Spy vs Spy - Cozy Bear Hackers Hacked

In the Summer of 2015, Dutch intelligence services were the first to alert their American counterparts about the cyber-intrusion of the Democratic National Committee by Cozy Bear, a hacking group believed to be tied to the Russian government.

Intelligence hackers from Dutch AIVD (General Intelligence and Security Service) had penetrated the Cozy Bear computer servers as well as a security camera at the entrance of their working space, located in a university building adjacent to the Red Square in Moscow.

Over the course of a few months, they saw how the Russians penetrated several US institutions, including the State Department, the White House, and the DNC. On all these occasions, the Dutch alerted the US intelligence services, Dutch TV programme Nieuwsuur and de Volkskrant, a prominent newspaper in The Netherlands, jointly report recently.

This account is based on interviews with a dozen political, diplomatic and intelligence sources in The Netherlands and the US with direct knowledge of the matter. None of them wanted to speak on the record, given the classified details of the matter.

Not only had Dutch intelligence penetrated the computer network of the hackers, they also managed to hack a security camera in the corridor. This allowed them to see exactly who entered the hacking room.

Information about these individuals was shared with the US intelligence services. Dutch intelligence services consider Cozy Bear an extension of the SVR, the Russian foreign intelligence service, which is firmly controlled by President Putin.

The information shared by The Netherlands about the hacks at the DNC ended up on the desk of Robert Mueller, the Special Prosecutor leading the FBI investigation into possible Russian interference in the American elections. As early as December, the New York Times reported that information from, among others, Australia, the United Kingdom and The Netherlands had propelled the FBI investigation.

One of the claims made is that the Dutch counter-hackers were able to infiltrate a Russian cyber-gang known as Cozy Bear and keep an eye on them. And when we say “keep an eye on”, we mean it quite literally.

Apparently, the Dutch penetrated a security camera in the corridor leading to the hackers’ office, giving the counter-spies a view of everyone who came and went, information that was shared with US intelligence.

The Cozy Bear crew, it seems, didn’t realise that they’d been counter-hacked and betrayed by their own network.

NOS continues by saying that there were “about 10 people” in the Cozy Bear group, an imprecision that suggests either that the hacked camera didn’t have very good image quality, or that some of the group worked off-site.

Nevertheless, it’s an almost delightful irony that the hackers’ own security precautions were turned against them.

Two-faced CCTV cameras are, sadly, not a new topic on Naked Security.

The current trend to ‘Internetify’ as many devices as possible, what’s known as the IoT, or Internet of Things, is happening at such a dramatic (and competitive) rate that security often takes back seat, or even no seat at all.

We’ve written about security blunders in IoT products from dolls to sex toys; from light bulbs to kettles; from routers to printers – and many other IoT devices, too.

What to do?

We don’t know exactly how the Dutch hacking team took over the camera in this story, it could have been via a security flaw in the camera itself, via the software that controlled the camera, or via some other related compromise on the hackers’ network.

But if you are planning on plugging in anything such as an internet enabled camera, thermostat or light switch at home, here are some tips to help you get started as safely as you can:

  • Make sure your device has been updated to the latest firmware. Firmware refers to the combined operating system plus software bundle that controls the device itself, usually stored on flash memory inside the unit.

    Vendors are supposed to ship security patches from time to time; these are usually applied by downloading them to your desktop or laptop computer and using a special app to “burn” them to the device. Find out your model number and check the vendor’s download pages regularly.  
     
  • Make sure any remote access features are turned off before you go live. Many IoT devices come with a management app you can run on your desktop or laptop computer, so hunt around through the configuration options looking for any features to do with “remote administration”.

    Ideally, your IoT devices should be set up so they can be configured only from inside your network. That way, crooks have to break into your network and then into the device, instead of being able to hack away at the device itself remotely.  
     
  • Make sure you’ve changed default passwords and chosen decent replacements. Many IoT devices come with default login credentials such as root/root, admin/admin, and other combinations that are widely circulated on the internet. Don’t make it easy for the crooks: learn how to pick a proper password.

NOS News:     Naked Security

You Might Also Read: 

Russian Hackers Trying To Infiltrate US Senate:

Meet The Fancy Bears:

Guide to Russian Infrastructure Hacking:
 

« AI Can Turn Hollywood Stars Into Pornographic Actors
Russia's New Generation Of Military Robots »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

TenIntelligence

TenIntelligence

TenIntelligence provides due diligence, brand protection and fraud investigation services including digital forensics.

Samsung Knox

Samsung Knox

Samsung Knox brings multi-layered defence-grade security to your business’s smartphones and tablets.

TrainACE

TrainACE

TrainACE, is a professional computer training school offering courses in information technology with a focus on Advanced Security training.

Cyber Security Austria (CSA)

Cyber Security Austria (CSA)

Cyber Security Austria (CSA) is an independent non-profit association with the aim to address security issues in the area of IT/cyber security of critical/strategic infrastructures in Austria.

ICS-CSR

ICS-CSR

ICS-CSR is a research conference bringing together researchers with an interest in the security of industrial control systems.

Nameshield Group

Nameshield Group

Nameshield is one of most experienced domain name registrars, trademark protection specialists and managers of online reputational risk in the world today.

Aries Security

Aries Security

Aries Security provides a premiere cyber training range and skills assessment suite and develops content for all levels of ability.

BlackRidge Technology

BlackRidge Technology

BlackRidge Technology develops, markets and supports a family of products that provide a next generation cyber security solution for protecting enterprise networks and cloud services.

Intrinium

Intrinium

Intrinium is an Information Technology and Security Solutions company, providing comprehensive consulting and managed services to businesses of all sizes.

Finnish Security & Intelligence Service (SUPO)

Finnish Security & Intelligence Service (SUPO)

The Finnish Security and Intelligence Service is a government agency tasked with combating serious threats to national security in Finland.

Security & Intelligence Division (SID) - Singapore

Security & Intelligence Division (SID) - Singapore

Security & Intelligence Division (SID) protects Singapore from external threats and safeguards its interests in areas related to terrorism, cyber security, other transnational threats, and geopolitics

Trace3

Trace3

Trace3 is a pioneer in business transformation solutions, empowering organizations to keep pace with the rapid changes in IT innovations and maximize organizational health.

Orro Group

Orro Group

Orro create 'future now' solutions that make it faster, simpler and safer for you to access, store and share information. Wherever, whenever and with whomever you want.

Clearvision

Clearvision

As an Atlassian Platinum Solution Partner, Clearvision works with teams in the UK and US, providing solutions for the Atlassian stack, Git and open source tooling.

Dig Security

Dig Security

Dig Security offers the first data detection and response (DDR) solution, providing real-time visibility, control and protection of your data assets across any cloud.

Synoptek

Synoptek

Synoptek is a global systems integrator and managed IT services provider (MSP). We offer comprehensive IT management and consultancy services to organizations worldwide.