2024 US Presidential Election Cyber Intrusion: Part 3 - Hostile Nation State Actors

Part 3 of a series that will analyze critical cyber security aspects during the countdown  to the 2024 US Presidential Election, beginning with Covert Influence Operations then Nation State Threat Actors, Hactivism and Cybercrime.


The upcoming US Presidential Election is facing a range of cyber security challenges from nations that oppose the democratic foundation of the Western world.

Based on the ever-evolving nature of this cyber threat landscape, the election period will attract a complex theatre of nation state-level cyber activity involving the deployment of intrusive attack vectors, influence campaigns and hybrid threats combing both methods.

Iran

Based on the highly unstable foreign affairs climate between the US and Iran, several Tehran-aligned threat groups will likely seek to compromise the 2024 US Presidential Election.

Firstly, domains have already started to impersonate US media organisations and think tanks demonstrating overlaps with the malicious infrastructure of Mint Sandstorm - a state-level hacker unit that has demonstrated persistent attacks against Western governments and organisations that deal with Iranian sanctions. These infrastructural similarities relate to naming and registration patterns that are likely designed for credential harvesting attacks .

What should be noted, is that Mint Sandstorm have a track record of interfering with the US political arena - the unit attempted to compromise the 2020 US election by targeting email accounts belonging to US presidential campaign staff . This trend has not changed as throughout the past 6-months, Mint Sandstorm has already launched credential phishing attempts against email accounts of individuals linked with President Joe Biden and former President Donald Trump as well as current and former US government officials, including Vice President and Democratic Party forerunner, Kamala Harris . The disclosure of this intelligence was soon followed up by the FBI, Cybersecurity and Infrastructure Security Agency (CISA) and the Office of the Director of National Intelligence (ODNI) releasing a joint statement on August 19th, 2024, attributing the recent cyber-attack aimed towards the campaign of former President Donald Trump to hostile Iranian actors . 

Next up, we have UNC2448, an Iranian state-level cyber force that has an extensive history of exploiting zero-day security flaws to compromise Western pollical establishments. Notable to the US Presidential Election is that individual actors operating within this state hacking group have previously been indicted for launching ransomware attacks against US organisations , as well as exploiting the Log4Shell vulnerability (CVE-2021-44228) to compromise a Federal Civilian Executive Branch (FECB) organization in 2022 .

Finally, CISA also disclosed that the Iranian activity group, tracked as Lemon Sandstorm, targeted US federal agencies in 2020 by exploiting VPN vulnerabilities and installing web shells. The group also targeted the 2020 US election by a US city website to report election results, an incident that was reported by the head of US Cyber Command’s Cyber National Mission Force.

More recently, the FBI disclosed  that these state hackers have continued to operate in the interests of the Iranian government by now collaborating with ransomware gangs to target critical infrastructure providers in the US, by forming alliances with high-profile Russian ransomware actors in exchange for a cut of the ransom payments. This collaboration likely reflects the growing strategic cooperation between the Russian Federation and the Iranian regime, as both states continue to be heavily sanctioned by western governments in response to their involvement with international conflicts and nuclear developments.

As a result, we have assessed that Iranian hackers will likely incorporate the finance sector into these operations with the aggressiveness of these attacks likely to be shaped by the outcome of the upcoming US Presidential Election.

For instance, a Republican Party victory in November will cause Iran to come under increased financial strain, with Donald Trump likely to continue to enforce economic sanctions against Tehran relating to the Joint Comprehensive Plan of Action, which is Iran’s nuclear deal that was signed in 2015.

Russia

A combination of disruptive and influence operations will likely be the foundation of Russia’s cyber targeting of the 2024 US Presidential Election which would reflect its “information confrontation doctrine,” combining reconnaissance and disruptive efforts with follow-up psychological operations.

We have observed the implementation of this three-stage protocol in previous campaigns where Moscow state actors have engaged in data theft from target systems, deployed their notorious wiper malware strains, and followed this by advertising the success of their operations by providing evidence of compromise through social media avenues, such as Telegram.

Below is an overview of the Russian cyber units that will likely target the upcoming election with high capability and hostile intent, both directly and indirectly. All of the cyber groups mentioned will likely ramp up the aggressiveness of their efforts as we get closer to November 5th, in retaliation to the US Department of Justice recently indicting individual hackers that were operating under the direction of Unit 29155 of the Russian General Staff Main Intelligence Directorate (also known as its GRU).  

The first threat is Seashell Blizzard , a high impact Russian military intelligence asset that previously attempted to interfere with the US Presidential Election back in 2016 . Linked with Russia’s GRU military intelligence branch, we have assessed that the threat posed by the unit has recently been heightened due to likely collaborated efforts with the recently created “Cyber Army of Russia Reborn” hacktivist persona, allowing for a hybrid approach of disruptive efforts with agile espionage.

Secondly, the Russian State-backed Forret Blizzard, will also likely target the election, with the primary objective of the threat unit to collect intelligence against global targets in support of Russian foreign policy initiatives. This Russian military intelligence activity group has previously engaged in sustained effort to hack into the computer networks of the Democratic Congressional Campaign Committee, the Democratic National Committee, and the presidential campaign, as well as orchestrating a leak campaign as the “DC Leaks” persona back in 2016 .

