Page 18 of 53 FirstFirst ... 8161718192028 ... LastLast
Results 341 to 360 of 1043

Thread: Russian Info, Cyber and Disinformation (Jan-June 2017).

  1. #341
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Russian software engineer was detained in Barcelona in possible connection to U.S elections hack:

    Barcelona has the largest Russian expat community outside of Russia...and the largest mob collection point as well...

    Background story on the worldwide hunt for Russian hackers in general...this particular arrest has not been signaled yet in western MSM but picked up in Russian MSM.......
    http://www.miamiherald.com/news/nati...141998499.html

    Was actually surprised to see Russian reports of a Russian hacker arrested for US elections hacking....

    LOCATED original Russian source....

    First mentioned in this Russia twitter account
    Mikhail Golub‏#
    @golub
    Программист из Петербурга задержан в Испании по запросу США.
    Не хочет русский хакер отдыхать на Байкале

    Actual referenced Russian media source.
    http://www.rosbalt.ru/world/2017/04/09/1606078.html

    Article is in Russian.....

  2. #342
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Israel's Communist Party consistently backs Assad & Russian intervention. Apparently when it's Russia+Iran intervening it's not imperialism

    Israel's Communist Party prevented issuing of an Arab Joint List condemnation of the chemical massacre in Syria

    It is extremely interesting to watch how the left and right in Europe together with the US ultra right IE white nationalists and white supremacists rally around Russian propaganda when it comes to the Syrian CWs attack...

    Kremlin's pet Italian fascist @matteosalvinimi is only "following orders"

    "Use of gas in Syria? I want proof"

    https://twitter.com/lega_nord/status...0789265711106#

  3. #343
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Quote Originally Posted by OUTLAW 09 View Post
    Russian software engineer was detained in Barcelona in possible connection to U.S elections hack:

    Barcelona has the largest Russian expat community outside of Russia...and the largest mob collection point as well...

    Background story on the worldwide hunt for Russian hackers in general...this particular arrest has not been signaled yet in western MSM but picked up in Russian MSM.......
    http://www.miamiherald.com/news/nati...141998499.html

    Was actually surprised to see Russian reports of a Russian hacker arrested for US elections hacking....

    LOCATED original Russian source....

    First mentioned in this Russia twitter account
    Mikhail Golub‏#
    @golub
    Программист из Петербурга задержан в Испании по запросу США.
    Не хочет русский хакер отдыхать на Байкале

    Actual referenced Russian media source.
    http://www.rosbalt.ru/world/2017/04/09/1606078.html

    Article is now being reported in English.....

    Russian computer programmer arrested in Spain. RT claims authorities suspect connection to U.S. election hacking

    Article is in Russian.....
    Article is now being reported in English.....

    Russian computer programmer arrested in Spain. RT claims authorities suspect connection to U.S. election hacking

    http://www.reuters.com/article/us-sp...-idUSKBN17B0O2

    Russian hacker Petr Levashov allegedly created virus used to help Trump win, per HK-based publication

    THIS may in fact be key as there is solid evidence that the large scale bot nets that drove proTrump social messaging were controlled from a central point...the how has been the puzzle we are looking for....

    The New York Times

    @nytimes
    Spain Arrests Russian Thought to Be Kingpin of Computer Spam
    http://nyti.ms/2ogoS9W
    Last edited by OUTLAW 09; 04-10-2017 at 04:33 AM.

  4. #344
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Booby-trapped Word documents in the wild exploit critical Microsoft zero-day
    https://arstechnica.co.uk/?post_type=post&p=200327#


    I am way old enough to remember when MS Word Marco virus was the thing of the day and when the Monkey virus was "in"......

    We have come a long way...but surprisingly some of the newer malware are going back to those early days and incorporating some of those features to throw off viral detectors....as the latest viral detectors are not geared to detect such basic ones...

  5. #345
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Quote Originally Posted by OUTLAW 09 View Post
    Article is now being reported in English.....

