Anonymous’ Cyberwar With ISIS And It’s Unintended Consequences.

In the aftermath of the Paris Terrorist Attacks, there is a new target on ISIS: A Declaration of Cyber War. The hacker activist group, Anonymous is using social media to retaliate against ISIS for their reign of terror in the city of light.

In a new YouTube video Anonymous vowed to take out ISIL: “We are tracking down members of the terrorist group responsible for these attacks we will not give up we will not forgive and we’ll do all that is necessary to end their actions.”

Efforts to take down the organization's Web sites and expose its supporters could interfere with carefully planned law enforcement operations. Anonymous’s cyber war with ISIS may have unintended security consequences.

As French police scoured Paris and surrounding areas in search of those responsible for Friday 13th terrorist attacks on the French capital, a group of cyber activists took aim at the Islamic State’s online presence. The computer-hacker federation known as Anonymous claims to have disabled at least 5,500 pro-ISIS Twitter accounts and exposed thousands of the terror group’s supporters who use the social media site.

Anonymous announced its current campaign on November 14, the day after ISIS (the Islamic State in Iraq and Syria) claimed responsibility for murdering at least 129 people and injuring more than 300 in various locations throughout Paris. The hacktivist group released a video that begins with dramatic music and what, appears, to be images of the Paris attacks. Halfway into the video a person wearing Anonymous’s symbolic Guy Fawkes mask announces that the group is tracking down ISIS members and supporters and then proclaims, “We’ll not give up. We will not forgive. And we’ll do all that is necessary to end their actions.”

Law enforcement and cyber counterterrorism experts generally welcome the digital havoc that groups like Anonymous can wreak on terrorist organizations’ online communication and recruiting efforts. That is, as long as these uncoordinated cyber antiterrorism campaigns do not end up scuttling months of undercover investigative police work. 

Anonymous could be the digital equivalent of a renegade cop going to great lengths to catch a bad guy at the expense of ruining a painstakingly organized federal investigation to take down a larger crime ring.

The hacktivist collective does this by exposing its adversaries’ Twitter accounts (and reporting them to the company) or paralyzing opposition Web sites by flooding them with online traffic. The group’s secretive nature gives it a lot of latitude for operating outside the law. 

“This means they can create collateral damage on the Internet without having to answer for it,” says Scott Borg, director and chief economist for The US Cyber Consequences Unit, an independent, nonprofit cybersecurity research institute.

Groups operating outside official law enforcement and intelligence channels can make legitimate communications and business difficult to carry out, or even interfere with the intelligence community's efforts, Borg says. If Anonymous shuts down a terrorist Web site or online forum that government agents have already infiltrated, this could hinder valuable counterterrorism surveillance and data collection. This is especially important because gathering useful information on Islamic State forums is typically difficult. 

The terror group often uses Web-hosting companies unwilling to cooperate with Western governments and regularly switches hosting companies to avoid being shut down. The US has a lot of ways of going after these organizations and can target new communications channels when old ones are blocked, but ISIS’s way of operating in stealth online makes this difficult, Borg adds.

The key to successfully disrupting terrorist organizations online is to shut down their recruiting and propaganda efforts while tapping into the valuable intelligence their forums can provide, according to the executive director of Ghost Security Group, who goes by the name “DigitaShadow” in order to not reveal his true identity. 

His organization formed as a nonprofit counterterrorism network delivering intelligence to US government agencies earlier this year, a few days after terrorists attacked the Parisian paper Charlie Hebdo. They have gained some notoriety in recent months for their role in helping disrupt ISIS’s funding efforts as well as planned attacks in New York City and Tunisia.

Ghost Security Group’s 15 members in the US, Europe and the Middle East have taken down 149 terrorism-related propaganda sites so far, DigitaShadow says. “We leave Islamist-related forum or communication platforms intact for intelligence reasons, waiting for participants to make a mistake,” he adds. “We shut down any propaganda sites that push out videos or graphic or gory pictures because they don’t have any intelligence value.”

