Showing posts with label Syrian. Show all posts
Showing posts with label Syrian. Show all posts

Monday, December 30, 2013

Bits Blog: The Syrian Electronic Army Is at It Again

Monday, May 20, 2013

Hunting for Syrian Hackers’ Chain of Command

The hacking group that calls itself the S.E.A. struck again on Friday, this time breaking into the Twitter accounts and blog headlines of The Financial Times. The attack was part of a crusade that has targeted dozens of media outlets as varied as The Associated Press and The Onion, the parody news site.

But just who is behind the S.E.A.’s cybervandalism remains a mystery. Paralleling the group’s boisterous, pro-Syrian government activity has been a much quieter Internet surveillance campaign aimed at revealing the identities, activities and whereabouts of the Syrian rebels fighting the government of President Bashar al-Assad.

Now sleuths are trying to figure out how much overlap there is between the rowdy pranks playing out on Twitter and the silent spying that also increasingly includes the monitoring of foreign aid workers. It’s a high-stakes search. If researchers prove the Assad regime is closely tied to the group, foreign governments may choose to respond because the attacks have real-world consequences. The S.E.A. nearly crashed the stock market, for example, by planting false tales of White House explosions in a recent hijacking of The A.P.’s Twitter feed.

The mystery is made more curious by the belief among researchers that the hackers currently parading as the S.E.A. are not the same people who started the pro-Assad campaign two years ago.

Experts say the Assad regime benefits from the ambiguity. “They have created extra space between themselves and international law and international opinion,” said James A. Lewis, a security expert with the Center for Strategic and International Studies.

The S.E.A. emerged during the Syrian uprisings in May 2011, they said, to offer a pro-Assad counternarrative to news coming out of Syria. In speeches, Mr. Assad likened the S.E.A. to the government’s own online security corps, referring to the group as “a real army in a virtual reality.”

In its early incarnation, researchers said, the S.E.A. had a clearly defined hierarchy, with leaders, technical experts, a media arm and hundreds of volunteers. Several early members belonged to the Syrian Computer Society, a technical organization run by Mr. Assad before he became president. Until last month, digital records suggest, the Syrian Computer Society still ran much of the S.E.A.’s infrastructure. In April, a raid of S.E.A. Web domains revealed that the majority were still registered to the society.

S.E.A. members initially created pro-Assad Facebook pages and spammed popular pages like President Obama’s and Oprah Winfrey’s with pro-Syrian comments. But by the fall of 2011, S.E.A. activities had become more premeditated. They defaced prominent Web sites like Harvard University’s with pro-Assad messages, in an attack a spokesman characterized as sophisticated.

At some point, the S.E.A.’s crucial players disappeared and a second crop of hackers took over. The current group consists of roughly a dozen new actors led by hackers who call themselves “Th3 Pr0” and “The Shadow” and function more like Anonymous, the loose hacking collective, than a state-sponsored brigade. In interviews, people who now identify as the S.E.A. insist they operate independently from the Assad regime. But researchers who have been following the group’s digital trail aren’t convinced.

“The opportunity for collaboration between the S.E.A. and regime is clear, but what is missing is proof,” said Jacob West, a chief technology officer at Hewlett-Packard. As governments consider stronger responses to malicious cyberactivity, Mr. West said, “the motivation for Syria to maintain plausible deniability is very, very real.”

Long before the S.E.A’s apparent changing of the guard, security researchers unearthed a stealthier surveillance campaign targeting Syrian dissidents that has since grown to include foreign aid workers. Morgan Marquis-Boire, a researcher at the Citizen Lab at the University of Toronto, uncovered spyware with names like “Dark Comet” and “BlackShades” sending information back to a Syrian state-owned telecommunications company. The software — which tracked a target’s location, read e-mails and logged keystrokes — disguised itself as an encryption service for Skype, a program used by many Syrian activists.

Mr. Marquis-Boire has uncovered more than 200 Internet Protocol addresses running the spyware. Some were among the few kept online last week during an Internet disruption in Syria that the government blamed on a “technical malfunction,” but experts described as a systematic government shutdown.

This article has been revised to reflect the following correction:

Correction: May 17, 2013

An earlier version of this article based on previous reporting referred incorrectly to a representative of The Financial Times, Ryann Gastwirth. She is a spokeswoman, not a spokesman.

Monday, May 13, 2013

Bits Blog: Details Emerge About Syrian Electronic Army’s Recent Exploits

The Onion released a screenshot of the phishing e-mail used to hack into the company's Twitter account.The Onion The Onion released a screenshot of the phishing e-mail used to hack into the company’s Twitter account.

At The Onion it’s all fun and games, except when the company’s Twitter account gets hacked.

This week, after the parody site became the latest publication to have its Twitter account hacked by the Syrian Electronic Army, The Onion took a more serious note, explaining in a detailed blog post how the company’s account was hacked, and warning others how to avoid the exploit.

In the blog post, Onion engineers explained that the company’s Twitter account was hacked using a basic phishing exploit, where a false e-mail redirected people to a fake Web site which then asked for Google Apps credentials.

“At least one Onion employee fell for this phase of the phishing attack,” the company said.

Exposing details about an attack is not the normal approach companies take after they are hacked. The New York Times revealed earlier this year how Chinese hackers breached its systems, but that was an anomaly. Most companies fear what such disclosures will do to their reputations, or their stock price.

The Associated Press, for example, has remained silent after its Twitter account was hijacked and a fake message was posted about explosions at the White House.

In recent attacks on The A.P., Human Rights Watch, and the Onion, the group used sophisticated ”spearphishing”attacks to break into each organization. Employees received similarly worded e-mails, asking them to click on a fake news article that then redirected them to a fake Google Mail or Microsoft Webmail site where they were asked to re-enter their username and password.

The hackers used their login credentials to send e-mails to other employees from their inboxes until they found people with access to the organization’s social media accounts. Once inside those people’s inboxes, the hackers reset their Twitter passwords, giving them exclusive access to the account, until Twitter could suspend it. In the case of The A.P., a single Tweet was sufficient to nearly crash the stock market.

One hacker, who identifies himself only by his hacker handle Th3 Pr0, said the group attacked The A.P. because the Syrian Electronic Army believed the United States was “supporting the terrorist groups in Syria” and because the United States had seized its Web domains. Th3 Pr0 said the group was able to trick more than 50 A.P. employees to click on its malicious link, including a handful of the organization’s social media editors. Th3 Pr0 sent The New York Times several screenshots taken during the AP attack to prove the Syrian Electronic Army, or S.E.A., was behind it.

Security researchers tracking the hackers also confirmed the group was responsible. According to forensics reports, several recent Twitter hacks by the group, including an attack on Human Rights Watch last March and The Onion this week, were orchestrated from the same Internet addresses in Russia. But they believe those addresses are a proxy that masks the true origin of the attacks, which they say, is in Syria.

“From examining the details of this incident, as well as those effecting The A.P., Guardian and others, it’s clear that the S.E.A. is not using complex methods of attack,” The Onion’s tech team wrote. “All of the hacks so far have been a result of simple phishing, or possibly dictionary attacks — all of which are preventable with a few simple security measures.”

Among the tactics that can be used to ward off attacks, the engineers note that people should be aware of suspicious links and setting up a Twitter account on a different e-mail address than the one belonging to your organizations.

But The Onion has also managed to have a little fun at its own expense this week posting a satirical article on its hacking, titled: “Onion Twitter Password Changed To OnionMan77: ‘That Ought To Do It,’ Company Sources Confirm.” Then it posted another piece making fun of the hackers.

Sunday, December 2, 2012

Official Syrian Web Sites Hosted in U.S.

By nightfall, after being contacted by The New York Times, several host companies said they were taking down those sites. They and similar companies had been identified in reports published by Citizen Lab, a research laboratory that monitors North American Web service providers that host Syrian Web sites.

For example, the Web site of SANA, the Syrian state news agency, is hosted by a Dallas company, SoftLayer Technologies. It is one of a handful of Internet providers based in the United States that sell their services, often unknowingly, to Web sites operated by the government of President Bashar al-Assad.

HostDime.com in Orlando, Fla., hosts the Web site of Syria’s Ministry of Religious Affairs. Jumpline.com hosts the site of the country’s General Authority for Development. The government of Hama, a city that has seen heavy clashes between rebels and government troops, operated its Web site through WeHostWebSites.com in Denver.

An executive order by President Obama prohibits American companies from providing Web hosting and other services to Syria without obtaining a license from the Treasury Department.

On Thursday, State Department officials confirmed that providing the services was a violation of the United States sanctions. “Our policies are designed to assist ordinary citizens who are exercising their fundamental freedoms of expression, assembly and association,” a spokesman, Mark C. Toner, said.

A SoftLayer spokesman, Andre Fuochi, would not comment about the SANA Web site, but in a statement he said the company “rigorously” enforces “prevailing laws and regulations and acts swiftly and vigorously if we find our users to be in violation.”

Dennis Henry, the vice president of operations at HostDime.com, said he had been unaware of the Syrian government Web site, but that it was hosted by a customer’s server housed in HostDime.com’s data center.

“We have contacted our direct client whose server is housing the Web site to express our concerns,” Mr. Henry said. On Friday, Mr. Henry said the company had removed the Web site.

Mike Griffin, an owner of Handy Networks, a wholesale Web service and the owner of WeHostWebSites.com, said he too had been unaware of the Syrian government Web site but had asked that it be removed.

“We comply with all U.S. sanctions, including those prohibiting the exportation of Web hosting services to Syria,” he said.

Upon being told of the Syrian Web site, Jumpline’s chief operating officer, Andy Mentges, said in an e-mail that it would be “shut down within the hour.”

The Internet shutdown across Syria on Thursday underscored how the 20-month conflict, which has left more than 40,000 people dead, has increasingly moved to the Web. Both sides use cyberattacks to advance their causes.

The hosting of government Web sites overseas represents a growing technological sophistication by the Assad government. “Look what they did with chemical weapons. They can do the same with communications,” said Robert B. Baer, a former C.I.A. operative based in the Middle East. “When the Syrians want to do something, they can do it.”

It is also likely that Syrian rebel and jihadi groups host Web sites inside the United States. The Syrian government appears to be aware that its Web sites are safer and easier to control when operated on servers inside the country.

In July, the Assad government ordered that all official Web sites be hosted inside Syria. But in case of an emergency or an Internet shutdown like the one on Thursday, the government also maintains Web sites based in the United States, Canada and Britain, said Helmi Noman, a senior researcher at Citizen Lab.

“This most recent Internet disruption in Syria highlights the issue of Web hosting and how the regime is able to make use of servers outside Syria to promote its message while locally hosted sites are down,” Mr. Noman said.

Syrian Forces Strike Rebels on Damascus Outskirts

Narciso Contreras/Associated PressA fire to keep a family warm was visible on Thursday in a part of Aleppo, Syria, that is controlled by rebels. In Damascus, flights were suspended for a second day.

BEIRUT, Lebanon — Syrian forces pummeled the outskirts of Damascus with artillery and airstrikes on Friday, antigovernment activists reported, apparently in an effort to insulate the city — the cornerstone of President Bashar al-Assad’s rule — from rebels who have pushed deeper into a semicircle of suburbs along the city’s eastern and southern edges.

Foreign airlines suspended flights into Damascus International Airport for a second day as the air force bombarded rebels along the airport road. Rebels clashed with government forces along the road, lobbing a mortar onto a bridge, activists reported.

Holding Damascus, the capital, is crucial for the government, which keeps its highest concentration of troops and its most loyal and best-trained units in and around the city. Though rebels were unlikely to be able to overrun Damascus soon, analysts said, the encroachment of fighting there — particularly at the airport — has a profound psychological effect on government supporters, making them feel trapped. It also forces the military to pull resources from other areas to defend the capital.

Damascus residents reached by phone and by Skype reported hearing explosions and seeing billowing smoke in the distance, and they described an atmosphere of tension and fear. Government checkpoints were so numerous that it was difficult to travel anywhere without passing through one.

Activists reported that violence had spilled into areas that had usually been calm. A mortar shell landed on Baghdad Street, a downtown thoroughfare, killing a 22-year-old man, said Salam Mohammed, an activist in Damascus. There were clashes at Mezze Airport, west of the capital, near a wealthy pro-government area that had usually been isolated from fighting, another activist said.

Emile Hokayem, an analyst at the International Institute for Strategic Studies, described the fighting as “part of the strategy of encirclement of the city.”

“The rebels are making a very strong point: that they can go after anything that is seen as critical infrastructure,” Mr. Hokayem said, adding that while the government would be able to reopen the airport and the airport road, “the cost of doing so is only going to increase over time.”

Fighting has plagued the Damascus suburbs throughout the 20-month conflict, and rebels have tried several times to push into the city. Most recently, they held the southern neighborhood of Medan for several days over the summer. The government responded by moving forces from other areas to Damascus, analysts said, and there were indications that it had also done so in recent days. Activists reported that government forces had withdrawn from one of their last bases in the remote eastern province of Deir al-Zour, leaving rebels in control of oil fields there.

There was less detailed information than usual about the conflict on Friday because Internet access was cut to the entire country for a second day, in what seemed to be a government effort to disrupt the communications of its opponents, although some activists and other residents used the Web through satellite services.

Fighter jets bombarded neighborhoods in Daraya, south of the capital, and in East Ghouta, to the east, and artillery pounded other areas in the crescent of territory where rebels have been trying to consolidate gains. Activists and analysts said the attacks could herald a counteroffensive, or might simply be further retaliation against pro-rebel areas.

Hania Mourtada and Anne Barnard reported from Beirut, and Hala Droubi from Dubai, United Arab Emirates.

This article has been revised to reflect the following correction:

Correction: November 30, 2012

An earlier version of this article reversed the given name and surname of an activist in the Damascus suburbs who said rebels had recently captured 40 pro-government militiamen, and misspelled his given name. He is AlBaara Abdul Rahman, not Abdul Rahman al-Barra.