David Gilbert Profile picture
Nov 28, 2018 69 tweets 29 min read Read on X
Here's @JohnHultquist kicking off #CYBERWARCON Image
Kicking things off is @RidT talking about the history of disinformation campaigns #CYBERWARCON Image
What disinformation in the 1930s looked like #CYBERWARCON Image
Investigating the 1930 case, @RidT says he realised that forensics alone were not sufficient to get to the bottom of what happened. You need geopolitical context.
Next up is @camillefrancois talking about information operations on social media designed to disseminate hacked materials #CYBERWARCON
Speaking about the #DopingLeaks incident two years ago, a network map shows that the people who should be driving the conversation (sports/media) are on try periphery while spam accounts are at the centre of the conversation #CYBERWARCON
Talking about #DCLeaks, we see that media activity is way up, accounting for 34% of the conversation Twitter. #CYBERWARCON
Network Mao of #PodestaLeaks shows that this leak was marketed differently and really resonates with the conservative media/Trump supporters #CYBERWARCON Image
Francois says that if you want to conduct disinformation dissemination campaigns, you need accounts that are woven into the network already. Spinning up accounts and pushing out hashtags will no longer work #CYBERWARCON
Next up is Alex Orleans from @FireEye looking at how Russian hackers are targeting US electrical grids #CYBERWARCON
#CYBERWARCON had been hacked.... Well they can't get the slides to work at least
They have removed the Russians from the network and #CYBERWARCON is back on...
Alex Orleans now talking about Russian hacking group known as Temp.Isotope (aka Berserk Bear, Energetic Bear, DragonFly 2.0) who are the group hacking the US grid. Their work was first reported over a year ago fortune.com/2017/09/06/hac… #CYBERWARCON
The US electrical grid is actually 5 grids, with more than 3000+ power companies. It’s the "most complex quilt” ever built by humans according to @chrissistrunk #CYBERWARCON
“The day everything changed” was Dec. 23, 2015 when a Russian hacking group took control of a Ukraine electrical grid and shut off power for over 200,000 people #CYBERWARCON
New compliance standards have harden the core parts of the US electrical gird, but the Russians continue to target the grid anyway. So you need to ask why? #CYBERWARCON
And this is the answer: Image
Russian continue to conduct attacks on the grid, because it means the US has to deal with the threat (costs money and time) and feeds into influence operations among US citizens #CYBERWARCON
Russians taking advantage of the fact that US citizens don’t really understand how the grid works, and media misinterpretations adds to the problem #CYBERWARCON
Orleans doesn’t see a disruptive attack from Russia any time soon, as their strategy is "death by a thousand cuts” #CYBERWARCON
Orleans says that we still don’t know how deeply Russia has penetrated the electrical grid….which is a little worrying #CYBERWARCON
Next up at #CYBERWARCON is @RecordedFuture talking about how control of the internet is influencing Yemen’s civil war….something that has not been talked about much
How not to colour code a map #CYBERWARCON Image
Yemen’s internet is not great. In terms of user bandwidth Yemen ranks 189 out of 189 countries. Most of the internet infrastructure is based in Sana’a meaning when Houthi gained control of capital, they also gained control of the internet. #CYBERWARCON
If the government seized the port city of Al-Hudaydah, it would be able to cut off Houthi access to the internet, as that is where the submarine cable lands #CYBERWARCON
Houthis have been using Netsweeper to censor the internet, while there is also evidence of people using Tor and OpenVPN to get around the censorship #CYBERWARCON
There are a lot o major vulnerabilities in the Yemennet infrastructure leaving it open to surveillance and monitoring and there is evidence that Chinese-made routers have purposely built backdoors #CYBERWARCON
The Houthi government is using #CoinHive to secretly mine cryptocurrencies to aid their efforts
Next up at #CYBERWARCON is @nejenkins from the Cyber Threat Alliance and @Jason_Healey from Columbia University talking about whether US cyber deterrence operations are making things better or worse #CYBERWARCON
Trying to assess where the US new deterrence policy is working is difficult, even with hard data says Healy #CYBERWARCON
Knowing what attacks the US were conducting would help categories the severity of the attacks conducted by adversaries, Healy says. Unlikely this type of info will be make public any time soon #CYBERWARCON
The OPM hack was within acceptable limits of espionage efforts according to @Jason_Healey - Bolton has specifically singled out OPM as crossing the line #CYBERWARCON
Healy adds that as far as he is aware no one in the administration is trying to decide is the new policy is working or not. Which is a problem... #CYBERWARCON
Next up at #CYBERWARCON is Olga Belogolova and Madelyn Wilson from #Facebook who are talking about how they tracked disinformation campaigns during the #midterms
Here are the reasons Facebook gives for why disinformation campaigns take place on social media.....one that is missing is how easy it is to weaponize these platforms. They much have just forgot to include that one #CYBERWARCON Image
Facebook says there are huge variations between information operations from different countries - different strategies, different goals, different methods (ads, WhatsApp, pages, install etc) #CYBERWARCON
