Putin and Putinism – News Review
The same Russian military intelligence outfit that hacked the Democrats in 2016 has renewed vigorous U.S. election-related targeting, trying to breach computers at more than 200 organizations including political campaigns and their consultants, Microsoft said Thursday.
The intrusion attempts reflect a stepped-up effort to infiltrate the U.S. political establishment, the company said.
“What we’ve seen is consistent with previous attack patterns that not only target candidates and campaign staffers but also those who they consult on key issues,” Tom Burt, a Microsoft vice president, said in a blog post. U.K. and European political groups were also probed, he added.
Most of the hacking attempts by Russian, Chinese and Iranian agents were halted by Microsoft security software and the targets notified, he said. The company would not comment on who may have been successfully hacked or the impact.
Although U.S. intelligence officials said last month that the Russians favor President Donald Trump and the Chinese prefer his Democratic challenger, former Vice President Joe Biden, Microsoft noted Thursday that Chinese state-backed hackers have targeted “high profile individuals associated with the election,” including people associated with the Biden campaign.
China’s hackers largely gather intelligence for economic and political advantage, while Russia tends to weaponize stolen data to destabilize other governments.
Microsoft did not assess which foreign adversary poses the greater threat to the integrity of the November presidential election. The consensus among cybersecurity experts is that Russian interference is the gravest. Senior Trump administration officials have disputed that, although without offering any evidence.
“This is the actor from 2016, potentially conducting business as usual,” said John Hultquist, director of intelligence analysis at the cybersecurity firm FireEye. “We believe that Russian military intelligence continues to pose the greatest threat to the democratic process.”
The Microsoft post shows that Russian military intelligence continues to pursue election-related targets undeterred by U.S indictments, sanctions and other countermeasures, Hultquist said. It interfered in the 2016 campaign seeking to benefit the Trump campaign by hacking the Democratic National Committee and emails of John Podesta, the campaign manager for Hillary Clinton, and dumping embarrassing material online, congressional and FBI investigators have found.
The same GRU military intelligence unit, known as Fancy Bear, that Microsoft identifies as being behind the current election-related activity also broke into voter registration databases in at least three states in 2016, though there is no evidence it tried to interfere with voting.
Microsoft, which has visibility into these efforts because its software is both ubiquitous and highly rated for security, did not address whether U.S. officials who manage elections or operate voting systems have been targeted by state-backed hackers this year. U.S. intelligence officials say they have so far seen no evidence of infiltrations.
Thomas Rid, a Johns Hopkins University geopolitics expert, said he was disappointed by Microsoft’s refusal to differentiate threat level by state actor.
“They’re lumping in actors that operate in a very different fashion, probably to make this sound more bipartisan,” he said. “I just don’t understand why.
“Microsoft said in the past year it has observed attempts by Fancy Bear to break into the accounts of people directly and indirectly affiliated with the U.S. election, including consultants serving Republican and Democratic campaigns and national and state party organizations — more than 200 groups in all.
Also targeted was the center-right European People’s Party, the largest grouping in the European Parliament. A party spokesperson said the hacking attempts were unsuccessful. The German Marshall Fund of the United States, a think tank, was another target. A spokesperson said there was no evidence of intrusion.
Microsoft did not say whether Russian hackers had attempted to break into the Biden campaign but did say that Chinese hackers from the state-backed group known as Hurricane Panda “appears to have indirectly and unsuccessfully” targeted the Biden campaign through non-campaign email accounts belonging to people affiliated with it.
The Biden campaign did not confirm the attempt, although it said in a statement that it was aware of the Microsoft report.
Iranian state-backed hackers unsuccessfully tried to log into accounts of Trump campaign and administration officials between May and June of this year, the blog said.
“We are a large target, so it is not surprising to see malicious activity directed at the campaign or our staff,” Trump campaign deputy press secretary Thea McDonald said. She declined further comment.
Tim Murtaugh, the campaign’s communications director, said: “President Trump will beat Joe Biden fair and square and we don’t need or want any foreign interference.”
In June, Google disclosed that Hurricane Panda had targeted Trump campaign staffers while Iranian hackers tried to breach accounts of Biden campaign workers. Such phishing attempts typically involve forged emails with links designed to harvest passwords or infect devices with malware.
Although both Attorney General William Barr and National Security Adviser Robert O’Brien have said China represents the greatest threat to U.S. elections, Microsoft’s only mention of a Trump administration official targeted by Chinese hackers is “at least one prominent individual formerly associated” with the administration.
Graham Brookie, director of digital forensic research at The Atlantic Council, disputes the claim made by Barr and O’Brien that China poses the greater threat to this year’s election. Brookie’s lab is at the forefront of unearthing and publicizing Russian disinformation campaigns.
Brookie confirmed that his employer was among targets of Hurricane Panda but said there was no evidence the hacking attempts, which he said were unsuccessful, had anything to do with the 2020 election.
“We have every indication that this was an instance of cyber-espionage, information gathering, as opposed to electoral interference,” he said.
By contrast, Brookie said, “it’s pretty evident that the Russian attempts (Microsoft disclosed) were focused on electoral processes and groups working on that.”
Microsoft noted a shift toward greater automation in Fancy Bear methods for trying to steal people’s log-in credentials, which previously largely relied on phishing. In recent months, the group has employed so-called brute-force attacks that barrage an account login with short rapid bursts of potential passwords. It has also used a different method that makes only intermittent login attempts to avoid detection.
Fancy Bear has also stepped up its use of the Tor anonymizing service to hide its hacking, Microsoft said.
Voice of America – English
“Nato Russia” – Google News
Rival Libyan political leaders held joint talks Thursday in Morocco and Egypt amid reports of some breakthroughs over key issues, including elections and uniting rival governments.
Arab media reported breakthroughs on several key points during talks between rival Libyan political leaders outside the Moroccan capital, Rabat. It was not clear if any of the breakthroughs would last into further negotiations in Geneva next week.
Khaled al-Mishri, the Islamist head of the Council of State in Tripoli, told Al Jazeera TV Wednesday, “We cannot say that the (Morocco meetings) are … real dialogue sessions so far. Rather, they are preliminary consultations for the start of the dialogue.”
Libya analyst and political writer Abdel Basset Ben Hamill said the Moroccan talks were not expected to follow the same track as the upcoming Geneva talks, and in any case, “There is absolutely no talk about disbanding militias and making mercenaries leave the country.”
Libya is currently divided between eastern and western governments locked in a military stalemate.
Arab League deputy head Hossam Zaki stressed in a press conference in Cairo that Libya negotiations will not be easy.
He said that in all honesty, the Libya dossier is going to require the goodwill of all sincere parties who want to get the country out of this impasse.
Arab League head Ahmed Aboul Gheit condemned Turkey for interfering in the internal affairs of Arab countries, after a meeting in Cairo to discuss the Libya situation.
He said that Arab states widely oppose Turkish interference. He argued that Arab states must combat this kind of interference so that they don’t become a battleground for internecine conflicts.
Turkey backs the U.N.-recognized Government of National Accord based in Tripoli and has provided military support for its forces.
While it was not clear if any of the discussions in Morocco included binding agreements, members of both delegations told Arab media that one of the key points of agreement was to “divide positions in the ruling Council of State from among (Libya’s) three geographic regions.”
Libyan media also reported that negotiators in Switzerland, where talks are due to get underway on September 17, have agreed that elections must be held by December 2021 based on a mutually acceptable constitutional framework.
Voice of America – English
“Nato Russia” – Google News
“Russia international behavior” – Google News