Russian Cyber Operations: State-led Organised Crime

Russia is emulating approaches used by cyber-criminals as it blurs the line between state and non-state activities in cyberspace. 

The recent activities of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation, Russia’s military intelligence, otherwise known by its traditional (if slightly inaccurate) acronym of the GRU, on the territories of the UK and other European countries are by now well documented. 

However, less media and public attention is paid to the GRU’s hostile cyber activities, despite the fact that last month, the UK and its allies directly attributed a series of hostile cyber-attacks to the Russian military intelligence service. 

This provides a better understanding of some of the Russian offensive cyber-attack tools, the nature of certain Russian cyber operations and a glimpse into future trends in Russian cyber activity. And here is a brief rundown through some of the tools at Moscow’s disposal.

Bad Rabbit ransomware encrypts hard drives and renders IT inoperable. 
Most public references to Bad Rabbit appeared last month, and they also featured in the UK’s National Cyber Security Centre (NCSC) report, which states that it caused disruption to the underground railways system in the Ukrainian capital of Kiev, as well as to Odessa airport, Russia’s central bank and two Russian media outlets. Here we have a clear example that Russia has the technical capability to disrupt critical national infrastructure.

However, looking beyond the actors behind the malware and disruption caused, the infection methodology is one commonly used by cyber criminals. Trend Micro, a major Japanese cyber security company, claims that Bad Rabbit spreads via fake Adobe Flash updates, tricking users into clicking the malware by falsely alerting the user that their Flash player requires an update. 

Once the victim’s PC is infected and user data is encrypted, Bad Rabbit reboots the system and a classic ransom message is then displayed. Once Bad Rabbit has accessed one computer within a corporate network, it may use the ‘Eternal Romance’ exploit kit to spread to other computers within the network. An exploit kit is a reconnaissance tool that scans for vulnerabilities in systems to work out weak points for attackers to compromise.

Next up is VPNFilter malware, which was attributed to Russian state-sponsored actors in a joint Technical Alert issued by Britain’s NCSC, together with the US’s FBI and the Department for Homeland Security in April. VPNFilter malware permits attackers to perform ‘man-in-the-middle’ attacks by intercepting traffic that passes through vulnerable routers. 

It has infected thousands of home and small business routers, and network devices worldwide. Once initialised, it downloads an image from Photobucket.com, a US image-hosting website, that enables a connection between the compromised device and the attackers’ command-and-control server. This allows for malware to be downloaded onto the compromised device, before further stages increase the malicious capability of the malware.

Using VPNFilter, attackers can intercept web traffic and insert malicious code that enables them to exfiltrate data, collect files, disable access to the compromised router, and skim website log-in credentials. VPNFilter changes HTTPS requests to ordinary HTTP requests, meaning data that is meant to be encrypted is sent insecurely. 

Finally, the malware contains a ‘kill’ command, which if executed, removes all traces of it, before permanently shutting down the compromised router. Despite the complex and multi-functional nature of this malware, hard-resetting the device to its factory state (after backing up data) will remove it.

The attributions from the international community continue, with reference to additional attack tools used by the Russian threat group known as APT28. ¬X-Agent is a remote access tool used by APT28 to enable attackers to extract files and record keystrokes. 

A legitimate piece of software called CompuTrace has been modified by APT28 to provide the GRU with the ability to modify system memory. Meanwhile, X-Tunnel provides APT28 with a secure tunnel to an external command-and-control server from where the attacker can send malicious commands to compromised networks and devices. 

Finally, Zebrocy is a tool that logs keystrokes and uploads files. Zebrocy is delivered primarily via phishing attacks that contain malicious Microsoft Office documents with macros. Again, this is another common delivery mechanism used by both state actors and organised criminals and requires human intervention to grant permission to install the malware.

The NCSC and its international partners state that the GRU is ‘almost certainly responsible’ for multiple successful and attempted cyber-attacks, using the various tools and techniques listed above. 

However, just because there is now near certainty on the identity of the threat actor behind these cyber-attacks, this will not change the steps to defend against them. 

Most risk can be reduced through basic risk-management techniques. For compromised routers, users should install the latest firmware version, change the router’s username and password, and switch-off insecure interfaces (for example, remote web admin access or unused protocols like Telnet). 

Education and awareness can help users to spot fraudulent Adobe Flash updates and malicious links. Finally, the cyber threat intelligence community should work together to share indicators of compromise.

However, although they use widely known infection methods, this is not to say that Russian state attackers do not deploy a suite of malware that enables technically advanced cyber operations. 

The threat intelligence company FireEye published a report on APT28 stating that attack tools developed by this group can be easily modified to assist a specific operation, and within this group there is a philosophy of implementing zero-day attacks. According to FireEye, the group has access to skilled developers who conduct technical counter-analysis.

Now that there has been a step change in approach with the attribution of cyber-attacks, policymakers will wonder how the Russian state’s cyber machine will react. It seems likely that Russian state actors will continue to operate in a way that mirrors the activity of organised cybercrime groups. This creates a plausible narrative that these attacks are not state-led, and the techniques used by organised criminals suit the strategic aims of Russian state actors. 

The GRU has been deploying malware with delivery mechanisms commonly used in cybercrime campaigns, which meant that the recent cyber-attacks were initially perceived to be criminal in nature (rather than state-led). Added to this, Russian organisations have been part of the collateral damage from GRU-led cyber-attacks, making attribution even more complicated.

The GRU may seek to outsource more of its malicious cyber activity to organised criminals for greater plausible deniability. This poses a question as to what role law enforcement agencies should play in investigating cyber-related hostile state activity. 

The blurred lines between state and criminal cyber activity has the potential to create confusion as to how law enforcement and the security services should work together to investigate, disrupt and prosecute malicious cyber actors.

Attribution alone is unlikely to deter the Russian state from carrying out cyber-attacks. It is likely that similar style cyber-attacks will occur in the coming years and the GRU will continue to deploy malware and exploit kits that infect victims at scale, including Russian citizens. There may be an increase in automated attacks that successfully infect even more victims and provide greater anonymity for the attacker. 

For all the hyperbole relating to Western offensive cyber capability, the most effective tool to tackle the threat will be robust cyber risk-management strategies at both national and organisational level, together with diplomatic, legal and economic measures to deter future attacks.

RUSI

You Might Also Read:

What Is The GRU & Who Does It Hack?:

Russian Cyber Strategy And Tactics:

 

 

« Facebook CEO Zuckerberg Backed Sharing Customer Data
Germany Detects New Russian Cyber-Attack »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Teradata

Teradata

Teradata is a leading provider of enterprise big data analytics and services. Applications include Cyber Security Analytics.

EC-Council

EC-Council

EC-Council is a member-based organization that certifies individuals in various e-business and information security skills.

Convercent

Convercent

We offer comprehensive and integrated compliance management, reporting, and analytics. A 360-degree view of compliance drives efficiency by aligning initiatives and data into a single dashboard.

Datacom Systems

Datacom Systems

Datacom Systems is a leading manufacturer of network visibility solutions.

Sequitur Labs

Sequitur Labs

Sequitur Labs is developing seminal technologies and solutions to secure and manage connected devices of today and in the future.

ThreatSpike Labs

ThreatSpike Labs

ThreatSpike Labs provides the first end-to-end fully managed security service for companies of all sizes.

R2S Technologies

R2S Technologies

R2S can help you implement a cyber security framework to ensure your business is more resilient towards the growing threat of cyber crime. We provide Web and Mobile Application Security Assessment..

CETIC

CETIC

CETIC is an applied research centre in the field of ICT. Key technologies include Big Data, Cloud Computing, the Internet of Things, software quality, and trust and security of IT systems.

First Point Group (FPG)

First Point Group (FPG)

First Point Group provide a global technological recruitment service worldwide. Within that we have a specialist team of Cyber Security recruiters.

Hub One

Hub One

Hub One is a leading player in digital transformation with expertise in broadband connectivity, business solutions for traceability and mobility, IOT in industrial environments and cybersecurity.

Cyberspace Solarium Commission (CSC)

Cyberspace Solarium Commission (CSC)

The Cyberspace Solarium Commission was established to develop a consensus on a strategic approach to defending the United States in cyberspace against cyber attacks of significant consequences.

Trava Security

Trava Security

Trava simplifies cyber risk management for business owners and IT professionals. Automated assessments, mitigation advising, and data-driven cyber insurance.

GovernmentCIO

GovernmentCIO

GovernmentCIO was founded with a single purpose: to transform government IT. We are thought leaders in data analytics, machine learning, cybersecurity and IT transformation.

Accops Systems

Accops Systems

Accops enables secure and instant remote access to business applications from any device and network, ensuring compliant enterprise mobility.

Advent One

Advent One

Advent One are recognised for solving intricate dilemmas, not only making technology work but building foundations that customers can grow upon in an effective and secure way.

Lupasafe

Lupasafe

Lupasafe is a software for businesses to see IT risks and insights, and provide vital training for employees.