A Report on Attackers in the Energy Industry CONTENTS

Total Page:16

File Type:pdf, Size:1020Kb

A Report on Attackers in the Energy Industry CONTENTS The state of the station A report on attackers in the energy industry CONTENTS Introduction 3 Outmoded and out there 4 Changing the game 4 The names 5 The profiles 5 Two groups, one spillover 9 A plethora of opportunity 10 Attack targets and the reasons behind them 10 The ‘How’ 11 Investigating and naming 12 Still succeeding 12 Mitigating 13 Conclusions 15 THE STATE OF THE STATION 2 INTRODUCTION Interconnected systems in the energy industry increase cyber vulnerabilities, with cyber attacks often going undetected for some time. Malicious actors are increasingly targeting critical infrastructure (CNI) sites and distribution facilities for energy, and cyber attacks have real-world effects. As energy companies save costs against the backdrop of a lower oil price, consolidating operations can weaken business resilience and redundancy levels. This gives rise to new, single critical points of failure, with any disruption across the supply chain potentially having increased consequences. Cyber attacks using individual vulnerabilities and exploits have, and always will be directed against the vast number of Programmable Logic Controllers (PLCs) in existence. However, connecting Industrial Control Systems (ICS) to the Internet and enterprise business networks is increasing. These factors, plus fewer backups in place with an increased dependency on fewer facilities, are only part of the picture. OUTMODED AND OUT THERE Many Operational Technology (OT) components connection was usual. Cyber security was not a have built-in remote operation capabilities, but are realistic threat when they were manufactured, and partly or entirely lacking in security protocols such legacy protocols and systems never had built-in as authentication. These concerns are not new, but security controls that we take for granted today. many have recognized the need for increased cyber Transitioning these systems to the Internet has security around CNI for years. opened them up to attacks from a myriad of angles. Critical infrastructure is unique in the threat Updates and security patching further complicate landscape, however. It is one of few sectors to be the issue – especially when a system needs to be tied to private and public infrastructure, with a wide “on” all the time. This leaves little-to-no time for spread of physical and mobile assets. Consequently, critical security improvements. Moreover, any there are a number of different factors that influence system costing millions and designed to work for who, how, and why attackers target CNI. decades is not going to be readily discarded and replaced by a new one, even if it is deemed to be A considerable number of CNI systems in use were insecure. Together, these factors allow attackers to installed before the advent of Stuxnet. Many of successfully penetrate ICSs. them were built decades ago before a 24/7 internet CHANGING THE GAME A variety of different adversaries, each with their ability to carry out other normal business functions, own motivations and tradecraft, constantly strive however. to compromise organizations that operate critical infrastructure. Nation-state sponsored Advanced Appropriating APTs to just nation-state groups belies Persistent Threat (APT) groups continue to seek the fact that the threat landscape has moved on, network foothold positions on CNIs and espionage however. Nation-state capabilities trickle down and opportunities in the interests of exercising become more widely available, giving other hacking political leverage. A realistic worst-case scenario groups the ability to be as advanced and persistent is a type of DoS attack against a power plant’s as APTs. Cyber criminals, who are generally after ICS infrastructure, driving the facility down and money, have acquired sophisticated tools as a making it unavailable for a long time. Potential result of the Shadow Brokers and Vault7 data outcomes include destroying the industrial control breaches and modified their operating procedures. devices and systems. As a rule, the segregation Money laundering techniques have also changed between operational and business IT assets (e.g. considerably, fueling ever-greater ransomware programmable logic controllers versus a corporate demands. user’s laptop) means that attacks of this type are unlikely to impact a power plant’s operational capability. They would impact a power plant’s THE STATE OF THE STATION 4 THE NAMES Determining the number of attackers/malwares/techniques targeting the energy industry is not an exact science, but 9 different ones stand out. These are: • Operation Sharpshooter (Lazarus Group) • Industroyer Malware – also known as • APT33 CrashOverride • GreyEnergy (the successor to the BlackEnergy • Dragonfly/Dragonfly 2.0 group) • Havex Malware • BlackEnergy 1, 2 and 3 Malware • ICS side-channel attack • TRITON/TRISIS Malware THE PROFILES Operation Sharpshooter: a name given by McAfee positions at unknown companies for a campaign which started on October 25, 2018. Additional evidence uncovered recently strengthens The job titles are: Strategic Planning Manager, suspicions that this campaign is operated by the Business Intelligence Administrator, and Customer Lazarus Group. Its current focus seems to be on Service Representative. These are distributed by an cyber espionage and reconnaissance. Using spear IP address in the United States through the Dropbox phishing, threat actors approach their targets service The group does not commonly attack the disguised as recruiters via a social media service energy