How To Counter Covert Action In The Digital Age

The case of Iran shows that countering covert action in the digital age requires transparency, persistence and international cooperation. But also that it is unrealistic to expect states to stop completely.

Governments, military forces and non-state groups use covert action to understand – and influence – what their adversaries and allies are doing. The digital age has created many new opportunities for covert action, but has also made traditional strategies much harder to conceal. Digital capitalism’s thirst for data generates detailed online footprints, whether working, shopping or spying.

In this environment, three key strategies for covert action have evolved. The first is implausible deniability, such as Russia’s ‘little green men’ in Ukraine after 2014 – a course of action forced, in part, by Russian soldiers using geolocated photos  and apps on the front line. The second is to use distraction and disinformation, hiding embarrassing or sensitive facts in a forest of false counterclaims. The third is to attempt to shield certain audiences from leaks, imposing censorship to limit domestic impact from international scandal, a strategy more often used by states with authoritarian tendencies.

Countering these changing strategies requires transparency, persistence and international cooperation, as evidenced by the case of Iran.

Iran & Covert Action

Iran is a focal point for covert action in world politics, from attacks on dissidents in the diaspora to Israeli assassinations of nuclear scientists in the heart of Iran. Iran’s evasion of US and other sanctions, including procurement of nuclear-related technologies, operates through a complex network of front companies. While the outbreak of nationwide protests in Iran last year, and their violent repression, rightfully diverted attention away from its nuclear programme, Iran’s uranium enrichment has continued to increase.

Iran’s strategy of implausible deniability has recently run up against mounting digital evidence, presenting a sharp dilemma for its leaders seeking to repair regional relations and dampen popular revolt.

Iran’s use of its state airline and small boats to supply drones for Russia’s war in Ukraine, as well as its ongoing support for actors in several destabilizing regional conflicts, has brought the issue of covert action into the foreground once again. Iran regularly deploys all three strategies above, from cyber-enabled influence operations to complex Internet restrictions. But it is Iran’s strategy of implausible deniability that has recently run up against mounting digital evidence, presenting a sharp dilemma for its leaders seeking to repair regional relations and dampen popular revolt.

Seized Missiles & Digital Clues

In early 2022, a UK Royal Navy frigate stopped two speedboats in the Gulf of Oman, seizing parts for cruise and surface-to-air missiles. Similar events also took place in 2019 and 2020, and most recently in February this year.

According to a UN report, Iran rejected any links between ‘the authorities of the Islamic Republic of Iran and those vessels and equipment therein’. However, the UK and other states have tracked Iranian missile construction for years, using public photos of Iranian weapons displays, as well as secret intelligence sources and technical analysis, to understand Iran’s various missile programmes, types, and ranges. This analysis uses key engineering features – such as the smoothness of finishes – to differentiate Iranian homemade parts from foreign versions.

States expect covert operations to be outed and make plans for how to best take advantage of this moment.

In this case, the UK had a very concrete piece of evidence tying the Iranian state to the smuggled weapons. The missile components were stored alongside a commercial remote-controlled quadcopter made in China, equipped with a high-resolution camera. UK analysts recovered the internal digital memory of the quadcopter controllers and found records of likely test flights at locations owned by the Iranian Islamic Revolutionary Guards Corps (IRGC) in Tehran. The colocation of this quadcopter – including IRGC location data – with missile parts in the same speedboat adds significant weight to the assessment that these were destined for Iran’s Houthi partners in Yemen.

While the users of the quadcopter recognized the potential for digital data to betray their covert action and had removed external memory cards for the controllers, the default for data collection in digital devices left a crucial clue.

Defeating Deception

The parts recovered by the Royal Navy also included detailed efforts at deception, a core part of covert action. Previous Iranian surface-to-air missiles had used engines manufactured by a Netherlands-based company. The recovered parts also had this company’s markings but included spelling mistakes that strongly suggest they are in fact Iranian replicas.

In cyber operations, Iranian actors have been uncovered through the discovery of code written in Farsi deep within malware used to target organizations across the Gulf states. However, such inferences must be taken with care as things are not always what they seem. Cyber espionage operations targeting Israel, also using Farsi, were initially thought to be Iranian in origin, until further research found technical links to a Chinese group.

But the secrecy of covert action is not absolute: states expect covert operations to be outed and make plans for how to best take advantage of this moment. Deception needs only to misdirect a defender or investigator long enough to achieve the desired aim. The successive stops of speedboats in the Gulf, the tricky attribution of cyber operations, and the ever-growing list of sanctioned Iranian entities, all exhibit the cat-and-mouse dynamic characteristic of covert action, albeit at a digitally accelerated pace. Ironically, coverage of Iranian covert action is not all bad: it maintains Iran’s reputation as an influential – if destabilizing – player in the region, therefore preserving a key rationale for international engagement.

Countering Covert Action In The Digital Age

The case of Iran helps identify ways to counter each of the three covert action strategies identified above.

First, counter implausible deniability by openly calling out covert action, with as much transparency as intelligence sources permit. The UK interdictions and UN panel of expert reports above are good examples of this practice. While narratives of attribution will always be contested, especially in an online world with an overload of misinformation and disinformation, the incremental weight of such reporting should not be underestimated.

Coverage of Iranian covert action is not all bad: it maintains Iran’s reputation as an influential – if destabilizing – player in the region.

Second, counter distraction and disinformation through international cooperation. The global priority of the Iranian nuclear file, and increasing awareness of its support to non-state armed groups, is the result of years of sustained exposure across different international forums. Although Iranian nuclear negotiations appear to be on indefinite pause at a multilateral level, creative and regional solutions are still possible.

Third, counter authoritarian censorship through persistent support for freedom of expression online, especially civil society. The irony of the recent China-brokered restoration of diplomatic relations between Iran and Saudi Arabia is that all three states have harsh attitudes to political dissidence online. Even if Iran and Saudi Arabia can now be franker about bilateral concerns – from alleged support for hostile news organizations to providing weapons to Yemen – an open debate on these issues for their citizens is not possible.

But although it is possible to counter covert action, it is not realistic to expect states to stop altogether. In fact, Iran’s actions seem to suggest that greater the pressure from the international system, the more covert action becomes cemented into the political priorities and practices of a state.

Dr James Shires is Senior Research Fellow, International Security Programme At Chatham House

You Might Also Read:

Selling Digital Insecurity:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Lawyer Admits To Using ChatGPT 
Take Practical Measures To Avoid An Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

tietoEVRY

tietoEVRY

TietoEVRY creates digital advantage for businesses and society. We are a leading digital services and software company with local presence and global capabilities.

Cyberwrite

Cyberwrite

Cyberwrite was founded to provide underwriters around the world a unique and innovative Cyber Underwriting platform.

Protiviti

Protiviti

Protiviti consulting solutions span critical business problems in technology, business process, analytics, risk, compliance, transactions and internal audit.

exceet Secure Solutions

exceet Secure Solutions

exceet Secure Solutions is your experienced specialist for Internet of Things (IoT), Heath Telematics, electronic signatures and timestamps and IT security.

miniOrange

miniOrange

miniOrange is a cloud and on-premise based identity and access management (IAM) solution provider.

Cybersecurity Professionals

Cybersecurity Professionals

Search vacancies from top cyber security jobs worldwide on CyberSecurity Professionals. View IT security jobs or upload your CV to be seen by recruiters from industry leading firms.

Go Grow

Go Grow

Go Grow is a business oriented accelerator program at Copenhagen School of Entrepreneurship. Targeted technologies include IoT, AI and Cybersecurity.

Mphasis

Mphasis

Mphasis is a leading applied technology services company applying next-generation technology to help enterprises transform businesses globally.

3Lines Venture Capital

3Lines Venture Capital

3Lines Venture Capital invests in exceptional founders and startups working on broad disruptive themes of Future of Work, AI enabled enterprises, and Industry 4.0.

Fusion Risk Management

Fusion Risk Management

Fusion Risk Management focuses on operational resilience encompassing business continuity, risk management, IT risk, and crisis and incident management.

IN4 Group

IN4 Group

IN4 Group is a skills, innovation and start-up services provider that specialises in supporting businesses with the training, communities, networks and advice they need to scale.

CyberScotland

CyberScotland

The CyberScotland Partnership is a collaboration of key strategic stakeholders, brought together to focus efforts on improving cyber resilience across Scotland in a coordinated and coherent way.

LoughTec

LoughTec

LoughTec secure, manage and connect IT infrastructure for businesses and organisations throughout the UK and Republic of Ireland.

Profian

Profian

Profian’s hardware-based solutions maintain your data's confidentiality and integrity in use, providing true confidential computing to meet regulatory and audit requirements.

SecAI

SecAI

SecAI is an innovative threat intelligence-driven, and AI-powered vendor aiming at cyber threat detection and response.

Cloud Native Computing Foundation (CNCF)

Cloud Native Computing Foundation (CNCF)

CNCF seeks to drive adoption of cloud native technologies by fostering and sustaining an ecosystem of open source, vendor-neutral projects.