    Russian computer programmer arrested in Spain. RT claims authorities suspect connection to U.S. election hacking

    http://www.reuters.com/article/us-sp...-idUSKBN17B0O2

    Russian hacker Petr Levashov allegedly created virus used to help Trump win, per HK-based publication

    THIS may in fact be key as there is solid evidence that the large scale bot nets that drove proTrump social messaging were controlled from a central point...the how has been the puzzle we are looking for....

    The New York Times

    @nytimes
    Spain Arrests Russian Thought to Be Kingpin of Computer Spam
    http://nyti.ms/2ogoS9W
    Apparently Pyotr Levashov linked to Russia's FSB in years past
    https://www.opendemocracy.net/od-rus...-crime#…

    He has been around since the 90s....considered to be the one of the world's top 5 spammers and has been known to FBI and CIA since early 2000s for his work with Russian FSB....

    Article has his alias and some of the other hackers he's operated with in the past:
    https://krebsonsecurity.com/2012/12/...-17872#…

    This was one of his most potent Trojan's.....

    https://threatpost.com/neverquest-tr...update/120605/

    The once prolific banking Trojan Neverquest received a major code revamp over the summer and is now armed with modifications that can more adeptly hijack a victim’s PC, inject code into webpages and steal credentials. The update represents a significant enough change to the malware that researchers have dubbed the latest samples Neverquest2.
    Over the past several months Arbor Networks’ Security Engineering and Response Team (ASERT), along with#other members of the security research community, have been tracking the slow and steady improvements added to Neverquest. There is consensus that the team behind the Trojan is gearing up for a new Neverquest2 assault.
    Related Posts
    NukeBot Banking Trojan Source Code Leaked Online by Author
    March 30, 2017 , 2:21 pm
    Latest Tax Scams Include Phishing Lures, Malware
    March 21, 2017 , 11:54 am
    Dridex Trojan Gets A Major ‘AtomBombing’ Update
    February 28, 2017 , 3:17 pm
    Neverquest is a version of the Gozi Trojan that was responsible for stealing millions of dollars from victims’ bank accounts during its run several years ago. The Neverquest malware family, also known as Vawtrak, has been around for more than three years and has in the past been distributed by the Neutrino EK.
    With this latest version, Arbor researchers note in a soon to be published technical analysis of the Trojan, that the team behind Neverquest2 has modified the malware to include plugins capable of delivering 266 new web-inject rules targeting specific type websites. Bank and financial websites make up the majority of sites targeted by Neverquest2 followed by: government agencies, wireless providers, payroll services and online public record aggregators. Notable, say ASERT researchers, is the addition of web-injection rules that now target Bitcoin commerce sites for the first time.
    Neverquest2, as with Neverquest, is designed to kick into action on infected computers whenever a user visits one of the pre-programmed targeted sites. Next, the web-injections occur, inserting extra fields into targeted web forms in order to steal PINs and other sensitive information.
    In 2014, several people were arrested and indicted in connection with using Neverquest in a web-injection attack that resulted in more than $1.5 million in fraudulent transactions on StubHub, the online ticket portal.
    The Trojan has evolved over the summer. Last month, cybersecurity firm PhishLabs noted that Neverquest2 uses a new domain generation algorithm to produce a large number of domain names that can be used to link to its command-and-control server.
    Another recent modification to Neverquest2, ASERT observed, has been the introduction of new modules to the Trojan adding new functionality. Two modules added to Neverquest2 over the summer include a “backconnect” and a certificate-stealing plugin.
    The backconnect module (bc_32.dll) adds support for general purpose remote access to an infected client. It includes a VNC server that can be installed on the infected host, according to ASERT. “The infected computer allows an attacker to be logged into the computer and see the victim’s desktop and get access to webcam video and see the browsing history of the victim. They have full access to the victim’s PC and can run arbitrary CMD commands and interact with the Task Manager,” according to an ASERT researcher.
    The second additional module (dg_32.dll) is a general purpose information stealing module that will hunt for and steal certificates stored on the victim’s infected computer. The dg_32.dll plugin “uses the CertOpenSystemStore() and related cryptographic APIs to gain access to certificate stores associated with private keys, certificate authorities, etc. It will scan the infected system for browser profiles, cookies, browsing history and browser cache entries,” according to ASERT’s report.
    ASERT said the improved Neverquest2 can also remotely access an infected system to install the Pony Trojan, also referred to as Fareit.
    Despite what researchers describe as a major overhaul for Neverquest, they say the primary goal for the Trojan remains the same: to modify the web page presented to the victim in order to steal account credentials or other sensitive information.
    “This particular recent sample of Neverquest2 is a well-written, modular, professional grade malware platform,” wrote ASERT researchers. “(Neverquest2) does not appear to contain a great deal more actual functionality beyond what was already present in the some of the original Neverquest samples going all the way back to 2015. But its incremental changes, such as the recent adoption of a DGA-style mechanism for the specification of its C&C servers, indicates that the threat is still under active development.”
    Another good article on him from Krebsonsecurity....

    10Apr 17
    Alleged Spam King Pyotr Levashov Arrested
    Authorities in Spain have arrested a Russian computer programmer thought to be one of the world’s most notorious spam kingpins.

    https://krebsonsecurity.com/2017/04/...shov-arrested/
    Last edited by OUTLAW 09; 04-10-2017 at 09:34 AM.

  6. #346
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    This white nationalist was one of Trump's biggest supporters and especially read on social media during the campaign...and was to be the main speaker at CPAC until his interview where he favored pedophilia with younger boys...kinda killed his career at Breitbart.com..

    Mediaite‏
    Verified account
    #EXCLUSIVE: Milo Yiannopoulos Breaks With Trump on Syria: ‘Not Why People Voted for Daddy’
    http://bit.ly/2oaLoRH

    "Daddy".......???????
    Last edited by OUTLAW 09; 04-10-2017 at 09:37 AM.

  7. #347
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    EU Mythbusters

    @EUvsDisinfo
    Why do we talk about "pro-Kremlin disinformation campaign" and not "Russian disinformation campaign":
    https://euvsdisinfo.eu/kt-kremlin-today/#

  8. #348
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    One of Russia's main social media trolls....in action...tied heavily into GRU...

    BREAKING #GRU InfoOp #Kots has been quickly deployed to Shairat aviation base in Syria to assess Tomahawks volley BDA.
    Attached Images Attached Images

  9. #349
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Quote Originally Posted by OUTLAW 09 View Post
    Apparently Pyotr Levashov linked to Russia's FSB in years past
    https://www.opendemocracy.net/od-rus...ers-in-crime#…

    He has been around since the 90s....considered to be the one of the world's top 5 spammers and has been known to FBI and CIA since early 2000s for his work with Russian FSB....

    Article has his alias and some of the other hackers he's operated with in the past:
    https://krebsonsecurity.com/2012/12/.../#more-17872#…

    This was one of his most potent Trojan's.....

    https://threatpost.com/neverquest-tr...update/120605/



    Another good article on him from Krebsonsecurity....

    10Apr 17
    Alleged Spam King Pyotr Levashov Arrested
    Authorities in Spain have arrested a Russian computer programmer thought to be one of the world’s most notorious spam kingpins.

    https://krebsonsecurity.com/2017/04/...shov-arrested/
    US says global spam scheme targeted after Russian mastermind nabbed
    http://wapo.st/2pkVrBz?tid=ss_tw#

  10. #350
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    How does Kremlin influence work in Central Europe?
    A new @cepolicy report
    https://goo.gl/9fSiLF

  11. #351
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    While Trump has been bashing Assad and Putin...Russia wants back Alaska...

    Alaska's Arctic policy adviser falls victim to Russian media provokatsiya.
    https://www.adn.com/arctic/2017/04/1...ws-in-russia/#

    Reverse fake news hits Russia....

