Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

1/26/2018
02:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Dutch Intel Agency Reportedly Helped US Attribute DNC Hack to Russia

The General Intelligence and Security Service of the Netherlands broke into Cozy Bear's network in 2014 and spotted the group launching attacks, de Volkskrant says.

Information provided by the General Intelligence and Security Service of the Netherlands (AIVD) helped US intelligence officials attribute to the Russians the controversial 2016 hacking attack on the Democratic National Committee (DNC), Dutch newspaper de Volkskrant reported this week.

According to the paper, agents from AIVD managed to infiltrate the network of a university building in Moscow's Red Square in summer 2014 that Russian threat group APT29, aka Cozy Bear, was using. The intrusion provided Dutch intelligence agents with unprecedented visibility into the activities of the group, which since 2010 has been linked to numerous attacks on government organizations, and energy and telecommunication companies.

AIVD's access to the network was so complete that Dutch agents were able to use a CCTV in the building to watch every move of the 10 or so Cozy Bear actors who used the network. By comparing photos gathered from the snooping with photos of known Russian agents, AIVD was able to determine with a high level of confidence Cozy Bear was led by Russia's Foreign Intelligence Service, the Dutch newspaper said.

It was that access that allowed Dutch agents to spot Cozy Bear launching an attack on the DNC network in summer 2015 and transferring emails and documents from the breached networks to its own servers. AIVD's information on the attack ultimately helped US intelligence agencies state with a high level of confidence that Moscow was involved in the attacks, de Volkskrant quoting several unnamed sources. The NSA and other intelligence agencies have publicly acknowledged receiving the help of a "western ally" in identifying the actor behind the DNC attack.

The DNC attack, and the subsequent leak of thousands of emails from Democratic candidate Hillary Clinton's campaign, later prompted accusations of Russian meddling in the 2016 Presidential election and the Trump campaign's alleged involvement in it.

The 2015 attack on the DNC network is not the only tip that Dutch have given US intelligence agencies in the two years or so while they had access to Cozy Bear's network.

AIVD's access to Cozy Bear's network also allowed the agency to warn US officials of an attack on the US State Department network in late 2014. The APT group had managed to obtain email addresses and login credentials belonging to several State Department employees and had used that to access a non-classified portion of the State Department network.

Teams from the NSA and FBI used information provided by the Dutch to eventually prevent Cozy Bear from expanding its access to more critical areas of the State Department network. The attack, which one official later described as the "worst ever," forced the State Department to shut down access to its email systems for a weekend in order to restore security.

During the attack, Cozy Bear managed to send an email purportedly from the State Department to an individual in the White House. The email essentially tricked the employee into sharing his email credentials with a Cozy Bear threat actor who then used it to access a server containing emails sent and received by then President Obama, the Dutch newspaper said. Cozy Bear, however, did not manage gain access to any classified system in the White House breach.

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/20/2019
Pledges to Not Pay Ransomware Hit Reality
Robert Lemos, Contributing Writer,  6/21/2019
AWS CISO Talks Risk Reduction, Development, Recruitment
Kelly Sheridan, Staff Editor, Dark Reading,  6/25/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-1619
PUBLISHED: 2019-06-27
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session ...
CVE-2019-1620
PUBLISHED: 2019-06-27
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could ex...
CVE-2019-1621
PUBLISHED: 2019-06-27
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker...
CVE-2019-1622
PUBLISHED: 2019-06-27
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software...
CVE-2019-10133
PUBLISHED: 2019-06-26
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.