industry, but the operation touching this using English-language job description titles for sector might have been collateral. Initial access: Spear phishing via service Execution: Scripting, user execution, command-line interface Persistence: Registry Run Keys / Startup Folder Defense evasion: Process injection, obfuscated files or information, file deletion, hidden files and directories Discovery: Account discovery, file and directory discovery, process discovery, system network configuration discovery, system network connections discovery, system time discovery, query registry Collection: Data from local system, automated collection Exfiltration: Automated exfiltration, exfiltration over command and control channel, data encrypted Command and control: Commonly-used port, remote access tools, web service, data encoding THE STATE OF THE STATION 5 APT33: believed to be supported by the December 2018, used a new variant of the Shamoon government of Iran focusing on cyber espionage disk wiper – a tool that wipes data on computers and reconnaissance. The malware has been tied to and can cause energy companies significant costs – an Iranian persona who may have been employed called Shamoon 3, which built on the capabilities of by the Iranian government to conduct cyber threat the previous versions. activity against its adversaries. Industry targets include mainly aviation and energy, It has shown increased activity since the US nuclear though it appears to be overall less advanced than deal withdrawal in May 2018. The latest attack, some other actors targeting the energy sector. It has against Italian oil and gas company Saipem in two aliases: Magic Hound, and Timber Worm. 2013 2016 - 2017 2018 First attributed cyber espionage Attacking aerospace and energy US nuclear deal withdrawal sparks operations in 2013. organizations. increased activity in APT 33 Initial access: Spear phishing link, spear phishing service Execution: Mshta, PowerShell, user execution, scripting, exploitation for client execution Persistence: Registry Run Keys / Startup Folder Privilege escalation: Valid accounts Defense evasion: Obfuscated files or information, de-obfuscate/decode files or information Credential access: Credential dumping, brute force Command and control: Data obfuscation GreyEnergy: the successor to BlackEnergy malware examined, is via a spear phishing attachment. still affecting Ukraine. Directed against energy and other high-value industry targets, the malware is The adversary uses decoy word documents with used to attack ICS control workstations running malicious macros used to download and execute Supervisory Control and Data Acquisition (SCADA) the GreyEnergy Mini Backdoor before escalating software and servers. privileges and installing the main one. Malware modules are encrypted or fileless in nature. Any The group focuses on cyber espionage and tools used are securely wiped from the target reconnaissance, with a high focus on stealth and systems. The most recent activity is traced to mid- leaving minimal footprints and traces. Initial access, 2018. like the majority of the groups/malware we have 2015 2014 - 2015 First GreyEnergy attributed 2016 2017 - 2018 The predecessor group “Black attack. Targeting an energy Early version of NotPetya worm Most recent activity recorded in Energy” is active and disappears company in Poland deployed by GreyEnergy. mid 2018 THE STATE OF THE STATION 6 Initial access: Exploit public-facing application, spear phishing attachment Execution: Scripting, service execution, user execution, PowerShell Persistence: Registry Run Keys / Startup Folder, modify existing service, Web Shell Privilege escalation: Valid accounts Defense evasion: Code signing, file deletion, masquerading, indicator removal on host, process injection, timestomp, deobfuscate/decode files or information, obfuscated files or information Credential access: Credential dumping, input capture, credentials in files, credentials in registry Discovery: Query registry, system information
Recommended publications
  • Xbt.Doc.248.2.Pdf
    MAY 25, 2018 United States District Court Southern District of Florida Miami Division CASE NO. 1:17-CV-60426-UU ALEKSEJ GUBAREV, XBT HOLDING S.A., AND WEBZILLA, INC., PLAINTIFFS, VS BUZZFEED, INC. AND BEN SMITH, DEFENDANTS Expert report of Anthony J. Ferrante FTI Consulting, Inc. 4827-3935-4214v.1 0100812-000009 Table of Contents Table of Contents .............................................................................................................................................. 1 Qualifications ..................................................................................................................................................... 2 Scope of Assignment ......................................................................................................................................... 3 Glossary of Important Terms ............................................................................................................................. 4 Executive Summary ........................................................................................................................................... 7 Methodology ..................................................................................................................................................... 8 Technical Investigation ................................................................................................................................ 8 Investigative Findings .......................................................................................................................................
    [Show full text]
  • Tstable of Content
    ZZ LONDON INTERNATIONAL MODEL UNITED NATIONS 2017 North Atlantic Treaty Organization London International Model United Nations 18th Session | 2017 tsTable of Content 1 ZZ LONDON INTERNATIONAL MODEL UNITED NATIONS 2017 Table of Contents Table of Contents WELCOME TO THE NORTH ATLANTIC TREATY ORGANIZATION .............................................................. 3 INTRODUCTION TO THE COMMITTEE .................................................................................................................. 4 TOPIC A: FORMING A NATO STRATEGY IN CYBERSPACE ............................................................................. 5 INTRODUCTION ............................................................................................................................................................... 5 HISTORY OF THE PROBLEM ............................................................................................................................................. 6 Timeline of notable attacks ....................................................................................................................................... 7 1998 – 2001 “MOONLIGHT MAZE” ....................................................................................................................... 7 2005 – 2011 TITAN RAIN & BYZANTINE HADES .................................................................................................. 8 2007 Estonia DDoS Campaigns ...............................................................................................................................
    [Show full text]
  • Security > Automotive > Blockchain > Virtual and Augmented Reality
    > Security > Automotive > Blockchain > Virtual and Augmented Reality AUGUST 2018 www.computer.org CALL FOR NOMINEES Education Awards Nominations Taylor L. Booth Education Award Computer Science and Engineering Undergraduate Teaching Award A bronze medal and US$5,000 honorarium are awarded for an outstanding record in computer science and engineering A plaque, certificate and a stipend of US$2,000 is education. The individual must meet two or more of the awarded to recognize outstanding contributions to following criteria in the computer science and engineering field: undergraduate education through both teaching and service and for helping to maintain interest, increase the • Achieving recognition as a teacher of renown. visibility of the society, and making a statement about the • Writing an influential text. importance with which we view undergraduate education. • Leading, inspiring or providing significant education content during the creation of a curriculum in the field. The award nomination requires a minimum of three • Inspiring others to a career in computer science and endorsements. engineering education. Two endorsements are required for an award nomination. See the award information at: See the award details at: www.computer.org/web/awards/booth www.computer.org/web/awards/cse-undergrad-teaching Deadline: 1 October 2018 Nomination Site: awards.computer.org r5p77.indd 77 5/9/18 3:30 PM IEEE COMPUTER SOCIETY computer.org • +1 714 821 8380 STAFF Editor Managers, Editorial Content Meghan O’Dell Brian Brannon, Carrie Clark Contributing Staff Publisher Christine Anthony, Lori Cameron, Cathy Martin, Chris Nelson, Robin Baldwin Dennis Taylor, Rebecca Torres, Bonnie Wylie Senior Advertising Coordinator Production & Design Debbie Sims Carmen Flores-Garvey Circulation: ComputingEdge (ISSN 2469-7087) is published monthly by the IEEE Computer Society.
    [Show full text]
  • A PRACTICAL METHOD of IDENTIFYING CYBERATTACKS February 2018 INDEX
    In Collaboration With A PRACTICAL METHOD OF IDENTIFYING CYBERATTACKS February 2018 INDEX TOPICS EXECUTIVE SUMMARY 4 OVERVIEW 5 THE RESPONSES TO A GROWING THREAT 7 DIFFERENT TYPES OF PERPETRATORS 10 THE SCOURGE OF CYBERCRIME 11 THE EVOLUTION OF CYBERWARFARE 12 CYBERACTIVISM: ACTIVE AS EVER 13 THE ATTRIBUTION PROBLEM 14 TRACKING THE ORIGINS OF CYBERATTACKS 17 CONCLUSION 20 APPENDIX: TIMELINE OF CYBERSECURITY 21 INCIDENTS 2 A Practical Method of Identifying Cyberattacks EXECUTIVE OVERVIEW SUMMARY The frequency and scope of cyberattacks Cyberattacks carried out by a range of entities are continue to grow, and yet despite the seriousness a growing threat to the security of governments of the problem, it remains extremely difficult to and their citizens. There are three main sources differentiate between the various sources of an of attacks; activists, criminals and governments, attack. This paper aims to shed light on the main and - based on the evidence - it is sometimes types of cyberattacks and provides examples hard to differentiate them. Indeed, they may of each. In particular, a high level framework sometimes work together when their interests for investigation is presented, aimed at helping are aligned. The increasing frequency and severity analysts in gaining a better understanding of the of the attacks makes it more important than ever origins of threats, the motive of the attacker, the to understand the source. Knowing who planned technical origin of the attack, the information an attack might make it easier to capture the contained in the coding of the malware and culprits or frame an appropriate response. the attacker’s modus operandi.
    [Show full text]
  • Cyber Law and Espionage Law As Communicating Vessels
    Maurer School of Law: Indiana University Digital Repository @ Maurer Law Books & Book Chapters by Maurer Faculty Faculty Scholarship 2018 Cyber Law and Espionage Law as Communicating Vessels Asaf Lubin Maurer School of Law - Indiana University, [email protected] Follow this and additional works at: https://www.repository.law.indiana.edu/facbooks Part of the Information Security Commons, International Law Commons, Internet Law Commons, and the Science and Technology Law Commons Recommended Citation Lubin, Asaf, "Cyber Law and Espionage Law as Communicating Vessels" (2018). Books & Book Chapters by Maurer Faculty. 220. https://www.repository.law.indiana.edu/facbooks/220 This Book is brought to you for free and open access by the Faculty Scholarship at Digital Repository @ Maurer Law. It has been accepted for inclusion in Books & Book Chapters by Maurer Faculty by an authorized administrator of Digital Repository @ Maurer Law. For more information, please contact [email protected]. 2018 10th International Conference on Cyber Conflict CyCon X: Maximising Effects T. Minárik, R. Jakschis, L. Lindström (Eds.) 30 May - 01 June 2018, Tallinn, Estonia 2018 10TH INTERNATIONAL CONFERENCE ON CYBER CONFLicT CYCON X: MAXIMISING EFFECTS Copyright © 2018 by NATO CCD COE Publications. All rights reserved. IEEE Catalog Number: CFP1826N-PRT ISBN (print): 978-9949-9904-2-9 ISBN (pdf): 978-9949-9904-3-6 COPYRigHT AND REPRINT PERmissiONS No part of this publication may be reprinted, reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording or otherwise, without the prior written permission of the NATO Cooperative Cyber Defence Centre of Excellence ([email protected]).
    [Show full text]
  • Investigative Techniques of N-Way Vendor Agreement and Network Analysis Demonstrated with Fake Antivirus
    2014 Annual ADFSL Conference on Digital Forensics, Security and Law Proceedings May 29th, 2:40 PM Investigative Techniques of N-Way Vendor Agreement and Network Analysis Demonstrated with Fake Antivirus Gary Warner The University of Alabama at Birmingham, [email protected] Mike Nagy The University of Alabama at Birmingham, [email protected] Kyle Jones The University of Alabama at Birmingham, [email protected] Kevin Mitchem The University of Alabama at Birmingham, [email protected] Follow this and additional works at: https://commons.erau.edu/adfsl Part of the Aviation Safety and Security Commons, Computer Law Commons, Defense and Security Studies Commons, Forensic Science and Technology Commons, Information Security Commons, National Security Law Commons, OS and Networks Commons, Other Computer Sciences Commons, and the Social Control, Law, Crime, and Deviance Commons Scholarly Commons Citation Warner, Gary; Nagy, Mike; Jones, Kyle; and Mitchem, Kevin, "Investigative Techniques of N-Way Vendor Agreement and Network Analysis Demonstrated with Fake Antivirus" (2014). Annual ADFSL Conference on Digital Forensics, Security and Law. 3. https://commons.erau.edu/adfsl/2014/thursday/3 This Peer Reviewed Paper is brought to you for free and open access by the Conferences at Scholarly Commons. It has been accepted for inclusion in Annual ADFSL Conference on Digital Forensics, Security and Law by an (c)ADFSL authorized administrator of Scholarly Commons. For more information, please contact [email protected]. ADFSL Conference on Digital Forensics, Security and Law, 2014 INVESTIGATIVE TECHNIQUES OF N-WAY VENDOR AGREEMENT AND NETWORK ANALYSIS DEMONSTRATED WITH FAKE ANTIVIRUS Gary Warner [email protected] Mike Nagy [email protected] Kyle Jones [email protected] Kevin Mitchem [email protected] The University of Alabama at Birmingham Birmingham, AL ABSTRACT Fake AntiVirus (FakeAV) malware experienced a resurgence in the fall of 2013 after falling out of favor after several high profile arrests.
    [Show full text]
  • Analysis Report Blackenergy
    Analysis Report iTrust-Analysis-001 May 2016 BlackEnergy - Malware for Cyber-Physical Attacks About iTrust iTrust is a multidisciplinary research centre located in the Singapore University of Technology and Design (SUTD), established collaboratively by SUTD and the Ministry of Defence, Singapore (MINDEF). The focus of iTrust is on cyber security, spanning across three research areas: a. Cyber Physical System (CPS); b. Enterprise Networking / Security; and c. Internet of Things (IoT). iTrust researchers focus on the development of advanced tools and methodologies to ensure security and safety of current and future cyber physical systems and Internet of Things (IoT) systems. Systems of interest include large infrastructure of national importance such as power grid, water treatment, and oil refineries as well as cyber-devices such as smart watches, pacemakers, defibrillators, insulin pumps, and VNS implants. Cyber physical systems is one of the many areas we are working on. The focus of the proposed research is to improve our understanding of cyber threats to CPSs and to develop and experiment with strategies to mitigate such threats. Our approach is based on well understood technical foundations borrowed from the interdisciplinary fields of control theory, artificial intelligence, game theory, networking, and software engineering. The techniques propose will be evaluated against, and demonstrated in our Secure Water Treatment (SWaT) Testbed, Water Distribution System (WADI) testbed, and Electric Power and Intelligent Control (EPIC) testbed. Similarly, shielded room laboratory for IoT research. iTrust researchers are drawn from across SUTD and with a strong collaboration with Massachusetts Institute of Technology (MIT), enrich the depth, breadth, and quality of research.
    [Show full text]
  • Yokogawa Innovative Plant Automation Security Solutions
    White Paper : Yokogawa Innovative Plant Automation Security Solutions Contents 1. Industrial Automation and Business Network Integration .......... 2 1.1. Necessity of IA System Security ................................................................................... 2 1.2. Yokogawa Cyber Security for Industrial Control System ............................................... 3 1.3. IA System Security Priorities .......................................................................................... 4 2. Continuous Security Concept ........................................................ 6 2.1. What are the Demands ................................................................................................. 6 2.2. Security Lifecycle Approach ........................................................................................... 6 2.3. Defense in Depth ........................................................................................................... 8 2.4. Yokogawa Security Competency Laboratories .............................................................. 8 3. Security Design and Implementation Solutions ........................... 9 3.1. Typical Network Architecture.......................................................................................... 9 3.2. Standardized Security Solutions .................................................................................. 10 3.3. Secure Designed Products .......................................................................................... 15 4. Security Operation
    [Show full text]
  • ESET THREAT REPORT Q3 2020 | 2 ESET Researchers Reveal That Bugs Similar to Krøøk Affect More Chip Brands Than Previously Thought
    THREAT REPORT Q3 2020 WeLiveSecurity.com @ESETresearch ESET GitHub Contents Foreword Welcome to the Q3 2020 issue of the ESET Threat Report! 3 FEATURED STORY As the world braces for a pandemic-ridden winter, COVID-19 appears to be losing steam at least in the cybercrime arena. With coronavirus-related lures played out, crooks seem to 5 NEWS FROM THE LAB have gone “back to basics” in Q3 2020. An area where the effects of the pandemic persist, however, is remote work with its many security challenges. 9 APT GROUP ACTIVITY This is especially true for attacks targeting Remote Desktop Protocol (RDP), which grew throughout all H1. In Q3, RDP attack attempts climbed by a further 37% in terms of unique 13 STATISTICS & TRENDS clients targeted — likely a result of the growing number of poorly secured systems connected to the internet during the pandemic, and possibly other criminals taking inspiration from 14 Top 10 malware detections ransomware gangs in targeting RDP. 15 Downloaders The ransomware scene, closely tracked by ESET specialists, saw a first this quarter — an attack investigated as a homicide after the death of a patient at a ransomware-struck 17 Banking malware hospital. Another surprising twist was the revival of cryptominers, which had been declining for seven consecutive quarters. There was a lot more happening in Q3: Emotet returning 18 Ransomware to the scene, Android banking malware surging, new waves of emails impersonating major delivery and logistics companies…. 20 Cryptominers This quarter’s research findings were equally as rich, with ESET researchers: uncovering 21 Spyware & backdoors more Wi-Fi chips vulnerable to KrØØk-like bugs, exposing Mac malware bundled with a cryptocurrency trading application, discovering CDRThief targeting Linux VoIP softswitches, 22 Exploits and delving into KryptoCibule, a triple threat in regard to cryptocurrencies.
