Cyber-Spies For Hire

Reports of malicious and targeted cyber-attacks are becoming increasingly common around the world. In early February, for example, Australia’s security agencies revealed they were investigating an attempt to hack on the country’s parliament and hadn’t ruled out another country being behind it. 

As more complex and potentially damaging attacks into critical national infrastructure systems are discovered, calls are growing louder for international rules to govern this emerging battlefront. 

Efforts towards cyber-arms control have predominantly centred around a model where the “arms” relates to weaponised code – specific hacking tools or the software vulnerabilities that enable them.  Attempts have been made to curtail the proliferation and spread of what are called “zero-day exploits”, the flaws in a program’s code that allow malicious attackers to interfere with the systems that run them. 

A recent Reuters expose of the operations of a clandestine wing of the United Arab Emirates’ (UAE) National Electronic Security Authority (NESA) exposed another component of offensive cyber-attacks, expertise. This issue sparked further international attention when the FBI announced charges in mid-February against Monica Witt, a former US Air Force analyst, accused of espionage and defecting to Iran.

Cyber Mercenaries
The Reuters investigation detailed how some former employees of the US National Security Agency (NSA), operatives with expertise in digital penetration techniques, online intelligence gathering and offensive cyber-operations, were contracted via a Maryland-based firm to work for the UAE. 

The investigation makes specific mention of one of the tools, Karma, that these contractors employed on behalf of the UAE against specific targets. 

This hacking tool allowed its operators to gain uninvited and remote access to a target’s Apple phone through an unspecified flaw which is now believed to have been fixed by Apple. Reuters reported that the targets of these attacks ranged from human rights activists, to American journalists.

The article raised questions about whether these contractors might have provided their NESA employees with advanced cyber-capabilities developed by their former employer, the NSA. But the subtext of the Reuters investigation is that the expertise of these former intelligence officers is just as attractive to their new employers as any tools they might bring with them. In a separate article, specifically examining Karma, Reuters alleges that it was purchased by the Emirati government from a vendor outside of the country. 

In effect, the UAE had hired a team of out-of-work specialist engineers who couldn’t bring the tools they had used in the US with them, so it then bought them the tools they needed to get the job done. This suggests that there are two components required to kit out any state or group with advanced cyber-capability: the tools and the expertise. 
Tools and Expertise

Global efforts are underway to govern the tools used in cyber-attacks, such as the Global Commission on the Stability of Cyberspace, which introduced a series of international norms about the use of cyberspace to promote the stability of the internet and good practice of everyone involved. 

Other efforts have been on the legislative level, such as specific additions to the Wassenaar Arrangement, an export control arrangement that seeks to curtail the spread of civilian technologies that can be put to militarised use. But the expertise of cyber operatives has so far seen limited attention. In the scenario described by Reuters, NESA and its Project Raven could not have operated without either the tools or the expertise. The tool itself, Karma, and the expertise and experience required to use it and train others to do so, both require significant investment. 

The dangers of state investment in the collecting of software flaws and the creation of powerful tools which then exploit these previously unknown weaknesses was painfully demonstrated through the leaking of the vulnerability stockpiled by the NSA, EternalBlue. 

This was the backbone of the WannaCry attack which made international headlines in 2018 through its impact on the British NHS and other international business and government services.

But concerns should be growing about the capability that states invest in the skill sets of the people who discover and then weaponise flaws in the software which power our increasingly interconnected and internet-dependent lives. 

Governments across the world are gearing up for what they see as the next domain of warfare by trying to recruit existing talent to government projects or through training the next generation of cyber-security experts who they hope will give them an advantage. 

There’s a risk that in global efforts which focus on states’ use of cyber tools and exploitation of vulnerabilities in programming code, there is a legislative and governance gap developing. 

This could see states invest in training the cyber-spies, saboteurs or soldiers of the future only to find those critical skills and the capability they provide being snapped up by the highest bidder.

The Conversation

You Might Also Read: 

Spyware Proliferates To 45 Countries:

 

« Top Six Cyber Secure Countries
Criminal Groups Offer Big Salaries For Cyber Skills »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Celestya

Celestya

Celestya is dedicated to providing the most advanced and cost effective systems for human behavior education on cybersecurity awareness training.

Compumatica

Compumatica

Compumatica is a leading European ICT security manufacturer for cybersecurity and encryption products. Solutions include network security, SCADA/ICS security, Mobile/BYOD and email encryption.

GE Digital

GE Digital

GE Digital is a leading software company for the Industrial Internet. Products include Industrial Cyber Security for Operational Technology (OT).

CSI

CSI

CSI is a Managed Service Provider (MSP) delivering Hybrid Multi-Cloud, Data Protection, and Cyber Security solutions to highly regulated industries.

DynaRisk

DynaRisk

DynaRisk helps companies protect their staff, clients and supply chain from cyber threats by enabling people to take action for themselves.

Synelixis Solutions

Synelixis Solutions

Synelixis Solutions is a high-tech company founded to provide complete telecommunications, networking, security, control and automation solutions.

Cloudsine

Cloudsine

Cloudsine (formerly Banff Cyber Technologies) is a cloud technology company specializing in cloud adoption, security and innovation.

Measured Insurance

Measured Insurance

Measured Insurance are bridging the gap between technology and Insurance using AI-Powered analytics that track clients’ exposure in real time to create smarter insurance products.

Stratia Cyber

Stratia Cyber

Stratia Cyber is an independent, technology agnostic company providing high quality, pragmatic cyber security consultancy and expertise.

Marlink

Marlink

Marlink smartly integrates hybrid, future-ready network solutions so you can benefit from the best available connectivity and IT to accelerate your digitalisation and empower your remote operations.

Arelion

Arelion

Arelion is a leading light in global connectivity and we've been keeping the world connected for nearly three decades.

NexusTek

NexusTek

NexusTek is a managed IT services provider with a comprehensive portfolio comprised of end-user services, cloud, infrastructure, cyber security, and IT consulting.

Sayers

Sayers

Sayers is best known for its ability to solve business challenges with IT solutions. Our areas of expertise include cloud, storage, virtualization, security, mobility and networking.

Nexer

Nexer

Nexer is a modern tech company with expertise in strategy, technology and communication with a strong vision.

MyTurn Career LLC

MyTurn Career LLC

Looking for a rewarding career in cybersecurity? Explore a wide range of cybersecurity jobs and opportunities in this rapidly evolving field.

IDCARE

IDCARE

IDCARE is Australia and New Zealand’s national identity & cyber support service. Our service is the only one of its type in the world.