HomeSecurityHow digital "femmes fatales" stole Syrian battle plans

How digital 'femmes fatales' stole Syrian battle plans

Figures of doomed female spies have existed many in history, with the most famous being Mata Hari and perhaps more recently Anna Chapman. The «tradition» seems to continue in today's networked era, even if the «doomed women» who trapped members of the Syrian opposition, stealing battle plans and other extremely important details for their operations against the Assad regime.

According to an extensive study by cybersecurity firm Fire Eye, between November 2013 and January 2014, unknown hackers stole large amounts of data, including documents and Skype conversations that revealed the opposition's overall strategy, tactical battle plans, supply needs, and large volumes of personal data and chat files belonging to members of the forces fighting against President Assad's government forces.

Syria Islamic State Kobani

“While we do not know who conducted this hacking operation, if this data had been obtained by Assad’s forces or their allies, it would have given them a significant advantage on the battlefield,” the study states.
In this operation, the perpetrators used a well-known tactic, which may have changed over the centuries, but in essence remains unchanged: ensnaring (or “fishing”) targets through conversations with (allegedly) attractive women who appeared to be positively aligned with the Syrian opposition.

 

«An female avatar started a conversation on Skype and shared a “personal” photo of herself with the target. Before sending it, she usually asked what device the user was using – Android phone or computer- most likely aiming to send specially “targeted” malicious software (malware). As soon as the target downloaded the malware‑laden photo, the attackers gained access to his device, searched through his files and selected and stole data that identified opposition members, the logs of their Skype conversations and contacts and a large number of documents that provided valuable information about the military operations being planned against the forces of President Assant» is noted in the research.

Detailed findings are as follows:

    • The data stolen: The perpetrators stole hundreds of files and 31,107 recorded Skype chats that included discussions about plans and logistical support for attacks against Assad's forces.
    • The victims: The targets included armed opposition fighters, media activists, aid workers, etc. The victims were located in Syria, the wider region and beyond.
    • Tactics and techniques: The perpetrators used female Skype avatars to initiate conversations with their targets and infect their devices with malware. “She” would ask the target if they were using Skype on an Android device or a computer, in an attempt to send malware specifically tailored for the device. The perpetrators also maintained a seemingly pro-opposition website that contained links to malicious downloads and Facebook profiles, also with malicious links. They conducted these operations using servers located outside of Syria.
    • Malware: The perpetrators used a wide range of malware tools, suggesting access to development capabilities. They used both widely available and custom malware to hit their targets, including the DarkComet RAT, a specially crafted keylogger, and media with different shellcode payloads.
  • Possible sponsors: Although there is only limited evidence regarding the origin of the activity, Fire Eye's research has pointed to multiple references to Lebanon - both in the context of the malware study and in the activity of the avatars on social networks.

Types of information that were stolen

The unknown actors gathered a significant amount of data, from databases for Skype accounts to documents with schematics and photographs. Most of this data was collected from May 2013 to December of the same year. Some of the databases they stole date back to 2012. «The actors carefully chose what they stole, there were only a few instances where movies, empty files, licenses, baby photographs, school documents and other seemingly unrelated materials were downloaded.».

The volume of data

 

SYRIAThe «radiography» of the data that were stolen was as follows: 7.7 GB of stolen data, 12,356 contacts, 64 databases from Skype accounts, 31,107 conversations, 240,381 messages.

Primary objective was military‑type information, and particular emphasis seemed to be placed on files with name lists. Dozens of lists with fighter names who were members of armed groups were found. Some lists included names and dates of birth, while others contained weapons and the serial numbers of men, blood groups and phone numbers.

The actors also stole lists of officers in the forces of Asant and images of alleged Hezbollah fighters who had been captured or killed inside Syria, as well as images of fighting‑age men with weapons or paramilitary uniforms. Additionally, political‑content chat logs were also stolen, as the interlocutors discussed alliances and criticized individuals. Some files contained details about the opposition’s political structures, including the formations of political parties, etc. Moreover, material was obtained concerning humanitarian activities in Syria and surrounding countries, refugee data, information about media operations, and certificates that would allow monitoring the opposition’s communications over time.

The digital «abduction»

CHAT

The use of female avatars was a key characteristic of the campaign, aimed at initiating discussions with men of the Syrian opposition on Skype and followed by linking on Facebook. The avatars had realistic names for the area and approached victims with a series of personal questions. The first two were usually «how do you log into Skype?"

With a computer or with your phone?» and “how old are you?». The first is considered to have aimed to determine what kind of malware should be sent to compromise the target's device. Then they requested a photo of the victim and sent a “personal photo»” of the woman in exchange. The “photo»” was actually an executable file, which, when the user executed it, displayed a photo of a woman while simultaneously the DarkComet RAT ran in the background. From then on, the victim's computer was under the control of the perpetrators.

The remaining personal questions are considered to have helped the actors gather information about the target. Sometimes they would restart discussions with victims after a long absence to collect additional details.

Origin

The means and tactics of the actors contrast with methods used by other Syrian groups. Additionally, there are indications that the organization may have its headquarters outside of Syria.

The malware that was used does not share administration and control servers (command&control servers) with corresponding activity that has been recorded by companies such as Kaspersky, Trend Micro, CitizenLab and the Electronic Frontier Foundation. Furthermore, the activity does not align with tactics or means related to activity that is associated with ISIS. Indicators found point towards Lebanon, as there are several references, some of which on social media pages suggest that the avatars belong to refugees in the country, or to citizens of Lebanon.

Conclusions

As emphasized at the end of the research, unlike other activities that have been recorded, it is not simply cyber‑espionage aimed at gaining an informational advantage or achieving a strategic goal. Instead’ this activity, which takes place amid an ongoing conflict, provides useful military intelligence that can be exploited for immediate advantages on the battlefield. It provides the kind of information that can cut off a vital supply route, reveal a planned ambush, and identify and enable the tracking of important individuals. This information likely plays a significant role in the opponent’s operational plans and tactical decisions. However, this tactical advantage comes with a potentially devastating human cost».

Huffingtonpost

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS