How To Counter Covert Action In The Digital Age

The case of Iran shows that countering covert action in the digital age requires transparency, persistence and international cooperation. But also that it is unrealistic to expect states to stop completely.

Governments, military forces and non-state groups use covert action to understand – and influence – what their adversaries and allies are doing. The digital age has created many new opportunities for covert action, but has also made traditional strategies much harder to conceal. Digital capitalism’s thirst for data generates detailed online footprints, whether working, shopping or spying.

In this environment, three key strategies for covert action have evolved. The first is implausible deniability, such as Russia’s ‘little green men’ in Ukraine after 2014 – a course of action forced, in part, by Russian soldiers using geolocated photos  and apps on the front line. The second is to use distraction and disinformation, hiding embarrassing or sensitive facts in a forest of false counterclaims. The third is to attempt to shield certain audiences from leaks, imposing censorship to limit domestic impact from international scandal, a strategy more often used by states with authoritarian tendencies.

Countering these changing strategies requires transparency, persistence and international cooperation, as evidenced by the case of Iran.

Iran & Covert Action

Iran is a focal point for covert action in world politics, from attacks on dissidents in the diaspora to Israeli assassinations of nuclear scientists in the heart of Iran. Iran’s evasion of US and other sanctions, including procurement of nuclear-related technologies, operates through a complex network of front companies. While the outbreak of nationwide protests in Iran last year, and their violent repression, rightfully diverted attention away from its nuclear programme, Iran’s uranium enrichment has continued to increase.

Iran’s strategy of implausible deniability has recently run up against mounting digital evidence, presenting a sharp dilemma for its leaders seeking to repair regional relations and dampen popular revolt.

Iran’s use of its state airline and small boats to supply drones for Russia’s war in Ukraine, as well as its ongoing support for actors in several destabilizing regional conflicts, has brought the issue of covert action into the foreground once again. Iran regularly deploys all three strategies above, from cyber-enabled influence operations to complex Internet restrictions. But it is Iran’s strategy of implausible deniability that has recently run up against mounting digital evidence, presenting a sharp dilemma for its leaders seeking to repair regional relations and dampen popular revolt.

Seized Missiles & Digital Clues

In early 2022, a UK Royal Navy frigate stopped two speedboats in the Gulf of Oman, seizing parts for cruise and surface-to-air missiles. Similar events also took place in 2019 and 2020, and most recently in February this year.

According to a UN report, Iran rejected any links between ‘the authorities of the Islamic Republic of Iran and those vessels and equipment therein’. However, the UK and other states have tracked Iranian missile construction for years, using public photos of Iranian weapons displays, as well as secret intelligence sources and technical analysis, to understand Iran’s various missile programmes, types, and ranges. This analysis uses key engineering features – such as the smoothness of finishes – to differentiate Iranian homemade parts from foreign versions.

States expect covert operations to be outed and make plans for how to best take advantage of this moment.

In this case, the UK had a very concrete piece of evidence tying the Iranian state to the smuggled weapons. The missile components were stored alongside a commercial remote-controlled quadcopter made in China, equipped with a high-resolution camera. UK analysts recovered the internal digital memory of the quadcopter controllers and found records of likely test flights at locations owned by the Iranian Islamic Revolutionary Guards Corps (IRGC) in Tehran. The colocation of this quadcopter – including IRGC location data – with missile parts in the same speedboat adds significant weight to the assessment that these were destined for Iran’s Houthi partners in Yemen.

While the users of the quadcopter recognized the potential for digital data to betray their covert action and had removed external memory cards for the controllers, the default for data collection in digital devices left a crucial clue.

Defeating Deception

The parts recovered by the Royal Navy also included detailed efforts at deception, a core part of covert action. Previous Iranian surface-to-air missiles had used engines manufactured by a Netherlands-based company. The recovered parts also had this company’s markings but included spelling mistakes that strongly suggest they are in fact Iranian replicas.

In cyber operations, Iranian actors have been uncovered through the discovery of code written in Farsi deep within malware used to target organizations across the Gulf states. However, such inferences must be taken with care as things are not always what they seem. Cyber espionage operations targeting Israel, also using Farsi, were initially thought to be Iranian in origin, until further research found technical links to a Chinese group.

