How Cyber Propaganda Influenced Politics in 2016

Throughout history, politically motivated threat actors have been interested in changing the public opinion to reach their goals.In recent years the popularity of the Internet gave these threat actors new tools. Not only do they make use of social media to spin the news, spread rumors and fake news, but they also actively hack into political organisations.

Political organisations are a relatively easy target for threat actors who want to cause harm. By their very nature, political parties must be able to communicate openly with their members, the press and the general public.

A political party is particularly vulnerable to spying campaigns and cyber-attacks during a hectic election period, where security measures might be considered a burden to daily operations. Recent events in 2016 have demonstrated how important security is for political organizations.

In 2016, we saw at least eight different high-profile attack campaigns against political organisations in countries like the United States, Germany, Ukraine, Turkey, and Montenegro. These campaigns were not meant for espionage alone, but for active interference with political processes and to influence public opinion.

WikiLeaks and mainstream media were used to get the general public to learn about alleged scandals that may or may not have happened in the political organizations that were targeted. Stolen data was published, but the authenticity of the data was usually not confirmed. This leaves room for threat actors to alter the stolen data to their own benefit and present it as if it was real and unaltered.

By publishing carefully selected pieces of unaltered stolen data, threat actors can better influence public opinion towards a direction that is favorable to their interests.

In 2016 the Democratic Party in the US was allegedly hacked by Pawn Storm, a threat actor group known for targeting people and organizations that might be perceived as a threat to Russia.

For example, between 2014 and 2016 Pawn Storm set up dedicated campaigns against the armed forces of at least a dozen countries. Pawn Storm’s activities show that foreign and domestic espionage and influence on geopolitics are the group’s main motives, and not financial gain.

It is a fact that e-mails were stolen from members of the Democratic Party. These e-mails were leaked by WikiLeaks and dcleaks[.]com, a website that’s likely controlled by the Pawn Storm actors.

We can confirm that in March and April of 2016, Pawn Storm launched an aggressive credential phishing campaign against corporate and free webmail accounts of various high ranking members of the Democratic Party in the US.

During the campaign, dozens of politicians, Democratic National Committee (DNC) staff, speech writers, data analysts, former staff of the Obama campaign, staff of the Hillary Clinton campaign, and even corporate sponsors were targeted multiple times.

We know this because we have been tracking credential phishing attacks by Pawn Storm since 2014. We were able to obtain a substantial amount of click statistics on tens of thousands of individual phishing URLs, and published an early analysis of this data in 2015.

In June 2016, we discovered a serious compromise of the website of the DCCC (Democratic Congressional Campaign Committee) that showed fingerprints of the Pawn Storm actor group. We believe we were one of the first ones to discover the compromise, and we disclosed it responsibly to US authorities immediately. Within hours after we reported the issue, the compromise was addressed and the DCCC website got cleaned up.

There have been instances when Pawn Storm uses mainstream media to get the general public to know about their brazen attacks. It has been confirmed by several mainstream media outlets that they were offered exclusive access to data that was stolen by Pawn Storm.

This shows that apart from WikiLeaks, mainstream media are also attempted to be used by threat actors who want to influence public opinion and cause harm to political organisations.

The US is not the only country where political organisations got targeted in 2016.  In fact, the problem is much more widespread. In April and May 2016 German Chancellor Angela Merkel’s political party, the Christian Democratic Union (CDU), was targeted by Pawn Storm.

We don’t know whether the attacks were successful, but they were confirmed by German authorities. No information has been leaked yet, but in other cases, Pawn Storm waited more than a year before they started to publish stolen data.

Early February 2016 Pawn Storm targeted the Turkish parliament. Other researchers have noted that a particular threat actor targeted political parties between March and August 2016, including the Die Freiheit party in Germany, the AK party in Turkey, and two other parties in Ukraine.

We do not know whether these attacks were carried out by Pawn Storm as well. However, one of the e-mail addresses that was used in these attacks was also targeted and likely compromised by Pawn Storm just a few days before the campaign against the Turkish AK party started. Regardless of who the threat actor was in these cases, it is clear that several political parties outside the US were targeted.

Attacks against political parties are not likely to stop any time soon.

In October 2016, a special credential phishing attack was launched against the parliament of Montenegro, most likely by Pawn Storm once again.

In the spring of 2017, several European countries are scheduled to hold elections, including Bulgaria, France, Germany, the Netherlands, and Norway. Political organisations and other high profile organizations are urged to take measures to avoid becoming the next victim of foreign threat actors who want to influence elections and public opinion.

Trend Micro:       Hackers Target France’s Presidential Election:     

German Spy Chief Fears Russian Interference In 2017 Elections:

 

 

« US Army Wants To 3D-Print Mini-Drones
Nissan Self-Drive Trial Begins In London »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Huntsman Security

Huntsman Security

Huntsman Security provides technology to enable real-time security monitoring and immediate visibility of advanced threats and compliance issues.

TrustArc

TrustArc

TrustArc provide privacy compliance and risk management with integrated technology, consulting and TRUSTe certification solutions – addressing all phases of privacy program management.

GreatHorn

GreatHorn

GreatHorn offers the only cloud-native security platform that stops targeted social engineering and phishing attacks on communication tools like O365, G Suite, and Slack.

PRODAFT

PRODAFT

PRODAFT, Proactive Defense Against Future Threats, is a cyber security and cyber intelligence company providing solutions to commercial customers and government institutions.

Ellipsis Technologies

Ellipsis Technologies

Ellipsis Technologies is a diversified technology company that develops innovative security software for websites and online applications.

LSoft Technologies

LSoft Technologies

LSoft Technologies is a leader in data recovery software technologies.

ICS Cyber Security Conference

ICS Cyber Security Conference

SecurityWeek’s Industrial Control Systems (ICS) Cyber Security Conference is the largest and longest-running event series focused on industrial cybersecurity.

WiSecure Technologies

WiSecure Technologies

WiSecure Technologies aims to develop cryptographic products meeting requirements in the new economic era.

Allthenticate

Allthenticate

Allthenticate Single Device Authentication (SDA), enables seamless authentication in both the physical and digital words while unifying management in one easy-to-use interface.

CyberMDX

CyberMDX

CyberMDX delivers proactive security built for hospital devices. 360° visibility, insight, and protection for all connected hospital technologies.

FREE eBook: Practical Guide To Optimizing Your Cloud Deployments

FREE eBook: Practical Guide To Optimizing Your Cloud Deployments

AWS Marketplace eBook: Optimizing your cloud deployments to accelerate cloud activities, reduce costs, and improve customer experience.

Mission Critical Partners (MCP)

Mission Critical Partners (MCP)

Mission Critical Partners is committed to delivering innovative solutions that help our clients enhance and evolve their critical-communications systems and operations.

Arista Middle East

Arista Middle East

Arista Middle East is part of Global Arista Technologies specializing in OT Cybersecurity.

BCX

BCX

BCX, a subsidiary within Telkom Group, is one of Africa’s largest systems integrator and digital transformation partners for enterprises and public sector organisations.

Index Engines

Index Engines

Index Engines is the world’s leading AI-powered analytics engine to detect data corruption due to ransomware.

Viatel Technology Group

Viatel Technology Group

Viatel Technology Group is a complete digital services provider. We have over 26 years’ experience delivering fully managed security, networking, cloud and communications services.