joint news conference with Czech Prime Minister Petr Fiala (not seen), as Russia’s attack on Ukraine continues, in Kyiv, Ukraine October 31, 2022. REUTERS/Viacheslav Ratynskyi

Combine harvesters load a truck with wheat in a field near the village of Tomylivka, as Russia’s attack on Ukraine continues, in Kyiv region, Ukraine August 1, 2022. REUTERS/Viacheslav Ratynskyi/File Photo
Categories
Audio Sources - Full Text Articles

Biden to meet with Ford CEO, UAW Friday on economy

2022-11-18T14:18:00Z

U.S. President Joe Biden speaks to the media after an alleged Russian missile blast in Poland, in Bali, Indonesia, November 16, 2022. REUTERS/Kevin Lamarque

U.S. President Joe Biden on Friday will meet on the economy with business and labor leaders, including the chief executives of Ford Motor Co (F.N), Kaiser Permanente and Carrier Global Corp (CARR.N) and the United Auto Workers union’s president, a White House official said.

The White House meeting, which will be in-person and virtual, will also include the presidents of the Service Employees International Union and United Food and Commercial Workers union, the official said.

Attendees will discuss the economy and meeting participants’ perspectives on the economy “and ideas they have to continue bringing inflation down,” the official said.

The White House has often cited a shortage of semiconductor chips as a key factor in higher prices for cars and trucks and overall inflation. Biden signed legislation in August that provides $39 billion in chip manufacturing subsidies.

Also attending is White House National Economic Council director Brian Deese and Treasury Secretary Janet Yellen.

The Treasury Department, which has faced calls from foreign governments and many automakers over the U.S. government’s restrictive electric vehicle tax credit policy that bars any vehicles assembled outside North America from qualifying, plans to issue guidance on how the EV tax credits will be implemented.

Ford CEO Jim Farley said on Tuesday the automaker will need to build more components for electric vehicles in its own factories so “everyone has a role” in the future.

Electric vehicles will require 40% less labor to build than current combustion vehicles, Farley told a conference in Detroit.

The UAW is seeking an election to represent about 900 workers at a General Motors (GM.N)-LG Energy (373220.KS) battery cell manufacturing joint venture in Ohio after the companies refused to recognize the union.

The UAW petition is seeking a Dec. 7-8 election of workers at Ultium Cells after a majority of employees had signed cards authorizing the union to represent them.

In May, Biden, in a trip to South Korea, expressed support for workers seeking to unionize joint venture battery plants. Detroit’s Big Three automakers all have battery plants in the works with Korean partners.

Categories
Audio Sources - Full Text Articles

Soccer-mad Germans turning their backs on World Cup

BERLIN (AP) — Normally when the World Cup comes around, Germans proudly fly their country’s flag and enthusiastically back their team.

Not this time.

Anyone walking around Berlin this week will struggle to notice any signs of World Cup fervor. There are no flags, no signs, no public viewing events – no indication that the soccer-mad country’s bid for a fifth world title is about to begin with a game against Japan on Tuesday.

Qatar’s human rights record and treatment of migrant workers have spoiled the party for many.

“We don’t want to enjoy a World Cup like this,” Bernd Beyer of the Boycott Qatar 2022 initiative told The Associated Press. “The fans do not identify with it and are saying they don’t want to have anything to do with it.”

There were widespread protests against the tournament during Bundesliga and second division games over the past few weekends, with fans holding banners blasting the human rights situation in Qatar and recent comments by World Cup ambassador Khalid Salman denouncing homosexuality.

The lack of enthusiasm also has had a commercial impact. Retailers have previously capitalized on the buzz around major tournaments with Germany team-related offers. Former Germany coach Joachim Löw and his players could be seen everywhere promoting various goods and services. This time, the Association of German Sports Retailers says sales of fan articles are way down compared to previous World Cup years.

“So far it’s not even half of what is usually sold in stores at major events of this kind,” the association’s president Stefan Herzog told the RND newspaper group.

Adidas said demand for Germany kits was low and that its biggest seller to date was Mexico’s jersey, considered by some to be among the most stylish of the shirts worn by the 32 World Cup teams.

Sales of TV sets, which generally go up for major sporting events, are also down, RND reported.

Chancellor Olaf Scholz’s spokesman, Steffen Hebestreit, told reporters in Berlin on Friday that the German leader will follow the national team’s matches if his schedule allows. He said he wouldn’t rule out Scholz traveling to the final if Germany makes it that far. Asked about fans’ plans for a boycott, Hebestreit said that “this World Cup was awarded and will now take place under difficult circumstances.”

Bundesliga clubs including Bayer Leverkusen and Borussia Mönchengladbach have criticized the decision to give the World Cup to Qatar and said they will only give it minimum attention on their websites and social media platforms. Another club, Hoffenheim, says it won’t report on the tournament at all.

“There’s just a multitude of things that have happened and are happening there that overshadow the great joy of sporting competition,” Jörg Schmadtke, the sporting director of Bundesliga club Wolfsburg, told the Wolfsburger Allgemeine Zeitung newspaper last week.

Schmadtke said he didn’t even know if he will watch the games on TV.

“It doesn’t move me like in previous years, when I looked forward to such a tournament,” Schmadtke said.

Qatar Holding LLC holds a 10.5% stake in automobile giant Volkswagen, which owns Wolfsburg.

Qatar has repeatedly pushed back against criticism over its human rights record, insisting the country has improved protections for migrant workers.

In contrast to previous tournaments, there will be no major public viewing events due to various factors including the cold weather, complications caused by the coronavirus pandemic, and the difficulties staging more outdoor parties during the Christmas market season.

The usual massive “fan mile” viewing party at Berlin’s Brandenburg Gate was nixed in September, when the organizing company said it wasn’t feasible this year. Around 9 million supporters took part in it when Germany hosted the tournament in 2006.

German fans are not the only ones who appear to be unimpressed by this year’s World Cup. Belgium’s soccer federation this week dropped plans to set up a fan zone for supporters to follow games on big screens citing a lack of demand, and Paris and other French cities also nixed public viewing parties. In Barcelona, mayor Ada Colau said she would not “dedicate public resources nor public spaces for the viewing of a World Cup that is being held in a dictatorship.”

In Germany, hundreds of bars are refusing to show World Cup games, said Beyer of the Boycott Qatar 2022 initiative. Among them is the Dortmund pub Mit Schmackes, owned by 2014 World Cup winner Kevin Grosskreutz.

“We love soccer and we can also say that we live soccer. The reasons are clear – that’s why we will decline to broadcast the World Cup matches in Qatar, even if this results in losses for us,” the pub said in an Instagram post to which Grosskreutz replied with three fire emojis to indicate his approval.

The Fargo bar in Berlin is another not showing the tournament.

“I’ve been showing the World Cup in my premises since 2006. They were always events where people got together, we cheered and celebrated, hugged each other. With the background to this World Cup, you can no longer do that with a clear conscience,” Fargo owner Lennart Kloehn told the local Tagesspiegel newspaper.

___

AP World Cup coverage: https://apnews.com/hub/world-cup and https://twitter.com/AP_Sports

Categories
Audio Sources - Full Text Articles

G7 Warns of Growing “hybrid threats” from Russia’s Цar

000_32nv46a.jpg

Russia’s war in Ukraine has a “significant impact” on the security of other countries, G7 interior ministers said on Friday, Nov. 18, warning of attacks on key infrastructure and risks posed by returning foreign fighters.

German Interior Minister Nancy Faeser reaffirmed the Group of Seven’s “unwavering solidarity” with Ukraine, after hosting two days of talks in the western town of Eltville.

“The war of aggression against Ukraine has had a significant impact on the internal security of G7 countries,” the ministers from Britain, Canada, France, Germany, Italy, Japan and the United States said in a joint communique.

Europe was stunned earlier this week when a missile blast struck a Polish village near the Ukrainian border, killing two people and raising fears of a dangerous escalation in the conflict.

Kyiv’s allies have since said the explosion was probably caused by a Ukrainian air defence missile — while stressing Moscow was ultimately to blame for starting the conflict.

Faeser and her counterparts in the club of rich nations said they were closely monitoring the fallout from Russia’s war, including the rise of “hybrid threats” designed to destabilise democracies and spread insecurity.

“Hybrid threats to our critical infrastructure, in addition to information manipulation, have increased significantly since the start of Russia’s war,” the interior ministers said.

The explosions that damaged the Nord Stream gas pipelines between Russia and Germany in September had highlighted “the need to better protect our critical infrastructure”, they said.

Sweden on Friday confirmed that the blasts were caused by sabotage. Washington and Moscow have both denied any involvement in the incident and each has pointed the finger at the other.

“Developing stronger overall security awareness… and building partnerships at the national and international level, including with the private sector, is crucial to become more resilient,” the G7 interior ministers said.

They also warned of new threats that could emerge when foreign fighters return home Ukraine with combat experience, as well as the risks posed by the increased flow of weapons in the region.

“A small number” of volunteer fighters in Ukraine “could pose a heightened threat upon their return”, they said.

The G7 ministers pledged to work closely with Ukraine on “a strict arms control regime” to prevent the illegal trade of firearms and ammunition.

The post G7 Warns of Growing “hybrid threats” from Russia’s Цar appeared first on Kyiv Post.

Categories
Audio Sources - Full Text Articles

Iran’s export of drones to Russia will lead to more proliferation and threaten US partners

Russia’s increasing use of Iranian drones in the war in Ukraine has spotlighted the danger that Iran’s drones pose globally and regionally. The outcome may be an expanded Iranian drone program, increased proliferation of the drones, and knowledge sharing between Moscow and Tehran that adversely affects Western partners in and outside the Middle East.

Moscow’s acquisition of Iranian military technology, specifically unmanned aerial vehicles (UAVs), represents a new chapter in Iran-Russia relations. It reverses several decades in which Iran sought technology transfers from Russia and other more advanced military powers.

Since Russia invaded Ukraine in February, it has relied on various stand-off weapons. This appears to be linked to Moscow’s desire not to risk using its air force over Ukraine, and a preference for cheaper munitions, such as artillery, to decimate portions of Ukraine. UAVs, or drones, present a way for Moscow to exploit a niche in military technology. Russia began looking into acquiring Iranian drones starting in June, according to US assessments. Whereas drones were once primarily used for surveillance or targeted air strikes, usually by Western countries, now Iran has become a drone warfare pioneer.

For Russia, Iran’s drones represent affordable off-the-shelf weapons it can expend in Ukraine. Iran, meanwhile, gains by finding a new market for its systems and seeing them being used in large numbers. No other country has used Iran’s drones in such quantity. Nevertheless there is still debate within Iran about the efficacy of the exports to Russia.   

Iran’s drones fill a unique niche for Russia in the realm of kamikaze drones or what are also called loitering munitions. These weapons are launched from a canister or rack that can be mounted on a truck, with the drone having a warhead encased within its body. Unlike more expensive drones, such as the US Reaper, the Iranian Shahed 136 is built for a one-way mission. The drone is slightly larger than a person and looks like a flying delta-wing. These Iranian drones may have a person controlling them, but often they fly via a pre-programmed route of waypoints and then slam into a target.

Iran makes other types of drones that may also be exported to Russia. These include the Shahed 129, which is designed to look like a US Predator drone, and the Shahed 191, which looks like a delta-wing, similar to a US Sentinel spy drone. It’s not clear if either of these would meet Russia’s needs or if Russia will opt for other types of kamikaze-style drones. Ukraine had said earlier this year that Iran has transferred 2,400 drones to Russia, but it is difficult to estimate the total number transferred by the end of the year. Iran has maintained it sent the drones before the war began.

Iran has used drones since the 1980s, partly to compensate for a lack of new warplanes after the fall of Mohammad Reza Shah Pahlavi’s regime and during its eight-year war with Iraq. Iran’s cities were targeted by Iraq during that conflict and drones became a way for Iran to confront Iraq and later to project power around the region. Over the years, Tehran built families of drones, increasing their range and adding munitions. Much has been written on aspects of Iran’s drone program as it proliferated over the years.

Why kamikaze drones meet Russia’s needs

While Iran has tried to reverse engineer downed American drones, its real success has been using loitering munitions flown on one-way kamikaze missions, like a cruise missile. Similar types of drones and cruise missiles were used in the attack on Saudi Arabia’s Abqaiq facility in 2019, which have been attributed to Iran or Iran-backed militias. Iranian-style drones have also been used in Yemen by Houthi rebels since 2015. With ranges of more than 1,000 km and a warhead of several dozen pounds, the Shahed-136—the type used in Ukraine by Russia—can wreak havoc on infrastructure and civilians. Ukrainian President Volodymyr Zelensky has accused Iran of training “Russian terrorists” to use the drones. 

As a customer for Iran, Russia matters more than militias because it’s a nation state and a major power.

Tehran has also exported drones to militias. It moved drones to Iraq during the war on the Islamic State of Iraq and al-Sham (ISIS), increasing the capabilities of Popular Mobilizations Forces (PMFs). Beginning in at least 2016, they were used over the Persian Gulf to harass US naval ships. Later, in 2018, Iran targeted Israel with drones flown from Syria, Iraq, and later from Iran itself, and exported drone technology to the Gaza Strip. This illustrates the expanding circle of Iran’s drone capabilities. Drones were also used by proxies in Lebanon and separately in Iraq and Syria, where they have threatened US forces operating against ISIS. In July 2021, Iranian drones were also involved in an attack on a commercial ship, killing two people in the Gulf of Oman. Additionally, Iran inaugurated a drone factory in Tajikistan over the last year. Each of these extensions represents a new level of success or capability.

Drones were once a Middle East-centric issue, with Israel, the US, and several Gulf states already working to counter the growing drone threat. Now Iran’s drone exports to Russia have led to concerns in the West. To some extent, drones have superseded Iran’s advancing nuclear program as a concern for Western partners.

Implications of Iranian drones in Russian hands

There are several possible outcomes for Iran’s drone exports to Russia. One is that Iran’s drones won’t win the war in Ukraine, thereby illustrating their limitations over time. Ukrainian air defenses are already shooting down the drones in large numbers. Iran will likely study how Western air defense responds to the drones and try to recalibrate them based on their failure rate. Attrition of the drones may encourage Russia and Iran to work more closely. For instance, a video purporting to show a future scenario in which a swarm of Shahed 136 drones attacked the Shaybah energy facility in Saudi Arabia was published in early November. This shows how Iran’s experience in Ukraine might boomerang back to the Middle East.

Iran’s drones could also be a threat to European countries, especially if any conflict grows beyond Ukraine. The major implication for European countries today is that they get to see how the weapon systems they supply to Ukraine measure up against drones. Germany and other European states have already been able to get a look at how anti-aircraft systems are performing and they will learn more over the coming months and be able to analyze successes and failures.

In the meantime, the Iran-Russia drone alliance will provide much-needed cash or cash-in-kind infusions for Iran, which remains under heavy US sanctions. Additionally, Iran-Russia knowledge sharing on technology may improve the Shahed 136 or similar drones that Iran may export. Similarly, expertise gained in Ukraine poses a threat to the US, Israel, the Gulf, and other partner forces in the Middle East. In a like manner, Iran is increasingly standardizing the assembly of drones, streamlining them to become more lethal and efficient. Finally, Iran is likely to find more markets for its drones among nation states, with possible links to China for procurement of drone components.

Iran’s supply of drones to Russia has been one of the major surprises of Moscow’s war on Ukraine. The use of a new type of unmanned technology, which is employed in a unique way by Moscow, has broad implications for Iran’s drone program and the way the drone threat may be perceived in the Middle East and Europe.

Seth J. Frantzman is the author of Drone Wars: Pioneers, Killing Machines, Artificial Intelligence and the Battle for the Future. He has a PhD from the Hebrew University of Jerusalem and is a journalist and researcher covering Middle East security issues and defense topics.

The post Iran’s export of drones to Russia will lead to more proliferation and threaten US partners appeared first on Atlantic Council.

Categories
Audio Sources - Full Text Articles

GRU 26165: The Russian cyber unit that hacks targets on-site

Russian hackers are not always breaching targets from afar, typing on their keyboards in Moscow bunkers or St. Petersburg apartment buildings. For some Russian government hackers, foreign travel is part of the game. They pack up their equipment, get on international flights, and covertly move around abroad to hack into computer systems.  

Enter GRU Unit 26165 (of the military intelligence agency Glavnoye Razvedyvatelnoye Upravlenie), a military cyber unit with hackers operating remotely and on-site. Despite the security risks on-site cyber operations pose to governments and international organizations, and the questions they raise about how the West should track and combat Russian state hacking, Russia’s activities in this realm are not receiving sufficient policy attention. 

GRU Unit 26165, the 85th Main Special Communications Center 

In March 2018, after the GRU tried to murder former Russian intelligence officer Sergei Skripal and his daughter Yulia in Salisbury, England using a Novichok nerve agent, the Kremlin came under international fire. British intelligence officials blamed the GRU, where Skripal used to work (and later became a British informant); the multinational Organization for the Prohibition of Chemical Weapons (OPCW), which enforces the Chemical Weapons Convention, launched an investigation; and in June of the same year, OPCW countries voted to let the body attribute chemical weapons attacks to particular actors. (A year later, the OPCW would formally ban Novichok nerve agents.) Additional journalistic investigations into the perpetrators, meanwhile, continued to point to the GRU’s involvement. 

Although the OPCW’s investigation was not made public for months, the Russian government decided to move quickly against the organization, turning to a tactical cyber unit to do so. 

OPCW Headquarters

On April 10, 2018, four Russian nationals landed at Amsterdam Schiphol Airport in the Netherlands. With diplomatic passports in hand, they were met by a member of the Russian embassy in The Hague. After loading a car with technical equipment—including a wireless network panel antenna to intercept traffic—the four individuals scouted the OPCW’s headquarters in The Hague for days, taking photos and circling the building before being intercepted by the Dutch General Intelligence and Security Service (Algemene Inlichtingen- en Veiligheidsdienst or AIVD) and sent back to Moscow. Seemingly, the plan had been for the operatives to hack into the OPCW’s systems to disrupt investigations into the attempted GRU chemical weapon attack.  

The Netherlands made all of this public on October 4, 2018, with Dutch intelligence identifying the four operators by name—Aleksei Sergeyevich Morenets and Evgenii Mikhaylovich Serebriakov were described as “cyber operators” and Oleg Mikhaylovich Sotnikov and Alexey Valerevich Minin were described as “HUMINT (human intelligence) support.” The AIVD linked all of these individuals to Russia’s GRU. A Department of Justice (DOJ) indictment issued on the same day went a step further, linking the hackers—Morenets and Serebriakov—to GRU Unit 26165. 

Unit 26165, otherwise known as Fancy Bear, was already known for breaking into systems from afar, including the Democratic National Committee in 2016 and World Athletics (previously the International Amateur Athletic Federation) in 2017. Yet, the revelations around the attempted OPCW hack made clear that Unit 26165 does much more. The full DOJ indictment, subsequently published by the National Security Archive at The George Washington University, alleged that Morenets “was a member of a Unit 26165 team that traveled with technical equipment to locations around the world to conduct on-site hacking operations to target and maintain persistent access to WiFi networks used by victim organizations and personnel.” Serebriakov also belonged to such a team. While Unit 26165 often conducts remote hacks from Russia, the indictment stated that “if the remote hack was unsuccessful or if it did not provide the conspirators with sufficient access to victims’ networks,” Unit 26165 would carry out “‘on-site’ or ‘close access’ hacking operations.” 

The OPCW incident was not the first time these particular hackers went abroad to conduct operations. According to the DOJ, Morenets traveled to Rio de Janeiro, Brazil, and Lausanne, Switzerland, in 2016 to breach the into WiFi networks used by people with access to the US Anti-Doping Agency, the World Anti-Doping Agency, and the Canadian Center for Ethics in Sport. Serebriakov, the indictment stated, also participated in these on-site hacking operations. Both individuals allegedly planned to target the Spiez Laboratory in Switzerland after the OPCW hack. The indictment alleged that Ivan Sergeyevich Yermakov, also part of GRU Unit 26165, provided remote reconnaissance support for his colleagues’ on-site hacking operation against the OPCW. 

Additionally, it is speculated that these on-site hackers were supported by another GRU unit, which is where the other two Russians caught in the Netherlands by the AIVD enter the picture. Sotnikov and Minin were described generically by the Dutch as HUMINT support for the two hackers, and as “Russian military intelligence officers” by the DOJ’s full indictment. Neither of these government documents mentions a specific GRU unit associated with Sotnikov or Minin. 

Published in tandem with the October 4, 2018 state disclosures was a new Bellingcat investigation linking Morenets’ Russian car to the Unit 26165 building in Russia. It also linked Minin’s car registration to the GRU “Conservatory.” The Conservatory—formally numbered GRU Unit 22177—is the Russian Defense Ministry’s Military Academy and a training site for the GRU, located in Moscow near GRU headquarters and other GRU training facilities. Due to Minin’s connection to 22177 and the Dutch and US governments’ vague references to Sotnikov and Minin as “HUMINT support” and “Russian military intelligence officers” separate from Unit 26165, numerous articles have speculated that operatives from another GRU unit were tasked to support the mission in The Hague. 

Stepping back, assessing the picture 

Policymakers should use this information as a case study for how Russian government hackers—and, theoretically, state hackers from other adversary countries—move around the world to break into systems. The use of on-site cyber operations abroad seems unique to this GRU team, with many possible motivations at play. It is unclear how high up the oversight chain these on-site operations go. What is clear, though, is that Western governments cannot restrict their hunt for Russian hackers to the digital sphere; they must also remember how Russian hacking fits into broader Russian intelligence activities, including overseas. 

There are several takeaways and implications that result from this information. The on-site, overseas cyber operations of GRU Unit 26165 appears to stand out from other Russian government cyber units. Of course, cyber capabilities are a part of intelligence operations more broadly, and many human operations around the world leverage cyber reconnaissance on an ongoing basis. Nonetheless, when the United Kingdom (UK) released its own statement on Russian government cyber activity in October 2018, it clearly differentiated between the activities of Unit 26165 in the Netherlands, Brazil, and Switzerland and those of Unit 74455 (Sandworm), which it stressed “were carried out remotely—by GRU teams based within Russia.” The DOJ indictment appears to suggest, although this is not totally clear, that hackers going abroad are part of at least one specific sub-team within the broader cyber unit. Further, the DOJ indictment lists numerous examples of on-site hacks or hack attempts, but publicly available information has not exposed the same kind of on-site operations by Russia’s Foreign intelligence Service, the SVR. 

The motivations behind the on-site operations of Unit 26165 are also a key question. Based on publicly available information, its proclivity for “close access” operations leans toward disrupting high-profile investigations into potentially embarrassing Russian government activity. The first set of reported hacks targeted international investigations into allegations of Russian doping at the Olympics; the second set of hacks targeted the international investigation into the attempted murder of the Skripals with chemical weapons. It is possible, therefore, that protecting the Kremlin’s image is a high priority. Simultaneously, the DOJ indictment stated that Unit 26165 carries out on-site operations when remote operations are unsuccessful, suggesting a more functional, effects-oriented motive for sending hackers overseas. 

However, there is another possibility: The GRU may simply be using on-site operations when it needs to draw attention away from its own failures. The botched attempt to murder Sergei and Yulia Skripal was carried out by GRU Unit 29155, a Russian military intelligence and assassination team with close relationships to the Signal Scientific Center federal research facility and the Ministry of Defense’s State Institute for Experimental Military Medicine in St. Petersburg, entities suspected of managing Russia’s Novichok program. GRU operatives are well-known for their high-risk appetites and sometimes overt violence, even relative to other Russian intelligence organs like the Federal Security Service (FSB), Russia’s domestic security agency. (That said, the FSB is a violent organization, too, carrying out repressive tactics in Russia and, in 2019, assassinating a Georgian asylum seeker in Berlin.) 

This tendency is playing out in cyberspace already, given that GRU teams are behind the NotPetya malware attack, shutdowns of Ukrainian power grids, and other more destructive, publicly visible operations. Such cyber activities, in line with broader intelligence cultures, stand in contrast to agencies like the SVR, which appears to place a premium on covertness, both online and offline. Wanting to frantically undermine an investigation into its own failed operation, it is not out of the question that the GRU sent Unit 26165 operatives overseas. That Unit 26165 hackers Morenets and Serebriakov may have had support from other parts of the GRU (HUMINT operators Sotbikov and Minin) in the OPCW plot suggests possible broader intra-agency coordination. But again, it is easy—and sometimes misguided—to assume there is more coordination within the Russian security services than actually occurs. 

All of this raises a final and more interesting question always at play in the Russian cyber ecosystem: How far up the chain does oversight of on-site hacks go? 

Cyber and information operations with high political sensitivity, which Moscow conceptualizes more cohesively than in the West, are more likely to be supervised by the Kremlin. The US intelligence community assessed, for example, that the influence actions targeting the 2016 US election were “approved at the highest levels of the Russian government,” and a similar conclusion was reached vis-à-vis President Vladimir Putin and Russia’s election interference in 2020. This may also be true for more traditional intelligence operations. When the UK finished its investigation into the murder of former Russian spy Alexander Litvinenko, who was killed on British soil with the radioactive material Polonium-210, it concluded that Putin and Russian Security Council head Nikolai Patrushev “probably” approved the killing. 

The GRU’s botched murder attempt on the Skripals garnered significant international attention. At the time, Russian officials were already criticizing the OPCW’s investigations into the Assad regime’s use of chemical weapons in Syria—called an attempt “to make the OPCW draw hasty but at the same time far-reaching conclusions” by Russia’s deputy foreign minister. When the investigation into the Skripal poisonings began, senior officials like Russian Foreign Minister Sergei Lavrov falsely claimed that a lab used by the OPCW picked up traces of a nerve agent possessed by NATO countries but not Russia. Putin, meanwhile, has always held particular contempt for people he perceives as betraying the Russian nation, once saying that “traitors always meet a bad end,” suggesting a kind of personal anger directed at individuals like Sergei Skripal who became agents for the West. The Olympic doping investigations, too, proved an embarrassment for Moscow. 

In this vein, it is quite possible that higher-level Kremlin officials may direct the GRU to act against investigations like OPCW’s, prompting the GRU to deploy Unit 26165 hackers to the Netherlands. It is also plausible that the activities of Unit 26165 merely reflect broader intelligence collection priorities, spying on those trying to “hurt” Russia, such as investigators looking into Russian athlete doping. Since there are few publicly known cases of Unit 26165 conducting “close access” operations, perhaps these are not representative samples, with the GRU carrying out these activities on its own after all. 

Regardless, the GRU is clearly sending hackers overseas to carry out operations. Going forward, Western intelligence and law enforcement personnel, as well as multinational organizations, would be wise to pay attention. 

The Atlantic Council’s Cyber Statecraft Initiative, under the Digital Forensic Research Lab (DFRLab), works at the nexus of geopolitics and cybersecurity to craft strategies to help shape the conduct of statecraft and to better inform and secure users of technology.

The post GRU 26165: The Russian cyber unit that hacks targets on-site appeared first on Atlantic Council.

Categories
Audio Sources - Full Text Articles

January 6th Committee hints at its big endgame

Keep Palmer Report going! Our articles are all 100% free to read, with no forced subscriptions and nothing hidden behind paywalls. If you value our content, you’re welcome to pay for it:

Pay $5 to Palmer Report:

Pay $25 to Palmer Report:

Pay $75 to Palmer Report:


Keep Palmer Report going! Our articles are all 100% free to read, with no forced subscriptions and nothing hidden behind paywalls. If you value our content, you’re welcome to pay for it:

Pay $5 to Palmer Report:

Pay $25 to Palmer Report:

Pay $75 to Palmer Report:

Sign up for the Palmer Report Mailing List.


One of the downsides to the Republicans winning a small and dysfunctional House majority is that the January 6th Committee will no longer exist beyond the end of the year. Well, actually, that’s not necessarily true, and we’ll get to that in a minute. But first the big news about the committee’s upcoming big crescendo.

The January 6th Committee has spun off a subcommittee whose job is to decide “whether to make criminal and civil referral referrals” to the Department of Justice, according to The Guardian’s Hugo Lowell. This means that the committee is indeed preparing to make DOJ referrals. It also suggests, to me at least, that the people appointed to the subcommittee are going to be the ones to make the decisions about what referrals to send. So who’s on this subcommittee?

It turns out Jamie Raskin is running the show, with Liz Cheney, Adam Schiff, and Zoe Lofgren also on the subcommittee. Raskin was a law professor, to it makes sense that he’s in charge of this process. There has been much consternation among the media and the public about whether the committee will make criminal referrals to the DOJ against Donald Trump and others for their January 6th crimes. But in reality, Attorney General Merrick Garland has already publicly stated that the DOJ has been watching the hearings. So the DOJ is already going to do what it’s going to do in that regard.

What stands out to me are the two areas in which Congress can influence the DOJ’s decision-making: contempt of Congress and lying to Congress. Thus far we’ve seen the January 6th Committee make contempt referrals against four people. The DOJ has indicted two of them, Peter Navarro and Steve Bannon, and the latter has since been tried and convicted.

These four contempt referrals were strategically made at specific times for various reasons. But the reality is that there are quite a number of referrals that the committee can still send. For instance, the likes of Roger Stone and Alex Jones pleaded the fifth to essentially every question, and there is a legal argument to be made that doing so is contempt. You’re only allowed to plead the fifth in response to specific questions where you could reasonably fear your answer could be used against you by prosectors – and you can’t make that argument when you plead the fifth to every question including harmless questions about formalities.