But there are some similarities, including the use of state-owned media to amplify the message, similar linguistic mistakes, leveraging memes and pop culture, trying to co-opt activist communities to disseminate fake news #CYBERWARCON
Interesting to hear these Facebook employees talking about FB, Instagram, WhatsApp, Messenger as all being part of a single, unified platform....not sure antitrust regulators would be happy about that #CYBERWARCON
Asked about issues in Myanmar, Facebook trots out the line that it is putting more resources into the problem #CYBERWARCON
Asked by @RidT if a dimishing return on investment for campaigns means we have seen peak disinformation on Facebook, Madelyn Wilson says she can't say if that's the case #CYBERWARCON
@RidT #CYBERWARCON is back after lunch. Next up are six lightning talks. First is a look at th eTriton malware that targeted ICS controllers and used by Temp.Vales which is linked to a Russian government scientific institute
@RidT Next up is Dan O’Keefe who is talking about the Houthi Information operations #CYBERWARCON
@RidT O\’Keefe highlights @USAKillsYemeni as an example of an account that trying to create campaigns that look like an activist grassroots campaign #CYBERWARCON
Next up is @k_sec talking about Russian-speaking state-sponsored hacking groups and how they are linked #CYBERWARCON
Next is @criskittner and @tiskimber talking about outsourcing cyberwar — how much does it cost for other nations to conduct a cyberwar? #CYBERWARCON
Outsourcing is done by most legitimate businesses and can bring benefits in terms of speed and cost-savings — and the same benefits are there for cybercriminals or nation state, with the added benefit of muddying the waters in terms of attribution #CYBERWARCON
You can easily go into any underground hacker forum and find people selling access to pretty much any enterprise. Prices differ depending on industry — financial company costs $3600 while educational company costs less than $2000 #CYBERWARCON
As well as malware, you can outsource influence operations, buying 1,000 followers for as little as $20 — and these services are not even hidden, available freely on the open web #CYBERWARCON
Next up is @SiminK_ talking about Iran’s influence operations #CYBERWARCON
@SiminK_ Most of the spread of disinformation in Iran happens on Instagram because it is highly popular and not blocked in the country. Focusing on FB and Twitter misses a big part of the picture @SiminK_ #CYBERWARCON
Final lightning talk is from @Adam_Cyber who is talking about what will the next destructive attack look like? #CYBERWARCON
Meyer says that you can predict the next Russian destructive attack simply by looking at important dates on the calendar #CYBERWARCON Image
Next up is Lauren Cooper from Carnegie Mellon who is talking about China’s efforts to target and disrupt US universities #CYBERWARCON
Number of Chinese students exploded in the last decade, going from 67,000 in 2006 to over 350,000 in 2016 #CYBERWARCON
Chinese Communist ideology spread in the US through Confucius Institutes which are joint venture between US universities and organisation called Hanban, which reports directly to the Ministry of Education in Beijing #CYBERWARCON
Another soft power effort is the China-United States Exchange Foundation, founded by billionaire Tung Chee Hwa, who headed up on of China’s main propaganda’s organs #CYBERWARCON
The result of this is the theft of valuable IP and the infiltration of computer network operations, as well as talent recruitment. The Thousand Talents Plan was a recruitment scheme to lure talent to China #CYBERWARCON
Some of those who were recruited in the areas where China wants to become a world leader Image
Artificial Intelligence is "the next battlespace” for China, Cooper says, referencing its plans to become a world leader by 2030. In Berkeley, the research lab received a $1 million grant from the US government's favourite Chinese tech company Huawei
The future? First off Chinese student visas will decrease dramatically. There will also be more pressure on Chinese students from the CCP. Also Chinese universities have built up their expertise meaning students won’t have to travel #CYBERWARCON
Next up at #CYBERWARCON is @juanandres_gs who is going to talk about APTs
The current way of describing APTs (usually using the word “sophisticated”) is just not good enough, so we need to come up with new ways of talk about them - @juanandres_gs says, #CYBERWARCON
It is important to build dynamic rather than static profiles of these hacking groups, because they change. Operatives leave/die/defect, the geopolitical context changes, resources change, #CYBERWARCON
Next up at #CYBERWARCON is @kyleehmke who is talking about how to identify information operations using cyber threat intelligence tools
@kyleehmke Ehmke talking about the tools he used to identify the people behind a campaign launched by the Russian troll farm in 2016 on Facebook #CYBERWARCON
Using the same techniques he used to investigate the Russian troll factory, Ehmke looked at Definers, the PR company who Facebook hired to smear opponents. He found sites about Tim Cook, building a border wall and a lot of others Image
Next up is Robert Lipovsky from @ESET talking about Grey Energy. #CYBERWARCON
The evolution from BlackEnergy to GreyEnergy, via Telebots Image
Here's @t_gidwani closing out #CYBERWARCON Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with David Gilbert