    [Show full text]
  • Table of Content
    ZZ LONDON INTERNATIONAL MODEL UNITED NATIONS 2018 World Conference on Cybersecurity (WCC) London International Model United Nations 19th Session | 2018 Table of Content I ZZ LONDON INTERNATIONAL MODEL UNITED NATIONS 2018 Table of Contents Introduction Letters .................................................................................................... 1 Yuji DEVELLE ........................................................................................................ 1 Chloe AMELLAL .................................................................................................... 1 Isabel VICARÍA BARKER ..................................................................................... 2 Introduction to the Committee ................................................................................... 3 Topic A: Defining Cyberspace and Classifying Cyber-attacks .............................. 5 Introduction .............................................................................................................. 5 Key Concepts ............................................................................................................ 6 Cyberspace .............................................................................................................. 6 Cyber warfare vs. cyber crime................................................................................ 8 Cyber-attacks ........................................................................................................ 10 Hacking ................................................................................................................
    [Show full text]
  • 10Th International Conference on Cyber Conflict Cycon X: Maximising Effects
    2018 10th International Conference on Cyber Conflict CyCon X: Maximising Effects T. Minárik, R. Jakschis, L. Lindström (Eds.) 30 May - 01 June 2018, Tallinn, Estonia 2018 10TH INTERNATIONAL CONFERENCE ON CYBER CONFLicT CYCON X: MAXIMISING EFFECTS Copyright © 2018 by NATO CCD COE Publications. All rights reserved. IEEE Catalog Number: CFP1826N-PRT ISBN (print): 978-9949-9904-2-9 ISBN (pdf): 978-9949-9904-3-6 COPYRigHT AND REPRINT PERmissiONS No part of this publication may be reprinted, reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording or otherwise, without the prior written permission of the NATO Cooperative Cyber Defence Centre of Excellence ([email protected]). This restriction does not apply to making digital or hard copies of this publication for internal use within NATO, or for personal or educational use when for non-profit or non-commercial purposes, providing that copies bear this notice and a full citation on the first page as follows: [Article author(s)], [full article title] 2018 10th International Conference on Cyber Conflict CyCon X: Maximising Effects T. Minárik, R. Jakschis, L. Lindström, (Eds.) 2018 © NATO CCD COE Publications NATO CCD COE Publications LEGAL NOTICE: This publication contains the opinions of the respective authors only. They do not Filtri tee 12, 10132 Tallinn, Estonia necessarily reflect the policy or the opinion of NATO Phone: +372 717 6800 CCD COE, NATO, or any agency or any government. NATO CCD COE may not be held responsible for Fax: +372 717 6308 any loss or harm arising from the use of information E-mail: [email protected] contained in this book and is not responsible for the Web: www.ccdcoe.org content of the external sources, including external websites referenced in this publication.
    [Show full text]
  • Cyber-Terrorism Activities Report No. 16 January
    ICT Cyber-Desk PERIODIC REVIEW Cyber-Terrorism Activities Report No. 16 January – March 2016 Highlights This report covers the period of January - March 2016 and covers two main subjects: cyber-terrorism (offensive, defensive, and the media, and the main topics of jihadist discourse) and cyber-crime, whenever and wherever it is linked to jihad (funding, methods of attack). The following are among the issues covered in this report: The continuing trend of publishing information security guidelines and recommendations, including information and recommendations for correct methods of operation and software manuals, or services with a high encryption or anonymity level. Terrorist organizations continue to publish information about the dangers of intelligence and law enforcement officials who operate on the Internet to search for and locate terrorism supporters. In addition, all supporters are called on to continue spreading the organizations’ messages and guidelines for proper work. Officials in jihadist organizations continue to spread Best Practice guidebooks on the Internet and guidelines for using software and applications to increase information security. These are mainly used to encrypt data on the device and/or for data trafficking and maintaining the anonymity of Internet users. In addition, manuals for video processing are found. As previously stated, in recent years organizations have been using a wide range of software in order to create visual content at a professional level. Terrorists and terrorism supporters continue to hack Internet sites, especially as part of defacement attacks. In January 2016, Islamic State activists tried to recruit hackers to hack into government databases for pay. In February 2016, a television interview in Lebanon reported the existence of a Shi’ite hacker group, affiliated with Hezbollah, named Kadimon (translation – we are coming).
    [Show full text]