On another note, the committee has yet to reveal how many witnesses it’s caught lying (keep in mind, lying to Congress is a felony whether the person is under oath or not). So we have that to look forward to as well. I know that most folks are probably more interested in how the committee decides to formalize asking the DOJ to look at the actual January 6th-related underlying crimes that it’s uncovered. But process crimes like obstruction or lying to Congress are often what end up taking slippery career criminals down.


Finally, because Democrats have won the Senate majority, they will retain control of every regular Senate committee (Oversight, Judiciary, Intelligence, etc) for the next two years. So if the January 6th Committee feels that its work does need to continue for the long term, nothing says its investigation – or even its members – can’t be folded into a Senate committee in some way. It would be an unusual move, but these are unusual times.

Keep Palmer Report going! Our articles are all 100% free to read, with no forced subscriptions and nothing hidden behind paywalls. If you value our content, you’re welcome to pay for it:

Pay $5 to Palmer Report:

Pay $25 to Palmer Report:

Pay $75 to Palmer Report:

Write for the Palmer Report Community Section.


Keep Palmer Report going! Our articles are all 100% free to read, with no forced subscriptions and nothing hidden behind paywalls. If you value our content, you’re welcome to pay for it:

Pay $5 to Palmer Report:

Pay $25 to Palmer Report:

Pay $75 to Palmer Report:

The post January 6th Committee hints at its big endgame appeared first on Palmer Report.

Categories
Audio Sources - Full Text Articles

Keeping Up With Ransomware

Electronic-security_artwork_%28lock_%26_

Earlier this month, the White House hosted the second meeting of the International Counter Ransomware Initiative (CRI). One of many initiatives on cybersecurity advanced by the Biden administration, the CRI acts as a forum for partners and allies to “cooperate internationally across all elements of the ransomware threat.”

Addressing the various aspects of the ransomware threat has been a primary early goal of the Biden administration in cybersecurity. As my colleagues explained, “the U.S. government has begun to leverage a range of criminal, diplomatic, economic and military capabilities in order to combat the ongoing ransomware threat.” This whole-of-government approach attempts to thwart and disrupt cybercriminals and their infrastructure, prevent them from abusing financial systems, and impose costs on those jurisdictions that have become safe havens, while also leveraging public-private partnerships and diplomacy to improve information sharing, risk awareness, and resilience.

The theory behind this focus is that ransomware is relatively low-hanging cybersecurity fruit. Relatively few actors are responsible for a lot of the damage. Keeping software patched does wonders to prevent it. So the idea is that a series of cybersecurity “sprints” could make a big difference.

The government has certainly been active on the subject. The U.S. Department of Treasury sanctioned several virtual currency exchanges for facilitating transactions laundering the proceeds of ransomware schemes. The Conti and REvil groups shut down their operations. And when the CRI first met in October 2021, more than 30 countries committed to act together to mitigate the risk of ransomware.

Yet, in the war against ransomware, ransomware is at least holding its own. Ransomware-as-a-Service (RaaS) is growing in popularity, enabling more actors to easily target a broad range of sectors. Despite increased spending in cybersecurity, more companies report being victims of an incident, a trend that is expected to continue into next year. Newer ransomware strains are emerging. More incidents are being reported. And the average ransom paid is higher than ever before. Even more concerning, widespread adoption of double extortion schemes, in which the bad actor extracts the data before encrypting it and threatens to make it public, leads to more organizations deciding that paying the ransom might be in their best interest.

To begin the work of evaluating actual results against the undoubted commitments of the administration, I will endeavor to describe the areas of work mapped by the CRI and assess what we can expect from their efforts.

The Counter Ransomware Initiative: A Year In

In its statement from 2021, the CRI committed to a multipronged approach to tackling ransomware, by establishing working groups to address different aspects of the threat. The five groups were tasked to look into increasing resilience, disrupting malicious actors, tackling the financial mechanisms that are abused to launder ransomware payments, promoting public-private partnerships, and leveraging diplomacy. Each working group was led by different partners: Lithuania and India led the resilience group, Australia led the group on disruption, the U.K. and Singapore took the lead on tackling financial mechanisms, Spain ran point on public-private partnerships, and Germany ran the group on leveraging diplomacy.

After a year of working in their respective groups, the CRI met in person to discuss their accomplishments and put forth a program of action for the next year. In a departure from the previous meeting, 13 private companies were invited to attend this meeting, “represent[ing] a diverse range of size, regional reach, and focus.” Those companies were CrowdStrike, Mandiant, Cyber Threat Alliance, Microsoft, Cybersecurity Coalition, Palo Alto, Flexxon, SAP, Institute for Security and Technology, Siemens, Internet 2.0, Tata – TCS, and Telefonica. 

The inclusion of private-sector actors tracks with the administration’s focus on improving public-private partnerships to increase cybersecurity. Given that many of the action points in the statement will hinge on collaborating with private actors, it is a positive development that they were invited to speak to the CRI.

What started in 2021 as an identification of common challenges and lines of action that the multilateral group would tackle has now developed into a more concrete list of deliverables. The highlights from this year’s CRI include

  • Creating the International Counter Ransomware Task Force (ICRTF), led by Australia. 
  • Leveraging the regional cyber defense center in Lithuania as a “scaled version of the ICRTF” that can test the information sharing commitments.
  • Promoting a range of capacity-building activities, which include publishing a toolkit for responding to ransomware, attempting to develop “aligned frameworks and guidelines” for prevention and response, and holding counter-ransomware exercises and counter-illicit finance ransomware workshops.
  • Advancing information sharing between the CRI members and with the private sector, about ransomware tools and procedures, the systems used for laundering ransomed funds, and the implementation of anti-money laundering and countering the financing of terrorism standards.
  • Strengthening diplomatic engagement and addressing the ransomware threat across forums.

The action plan outlined in the 2022 joint statement reflects the importance of information sharing and capacity building, with a focus on disrupting the infrastructure that cybercriminals leverage to launder the proceeds of their schemes.

An Evolving Threat

All of these actions sound salutary and worthy. The trouble is that, while the CRI has been organizing committees and working groups, the ransomware bad actors have continued developing tools and techniques to target victims. The CRI and other related initiatives face a tough challenge. Despite some successes, increased awareness of the threat, increased spending on cybersecurity, and new partnerships, the ransomware forecast continues to look ominous.

