Showing posts with label cyberattacks. Show all posts
Showing posts with label cyberattacks. Show all posts

Wednesday, February 14, 2018

How Our Dependence on Global Shipping Will Come Back to Bite Us

This article was originally published by Cat Ellis at The Organic Prepper


global-shipping


If the general public understood how vulnerable our reliance on global shipping made us, they’d all become preppers overnight. Trucks, planes, and cargo ships are responsible for just about everything modern life depends upon. This reliance on global goods and long-distance shipping puts us all at risk.


Our Dependence Upon Global Shipping


Modern shipping keeps us clothed and fed. It brings us necessary medicines, fuel to the pumps, and delivers chemicals necessary to municipal water treatment plants. It is truly amazing how seamless it all appears to the average consumer, especially considering shipping’s global scale.


That is until there is a problem. Problems can be anything from a trucker’s strike to a plane crashing to a cyber attack shutting down the largest global shipping company.


Global shipping is a necessary evil in a world where we rely on global goods. When companies take their manufacturing operations overseas, the first thing we think of is lost jobs. But, we also put access to those goods at risk. Some of these risks include:



  • Relations with China breaking down over North Korea.

  • Hackers taking down software (navigation, customer orders, inventory tracking, systems diagnostics, etc) on ships, planes, trucks, and at ports and command centers.

  • An EMP causing all electronic systems to cease working.

  • Employees of shipping companies across an industry going on an extended strike.

  • Deteriorating domestic infrastructure interfering with the delivery of goods.

  • War/terrorism anywhere in the world causing delays and lost shipments of imports/exports.


Just a 24-Hour Delay Causes Shortages


A perfect example of this is shipping fresh food to Alaska all year long. Alaskan grocery stores do what they can to stock Alaska-grown items on their shelves, but due to the climate, Alaskans rely on imported produce and goods. The Anchorage Daily News reported on the impact of a single ship being delayed by just 24 hours for a repair.


Here’s what one of their agriculture experts had to say about why Alaska imports so much of its food.


Much of Alaska’s food comes up by container ship over the water. Some also arrives via trucks that take the Alaska Highway, or by air freight.


“It’s cheaper to barge or fly it in than it is to grow it here,” said Stephen Brown, a Palmer-based district agriculture agent with the University of Alaska Fairbanks. “The problem with that is that creates a very fragile food supply that’s very easy to be disrupted.” (source)


Further into the above-linked article, a recent disruption came when a ship needed repairs before heading up to Alaska.


A Tote Maritime Alaska ship was the one that was late getting to Anchorage last week, due to a weld that required a repair by divers in Tacoma.


“When there are disruptions to that supply chain, things can become difficult rather quickly. That’s when you can start to see shelves looking a little bit thinner. … Nobody wants to buy 2-week-old strawberries that are half-rotten,” said Grace Greene, vice president at Tote Maritime Alaska. “Having a tight supply chain is really critical.”


Cyberattacks Can Shut Down Global Shipping


This isn’t just an Alaska problem. Disruptions in shipping can happen anywhere and on a much larger scale. Recently, global shipping giant, AP Moller-Maersk, was hit by a major ransomware attack. This left ships sailing off course and ports were unable to accept ships.


According to Reuters:


The cyber attack was among the biggest-ever disruptions to hit global shipping. Several port terminals run by a Maersk division, including in the United States, India, Spain, the Netherlands, were still struggling to revert to normal operations on Thursday after experiencing massive disruptions. (source)


This was a wake up call for many in the industry. The article goes on to say


“The Maersk attack raises our awareness of the vulnerability of shipping and ports to technological failure,” said Professor David Last, a previous president of Britain’s Royal Institute of Navigation.


“When GPS fails, ships’ captains lose their principal means of navigation and much of their communications and computer links. They have to slow down and miss port schedules,” said Last, who is also a strategic advisor to the General Lighthouse Authorities of the UK and Ireland. (source)


There’s a Shortage of Truck Drivers


Add to this that we are experiencing a shortage of truck drivers due to fewer people looking for work, plus increased shipping costs due to increased regulations. The CEO of Tyson foods says:



“These additional costs are included in our outlook,” he told investors and analysts Feb. 8. “However, we’re assuming we’ll recover the majority through” higher prices for consumers.


The tightness in the trucking market probably won’t ease any time soon. Employers can’t find enough drivers — at least at the wages companies want to pay — as low unemployment spurs competition from other industries.


Construction jobs, for example, pay on par or better and allow workers to be home more with their families. Long-distance truckers can be on the road for weeks at a time. (source)



If a kink in the chain develops, there are fewer people capable of stepping in when needed.


Imagine If Truckers Went on Strike


If long-haul truckers were to strike, the store shelves would be bare within days. Everything from food, medicines, toilet paper, to gasoline would disappear from store shelves. Life as we know it would come to a grinding halt.


Back in 2008, diesel fuel prices rose so high that truckers protested and rallied in cities across the US, threatening to go on strike.


Independent U.S. truckers are planning to stop hauling freight Tuesday in protest of record-high diesel prices that drivers say they can no longer afford.


Independent truckers, who constitute 90 percent of the nation’s trucking fleet, are being hit especially hard by soaring diesel prices and compensation lags far behind rising costs, according to the American Trucking Association. (source)


Thankfully, we didn’t experience a nationwide trucker strike that time. The economy was already on shaky ground as it was.


Just 5 days Until Chaos


So, how long would we really have? You need to check out this article with a video on how we only have about five days before things get really bad. Two quotes from the video really stood out to me. First:


“The growth and population in this country, and the need for the movement of goods and services, is literally going to overwhelm the infrastructure as we know it today.”


And the second quote:


“We are now investing a smaller percentage of our Gross Domestic Product in transportation infrastructure than many third world countries.”


This is a recipe for a disaster if I ever saw one. According to the video, here’s what our situation would look like within 5 days:



  • Day One– We lose resupply of food and medicines, mail stops, and hospitals run out of clean linens.

  • Day Two– Gas stations are running out of gas, sanitation systems start to fail, local stores and ATMs run out of cash.

  • Day Three– Pumps are out of gas, stores have no fresh produce, banks run out of cash, and hoarding begins in earnest.

  • Day Four– Emergency vehicles and public transport run out of fuel, airports close, and trash piles up in the streets.

  • Day Five– Chaos


Unless something changes, we will have more people needing more goods and services, and we won’t be able to get them because our infrastructure won’t be able to handle it.


How Would You Have Fared?


Had truckers gone on a nationwide strike, or if the Petya ransomware attack had interfered with Maersk shipping for more than a few weeks, how would you have held out?


Thankfully, most of the scenarios that would impact shipping are temporary, perhaps a few days to a few weeks. Having just a three-month stockpile of food and supplies would cover most emergencies, including shipping delays.


You can easily put three month’s worth of necessities aside by adding by buying an extra food item each trip for your pantry. As for your other supplies, look at the five days detailed above. Use that as a guide for what to stock up on.


Here are a few more things to keep in mind.



And finally, get more toilet paper than you think you need. There are options, like personal cloths, squeeze-bottle bidets, and scrap paper, but none of them are quite like toilet paper.


The more you localize your family’s supply chain, the better off you’ll be during a disruption.


Any other ideas for prepping for an interruption of shipping?


Let me know in the comments.


***


Cat Ellis is an herbalist,  massage therapist, midwifery student, and urban homesteader from New England. She keeps bees, loves gardening and canning, and practice time at the range. She teaches herbal skills on her website, Herbal Prepper. Cat is a member of the American Herbalists Guild, and the author of two books, Prepper’s Natural Medicine and Prepping for a Pandemic.



The Pantry Primer


Please feel free to share any information from this article in part or in full, giving credit to the author and including a link to The Organic Prepper and the following bio.


Daisy Luther is the author of The Pantry Primer: A Prepper’s Guide To Whole Food on a Half Price Budget.  Her website, The Organic Prepper, offers information on healthy prepping, including premium nutritional choices, general wellness and non-tech solutions. You can follow Daisy on Facebook and Twitter, and you can email her at daisy@theorganicprepper.ca


Wednesday, December 20, 2017

North Korea Amassing Bitcoin To Fund Cyberattacks According To Crowdstrike CEO


Content originally published at iBankCoin.com


The CEO of cybersecurity firm Crowdstrike, George Kurtz, says North Korea is "absolutely" accumulating a giant pile of bitcoin to fund cyberattacks.

"They"re building a cache of bitcoin, if you think about it. It"s an anonymous currency, it can easily bypass any sort of sanctions because there are none on bitcoin, and the value has increased dramatically," Kurtz told CNBC"s "Squawk Alley." "It"s the perfect currency for North Korea to be hoarding." -CNBC



Can someone say "prohibited country" regulations?


The opinion comes on the heels of an op-ed in the WSJ by Homeland Security advisor Tom Bossert, who says North Korea was behind the WannaCry ransomware hack earlier this year, which demanded ransom in bitcoin.


The U.S. government has assessed with a "very high level of confidence" that a hacking entity known as Lazarus Group, which works on behalf of the North Korean government, carried out the WannaCry attack, said the official, who spoke on condition of anonymity to discuss details of the government"s investigation. -CNBC



The WannaCry hack is said to have cost billions, crippling hospitals, banks and companies around the world - and "highlights the capabilities that North Korea has in cyber," according to Kurtz.



Crowdstrike CEO on 2018 cyber threat outlook from CNBC.


Crowdstrike is the firm which analyzed the DNC servers and determined that Russia hacked them - however the Irvine, CA company came under fire in late 2016 when they had to retract a botched report on Russian hacking of Ukrainian artillery using the same "fancy bear" malware they also say the Kremlin used on the DNC servers.


The government of Ukraine issued a statement after the artillery report came out, calling it Fake News:


In connection with the emergence in some media reports which stated that the alleged “80% howitzer D-30 Armed Forces of Ukraine removed through scrapping Russian Ukrainian hackers software gunners,” Land Forces Command of the Armed Forces of Ukraine informs that the said information is incorrect.


Ministry of Defence of Ukraine asks journalists to publish only verified information received from the competent official sources. Spreading false information leads to increased social tension in society and undermines public confidence in the Armed Forces of Ukraine. –mil.gov.ua (translated) (1.6.2017)



So DHS"s Tom Bossert drops an op-ed on a North Korean hacking operation which only takes Bitcoin, and the CEO of Crowdstrike follows up with a stark warning on Bitcoin hoarding by Pyongyang. 




Follow on Twitter @ZeroPointNow § Subscribe to our YouTube channel


Monday, October 16, 2017

"Not The Russians" - British MPs Blame Iran For "Brute Force" Hack

Yet another purported example of Russia-linked hackers infiltrating the email accounts of powerful government officials    has been conclusively debunked.


The Guardian is reporting that a June incident where the accounts of dozens of UK ministers of parliament were infiltrated by shadowy hackers has been traced back to Iran. The UK intelligence community’s initial conclusion – that the attacks originated in Russia – has been refuted by an as-yet-unpublished report on the incident compiled by British intelligence.


Indeed, the intelligence community’s initial assumption appears to be another example of investigators jumping to a conclusion before a thorough analysis of the evidence has been completed. In a way, it echoes the response by several US states last month to the revelation that hackers had attempted to compromise their voting systems. Some states, including California and Wisconsin, apparently assumed the attacks were linked to Russia, until DHS informed them that it had found no evidence to support this conclusion.



The June 23 cyberattack affected the accounts of dozens of MPs, including Prime Minister Theresa May and several senior other senior ministers. The network that was compromised is used by every MP for interactions with constituents, the Guardian reported.


Initially, UK intelligence determined that hackers had attempted to gain access to accounts protected by weak passwords – despite repeated warnings to choose strong, hard-to-crack passwords.


An anonymous “security source” cited by the Guardian said the hackers used unsophisticated “brute force” attacks where the hackers use specifically designed programs to test out hundreds of thousands of different passwords combinations. “It was a brute-force attack. It appears to have been state-sponsored. The nature of cyber-attacks means it is notoriously difficult to attribute an incident to a specific actor.”


Conservative MP Andrew Bridgen added that the attack “absolutely” could leave some people open to blackmail. “Constituents want to know the information they send to us is completely secure,” he said.


Initially, suspicion had fallen upon foreign governments such as Russia and North Korea, both of which have been accused of orchestrating previous hacking attempts in the UK.


Liam Fox, the international trade secretary, said the incident reinforced the notion that MPs need to take extra precaution when securing their data.


“We know that our public services are attacked, so it is not at all surprising that there should be an attempt to hack into parliamentary emails,” he said. “And it’s a warning to everybody, whether they are in parliament or elsewhere, that they need to do everything possible to maintain their own cybersecurity.”


Given the furor that erupted after DHS ordered US government agencies to immediately remove security software designed by Russia-based firm Kaspersky Labs, the revelation about Iran’s involvement in the UK hacks should give intelligence agencies – not to mention lawmakers who seemingly blame Russia for every incidence of cyber meddling uncovered by US intelligence – pause. After the WSJ reported that Kaspersky’s software was essentially being leveraged by the Russian government to create an international spy network, German intelligence announced that they had found no evidence to support this claim.


And while many have blamed Russia-linked hackers for last year’s hack of DNC emails, including emails sent by Hillary Clinton Campaign Chairman John Podesta, Wikileaks’ Julian Assange is reportedly offering President Donald Trump conclusive evidence that he says would debunk this claim.


However, Chief of Staff John Kelly has rebutted one Congressman’s attempts to bring the deal to President Trump. But as the multiple investigations into whether Trump campaign colluded with the Russian government to sway the election in the president’s favor have apparently hit a wall, Assange’s evidence might be the key to silencing these suspicions, which have cast an unsubstantiated pall of illegitimacy over Trump’s first term in office.
 

Friday, July 21, 2017

Leaked Obama Plan To Fight Election-Day Meddling Included ‘Martial Law’





Tyler Durden
July 21st, 2017
Zero Hedge

Read by 89 people







This report was originally published by Tyler Durden at ZeroHedge.com


obama-quiet1


Former US President Barack Obama has been criticized by both Republicans and fellow Democrats for withholding information about Russia’s alleged interference in the US presidential election – criticism that has only intensified since President Donald Trump triumphed over Democrat Hillary Clinton in the November election.


Now, in yet another troubling sign that the Obama administration believed outside hacking groups posed a significant threat to the election, Time magazine reports that his administration had devised a detailed plan to fend off any cyberattacks that sought to falsify vote totals during the election. Obama has been criticized for not informing the American people about hacking attempts allegedly carried out by Russia-linked groups for fear of “rocking the boat” and damaging Clinton’s chances of victory.



Obama and former National Security Adviser Susan Rice


The 15-page plan, a copy of which was obtained by Time, stipulates that “in almost all potential cases of malicious cyber activity impacting election infrastructure, state, local, tribal, and territorial governments,” the governments would have primary jurisdiction to respond.


And if an attack were launched, the White House had several “enhanced procedures” it had prepared to fight back against the attackers.



The document “establishes the federal response plan for a cyber incident that is (or a group of related cyber incidents that together are) likely to result in demonstrable impact to election infrastructure during the 2016 United States presidential election. Furthermore, Obama’s plan appears to include contingencies for martial law…



“Though the plan emphasized the vital role that local authorities would play in combating the hackers, clarifying that they would have primary jurisdiction during an attack, it noted that for the deployment of “armed federal law enforcement agents” who would be deployed to polling places if hackers managed to halt voting.


It also foresaw the deployment of “Active and Reserve” military forces and members of the National Guard “upon a request from a federal agency and the direction of the Secretary of Defense or the President.”



The plan also authorized the creation of the federal “Cyber Response Group,’ which has the authority to form a Cyber Unified Coordination Group to coordinate these activities


The Department of Homeland Security established a committee to coordinate a response to any attempted election hacking. The group includes seven additional agencies on top of the FBI. They are:


  • DHS, National Protection and Programs Directorate.

  • National Association of Secretaries of State

  • State nad Local Election Officials

  • US Election Assistance Commission

  • National Institute of Standards and Technology

  • Department of Justice

  • The FBI

  • Department of Defense Federal Voting Assistance Program

Even though Obama had no intention of sharing this information with the public, the report ironically included a subsection outlining the administration’s policy for disclosing information about cyberattacks to the public. In anticipation of an attack, the group would develop integrated public relations guidance that seeks to maintain election infrastructure. The public relations guidance developed by those agencies will be fully coordinated before Nov. 1 2016, with the NSC to ensure that appropriate spokesperson re identified, remarks are fully consistent and joint messages are used in any potential cyber incident.”


On election day, the group set up a national monitoring center at FBI headquarters. The command center, which operated between 6 am and midnight, served as the launchpad for any counterattacks.


By Election Day, with widespread coverage of Russian hacking and then-candidate Donald Trump’s assertions that the vote would be rigged against him, Gallup found that only 30% of Americans had faith in the honesty of elections, while 69% did not.


Since news first broke that Russian-backed hackers had tried to infiltrate voting systems in 21 states, several notable Democrats – House intelligence Committee ranking member Adam Schiff among them – have criticized Obama’s unwillingness to disclose the information to the public.


First it was Susan Rice illegally ‘unmasking” Trump associates to try and create some illusory heft behind the allegations that the Trump campaign colluded with Russia to tilt the election in Trump’s favor. Then the public was informed about former Attorney General Loretta Lynch’s meeting with former President Bill Clinton and an investigation was launched. Today, Deputy AG Rod Rosenstein suggested that former FBI Director James Comey’s decision to leak his memo about a meeting between himself and President Trump – the one in which the president appeared to lean on his top cop to drop the bureau’s investigation into former National Security Advisor Mike Flynn – was improper.


This, combined with Special Counsel Robert Mueller’s announcement that he’s examining Trump’s finances as the next step in his investigation into allegations of collusion between the Trump campaign and the Russians, begs the question: When will Congress and the FBI switch gears and investigate the DNC?


Read the report in full below:


354227068 Russia Hacking President Obama s Previously Undisclosed Election Day Plan by zerohedge on Scribd



This report was originally published by Tyler Durden at ZeroHedge.com



Click here to subscribe: Join over one million monthly readers and receive breaking news, strategies, ideas and commentary.

Advanced Tactical Gas Mask

Please Spread The Word And Share This Post

Thursday, June 29, 2017

Ransomware Still Only Makes Up Small Share Of Growing Malware Threat

One type of malware has captured the attention of the world. Recent ransomware attacks show the devastating effects it can have on business and infrastructure.


After a worldwide attack with a cryptoworm called "WannaCry" in May, another attack with a strain of ransomware called "Petya" started on Tuesday and kept on spreading around the world on Wednesday.


As Statista"s Dyfed Loesche notes, malware has come a long way in the last ten years, as the infographic below shows.


Infographic: Ransomware Makes up Small Share of Growing Malware Threat | Statista


You will find more statistics at Statista


According to analysts with IT-security software firm G Data, the number of new malware specimen is likely to reach more than 7.4 million this year alone. Albeit this number seems to spell bad news only, the data also indicates that the malware growth rate is slowing.


It is also important to note that according to data provided by IT-security institute AV-Test, ransomware (such as "WannaCry" and "Petya") only makes up a very small share of all malware detected worldwide.


However, this just goes to show that the number of specimen of a certain kind of malware does not reflect its actual potential for damage.

NSA-Linked Hackers Raise Price Of Monthly Subscription to $61,000 After Tuesday's Cyberattack

In the wake of Tuesday’s massive global ransomware attack, the hacker group called the Shadow Brokers is again trying to capitalize on its reputation as a source of leaked NSA hacking exploits, saying it will up the price of a subscription service launched earlier this month, while also introducing a new “premium” feature.


The group introduced a monthly subscription service following last month’s WannaCry attack, after initially trying to sell its entire cache of NSA-funded cyberweapons for a staggering one million bitcoin (worth $2.5 billion at current prices). Both WannaCry and Tuesday’s attack, which has been blamed on the “Goldeneye” strain of the “Petya” ransomware, were aided by exploits that the Shadowbrokers allegedly stole from an NSA special-ops crew called “the Equation Group.”





Now, the Shadowbrokers are marketing their wares not only at hackers, but at corporations who’d like to buy insurance against being hacked.


Here’s the Shadowbrokers, in their characteristic broken English, as reported by The Hill.





"Another global cyber attack is fitting end for first month of theshadowbrokers dump service. There is much theshadowbrokers can be saying about this but what is point and having not already being said? So to business! Time is still being left to make subscribe and getting June dump. Don’t be let company fall victim to next cyber attack, maybe losing big bonus or maybe price on stock options be going down after attack. June dump service is being great success for theshadowbrokers, many many subscribers, so in July theshadowbrokers is raising price," the ShadowBrokers wrote in an online message released early Wednesday.”



The Shadowbrokers launched its monthly subscription document leaks service this month at a price of $27,000 a month in digital currency. Their new release more than doubles the price to $61,000.  The group also announced a new premium service allowing customers to make requests for assistance or specific document releases.


The group has been active since August 2016, when it began leaking hacking tools that were allegedly developed by the NSA. It has also leaked documents appearing to show the NSA hacked a Middle Eastern banking services company to try and get at the company’s clients, according to the Hill.


One of the exploits released by the group back in April, known as EternalBlue, was instrumental in aiding last month’s WannaCry cyberattack. Both WannaCry and another NSA exploit were allegedly intrumental in Tuesday"s attack.


The group also publicly released a password to what Edward Snowden called the NSA’s “top-secret arsenal of digital weapons.” Back in April, the group released passwords to hacking tool binaries developed by the NSA in 2013 as a “protest” against President Donald Trump, whom they accused of betraying his base by launching a missile strike against a Syrian government airfield and for backing away from his commitment to combating globalism.  


The first reports of organizations being hit by Tuesday’s attack were from Russia and Ukraine, but the impact quickly spread westwards to computers in Romania, the Netherlands, Norway, and Britain. Companies affected included German pharmaceutical company Merck, Russia"s Rosneft and metals giant Evraz, Danish shipper Maersk, UK ad company WPP, and both the Ukrainian and Russian central banks.


Already, Ukrainian government officials are blaming the attack on a Russian entity – likely government-sponsored – claiming that the virus’s code was written in Russian, ignoring the fact that Russian firms were also attacked, and mirroring the laughable conclusion that the North Korean government was somehow responsible for the original WannaCry attack.


With two global attacks unfolding in the span of two months, it’s incredible that the public – not to mention investors – aren’t more worried. How long until these attacks become a weekly, or even daily, occurrence. And more importantly, how long until they begin to seriously disrupt the functioning of private infrastructure.


At least one former NSA employee chimed in with his two cents about the agency’s role in making these attacks possible.






Nobody has been able to say for certain who or what the Shadowbrokers are. But at least one famed NSA whistleblower has a theory:


William Binney - who exposed the NSA"s pervasive surveillance of Americans long before Snowden confirmed it - said he and his colleagues are fairly certain the Shadowbrokers aren"t really a group of rogue actors, but rather an insider employee at NSA.

Tuesday, June 27, 2017

"Massive Cyberattack" Spreads Across Europe, Hits Ukraine, Russia, UK, Denmark

Update 3: Germany"s Merck also confirms it has been affected by the cyberattack:




* * *


Update 2: RUSSIAN CENBANK SAYS AS A RESULT OF ATTACKS THERE HAVE BEEN ISOLATED CASES WHERE IT SYSTEMS INFECTED


* * *


Update: in addition to the below listed companies, all of which appear to have been targeted in the global cyberattack including Russia"s Rosneft and metals giant Evraz, Danish shipper Maersk, UK ad company WPP, the Ukraine central bank, government and airport, more targets are emerging including Norway"s national security authority which has said that a Ransomeware attack is ongoing in Norway "similar to the attack on Maersk", while Russia"s Home Credit Bank said all domestic branches are closed because of the cyber attack.


As the Spectator adds, companies in Spain are also now affected by the cyberattack which appears to be a modification of the "WannaCry" virus, and has been named "Petya."


A Moscow-based cyber security firm, Group-IB, said it appeared to be a coordinated attack simultaneously targeting victims in Russia and Ukraine, according to Reuters.


* * *


Now that CNN is officially out of the "Russia hacking" fake news business, the Ukraine has decided to fill in the void, and moments ago Ukraine"s Deputy Prime Minister Pavlo Rozenko said that the government"s computer network was down, in what he claimed was a "massive cyberattack", one which has also impacted the central bank, power plant and airport, and promptly blamed Russia for being behind the attack without a shred of evidence. To "prove" the accusation, he posted a picture on Twitter of a computer screen showing an error message.


“We also have a network "down",” he wrote. “This image is being displayed by all computers of the government.” The photo showed his PC displaying a message claiming a disk “contains errors and needs to be prepared”, urging the user not to turn it off.



According to local press, numerous Ukrainian institutions were hit by a wave of cyber attacks earlier in the day, including banks, the state energy distributor and Kiev"s main airport. "We also have a network "down"," Rozenko said on Facebook.


Ukrainian state-run aircraft manufacturer Antonov was among the companies hit, along with state power distributor Ukrenergo, which said the attack did not affect power supplies.


According to Bloomberg, Kievenergo, a Ukrainian utility, switched off all computers after the hack, while another power company, Ukrenergo, was also affected, though “not seriously,” the Interfax news service reported. Ukrainian airports and railways are operating as usual, according to the Russian news service.


Ukrainian delivery network Nova Poshta halted service to clients after its network was infected, the company said on Facebook. Ukraine’s Central Bank warned on its website that several banks had been targeted by hackers.


After the attack, Ukraine quickly went for the empathy points, tweeting a meme from its official Twitter account.


“Some of our gov agencies, private firms were hit by a virus. No need to panic, we’re putting utmost efforts to tackle the issue,” the account tweeted. Attached was an infamous "this is fine" gif.



* * *


So who"s to blame? Why Russia of course.


Speaking to Interfax,the advisor to the Interior Minister of Ukraine, MP Anton Gerashchenko said that "a huge cyber-attack at Ukrainian companies on Tuesday has been organized by Russian intelligence services and it is one of the elements of the hybrid war against Ukraine,


"The intrusion is the biggest in Ukraine’s history,” Gerashchenko wrote on Facebook. The goal was “the destabilization of the economic situation and in the civic consciousness of Ukraine,” though it was “disguised as an extortion attempt,” he said.


"A huge cyber-attack has been started against Ukraine. It was done under the disguise that it is allegedly a virus… According to the preliminary information, this is an organized system, a kind of training by the Russian intelligence services. The attack aims at banks, media and transport communications," he said on 112.Ukraine TV Channel on Tuesday.


One wonders if that preliminary information came from the same FBI that incorrectly claimed the Qatar hack was organized by Russia, when Qatar itself later blamed the "blockade" countries as being behind it.


Gerashchenko said that the virus reached computers during several days and even weeks via getting mails. "Today, at 11:00 [the computers] that were affected by the virus in advance were activated. Thus, this is another example of using cyber-attacks in the hybrid war against our country," he said.


"I think that soon officers of the SBU, the cyber security department of the National Police will unveil the ways how this virus reached the targets and they propose the options to tackle the problem," he said.


* * *


Meanwhile, the fall out in Ukraine, which claimed the cyberattacks are a modified version of the "WannaCry" virus, has been extensive with Ukrainian state-run aircraft manufacturer Antonov among the companies reportedly hit, along with state power distributor Ukrenergo, which said the attack did not affect power supplies. The National Bank of Ukraine said an “unknown virus” was to blame, saying several unnamed Ukrainian banks were affected  along with financial firms.


“As a result of cyber attacks, these banks have difficulties with customer service and banking operations,” a statement said.


“The National Bank bank is confident that the banking infrastructure"s defense against cyber fraud is properly set up and attempted cyber attacks on banks" IT systems will be neutralised.”


Oschadbank, one of Ukraine"s largest state-owned lenders, said some of its services had been affected by a “hacking attack” but guaranteed that customer data was safe.


Computers and departure boards at Boryspil International Airport in Kiev – the largest in Ukraine – were also down. “The official site of the airport and the scoreboard with the schedule of flights aren"t working!” the airport’s acting director, Pavel Ryabikin, wrote on Facebook.



* * *


It wasn"t just Ukraine however. As The Independent writes, Danish shipping giant Maersk said its IT systems were down across “multiple sites and
businesses due to a cyber attack”, although it was unclear whether it
was related to the situation in Ukraine. The congolmerate is the largest container shipping
company in the world and also operates in the oil and gas sectors.


Russia"s Rosneft, a government-owned oil firm, also said it was targeted by a “massive hacker attack” on its servers, as was steel maker
Evraz. "The cyber attack could lead to serious consequences, however, due to
the fact that the Company has switched to a reserve control system,
neither oil production nor preparation processes were stopped,” a
statement from Rosneft said.


British advertising company WPP also said several units were affected by a suspected cyber attack.


Or, as Reuters summarizes:


  • SWISS GOV"T AGENCY SAYS UKRAINE, RUSSIA, ENGLAND AND INDIA ARE MOST AFFECTED BY VIRUS, NO INDICATION THAT SWISS COMPANIES AFFECTED

  • SWISS GOV"T AGENCY SAYS THERE ARE INDICATIONS THAT PETYA RANSOMWARE VIRUS IS CIRCULATING AGAIN

It was not clear how and why Russian hackers would be able to hack the entire world, Russia included, but that probably does not matter: Ukraine has blamed Russia for repeated cyber attacks targeting
crucial infrastructure during the past three years, including one on its
power grid that left part of western Ukraine temporarily without
electricity in December 2015. Today was just a continuation, and after all the world still demand Russia hacking narratives.

Tuesday, June 20, 2017

The Russian US Election Hacking Big Lie Got Bigger

The Russian US Election Hacking Big Lie Got Bigger | Russian-Hacking-US-elections | Propaganda Special Interests US News [image: Global Research]According to  Bloomberg News, “Russian Cyber Hacks on (the) US electoral system (are) far greater than previously known.”


A Big Lie – utter rubbish! The CIA, and likely NSA and FBI, can cyberattack targets anywhere, making it appear to have originated elsewhere – outside America from any other designated country.


Despite months of allegations, insinuations and accusations, not a shred of evidence suggests any Russian hacking of America’s November 2016 election or any other US target.



Claims otherwise are Big Lies. Repeated enough gets most people to believe them.


Bloomberg:



“Russia’s cyberattack on the US electoral system before Donald Trump’s election was far more widespread than has been publicly revealed, including incursions into voter databases and software systems in almost twice as many states as previously reported.”



Investigators in Illinois said “cyber intruders tried to delete or alter voter data,” according to Bloomberg – presenting no evidence of Russian involvement in what may or may not have happened, just more baseless claims with nothing verifying them.


In December, Jill Stein’s Wisconsin, Michigan and Pennsylvania electoral recount scam ended with her discredited.


In ruling against her, Pennsylvania US District Court Judge Paul Diamond said her hacked election claim “border(ed) on the irrational.”



“(T)here is no credible evidence that any ‘hack’ occurred, and compelling evidence (shows) Pennsylvania’s voting system was not in any way compromised.” Strong stuff!



Stein struck out the same way in Wisconsin and Michigan. No evidence suggests foreign hacking in any of America’s 50 states.


Not according to sources Bloomberg cited, claiming “(d)etails of the wave of attacks, in the summer and fall of 2016, were provided by three people with direct knowledge of the US investigation into the matter. In all, the Russian hackers hit systems in a total of 39 states, one of them said.”


Where’s the evidence? None was presented, just accusations with nothing backing them. Bloomberg cited the dubious Intercept report as proof of Russian hacking.


A previous article debunked what it called a leaked top secret NSA document, claiming without justification that “Russian military intelligence executed a cyberattack on at least one US voting software supplier and sent spear-phishing emails to more than 100 local election officials just days before last November’s presidential election.”


It said the document obtained was anonymously provided, “independently authenticated,” though lacking “ ‘raw’ intelligence on which” NSA claims were made.


An unnamed “US intelligence officer” cautioned about drawing conclusions from its material. Here’s a sample:



“Russian General Staff Main Intelligence Directorate actors…executed cyber espionage operations against a named US company in August 2016, evidently to obtain information on elections-related software and hardware solutions.”


“The actors likely used data obtained from that operation to…launch a voter registration-themed spear-phishing campaign targeting US local government organizations.”




Where’s the evidence? Claims without it are groundless. Besides, what motive could Russia have to hack America’s presidential election.


Duopoly government with two right wings rules, dirty business as usual winning all US elections. Russia and other countries have no ability to change things.


Attempting to hack America’s election system would be an exercise in futility – accomplishing nothing.


In Senate Intelligence Committee testimony, Comey repeated the Big Lie about Russian US election hacking, adding:


“They’re coming after America. They will be back.” Most significant from his testimony was admitting he unethically and maybe illegally leaked government memos about Trump to The NYT.


If government property, “a claim for criminal conduct could be made but it would be unlikely under existing precedent,” Law Professor Jonathan Turley explained.



“However, that does not mean that (his) conduct was either lawful or professional,” he added.



“(O)thers have been punished for releasing non-public information to the media…Comey and the FBI were tasked with finding” administration leakers. He’s one of them, discrediting him more than already.


As for claims about Russian US election hacking or anything else in America, ignore them.


Without proof, they’re baseless, part of longstanding Russia bashing – solely for its sovereign independence and opposition to US imperial lawlessness.

Thursday, June 8, 2017

British Think Tank Warns Hackers Could Access Nuclear Subs, Fears "Catastrophic Exchange Of Warheads"

Authored by Mac Slavo via SHTFplan.com,



Cyber security has become a preeminent issue in the modern world. That’s because so much of our standard of living is now reliant on computers that can often be easily hacked. Computers may make our lives easier, but they’ve given our civilization a whole new vulnerability to worry about. Our privacy, our infrastructure, and our financial systems are now at the mercy of hackers.


But those threats pale in comparison the vulnerability of our nuclear arsenals. Yes, you read that correctly. You’d think that the nuclear arsenals fielded by Western governments would have levels of security that are so tight, that they’d be virtually impossible to hack, but that’s not the case. According to the British American Security Information Council think tank, the UK’s Trident nuclear submarines are certainly vulnerable to hackers, contrary to the claims of the government.





“Submarines on patrol are clearly air-gapped, not being connected to the internet or other networks, except when receiving (very simple) data from outside. As a consequence, it has sometimes been claimed by officials that Trident is safe from hacking. But this is patently false and complacent,” they say in the report.



Even if it were true that a submarine at sea could not be attacked digitally, the report points out that the vessels are only at sea part of the time and are vulnerable to the introduction of malware at other points, such as during maintenance while docked at the Faslane naval base in Scotland.



The report says: “Trident’s sensitive cyber systems are not connected to the internet or any other civilian network. Nevertheless, the vessel, missiles, warheads and all the various support systems rely on networked computers, devices and software, and each of these have to be designed and programmed. All of them incorporate unique data and must be regularly upgraded, reconfigured and patched.”



Fortunately, this kind of cyber attack couldn’t be committed by just any old yahoo with a computer. It would require the resources that governments typically have access to. Still, this threat is sobering when you consider that these submarines apparently utilize the same Windows software that is used by Britain’s National Health Service, which was thoroughly infiltrated by the WannaCry malware last month.


So if someone did manage to hack these missiles, what could they do with them? Let’s just say that what could be done with these missiles will keep you up at night.





Hackers could take control of Britain’s atomic weapons and use them to start a “catastrophic” global nuclear war, tech experts have warned.



In a report published today, the British American Security Information Council (BASIC) said that cyber-spies could commandeer the systems which power the nation’s Trident submarines and then launch devastating attacks.



“A successful attack could neutralise operations, lead to loss of life, defeat or perhaps even the catastrophic exchange of nuclear warheads,” the report warned.



Back in the Cold War, people used to worry about the wrong people having access to “the red button.” But now nuclear war appears to be “just a click away.”

Thursday, May 25, 2017

This Is The World's Most Active Battlefield - Watch Cyber-War In Real-Time

Today’s most active battlefield is not located on the ground, in the air, or on the mighty seas. It’s taking place on the internet – and, as Visual Capitalist"s Jeff Desjardins notes, if you’re still a non-believer, spend a few minutes with the following live map to watch a representation of cyber attacks as they happen...


Created by Norse Corporation, a cyber intelligence firm that claims to get instant attack telemetry from over eight million sensors deployed worldwide, the map visualizes cyberwar in real-time and organizes attacks by type, origin, and target. (A full-screen version is also available.)



Source: Visual Capitalist


PREDATOR AND PREY


Who is responsible for these attacks, and who is the target?


In our few minutes of watching, the United States received nearly 70% of incoming attacks:


Cyberwar and types of attacks


While we were not expecting this live visualization to literally cover every single hack worldwide, this does seem to match up with the ratio from other sources. For example, in a previous infographic on cyberwar, we noted that the U.S. is targeted in 66% of web application attacks, and in 54% of cyber espionage hacks.


In our few minutes of watching, about half of the attacks also originated from the United States. However, many also were launched from other countries such as China, Ukraine, and The Netherlands.


THE SCALE IS REAL


While the idea of cyber warfare still seems like science fiction for many people, recent events such as the WannaCry ransomware attack have made the scale and potential implications of cyber warfare much more real.


WannaCry Map


The above map from AFP shows that the WannaCry attack was unprecedented in scale, infecting more than 230,000 computers in over 150 countries. Using an exploit developed by the NSA, WannaCry infected Britain’s National Health Service (NHS), Spain’s Telefónica, FedEx, and Deutsche Bahn, along with many other companies or countries.


Ultimately, the hack had a built-in “killswitch” that was discovered by internet security experts. It also seemed to be relatively ineffective at collecting hefty amounts of ransom. Despite all of this, the reality is that the hack shut down hospitals and other businesses, giving us a true taste of the scale and impact that a professionally-executed cyber attack could have in the future.

Wednesday, May 24, 2017

WannaCry Attackers Have Links To North Korea's Lazarus Group

Cybersecurity researchers at Symantec say they"ve found linkes between the WannaCry Ransomware attackers was likely carried out by a hacking group with ties to North Korea.


In a blog post, Symantec said the “Tools and infrastructure used in the WannaCry ransomware attacks have strong links to Lazarus, the group that was responsible for the destructive attacks on Sony Pictures and the theft of $81 million from the Bangladesh Central Bank.”


Here"s a summary of links provided by Symantec:


  • Following the first WannaCry attack in February, three pieces of malware linked to Lazarus were discovered on the victim’s network: Trojan.Volgmer and two variants of Backdoor.Destover, the disk-wiping tool used in the Sony Pictures attacks.

  • Trojan.Alphanc, which was used to spread WannaCry in the March and April attacks, is a modified version of Backdoor.Duuzer, which has previously been linked to Lazarus.

  • Trojan.Bravonc used the same IP addresses for command and control as Backdoor.Duuzer and Backdoor.Destover, both of which have been linked to Lazarus.

  • Backdoor.Bravonc has similar code obfuscation as WannaCry and Infostealer.Fakepude (which has been linked to Lazarus).

  • There is shared code between WannaCry and Backdoor.Contopee, which has previously been linked to Lazarus.

Symantec discovered that the WannaCry attackers used some of the same hacking tools that were previousky used in other Lazarus Group attacks. There are also, the group reported, “a number of links between WannaCry itself and Lazarus.”


The WannaCry ransomware, for example, shares some code with a piece of malware that has previously been linked to Lazarus.




Symantec also found that the WannaCry attackers used some of the same network infrastructure as the Lazarus Group. “There are a number of crossovers seen in the C&C servers used in the WannaCry campaigns and by other known Lazarus tools.”


Beginning a week ago Friday, the WannaCry virus infected thousands of computers around the world, threatening to destroy users" data unless a ransom was paid in bitcoin. Ultimately, the group received less than $100,000, and most of the data were destroyed.

Wednesday, May 17, 2017

America's Reign Of Terror: A Nation Reaps What It Sows

Authored by John Whitehead via The Rutherford Institute,





“The means of defense against foreign danger have been always the instruments of tyranny at home.” ? James Madison



Who designed the malware worm that is now wreaking havoc on tens of thousands of computers internationally by hackers demanding a king’s ransom? The U.S. government.


Who is the biggest black market buyer and stockpiler of cyberweapons (weaponized malware that can be used to hack into computer systems, spy on citizens, and destabilize vast computer networks)? The U.S. government.


What country has one the deadliest arsenals of weapons of mass destruction? The U.S. government.


Who is the largest weapons manufacturer and exporter in the world, such that they are literally arming the world? The U.S. government.


Which is the only country to ever use a nuclear weapon in wartime? The United States.


How did Saddam Hussein build Iraq’s massive arsenal of tanks, planes, missiles, and chemical weapons during the 1980s? With help from the U.S. government.


Who gave Osama bin Laden and al-Qaida “access to a fortune in covert funding and top-level combat weaponry”? The U.S. government.


What country has a pattern and practice of entrapment that involves targeting vulnerable individuals, feeding them with the propaganda, know-how and weapons intended to turn them into terrorists, and then arresting them as part of an elaborately orchestrated counterterrorism sting? The U.S. government.


Where did ISIS get many of their deadliest weapons, including assault rifles and tanks to anti-missile defenses? The U.S. government.


Which country has a history of secretly testing out dangerous weapons and technologies on its own citizens? The U.S. government.


Are you getting the picture yet?


The U.S. government isn’t protecting us from terrorism.


The U.S. government is creating the terror. It is, in fact, the source of the terror.


Just think about it for a minute: almost every tyranny being perpetrated against the citizenry—purportedly to keep us safe and the nation secure—has come about as a result of some threat manufactured in one way or another by our own government.


Cyberwarfare. Terrorism.


Bio-chemical attacks. The nuclear arms race.


Surveillance. The drug wars.


In almost every instance, the U.S. government has in its typical Machiavellian fashion sown the seeds of terror domestically and internationally in order to expand its own totalitarian powers.


It’s time to wake up and stop being deceived by government propaganda.


We’re not dealing with a government that exists to serve its people, protect their liberties and ensure their happiness. Rather, these are the diabolical machinations of a make-works program carried out on an epic scale whose only purpose is to keep the powers-that-be permanently (and profitably) employed.


Case in point: For years now, the U.S. government has been creating what one intelligence insider referred to as a cyber-army capable of offensive attacks.


As Reuters reported back in 2013:





Even as the U.S. government confronts rival powers over widespread Internet espionage, it has become the biggest buyer in a burgeoning gray market where hackers and security firms sell tools for breaking into computers. The strategy is spurring concern in the technology industry and intelligence community that Washington is in effect encouraging hacking and failing to disclose to software companies and customers the vulnerabilities exploited by the purchased hacks. That"s because U.S. intelligence and military agencies aren"t buying the tools primarily to fend off attacks. Rather, they are using the tools to infiltrate computer networks overseas, leaving behind spy programs and cyber-weapons that can disrupt data or damage systems.



As part of this cyberweapons programs, government agencies such as the NSA have been stockpiling all kinds of nasty malware, viruses and hacking tools that can “steal financial account passwords, turn an iPhone into a listening device, or, in the case of Stuxnet, sabotage a nuclear facility.”


And now we learn that the NSA is responsible for the latest threat posed by the “WannaCry” or “Wanna Decryptor” malware worm which—as a result of hackers accessing the government’s arsenal—has hijacked more than 57,000 computers and crippled health care, communications infrastructure, logistics, and government entities in more than 70 countries already.


All the while the government was repeatedly warned about the dangers of using criminal tactics to wage its own cyberwars.


It was warned about the consequences of blowback should its cyberweapons get into the wrong hands.


The government chose to ignore the warnings.


That’s exactly how the 9/11 attacks unfolded.


First, the government helped to create the menace that was al-Qaida and then, when bin Laden had left the nation reeling in shock (despite countless warnings that fell on tone-deaf ears), it demanded—and was given—immense new powers in the form of the USA Patriot Act in order to fight the very danger it had created.


This has become the shadow government’s modus operandi regardless of which party controls the White House: the government creates a menace—knowing full well the ramifications such a danger might pose to the public—then without ever owning up to the part it played in unleashing that particular menace on an unsuspecting populace, it demands additional powers in order to protect “we the people” from the threat.


Yet the powers-that-be don’t really want us to feel safe.


They want us cowering and afraid and willing to relinquish every last one of our freedoms in exchange for their phantom promises of security.


As a result, it’s the American people who pay the price for the government’s insatiable greed and quest for power.


We’re the ones to suffer the blowback.





Blowback: a term originating from within the American Intelligence community, denoting the unintended consequences, unwanted side-effects, or suffered repercussions of a covert operation that fall back on those responsible for the aforementioned operations.



As historian Chalmers Johnson explains, “blowback is another way of saying that a nation reaps what it sows.”


Unfortunately, “we the people” are the ones who keep reaping what the government sows.


We’re the ones who suffer every time, directly and indirectly, from the blowback.


We’re made to pay trillions of dollars in blood money to a military industrial complex that kills without conscience. We’ve been saddled with a crumbling infrastructure, impoverished cities and a faltering economy while our tax dollars are squandered on lavish military installations and used to prop up foreign economies. We’ve been stripped of our freedoms. We’re treated like suspects and enemy combatants. We’re spied on by government agents: our communications read, our movements tracked, our faces mapped, our biometrics entered into a government database. We’re terrorized by militarized police who roam our communities and SWAT teams that break into our homes. We’re subjected to invasive patdowns in airports, roadside strip searches and cavity probes, forced blood draws.


This is how tyranny rises and freedom falls.


We can persuade ourselves that life is still good, that America is still beautiful, and that “we the people” are still free.


However, as I make clear in my book Battlefield America: The War on the American People, the moment you tune out the carefully constructed distractions—the year-round sports entertainment, the political theatrics, the military’s war cries, the president’s chest-thumping, and the techno-gadgets and social media that keep us oblivious to what’s really going on in the world around us—you quickly find that the only credible threat to our safety and national security is in fact the government itself.


As science fiction writer Philip K. Dick warned, “Don’t believe what you see; it’s an enthralling—[and] destructive, evil snare. Under it is a totally different world, even placed differently along the linear axis.”


In other words, all is not as it seems.


The powers-that-be are not acting in our best interests.


“We the people” are not free.


The government is not our friend.


And America will never be safe or secure as long as our government continues to pillage and plunder and bomb and bulldoze and kill and create instability and fund insurgencies and police the globe.


So what can we do to stop the blowback, liberate the country from the iron-clad grip of the military industrial complex, and get back to a point where freedom actually means something?


For starters, get your priorities in order. As long as Americans are more inclined to be offended over the fate of a Confederate statue rather than the government’s blatant disregard for the Constitution and human rights, then the status quo will remain.


Stop playing politics with your principles. As long as Americans persist in thinking like Republicans and Democrats—refusing to recognize that every administration in recent years has embraced and advanced the government’s authoritarian tactics—then the status quo will remain.


Value all human life as worthy of protection. As long as Americans, including those who claim to value the sanctity of human life, not only turn a blind eye to the government’s indiscriminate killings of innocent civilians but champion them, then the status quo will remain.


Recognize that in the eyes of the government, we’re all expendable. As long as we allow the government to play this dangerous game in which “we the people” are little more than pawns to be used, abused, easily manipulated and just as easily discarded—whether it’s under the guise of national security, the war on terror, the war on drugs, or any other manufactured bogeyman it can dream up—then the status quo will remain.


Demand that the government stop creating, stockpiling and deploying weapons of mass destruction: nuclear, chemical, biological, cyber, etc. As long as the government continues to use our tax dollars to create, stockpile and deploy weapons of mass destruction—whether those weapons are meant to kill, maim or disable (as in the case of the WannaCry computer virus)—we will be vulnerable to anyone who attempts to use those weapons against us and the status quo will remain.


Finally, stop supporting the war machine and, as Chalmers Johnson suggests, “bring our rampant militarism under control”:





From George Washington’s “farewell address” to Dwight Eisenhower’s invention of the phrase “military-industrial complex,” American leaders have warned about the dangers of a bloated, permanent, expensive military establishment that has lost its relationship to the country because service in it is no longer an obligation of citizenship. Our military operates the biggest arms sales operation on earth; it rapes girls, women and schoolchildren in Okinawa; it cuts ski-lift cables in Italy, killing twenty vacationers, and dismisses what its insubordinate pilots have done as a “training accident”; it allows its nuclear attack submarines to be used for joy rides for wealthy civilian supporters and then covers up the negligence that caused the sinking of a Japanese high school training ship; it propagandizes the nation with Hollywood films glorifying military service (Pearl Harbor); and it manipulates the political process to get more carrier task forces, antimissile missiles, nuclear weapons, stealth bombers and other expensive gadgets for which we have no conceivable use. Two of the most influential federal institutions are not in Washington but on the south side of the Potomac River–the Defense Department and the Central Intelligence Agency. Given their influence today, one must conclude that the government outlined in the Constitution of 1787 no longer bears much relationship to the government that actually rules from Washington. Until that is corrected, we should probably stop talking about “democracy” and “human rights.”


Wednesday, May 10, 2017

'Anonymous' Issues Ominous World War 3 Warning: "The Citizens Will Be The Last To Know"

Using their signature Guy Fawkes character, the infamous hacktivist group Anonymous has issued an ominous new video - warning people around the world to "prepare" for World War 3 as the US and North Korea continue to move "strategic pieces into place" for battle.





All the signs of a looming war on the Korean Peninsula are surfacing... we’re watching as each country moves strategic pieces into place... but unlike past world wars... although there will be ground troops the battle is likely to be fierce, brutal and quick.



It will also be globally devastating on the environmental and economic levels.



... This is a real war with real global consequences... With three super powers drawn into the mix... Other nations will be coerced into choosing sides.



... The citizens will be the last to know...



As The New York Post reports, Anonymous - described online as a global network of hackers, intent on spreading “facts the government doesn’t want you to know” - claims the US and South Korea have been working together to keep the peace in the region, along with China and the Philippines, but their pleas have fallen “on deaf ears.”





They claim that the Trump administration has been also working closely with the Australians, sending a rotational deployment of more than 1,000 US troops to the country, along with a large fleet of military aircraft. Australia is ultimately considered to be a “strategic location in the Indian ocean,” Anonymous says.



“The citizen will be the last to know, so it is important to understand what the other nations are doing,” the group states, citing China’s warning last week to its people in the North. “The pragmatic Chinese, it seems, are starting to lose their patience.”



Another surefire sign that war is imminent, according to Anonymous, are the recent talks between President Trump and Philippines President Rodrigo Duterte.



The group concludes the video with an eerie message for those watching around the world.





“Prepare for what comes next,” they say. “We are Anonymous. We are Legion. We do not forgive. We do not forget.”




As SHTFplan.com"s Mac Slavo points out, both China and Russia are mobilizing troops to the North Korean border, and the United States now has a Naval strike group directly off the coast of the rogue state. With the North threatening to continue testing missiles and weapons of mass destruction, and the Trump administration officially stating that past policies of “patient diplomacy” no longer apply, it appears confrontation is imminent.


North Korea has responded to President Trump’s deployment of an aircraft carrier, surveillance drones and missile tests by saying that if even a single bullet is fired they will nuke the United States.


The geo-political strain in the region could lead to any number of potential triggers. The growing concerns have not gone unnoticed in Japan, which recently saw panic buying of emergency shelters and air purifiers skyrocket.


In the United States, retailers report that the sale of NBC/CBRN gas masks and anti-radiation pills has spiked in recent weeks amid fears of impending global disaster.


Elite billionaires are building bunkers and long term preparedness plans to survive disaster, while governments around the world are positioning pieces on the grand chessboard.


All signs point to serious trouble in the very near future.


The world sits on the brink of a war unlike anything mankind has ever witnessed.

Monday, January 2, 2017

If There Really Was Evidence Of Russian Hacking, The NSA Would Have It

Submitted by David Spring via TurningPointNews.org,


On December 29, 2016, the Hill posted an article discussing a 13 page report by the FBI and DHS claiming that their 13 page report was “evidence” of Russian hacking in US elections.
http://thehill.com/policy/national-security/312132-fbi-dhs-release-report-on-russia-hacking


Wikileaks has repeatedly stated that the source of its leaks was a disgruntled Democratic Party insider.
http://www.dailymail.co.uk/news/article-4034038/Ex-British-ambassador-WikiLeaks-operative-claims-Russia-did-NOT-provide-Clinton-emails-handed-D-C-park-intermediary-disgusted-Democratic-insiders.html


However, President Obama issued a press release on December 29 2016 using the DHS-FBI report to justify increasing sanctions against Russia.
https://www.whitehouse.gov/the-press-office/2016/12/29/statement-president-actions-response-russian-malicious-cyber-activity


I therefore decided to see what the evidence was of Russian involvement in US Elections. The Hill article linked to this 13 page government press release as its proof of Russian hacking.
https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296.pdf


The government press release written by DHS-FBI did not mention Wikileaks in its report. Nor did the report provide any evidence of Russian hacking in the US elections. Instead, the press release stated that “technical indicators” of Russian hacking were in the “CSV file and XML file attached with the PDF.” However, there was no CSV or XML file or link attached with the PDF. I was eventually able to find these two files at this link.
https://www.us-cert.gov/security-publications/GRIZZLY-STEPPE-Russian-Malicious-Cyber-Activity


To see the evidence of Russian hacking first hand, I downloaded the CSV file and converted it into a spreadsheet. The CSV file and the XML file both contained the same data. Here is the XML link to this data which can be viewed online in a web browser.
https://www.us-cert.gov/sites/default/files/publications/JAR-16-20296.xml


Both files provide a list of 895 “indicators” of Russian Hacking. Unfortunately, nearly all of these indicators are simply IP addresses. In other words, it is a list of 895 servers from from more than 40 countries around the world. But the list also includes a few website domain names. (Domain names are simply the name of the website such as Youtube.com). I looked up these website domain names with the the following tool which tells us who owns the domain names and where they are located:
https://www.whois.net/


My review of these domain names confirmed that none of these domain names have any relationship to Russian government hackers. Here are the results for four of the domain names provided by the DHS and the FBI as evidence of Russian hacking:





ritsoperrol.ru is not in use. It is registered to a private person. The named server hosting the domain is nserver: ns0.xtremeweb.de. This is a German web hosting and consulting company whose address and phone number are publicly listed on their website. It is highly unlikely that Russian hackers would use a public German web host to register and host their domain names.



littlejohnwilhap.ru is not in use and is available to be purchased. It is unlikely that Russian hackers would use a domain name like this to launch a cyber attack on the US.



wilcarobbe.com is taken and is not in use. It is registered to Arsen Ramanov in Groznenskaya Russia. His address, phone number and email address are all publicly listed. It is highly unlikely that Russian hackers would use a domain name that was publicly listed. Hackers are not idiots.



one2shoppee.com is taken and is registered with GoDaddy.com. It is not currently in use. But it is highly unlikely that Russian Hackers would register their domain names with GoDaddy – which is a US server. In fact, it is very unlikely that Russian hackers would ever use any US servers. They would only use their own servers.



How did these four domain names get on a list of Russian hackers? It is possible that some unknown agents took over these domain names and may have used them for some kind of hacking activity. However, the agents could have just as easily been from the US as from Russia. In fact, it is not likely that these domain names were taken over by Russian hackers for the simple reason that Russian hackers are way to smart to be using these silly tactics.


None of the 885 IP addresses have any confirmed relationship to Russian Government Hackers


An IP address is simply a numerical designation for a server. The 885 IP addresses listed in the DHS – FBI CSV file were even more interesting. The IP addresses were located on servers from the US and more than 40 nations around the world including more than 30 IP addresses supposedly located in China. Here are a few of the IP addresses


  • 167.114.35.70

  • 185.12.46.178

  • 46.102.152.132

  • 178.20.55.16

I looked up several of these IP addresses using the following tool:
http://whatismyipaddress.com/ip-lookup


Here are a four examples of IP addresses in the DHS-FBI report:





167.114.35.70 is a Canadian Corporate server specializing in the promotion of Bitcoin. They are within a few miles of the US border.



185.12.46.178 is a Swiss corporate server associated with the domain name leavesorus.com. The domain name leavesorus.com is currently available to be purchased. This indicates that this is a fake domain name and likely a fake corporation.



46.102.152.132 is another Swiss corporate server this one specializing in emails and associated with the domain name maxsultan.xyz which is a fake domain name. This also indicates that this is another fake corporation.



178.20.55.16 is a proxy server with no known location but has been used as a TOR router exit node. A proxy server is another name for a mirror or server used to bounce information from one server to another in order to hide the true location of the original server. This proxy server is associated with the domain name nos-oignons.net. This domain name was registered on December 31 2012 and is valid until December 31 2017. In other words, whoever got this domain name paid for its use for 5 years. But they did registered the domain name anonymously. The website associated with this server appears to be a group in France promoting the TOR router. They became an association in May 2013 – 5 months after getting the domain name. The group currently has 5 members and it costs one Euro to join this group. Their website was reported 9 days ago as having been infected with the Zues virus. This infection does not leave tracks on server logs. So it is difficult to tell where it came from. Removal of this virus requires a complete rebuild of the server. In short, some agency decided to take out this server and then use it to make a cyber attack on some US government agency and thus have the IP address listed on the DHS-FBI list as one of 895 indicators of Russian hacking.



Many of the IP addresses yielded the same dead end or otherwise highly suspicious result - meaning that some very large agency is using hundreds of servers in various countries around the world as a front for hacking attacks. I recently researched a series of attacks on my personal websites from hundreds of IP addresses using hundreds of servers that were supposedly located in the Ukraine. I was able to confirm the exact location in the Ukraine that was supposedly being used to launch literally thousands of attacks on my websites. However, it is not credible that anyone in the Ukraine has the millions of dollars needed to be running hundreds of servers in a remote Ukrainian location. Nor is it likely that anyone in rural Ukraine would even have the knowledge to take care of hundreds of servers even if they did have the millions of dollars needed to plow into buying these servers. Nor are they likely to have the knowledge needed to be running very complex cyber attacks. Ukraine is just not a good location for servers. This experience convinced me that attacks were being launched from other locations and were merely being routed through Ukraine in order to mislead people about where the attacks were really coming from.


Next, the CSV file provided by DHS-FBI listed the physical location of all 885 IP addresses. What is most ironic is that, only two of the 885 IP addresses were from servers in Russia. The most common location of the hacking servers was the United States. Over 30 of the servers were supposedly located in China. But it is known that the NSA has the ability to use satellite mirrors to hide the locations of their servers – making folks believe that the attacks are coming from China (or Ukraine or Mongolia) when in fact they are coming from servers located in the US.


01


Here are 50 more servers. Again, no Russians:


02


Here are 50 more servers. How can servers in the US be used as evidence of Russian hacking?


03


Here is another batch of 50 servers. Again, no Russians.


04


Wait a Minute… Is this the Smoking Gun???
Actually, there were two Russian servers located on lines 259 and 261. Here are the IP addresses.


  • 93.171.203.244

  • 95.105.72.78

Here is more information about each of these:





93.171.203.244 This is a clean broadband server located near Ufa which is a city in Russia with one million people. It is associated with an organization called Miragroup Ltd. The website is rxbrothers.ru. Naturally, this is a fake domain name which is available to be purchased. Miragroup is actually a corporation located in Great Britain.



95.105.72.78 is another clean broadband server located near Ufa. The organization is JSC Ufanet and the website is ufanet.ru which is a public broadband service started in 1997. Someone apparently is using this broadband service to hack the US government. Could this be the smoking gun that the Russian government is attacking the US? Think about it. If you were a Russian hacker, would you really use a public server located in some Russian town? I don’t think so. This is more like evidence that some hacker was using the local public library.



Imagine someone launching a cyber attack from the Seattle Public library – and then our government declaring that they have evident that the mayor of the City of Seattle was responsible for the attack because “nothing happens in Seattle without the approval of the Mayor!”. This is worse than a silly accusation. It is ridiculous. It is irresponsible.


Real Russian Hackers do not use Windows Servers


Only three of the servers provided in the DHS/FBI report included detailed information (despite the fact that the IP addresses provided information on all 895 servers and that DHS/FBI certainly have detailed information on all of the servers). All three servers listed in the report were Windows servers. It is highly unlikely that Russian hackers or Chinese hackers would be using Windows servers. Instead, all real hackers use Linux servers because Linux servers are much more secure than Windows servers.
https://techlog360.com/top-15-favourite-operating-systems-of-hackers/


If there really was evidence of Russian hacking, the NSA would have it


Former NSA leader turned whistleblower William Binney recently stated that if the Russians really did hack the Democratic Party servers, the NSA would certainly have real evidence (not the nonsense put out in the DHS-FBI CSV file). Here is his quote from a December 29 2016 article by Glenn Greenwald: “The bottom line is that the NSA would know where and how any “hacked” emails from the DNC, HRC or any other servers were routed through the network. This process can sometimes require a closer look into the routing to sort out intermediate clients, but in the end sender and recipient can be traced across the network.”
https://theintercept.com/2016/12/29/top-secret-snowden-document-reveals-what-the-nsa-knew-about-previous-russian-hacking/


Edward Snowden has not only confirmed that the NSA has this ability – but that he himself used an NSA program called XKEYSCORE to monitor such attacks.
https://theintercept.com/2016/07/26/russian-intelligence-hack-dnc-nsa-know-snowden-says/


Anyone with any kind of technical background in defending against hacker attacks would understand that what Binney, Snowden and Greenwald are saying is true. The evidence of their truth – most of which was supplied by Snowden from NSA documents – is overwhelming.


05


Conclusion


An important research principle is to follow the money. People around the world need to ask themselves who has the money and technical ability to be running hundreds and perhaps thousands of real servers and real IP addresses from fake corporations using fake websites in fake locations in more than 40 nations around the world? What agency has already been proven to be running mass surveillance on billions of people in more than 40 nations all around the world? Whose military cyber budget is more than 10 times larger than the cyber warfare budget of the rest of the world combined? There is certainly an elephant in the room – but it is not a Russian elephant.


At a televised press conference on April 2016, former NSA agent, Edward Snowden asked the Russian leader Vladimir Putin if the Russian government engaged in mass surveillance of millions of people in a manner similar to the NSA. Putin replied that Russian law prohibited the Russian government from engaging in mass surveillance. Putin then pointed out that the Russian military budget was less than 10% of the US military budget. So even if they wanted to engage in mass surveillance, they simply did not have the money.
https://www.theguardian.com/world/video/2014/apr/17/snowden-putin-russia-surveillance-phone-in-video


People also need to ask themselves why the FBI DHS chose to place their evidence in a CSV file and XML file rather than a normal document or spreadsheet. If this were real evidence, it would have been placed directly in the PDF report for everyone to read – not hidden away in a file the general public has little ability to read.


Finally, for the FBI or the DHS to claim that the XML-CSV file contains evidence or even indicators of Russian hacking is simply a false statement. It is a perfect example of fake news. Any news agency promoting this claim without doing even the most basic of research that would easily confirm it is false, should be listed as a fake news agency.


The real question that we should all be asking is why the DHS and FBI would destroy their reputation by posting such a fake report?


Several years ago, our CIA claimed that Iraq had weapons of mass destruction. We now know that Iraq had no weapons of mass destruction – meaning that we went to war and spent over a trillion dollars on a fake report. Is this new fake report a pretext for launching a cyber war against Russia? Is it intended to justify increasing US military spending?


It is hard to say what the real purpose of this fake DHS-FBI report is. But the fact that this silly list of IP addresses was the best evidence they could provide should be a strong indication that there really is no evidence of Russian hacking. Instead, it is more likely that Wikileaks is telling the truth in stating that they got the emails from a disgruntled Democratic Party insider.