According to several sources the US Secretary of Defense has ordered US Cyber Command to cease all planning for offensive cyber actions agsinst Russia.
Cyber warfare and wartime destruktive cyber attacks requires a lot of preparation. Ideally you want to have backdoors installed on your adversaries networks in peacetime, so you can strike at a moments notice, if needed. /2
This why we read of enemies cyber warfare units like ”Sandworm”, ”DragonFly” and ”Volt Typhoon” hacking US critical infrastructure all the time. They are playing the same game. Gain access in peace, so they can strike in war. /3
By halting such preparations (if indeed these news are correct) US is effectively giving up the capability to strike Russia without weeks or longer time to prepare. As far as we know, there has been no similar promise from Russia. /4
A unilateral cyber disarmament, against Russia at a critical time in geopolitics. /5
• • •
Missing some Tweet in this thread? You can try to
force a refresh
Russia and USA appears to have agreed to a prison exchange. USA gets several Western and Russian journalists arrested for various spy charges. Russia gets home... cybercriminals!
A thread /1
Who are these guys that Russia wants back so badly? Well, let's have look at the list:
Two of the men are harldy "cybercriminals". They were arrested for being involved in various schemes to import Western electronics to Russia. /2
Alexander Vinnik was arrested in 2017 for money laundering as CEO of a crypto exchange called BTC-E. BTC-E was later accused of handling money transfers for the GRU hackers known as “Fancy Bear” during the 2020 US election interference. /3
From the start, when Anonymous Sudan emerged, I have suspected that this was a group created by Russia to create anti-Swedish sentiment in Turkey by exploiting extremists that have burned the Quran in Sweden.
🧵/1
To sum it up; the name Anonymous Sudan first appeared at the same time as an extremist started to use free speech legislation to publicly burn Qurans in Sweden, even directly outside the embassy of Turkey. /2
While there is no smoking gun, circumstantial evidence points to all this being a Russian information operation.
Here is a highly suggestive timeline of these events in our blog post about Anonymous Sudan, for those who wants to dig deeper. /3
I would argue that the most significant event in cybersecurity in 2023 was the attack on two casinos in Nevada by the threat actor known as Octo Tempest and in this thread I will explain why.
🧵 /1
Octo Tempest, also known as Star Fraud or Scattered Spider is a group of hackers that highly likely consists of young men, from USA and possibly UK. They belong to an online community simply called “Comm”. /2
This community of young, invariably male, hackers and wannabe hackers is a toxic online mix of hacking, misogyny, and 4chan trash talk. /3 cyberscoop.com/youth-hacking-…
I have on several occasions argued that cybersecurity professionals need to be better at explaining cyber threats to C levels. One way to do that is to describe the cybercriminals’ business model.
A thread 🧵 /1
Cybercriminals’ business model may seem esoteric for the average cybersecurity professional, but that is closer to the language of a CFO and if you don’t have the CFO on your side, necessary cybersecurity will not happen. /2
How much profit a ransomware criminal can make is based on four variables.
R = The ransom amount
W = the victim’s willingness to pay a ransom.
D = The chance of successfully deploying the ransomware
T = The time in man hours it takes to complete the operation.
/3
This is a long thread on Russian cyber war in Ukraine, in which I will try to explain cyber war and comment on the Russian cyber war in Ukraine. /1
For those who don’t know me or what credentials I have. I am a civilian threat intelligence expert at @truesec, but I have previously worked 35 years in intelligence, mostly in Sigint. /2
@Truesec First, we need to define a few things, because words like “cyber war” are being thrown around and misused a lot.
Cyber Operations are the use of cyber capabilities, either in war or clandestinely in peace. Just like Special Forces operations. /3