Cybercriminals, it just so happens, are particularly adept at adjusting to new cybersecurity measures. After Microsoft decided to disable macros by default (one of the most successful ways in which malware is delivered to its victims), cybercriminals quickly began shifting to dropping malware through new methods like LNK files, according to a recent report by cybersecurity company Deep Instinct.

Fortinet’s threat intelligence group attributes an increase in ransomware variants to the popularity of RaaS offerings. An example of the professionalization of cybercrime, RaaS allows an operator to rent the ransomware to “affiliates” or “partners,” who then deploy it. In exchange for a cut of the ransom, more actors—regardless of their sophistication—can go after their victims.

The resilience isn’t just technical. While several high-profile groups have been disrupted in the recent past—like the REvil or Conti groups—they have a tendency to resurface shortly after in new forms. Disbanding and reappearing under “clean” identities is not uncommon, which adds a layer of complexity to the goal of disrupting operations. Without an updated international framework or the cooperation of those countries in which the criminals find shelter, the disruption of these groups more closely resembles a game of whack-a-mole than a takedown.

Ransomware gangs also have been successful at finding other ways to incentivize their victims to pay the ransom. Double and triple extortion are part of the new trends that cybersecurity researchers have been warning about for years.

Double extortion is now a well-established methodology. Here’s how it works: Before encrypting the files, the criminals extract the documents. If the victim refuses to pay the ransom, the cybercriminals can threaten to make that data public. The Australian health insurer Medibank is, for example, currently risking the disclosure of compromised data for approximately 9.7 million of its customers in a standoff with criminal group BlogXX (which may or may not be the former REvil group). In the past, data leaked in this fashion included sensitive personnel information, Ferrari repair manuals, and students’ psychological assessments

The efficacy of this scheme in securing a payment is such that “82 percent of the ransomware actors in the last year have begun moving to data extortion as well, and we’ve even seen some of them are dropping the ransomware,” as Adam Meyers, senior vice president of intelligence at cybersecurity firm CrowdStrike, warns

Some cybercriminals take the extortion a step further by turning their demands to those who would be affected by the disclosure. This is called triple extortion. Here, the sensitive nature of the data extracted is leveraged to extort those who would be personally impacted by the disclosure.

According to Meyers, the newer levels of extortion allow cybercriminals to regain control over the negotiations and change the calculus surrounding ransom payments. In his words, “the calculus of pay or not pay is heavily factored in on when data gets leaked, what are the regulatory compliance and legal impact, so that that can be astronomical compared to the ransom demand.”

The U.S. and Europe still account for the most targeted geographies. By some accounts, however, reported ransomware incidents are decreasing there while increasing in Latin America. And incidents in Africa and the ASEAN (Association of Southeast Asian Nations) region are on the rise, according to the 2021 Interpol Cyberthreat Assessment reports. Given that most of the CRI members are European (only three African, four Asian, three Latin American, and two Middle Eastern countries were part of the meeting), shifts in the distribution of ransomware incidents will test how international the CRI can be.

While the goal of the CRI might not be to replicate a U.N. General Assembly, the lack of representation might harm its goals. Reduced visibility into the ransomware trends in other regions could hinder the objective to achieve improved awareness for the overall threat environment. Strong capacity-building efforts and coordination with those countries that struggle most with technical and policy cyber capabilities could help stop them from becoming the focus of attention for cybercriminals looking for easy targets.

Another goal of the CRI is to raise the diplomatic cost for countries that allow their territories to become safe havens for criminals. This becomes even more crucial considering that nation-states can sometimes be the ones behind the ransomware attacks, leveraging the breach to accomplish their political goals. The good news is that the diplomatic community has been active on the cyber front: Governments now have an array of tools at their disposal to react to cybersecurity incidents. It remains to be seen, however, whether substantive change can be achieved when the countries that are considered safe havens (Russia, China, and Iran, most notably) do not participate in the CRI. Given today’s geopolitical context, this is to be expected. But the CRI might need to grapple with this challenge directly: What is the goal of diplomacy in this context?

Conclusion

Ransomware is, ultimately, an attractive venture for criminals. And as long as it remains so, new tactics, techniques, procedures, and variants will continue to surface. The Biden administration has been clear that the focus should not be just in responding to cybersecurity threats as they appear, but in building defenses and resilience. Which is why it is surprising to see a U.S.-led initiative focus so much on responding to the threat, rather than preventing it. Information sharing and lessons learned will be useful, but they do not nip ransomware in the bud. 

One frustrating takeaway from the CRI is that it may have had more success in erecting bureaucratic responses to ransomware than in actually countering ransomware. This may reflect the expected challenges of agreeing on anything with over 30 partners. It would be easy to be dismissive of the effort, given the data. As it enters into its second year, the CRI’s most concrete deliverable seems to be the future establishment of a task force.

Ransomware is alive and well. And as cybercriminals continue to adapt, change their methods, and go after new targets that are more likely to pay, the need to remain aware of new variants and trends is of the utmost importance. The CRI is trying to shape itself into a response mechanism, hopefully disrupting some of the bad actors. It’s possible that it is suited to the task. If, at the very least, the CRI proves to be a solid platform for capacity building, that will have a positive effect on the overall environment. This sounds less ambitious than swift transnational disruption of criminal networks, but it is a foundation over which change can happen.

 

Categories
Audio Sources - Full Text Articles

As Naomi Biden Gets Married, Here Is the History of White House Weddings

A rare event is taking place at the White House on Saturday. President Joe Biden’s granddaughter Naomi Biden, 28—the daughter of his son Hunter Biden—is set to wed fellow lawyer and politics junkie Peter Neal, 25. The New York Times reports that they live at the White House with the President and First Lady Jill Biden, as well.

Naomi Biden’s nuptials will be just the 19th wedding to take place at the White House in 222 years, and only the second since the turn of the century. The ceremony on the South Lawn will also make history. “There’s not been a South Lawn family wedding that I’m aware of,” says Stewart McLaurin, president of the White House Historical Association. Biden is also the first presidential granddaughter to be married at the White House.