DigitaShadow’s organization had acted as part of Anonymous for a few months after forming but is no longer affiliated with them. “They’ve attacked quite a few forums that had high-value Islamic State militants transmitting propaganda, trying to recruit young people and in some cases addressing weapons-manufacturing and ground movements,” he says. “It’s caused quite a disruption for intelligence.”

Borg contends, however, that Anonymous and the hacker community in general do more good than harm. Given the brutality of ISIS’s attacks, and its successful Internet recruitment efforts, the hacker collective’s latest rally against the terrorist organization is an acceptable risk. 

Anonymous launched a similar campaign against ISIS following its attack on Charlie Hebdo, claiming to disrupt tens of thousands of Twitter accounts connected to the terrorist organization.

Anonymous also claims to be spamming ISIS hashtags with “rickrolls,” messages that appear to be relevant but instead include a link to the music video for the 1987 Rick Astley hit song “Never Gonna Give You Up.” 
The cyber scuffle has not been entirely one-sided though. Anonymous tweeted recently that it had to take down its own site for reporting on Islamic State activity due to a high level of spam, although it is unclear whether the terror group was responsible. 
Ein News:http://http://bit.ly/1RmbtVX
Scientific American: http://bit.ly/1NFKlvj

« Bitwalking: Digital Currency Pays People to Walk
N. Korea Employs Grads for Cyber Warfare »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Sonatype

Sonatype

Sonatype protects the world's enterprise software from security, compliance, licensing risks, while reducing application development and deployment time.

Cross Identity

Cross Identity

Cross Identity (formerly Ilantus Technologies) is a complete IAM solution that is deep, comprehensive, and can be implemented even by non-IT persons.

Mantix4

Mantix4

Mantix4’s M4 Cyber Threat Hunting Platform actively defends against cyber threats.

Seltek Technology Solutions

Seltek Technology Solutions

Seltek provides Digital Forensics, eDiscovery, Cybersecurity Assessments and IT Support services.

Achtwerk

Achtwerk

Achtwerk manufacture the security appliance IRMA for critical infrastructures and networked automation in production plants.

Datec PNG

Datec PNG

Datec is the the largest end-to-end information and communications technology solutions and services provider in Papua New Guinea.

FraudHunt

FraudHunt

FraudHunt protects your website from account fraud, ad fraud, fraud clicks, and malicious bots.

Trusted Objects

Trusted Objects

Trusted Object's mission is to provide state of the art security solutions and services enabling a strong root of trust for the IoT ecosystem.

Anitian

Anitian

The Anitian Compliance Automation platform builds, configures, and monitors cloud environments to accelerate compliance for standards such as FedRAMP, PCI, ISO/GDPR and CJIS.

CloudVector

CloudVector

CloudVector's API Detection & Response platform is the only API Threat Protection solution that goes beyond the gateway to provide Shadow API Prevention and Deep API Risk Monitoring and Remediation.

Future Technology Systems Company (FutureTEC)

Future Technology Systems Company (FutureTEC)

FutureTEC is a leading Information Technology Solutions Provider, delivering world-class Information Security, Information Management, and Business Solutions.

Bright Security

Bright Security

Bright Security is a developer-centric Dynamic Application Security Testing (DAST) solution that helps organizations ship secure applications and APIs quickly and cost-effectively.

BitLyft

BitLyft

BitLyft is a managed detection and response provider that is dedicated to delivering unparalleled protection from cyber attacks for organizations of all sizes.

SphereX Technologies

SphereX Technologies

SphereX is the first on-chain security solution for Web3 applications.

Sec3

Sec3

Sec3 is a security and research firm providing bespoke audits and cutting edge tools to Web3 projects.

Boltonshield

Boltonshield

Boltonshield provide a unique and proactive approach to cyber defence with managed security services, integrated technologies, and a team of security experts, ethical hackers and analysts.