And finally, Midnight Blizzard , likely has hostile intent to interfere with the 2024 election, with the activity group previously compromising the Democratic National Committee (DNC) ahead of the 2016 US election. The activity group’s campaigns against this year’s US election will likely spillover into the US technology sectors, with the group previously compromising US technology companies and IT service providers to facilitate third party compromises of government and policy organisations. 

China

Chinese offensive efforts leading up to the election will likely involve Beijing state actors using a suite of cyber weapons to scan the country’s networks for security vulnerabilities, to access target systems and extract sensitive dataOperations will involve a combination of espionage and influence campaigns to gather intelligence on the dynamics of US politics and to sow discord amongst US citizens.

The PRC will also likely launch aggressive social media disinformation operations against US businesses and government officials to shape the global information domain in favour of Chinese interests and to portray the US electoral system as chaotic and dysfunctional.

Highlighted below is an overview of the Chinese nation-state hackers that will likely focus on the upcoming US Presidential election:

Firstly, Brass Typhoon poses a significant threat to both the Democratic and Republican parties. This is based on the unit’s track record of conducting widespread vulnerability exploitation that compromised US government entities ahead of the 2020  and 2022  US election proceedings. High ranking US election officials should be particularly vigilant to Brass Typhoon operations as the group is known to create fake profiles to engage in dialogue with high-profile entities to harvest information such as personal or work email addresses. 

Violet Typhoon will also likely be a factor, with the Chinese state group having a track record of engaging in nation-state activity by focussing on former government personnel and think tanks in the US. Notable to the 2024 US Presidential Election is that the hacker unit has demonstrated hostile intent to compromise the US democratic process by conducting phishing operations against US journalists focusing on politics and national security matters. The cyber unit also targeted President Biden’s campaign staff during the 2020 US election process , an event that was followed up in a March 2024 indictment, where the US Department of Justice disclosed that election campaign staff from both the Democratic and Republican parties were targeted throughout this period.

TO BE CONTINUED

Craig Watt is a Threat Intelligence Consultant at Quorum Cyber specializing in strategic and geopolitical intelligence.

Image: gguy44

You Might Also Read: 

2024 US Presidential Election: Hostile Nation State Actors - Part 2:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

 

 

 

« 2024 US Presidential Election Cyber Intrusion: Part 2 - Covert Influence Operations
A Landmark Ransom Attack On Healthcare »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Vaddy

Vaddy

Vaddy provide an automatic web vulnerability scanner for DevOps that performs robust security checks to ensure that web app code is secure.

Cybercrowd

Cybercrowd

Cybercrowd is a cyber security specialist offering technical services, cyber security assessments, guidance and security thought leadership.

CyberOne

CyberOne

CyberOne (formerly Comtact) offer a full stack cybersecurity service to ensure our customers understand the cyber maturity of their organisation.

Nouveau

Nouveau

Nouveau Solutions is a specialist IT managed services company with a strategic focus on delivering cloud, infrastructure, compliance, network and security solutions.

National Cyber Summit (NCS)

National Cyber Summit (NCS)

The National Cyber Summit is the preeminent event for cyber training, education and workforce development aimed at protecting our nation's infrastructure from the ever-evolving cyber threat.

Intelligent Business Solutions Cyprus (IBSCY)

Intelligent Business Solutions Cyprus (IBSCY)

IBSCY Ltd is a leading provider of total IT solutions and services in Cyprus specializing in the areas of cloud services and applications, systems integration, IT infrastructure and security.

Datplan

Datplan

Datplan offers a software solution that gives an overview of 8 key cyber risk areas, their threats, and risk management steps.

SHe CISO Exec

SHe CISO Exec

SHe CISO Exec is a sustainable global training and mentoring platform in information security and leadership.

Sunartek Labs

Sunartek Labs

Sunartek are equipped with expert resources and advanced technology to identify cyber threats and prevent any breach, bypassing the security network of your organization.

ST Engineering Antycip

ST Engineering Antycip

ST Engineering Antycip (formerly Antycip Simulation) is Europe’s leading provider of professional grade COTS simulation software, projection & display systems, and related engineering services.

ReasonLabs

ReasonLabs

ReasonLabs have created a next-generation anti-virus that is enterprise grade, yet accessible to any personal device around the world.

Adversa AI

Adversa AI

Adversa's mission is to build trust in AI and protect AI from cyber threats, privacy issues, and safety incidents.

LegalByte

LegalByte

LegalByte is a leading provider of comprehensive legal and forensic services dedicated to addressing the complex challenges of the digital age.

Cybit

Cybit

Cybit is the one-stop-shop for digital transformation that scales in line with your growth.

SydeLabs

SydeLabs

At SydeLabs, our mission is to ensure the comprehensive security of your AI systems.

Nexsan

Nexsan

Nexsan offers versatile and robust data storage solutions tailored to adapt seamlessly across a diverse range of sectors, ensuring reliable performance for critical data management.