But the secrecy of covert action is not absolute: states expect covert operations to be outed and make plans for how to best take advantage of this moment. Deception needs only to misdirect a defender or investigator long enough to achieve the desired aim. The successive stops of speedboats in the Gulf, the tricky attribution of cyber operations, and the ever-growing list of sanctioned Iranian entities, all exhibit the cat-and-mouse dynamic characteristic of covert action, albeit at a digitally accelerated pace. Ironically, coverage of Iranian covert action is not all bad: it maintains Iran’s reputation as an influential – if destabilizing – player in the region, therefore preserving a key rationale for international engagement.

Countering Covert Action In The Digital Age

The case of Iran helps identify ways to counter each of the three covert action strategies identified above.

First, counter implausible deniability by openly calling out covert action, with as much transparency as intelligence sources permit. The UK interdictions and UN panel of expert reports above are good examples of this practice. While narratives of attribution will always be contested, especially in an online world with an overload of misinformation and disinformation, the incremental weight of such reporting should not be underestimated.

Coverage of Iranian covert action is not all bad: it maintains Iran’s reputation as an influential – if destabilizing – player in the region.

Second, counter distraction and disinformation through international cooperation. The global priority of the Iranian nuclear file, and increasing awareness of its support to non-state armed groups, is the result of years of sustained exposure across different international forums. Although Iranian nuclear negotiations appear to be on indefinite pause at a multilateral level, creative and regional solutions are still possible.

Third, counter authoritarian censorship through persistent support for freedom of expression online, especially civil society. The irony of the recent China-brokered restoration of diplomatic relations between Iran and Saudi Arabia is that all three states have harsh attitudes to political dissidence online. Even if Iran and Saudi Arabia can now be franker about bilateral concerns – from alleged support for hostile news organizations to providing weapons to Yemen – an open debate on these issues for their citizens is not possible.

But although it is possible to counter covert action, it is not realistic to expect states to stop altogether. In fact, Iran’s actions seem to suggest that greater the pressure from the international system, the more covert action becomes cemented into the political priorities and practices of a state.

Dr James Shires is Senior Research Fellow, International Security Programme At Chatham House

You Might Also Read:

Selling Digital Insecurity:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Lawyer Admits To Using ChatGPT 
Take Practical Measures To Avoid An Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Trust Guard

Trust Guard

Trust Guard services provide complete security for your website.

European Network for Cyber Security (ENCS)

European Network for Cyber Security (ENCS)

ENCS’s core focus is around educating and solving cyber security challenges in the development and operation of energy grids across Europe.

Egis Technology

Egis Technology

Egis specializes in the IC design, research and development, and the testing and sales of capacitive fingerprint sensor.

e2e-assure

e2e-assure

e2e Protective Monitoring and Security Operations Centre (SOC) Service is a complete cyber defence service to protect your critical assets from cyber attacks and GDPR breaches.

Hexatrust

Hexatrust

The HEXATRUST club was founded by a group of French SMEs that are complementary players with expertise in information security systems, cybersecurity, cloud confidence and digital trust.

Abion

Abion

At Abion (formerly BRANDIT), we empower your business by providing comprehensive brand protection and web security services.

JupiterOne

JupiterOne

JupiterOne is the security product that is changing how organizations manage and secure their software defined assets.

Cyber Ireland

Cyber Ireland

Cyber Ireland brings together Industry, Academia and Government to represent the needs of the Cyber Security Ecosystem in Ireland.

Cyber Defence Solutions (CDS)

Cyber Defence Solutions (CDS)

Cyber Defence Solutions is a cyber and privacy Consultancy with extensive experience in the development and implementation of cyber and data security solutions to your assets.

UncommonX

UncommonX

UncommonX offers enterprise-class cybersecurity protection for mid-size organizations by combining adaptive threat and intelligence software with 24/7 industry experts.

Canonic Security

Canonic Security

Canonic streamlines app review, continuously monitors apps, and reduces the risks involved in third-party access to your data.

Guidepost Solutions

Guidepost Solutions

Guidepost Solutions are a diverse, global team of investigators, experienced security and technology consultants, and compliance and monitoring experts.

Toka Group

Toka Group

Toka empowers government agencies with critical and previously out-of-reach digital forensics, force protection and Intelligence capabilities, tackling the fields' most pressing challenges.

First Focus

First Focus

First Focus is a managed service provider for medium-sized organisations.

GitLab

GitLab

GitLab is a complete DevOps platform, delivered as a single application, fundamentally changing the way Development, Security, and Ops teams collaborate and build software.

Bitdefender Voyager Ventures (BVV)

Bitdefender Voyager Ventures (BVV)

Bitdefender Voyager Ventures is an early-stage investment vehicle focused on cybersecurity, data analytics and automation startups.