David Gilbert Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @daithaigilbert

Jun 20
US domestic extremists, including neo-Nazis, have been using AI for years, but new research shows that in 2024, their adoption of the technology has accelerated dramatically—and experts are deeply concerned.

1/6

wired.com/story/neo-nazi…
Extremists, initially skeptical about "the evils" of generative AI tools like ChatGPT, have changed their minds.

“In the last few years we’ve gone from seeing occasional AI content to AI being a significant portion of hateful propaganda content online" @MEMRIReports

2/6
A new trend this years is the adoption of gen AI video tools like OpenAI's Sora, with researchers seeing a marked increased in AI video featuring hate content in recent months — including a video of actress Emma Watson reading Mein Kampf aloud while wearing a Nazi uniform

3/6
Read 6 tweets
Jun 12
As Trump and the GOP continue to push voter fraud conspiracies ahead of the US elections, experts are seeing a resurgence in far-right paramilitary activism.

Now, a January 6th prisoner is trying to launch a 50-state armed militia from his jail cell.

1/7
wired.com/story/january-…
Jake Lang, caught on video swinging a bat at police during the Capitol riot, has been in jail for 3yrs.

“It's important to recognize that Lang is, first and foremost, a grifter who knows that his ‘political prisoner’ schtick is his only shot at relevance,” @Jon_Lewis27 says

2/7
From his jail cell in Brooklyn, Lang told me he's been working on his new militia, called the North American Patriot and Liberty Militia (or NAPALM for short), for a year.

3/7 Image
Read 7 tweets
Apr 8
For the last month I've been attending online webinars from election denial groups who are ramping up their efforts to try and disrupt the 2024 presidential election.

Here's what I found out:

(with typically wonderful art from @AnjaliNair25)

1/7

wired.com/story/election…
True the Vote and founder Catherine Engelbrecht have been trying to disenfranchise voters for more than a decade, but as the November elections rolls around they are now looking to recruit thousands of local activists to challenge voter rolls and disrupt election locations

2/7
In a series of webinars, Engelbrecht has been giving supporters a how-to guide to local organization as well as an introduction to the group's new IV3 tool, which automates voter registration challenges.

3/7 Image
Read 7 tweets
Feb 9
Russia's media is this morning celebrating a huge victory thanks to #TuckerCarlson's softball interview with Putin last night.

Here's how the Kremlin-backed outlets, as well as Telegram channels, and bot networks are spinning the encounter.

1/6

wired.com/story/tucker-c…
The homepages of all Russian media are dominated by stories about the interview. State-run news agency RIA Novosti's newsfeed had at least a dozen stories published since last night — focusing on how Putin had succeeded in "educating" the west about Russia/Ukraine history

2/6 Image
Memes about Carlson flooded pro-Kremlin Telegram channels, including ones calling for a national day of celebration for Tucker and images of him wearing a ushanka hat.

3/6
Image
Image
Read 6 tweets
Jan 29
Going to be monitoring the #takeourborderback convoy here today, watching numerous livestreamers who are in Viriginia broascasting from the convoy as it gets ready to depart for Texas

1/x

wired.com/story/extremis…
Last night some of those involved got kicked out of the parking lot where they were set to meet this morning, prompting a last-minute change of venue



2/x
And this morning, one of the livestreamers posted a picture claiming that four cars which had their types slashed in the parking lot of the hotel where convoyers were staying

3/x Image
Read 35 tweets
Jan 26
Tensions on the Texas border are already sky high, with GOP lawmakers calling for civil war & Trump calling to deploy the national guard

Now a convoy, organized by a far-right extremist who wants to hunt down migrants, is about to make things worse

1/5
wired.com/story/extremis…
The #TakeBackOurBorder convoy is spearheaded by Pete Chambers who claims to be a former green beret and plans to deploy tactics used fighting ISIS in Syria against migrants crossing the border.

Here he is on Alex Jones talking about deploying a "domestic internal defense"

2/5 Image
The convoy will begin Monday from Virginia, moving through Florida and Louisiana before ending up in Eagle Pass, Texas, where the standoff is taking place.

En route, the convoy will stop off at a brewery owned by Phil Waldron, who was central to fomenting #Jan6th

3/5 Image
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(