[time-brightcove not-tgx=”true”]

In a country without a royal family, a wedding in the presidential family at the so-called “people’s house” often becomes a cause for national celebration and public fascination.

The first White House wedding took place in 1812 during the James Madison presidency. The sister of the First Lady Dolley Madison, Lucy Payne Washington, wed Thomas Todd, an associate justice of the U.S. Supreme Court. Tony Rodham, First Lady Hillary Clinton’s brother, also continued the tradition of presidential siblings marrying at the White House; he married Senator Barbara Boxer’s daughter Nicole in 1994. (They divorced about seven years later.)

The first White House wedding of a child of a President took place in 1820, when Maria Hester Monroe married Samuel Gouverneur, who was a private secretary to her father President James Monroe. The first White House wedding of a President’s son took place in 1828, when President John Quincy Adams’ son John Adams II married his first cousin Mary Catherine Hellen.

Read more: Joe Biden Officiates His First Wedding Ceremony for Two White House Staffers

White House Weddings Biden
APPhotographs of brides married in the White House are displayed in the executive mansion in a glass-enclosed case in Washington, Aug. 1, 1966. Down the left side of the frame, top the bottom, are: President James Monroe’s daughter, Maria; President Rutherford B. Haye’s niece, Emily Platt, Miss Frances Folsom, married to President Grover Cleveland; and President Woodrow Wilson’s daughter, Eleanor. At center, President Wilson’s daughter, Jessie. At right, top to bottom: President U.S. grant’s daughter, Nellie; President Theodore Roosevelt’s daughter, Alice; and President Wilson’s niece, Alice Wilson.

But just because you’re the child of a president and getting married at the White House does not make you immune from embarrassing dad toasts. In a podcast interview, Lynda Johnson Robb talked about how the night before her 1967 wedding, her father, President Lyndon B. Johnson, did a dramatic reading of Secret Service reports of every time her fiancé snuck into and left the White House and joked that he was going to shred up the pieces of paper and use them as confetti for the wedding.

The first and only President to be married in the White House was Grover Cleveland. Cleveland was 49 and his bride Frances Folsom was just shy of her 22nd birthday when they wed in the Blue Room. The nation was obsessed with the nuptials. Folsom’s face appeared on products like soaps, and Americans bought the sheet music composed for their wedding.

The marriage was also a boon for his presidency. In many ways, Folsom “helped raise Grover Cleveland’s profile,” says Louis Picone, spokesperson for the Grover Cleveland Presidential Library. He sees Folsom as a predecessor to President John F. Kennedy’s glamorous and charming First Lady Jackie Kennedy. “Grover Cleveland was kind of seen as a little bit curmudgeonly and a workaholic, so she kind of softened him.”

On at least two occasions, presidents hosted weddings for people considered members of the White House family, even though they weren’t blood relatives. President Franklin D. Roosevelt and Eleanor Roosevelt hosted the wedding of friend and New Deal aide Harry Hopkins in the family quarters in 1942, and President Barack Obama hosted the wedding of White House photographer Pete Souza in the Rose Garden in 2013. Souza’s wedding to Patti Lease was the last time a wedding took place at the White House.

Read more: Former White House Photographer Pete Souza on Serving Two Presidents and Trolling a Third

The most recent comparable wedding to Naomi Biden’s celebration took place more than 50 years ago, when President Nixon’s daughter Tricia married aspiring lawyer Ed Cox in 1971.

“It’s been that long since there has been that level of that caliber of wedding at the White House,” says McLaurin of the White House Historical Association.

The wedding, broadcast to millions in the television era, was so elaborate that it stunned even previous White House brides like Alice Roosevelt Longworth, who wed there in 1906. When a TIME reporter asked her if the day brought back memories for her, she said, “‘No, it doesn’t bring back one goddamned memory. I was married before the days of Hollywood. This is quite a production.’”

Presidential Escort
Paul Demaria—NY Daily News Archive/Getty ImagesTricia Nixon on her way to the Rose Garden with her father, President Richard Nixon, at her White House wedding.

The affair made the cover of TIME’s June 14, 1971, issue, and the magazine dubbed the couple “an American marriage to be reckoned with.” Here’s how TIME covered the preparations for the event in the Rose Garden, which boasted a 400-person guest list:

In some ways, a White House wedding reflects the style of a presidency. Luci Johnson was married in the largest Roman Catholic church in the Western Hemisphere—in a ceremony to which, as Comedienne Edie Adams said, “only the immediate country was invited.” Tricia’s wedding will obey a Nixonian instinct for the via media. It will be neither the largest nor smallest: a simple spectacular.

One trait Tricia and Eddie zealously share is a passion for privacy. (Much of the White House staff often does not know whether Tricia is at home or halfway across the country.) That inclination has been somewhat strained since March, when they made their engagement public and began marshaling forces for the wedding. At first, Tricia hoped that the ceremony could be private. She relented because, as she told TIME’s Bonnie Angelo last week, “we both thought it fitting and appropriate to share it with so many of the American people.”

But how much to share? There followed long and delicate negotiations over television coverage. It was finally agreed that TV cameras could video-tape all of the wedding proceedings except the actual ten-minute ceremony. Even what the cameras can record cannot be shown live; the networks will telecast the tapes later in the day.

In the Richard Nixon Presidential Library and Museum is a handwritten note that the President wrote his daughter shortly after midnight on the day of their wedding. “You have made the right choice,” he wrote, “and I’m sure Eddie and you will look back on this time and be able to say -’The day indeed was splendid.’”

The details of Naomi Biden’s ceremony have been largely kept under wraps ahead of the wedding. When McLaurin ran into her at the White House recently, he explained to her how he’s been talking to journalists about past White House weddings and saw that the historic nature of her wedding was starting to sink in with her. “I told her, you yourself will now become part of White House history,” he says. “She was very excited. It’s not like you’re walking down the aisle in the family church in the neighborhood. This is the largest ceremonial stage in our country.”

—With reporting by Melissa August in Washington, D.C.

WP Radio
WP Radio
OFFLINE LIVE