Showing posts with label Crowdstrike. Show all posts
Showing posts with label Crowdstrike. Show all posts

Tuesday, March 28, 2017

Miami Herald — Were the hackers who broke into the DNC’s email really Russian?


Is the narrative breaking down owing to lack of evidence?

Miami Herald
Were the hackers who broke into the DNC’s email really Russian?
Glenn Garvin

Monday, March 27, 2017

Voice of America — Cyber Firm Rewrites Part of Disputed Russian Hacking Report

Voice of America
Cyber Firm Rewrites Part of Disputed Russian Hacking Report
Oleksiy Kuzmenko and Pete Cobus – WASHINGTON, March 25, 2017

U.S. #cybersecurity firm #CrowdStrike has revised and retracted statements it used to buttress claims of #Russian #hacking during last year’s American presidential election campaign. The shift followed a VOA report that the company misrepresented data published by an influential British think tank.
In December, CrowdStrike said it found evidence that Russians hacked into a Ukrainian artillery app, contributing to heavy losses of howitzers in Ukraine’s war with pro-Russian separatists.
VOA reported Tuesday that the International Institute for Strategic Studies (IISS), which publishes an annual reference estimating the strength of world armed forces, disavowed the CrowdStrike report and said it had never been contacted by the company.
Ukraine’s Ministry of Defense also has stated that the combat losses and hacking never happened.
CrowdStrike was first to link hacks of Democratic Party computers to Russian actors last year, but some cybersecurity experts have questioned its evidence. The company has come under fire from some Republicans who say charges of Kremlin meddling in the election are overblown.
After CrowdStrike released its Ukraine report, company co-founder Dmitri Alperovitch claimed it provided added evidence of Russian election interference. In both hacks, he said, the company found malware used by “Fancy Bear,” a group with ties to Russian intelligence agencies.
CrowdStrike’s claims of heavy Ukrainian artillery losses were widely circulated in U.S. media.
On Thursday, CrowdStrike walked back key parts of its Ukraine report.
The company removed language that said Ukraine’s artillery lost 80 percent of the Soviet-era D-30 howitzers, which used aiming software that purportedly was hacked. Instead, the revised report cites figures of 15 to 20 percent losses in combat operations, attributing the figures to IISS.
The original CrowdStrike report was dated Dec. 22, 2016, and the updated report was dated March 23, 2017.
The company also removed language saying Ukraine’s howitzers suffered “the highest percentage of loss of any … artillery pieces in Ukraine’s arsenal.”
Finally, CrowdStrike deleted a statement saying “deployment of this malware-infected application may have contributed to the high-loss nature of this platform” – meaning the howitzers – and excised a link sourcing its IISS data to a blogger in Russia-occupied Crimea.
In an email, CrowdStrike spokeswoman Ilina Dmitrova said the new estimates of Ukrainian artillery losses resulted from conversations with Henry Boyd, an IISS research associate for defense and military analysis. She declined to say what prompted the contact.
“This update does not in any way impact the core premise of the report that the FANCY BEAR threat actor implanted malware into a D-30 targeting application developed by a Ukrainian military officer,” Dmitrova wrote.
This is apparently a false claim:

"Crowdstrike, along with FireEye and other cybersecurity companies, have long propagated the claim that Fancy Bear and all of its affiliated monikers (APT28, Sednit, Sofacy, Strontium, Tsar Team, Pawn Storm, etc.) were the exclusive developers and users of X-Agent. We now know that is false.

"ESET was able to obtain the complete source code for X-Agent (aka Xagent) for the Linux OS with a compilation date of July 2015. [5]

"A hacker known as RUH8 aka Sean Townsend with the Ukrainian Cyber Alliance has informed me that he has also obtained the source code for X-Agent Linux. [11]

"If both a security company and a hacker collective have the X-Agent source code, then so do others, and attribution to APT28/Fancy Bear/GRU based solely upon the presumption of “exclusive use” must be thrown out.

"This doesn’t mean that the Russian government may not choose to use it. In fact, Sean Townsend believes that the Russian security services DO use it but he also knows that they aren’t the only ones."

Reached by VOA, the IISS confirmed providing CrowdStrike with new information about combat losses, but declined to comment on CrowdStrike’s hacking assertions.
“We don’t think the current version of the [CrowdStrike] report draws conclusions with regard to our data, other than quoting the clarification we provided to them,” IISS told VOA.
Dmitrova noted that the FBI and the U.S. intelligence community have also concluded that Russia was behind the hacks of the Democratic National Committee, Democratic Congressional Campaign Committee and the email account of John Podesta, Hillary Clinton’s campaign manager.
Note: The FBI and US Intelligence community has said that it relied on the Crowdstrike report without investigating and that they were also denied access to the DNC server that was allegedly hacked. In addition, there is reason to think that the incident was the result of an insider leak rather than a cyber hack.
The release of embarrassing Democratic emails during last year’s U.S. political campaign, and the subsequent finding by intelligence agencies that the hacks were meant to help then-candidate Donald Trump, have led to investigations by the FBI and intelligence committees in both the House and Senate.
Trump and White House officials have denied colluding with Russians.
See also

Fabius Maximus
Exposing the farcical claims about Russian hacking of the election
Editor

Sunday, March 26, 2017

Rush to Judgment— The evidence that the Russians hacked the DNC is collapsing

To begin with, Crowdstrike initially gauged its certainty as to the identity of the hackers with “medium confidence.” However, a later development, announced in late December and touted by the Washington Post, boosted this to “high confidence.” The reason for this newfound near-certainty was their discovery that “Fancy Bear” had also infected an application used by the Ukrainian military to target separatist artillery in the Ukrainian civil war.…

The definitive “evidence” cited by Alperovitch is now effectively debunked: indeed, it was debunked by Carr late last year, but that was ignored in the media’s rush to “prove” the Russians hacked the DNC in order to further Trump’s presidential ambitions. The exposure by the Voice of America of Crowdstrike’s falsification of Ukrainian battlefield losses – the supposedly solid “proof” of attributing the hack to the GRU – is the final nail in Crowdstrike’s coffin. They didn’t bother to verify their analysis of IISS’s data with IISS – they simply took as gospel the allegations of a pro-Russian blogger. They didn’t contact the Ukrainian military, either: instead, their confirmation bias dictated that they shaped the “facts” to fit their predetermined conclusion.
Now why do you suppose that is? Why were they married so early – after a single day – to the conclusion that it was the Russians who were behind the hacking of the DNC?...
Crowdstrike founder Alperovitch is a Nonresident Senior Fellow of the Atlantic Council, and head honcho of its “Cyber Statecraft Initiative” – of which his role in promoting the “Putin did it” scenario is a Exhibit A. James Carden, writing in The Nation, makes the trenchant point that “The connection between Alperovitch and the Atlantic Council has gone largely unremarked upon, but it is relevant given that the Atlantic Council – which is funded in part by the US State Department, NATO, the governments of Latvia and Lithuania, the Ukrainian World Congress, and the Ukrainian oligarch Victor Pinchuk – has been among the loudest voices calling for a new Cold War with Russia.” Adam Johnson, writing on the FAIR blog, adds to our knowledge by noting that the Council’s budget is also supplemented by “a consortium of Western corporations (Qualcomm, Coca-Cola, The Blackstone Group), including weapons manufacturers (Lockheed Martin, Raytheon, Northrop Grumman) and oil companies (ExxonMobil, Shell, Chevron, BP).”
Johnson also notes that CrowdStrike currently has a $150,000 / year, no-bid contract with the FBI for “systems analysis.”...
AnitWar

Thursday, March 23, 2017

Michael J. Sainato — Cybersecurity Firm That Attributed DNC Hacks to Russia May Have Fabricated Russia Hacking in Ukraine

The cyber security firm outsourced by the Democratic National Committee, CrowdStrike, reportedly misread data, falsely attributing a hacking in Ukraine to the Russians in December 2016.…
The report sheds further skepticism on CrowdStrike’s findings and objectivity in their conclusions, which several cyber security experts and former CIA and NSA officials have cast doubt on, especially given that several media outlets reported in early January 2017 that the DNC never allowed the FBI to examine their servers themselves, rather the FBI relied on forensic data gathered by CrowdStrike.
The investigation methods used to come to the conclusion that the Russian Government led the hacks of the DNC, Clinton Campaign Chair John Podesta, and the DCCC were further called into question by a recent BuzzFeed report by Jason Leopold, who has developed a notable reputation from leading several non-partisan Freedom of Information Act lawsuits for investigative journalism purposes. On March 15 that the Department of Homeland Security released just two heavily redacted pages of unclassified information in response to an FOIA request for definitive evidence of Russian election interference allegations. Leopold wrote, “what the agency turned over to us and Ryan Shapiro, a PhD candidate at MIT and a research affiliate at Harvard University, is truly bizarre: a two-page intelligence assessment of the incident, dated Aug. 22, 2016, that contains information DHS culled from the internet. It’s all unclassified — yet DHS covered nearly everything in wide swaths of black ink. Why? Not because it would threaten national security, but because it would reveal the methods DHS uses to gather intelligence, methods that may amount to little more than using Google.”
In lieu of substantive evidence provided to the public that the alleged hacks which led to Wikileaks releases of DNC and Clinton Campaign Manager John Podesta’s emails were orchestrated by the Russian Government, CrowdStrike’s bias has been cited as undependable in its own assessment, in addition to its skeptical methods and conclusions. The firm’s CTO and co-founder, Dmitri Alperovitch, is a senior fellow at the Atlantic Council, a think tank with openly anti-Russian sentiments that is funded by Ukrainian billionaire Victor Pinchuk, who also happened to donate at least $10 million to the Clinton Foundation.
In 2013, the Atlantic Council awarded Hillary Clinton it’s Distinguished International Leadership Award. In 2014, the Atlantic Council hosted one of several events with former Ukrainian Prime Minister Arseniy Yatsenyuk, who took over after pro-Russian President Viktor Yanukovych was ousted in early 2014...
Counterpunch
Cybersecurity Firm That Attributed DNC Hacks to Russia May Have Fabricated Russia Hacking in Ukraine
Michael J. Sainato

Wednesday, March 22, 2017

Think Tank: Cyber Firm [Crowdstrike] at Center of Russian Hacking Charges Misread Data


Voice of America, the US government international propaganda arm news service confirms the report of Moon of Alabama posted here at MNE earlier in the day that the Crowdstrike claim of Russian involvement in hacking the Ukrainian military was disproved.
[Dmitri] Alperovitch, a Russian expatriate and senior fellow at the Atlantic Council policy research center in Washington, co-founded CrowdStrike in 2011.
Voice of America
Think Tank: Cyber Firm at Center of Russian Hacking Charges Misread Data
Oleksiy Kuzmenko and Pete Cobus

Moon of Alabama — Fool Me Once ... - Crowdstrike Claimed Two Cases Of "Russian Hacking" - One Has Been Proven Wrong

The cyber-security company Crowdstrike claimed that the "Russia" hacked the Democratic National Committee. It also claimed that "Russia" hacked artillery units of the Ukrainian army. The second claim has now be found to be completely baseless. That same is probably the case with its claims related to the DNC.
Much of this has already been posted here previously, but b pulls it together. Moreover, it is relevant now owing to the recent testimony of FBI chief James Comey that the agency never actually investigated the alleged DNC "hack" forensically and there is good reason to think that it was actually a leak rather than a hack.

There are some good comments, too.

Internet security is highly important, of course, but without oversight it can lead to government management of the national and global information systems.

In this case Congress seems to be bent on a witch hunt rather than a real investigation.

Wednesday, January 11, 2017

George Eliason — Why Crowdstrike’s Russian Hacking Story Fell Apart 2 — The DNI Report Faked Sources

The only thread that holds the DNI report together at first glance is the false testimony and fake evidence Crowdstrike and Dmitri Alperovitch provided to the FBI and other agencies involved. When you look at the evidence presented and the sources it becomes evident that the Russian hack story doesn’t stand up against Crowdstrike’s own facts.
By examining facts, timelines, and sources needed for the DNI report, the only conclusion is the DNI report is strictly political. Because of this Craig Murray- Julian Assange’s story showing the emails were leaked is the only version of the story that stands. The facts on hand show criminality and negligence on the part of Crowdstrike, the FBI, and the DNI.…
More on US intelligence relying on Crowdstrike, Dimitri Alperovitch, and the Ukrainian connection through the Chalupa family, linked to Hillary Clinton.

Washington's Blog
Why Crowdstrike’s Russian Hacking Story Fell Apart 2 — The DNI Report Faked Sources
George Eliason

(George Eliason lives in Ukraine.)

Why Crowdstrike’s Russian Hacking Story Fell Apart — Say Hello to Fancy Bear (Jan 3) was part 1

Russia Hacking the Election the Inside Story ( Dec 21) was the intro.

Friday, January 6, 2017

Washington's Blog — DNC Refused to Give FBI Access to Its Servers … Instead Gave Access to a DNC Consultant Tied to Organization Promoting Conflict with Russia

As first reported by George Eliason, CrowdStrike’s Chief Technology Officer and Co-Founder Dimitri Alperovitch – who wrote the CrowdStrike reports allegedly linking Russia to the Democratic party emails published by Wikileaks – is a fellow at the Atlantic Council … an organization associated with Ukraine, and whose main policy goal seems to stir up a confrontation with Russia.
Remember how fast HRC's campaign manager Robbie Mook took the narrative to the press when the material was released by Wikileaks, claiming that t"he Russians did it" based on the Crowdstrike report?

Washington's Blog
DNC Refused to Give FBI Access to Its Servers … Instead Gave Access to a DNC Consultant Tied to Organization Promoting Conflict with Russia

Tuesday, January 3, 2017

George Ellison — Why Crowdstrike's Russian Hacking Story Fell Apart--Say Hello to Fancy Bear

In the wake of the JAR-16-20296 dated December 29, 2016, about hacking and influencing the 2016 election, the need for real evidence is clear. The joint report adds nothing substantial to the October 7th report. It relies on proofs provided by the cyber-security firm Crowdstrike that is clearly not on par with intelligence findings or evidence. At the top of the report is an "as is" statement showing this.
The difference between [Co-Founder and CTO of CrowdStrike Inc.] Dmitri Alperovitch's claims, which are reflected in JAR-1620296, and this article is that enough evidence is provided to warrant an investigation of specific parties for the DNC hacks. The real story involves specific anti-American actors that need to be investigated for real crimes.
Later in this article, you'll meet and know a little more about the real "Fancy Bear and Cozy Bear." The bar for identification set by has never been able to get beyond words like probably, may be, could be, or should be in their attribution.
The article is lengthy because the facts need to be in one place. The bar Dimitri Alperovitch set for identifying the hackers involved is that low. Other than asking America to trust them, how many solid facts has Alperovitch provided to back his claim of Russian involvement?
The December 29th JAR adds a flowchart that shows how a basic phishing hack is performed. It doesn't add anything substantial beyond that. Noticeably, they use both their designation APT 28 and APT 29 as well as the CrowdStrike labels of Fancy Bear and Cozy Bear separately.
This is important because information from outside intelligence agencies has the value of rumor or unsubstantiated information at best according to policy. Usable intelligence needs to be free from partisan politics and verifiable. Intel agencies noted back in the early '90s that every private actor in the information game was radically political....
Reads like a detective story. Longish but gripping. It's an argument that there was likely a criminal conspiracy involved, but not by either the Trump faction or "the Russians."

If you are following this, it is a must-read. Lots of new information and documentation.

OpEdNews
Why Crowdstrike's Russian Hacking Story Fell Apart--Say Hello to Fancy Bear
George Ellison
Crossposted at Washington's Blog

George Ellison lives in Ukraine.

Wednesday, December 14, 2016

Craig Murray — The Russian Bear Uses a Keyboard

I am about twenty four hours behind on debunking the “evidence” of Russian hacking of the DNC because I have only just stopped laughing. I was sent last night the “crowdstrike” report, paid for by the Democratic National Committee, which is supposed to convince us. The New York Times today made this “evidence” its front page story.…
The Keystone Cops portrayal of one of the world’s most clinically efficient intelligence services is of a piece with the anti-Russian racism which has permeated the Democratic Party rhetoric for quite some time. Frankly nobody in what is vaguely their right mind would believe this narrative.…
Of course there were hacking and phishing attacks on the DNC. Such attacks happen every day to pretty well all of us. There were over 1,050 attacks on my own server two days ago, and many of them often appear to originate in Russia – though more appear to originate in the USA. I attach a cloudfare threat map. It happens to be from a while ago as I don’t have a more up to date one to hand from my technical people. Of course in many cases the computers attacking have been activated as proxies by computers in another country entirely. Crowdstrike of course expect us to believe that Putin’s security services have not heard of this or of the idea of disguising which time zone you operate from.…
I don’t know what the DNC paid “Crowdstrike” for their narrative but they got a very poor return for their effort indeed. That the New York Times promotes it as any kind of evidence is a truly damning indictment of the mainstream media.
Craig Murray
The Russian Bear Uses a Keyboard
Craig Murray, former British ambassador to Uzbekistan and Rector of the University of Dundee (2007–10)