  12. #352
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Kremlin Trolls CI @KremlinTrolls
    That Kremlin Troll changed her name from @ArianaGicPerry to @GicAriana to cover her trail.

    She has been active ever since Crimea annexation by Russia and is definitely a solid Russian troll account...

    You will find that a number of Russian trolls often change their account names to provide the "fog of war"....

  13. #353
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Cyber breaches have cost shareholders billions since 2013:
    http://reut.rs/2nDzf9h

  14. #354
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Another Russian troll on the move again...after a period of silence....


    Return of pro-CW use @PartisanGirl ally Ted Postol and his affinity for Assad's regime.

    Remembering when Postol got himself aligned with holocaust denier @RyLiberty to talk about how neocons were after pro-CW use @PartisanGirl.

    Nobody should be surprised that Ghouta truther #1 Ted Postol ("the MIT") is back defending the "Axis of Resistance".
    Last edited by OUTLAW 09; 04-12-2017 at 04:23 PM.

  15. #355
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Best defense is offense: Russian Foreign Ministry spox Zakharova announces millions of US bots have attacked Russia

  16. #356
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    another reactivated Russian troll...
    EHSANI2‏#
    @EHSANI22
    Instead of reading and critiquing the document, some people are taking issue with my leading CW expert comment. Ok he is HMAR at MIT. Happy?

  17. #357
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Fakenews alleging troops poisoned in #Latvia #released on @BNSLithuania wire, #cyberattack suspected
    http://bit.ly/2ozoPH3

  18. #358
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Yes open source OSINT can push back....

    Open-source citizen journalists are fighting back against Russian hacking of Western institutions - via @techreview
    https://www.technologyreview.com/s/6...m_medium=post#


    Problem is MSM never really seems "to get it"....until way to late...

  19. #359
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Russian info warfare inside UK hard at work....

    Guess who just became a “Director” of Ghaith Armanazi’s British Syrian Society?

    RT’s favorite Brit, Peter Ford:
    https://beta.companieshouse.gov.uk/company/04619563


    Guess who organized the infamous #Damascus “conference” attended by Western analysts & journalists?

    = The British #Syria Society.

    Who's the head of #Syria's chemical weapons program?

    = Amr Armanazi (L)

    Who's the head of British #Syria Society?

    = Ghaith Armanazi (R)

    More info on the Armanazis can be found here: https://www.thetimes.co.uk/article/s...ck-fsnkrk6fw#…

    Here: https://en.zamanalwsl.net/news/25201.html#

    & here: http://foreignpolicy.com/2017/04/07/...assad-sarin/#…
    Attached Images Attached Images
    Last edited by davidbfpo; 04-13-2017 at 09:40 AM. Reason: fix link

  20. #360
    Council Member
    Join Date
    Nov 2013
    Posts
    35,749

    Default

    Say goodbye to the chemical weapons warehouse and hello to the Saudi missile for your Khan Sheikhoun conspiracy needs

    THIS individual is a confirmed Russian troll.....and who has been extremely active since the gas attack....
    Attached Images Attached Images

Similar Threads

  1. Malware & other nasty IT / cyber things
    By AdamG in forum Media, Information & Cyber Warriors
    Replies: 111
    Last Post: 02-07-2018, 10:37 PM
  2. Russian Info, Cyber and Disinformation (Catch all till 2017)
    By TheCurmudgeon in forum Media, Information & Cyber Warriors
    Replies: 373
    Last Post: 02-14-2017, 11:30 AM
  3. Syria in 2016 (January-March)
    By davidbfpo in forum Middle East
    Replies: 3135
    Last Post: 03-31-2016, 08:51 PM
  4. Social Media: the widest impact of (merged thread)
    By zenpundit in forum Media, Information & Cyber Warriors
    Replies: 55
    Last Post: 02-29-2016, 06:57 AM
  5. Ukraine: Russo-Ukr War (June-December 2015)
    By davidbfpo in forum Europe
    Replies: 3393
    Last Post: 12-31-2015, 11:53 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •