HomeinetISIS's cyber protection manual leaked

ISIS's cyber security manual leaked

Yesterday, several Twitter accounts announced a manual called ISIS OPSEC that outlines the terrorist group's cybersecurity practices. The leaked document, translated, describes various technical details that the group recommends to its new members.isis

While we initially thought the ISIS OPSEC manual was revealed by Anonymous' recent campaign against ISIS members, it appears that the US military has known about and studied the document for some time.

The Center for Combating Terrorism at West Point Military Academy has had the document since last year, and experts say it was written by the Kuwaity security firm to help journalists and political dissidents living in the Gaza Strip.

The original OPSEC document is written in Arabic (available here) and is supposed to help those who use it evade detection by Israeli intelligence.

Apparently, ISIS members obtained the document, presented it as their own, and began distributing it to their new members.

The content of the manual contains basic security tips, which aim to help beginners maintain a low profile and avoid detection by secret services.

ISIS's OPSEC manual details a range of services, devices, and applications that are permitted or prohibited.

So ISIS members can use:

● Twitter (via HTTPS or SMS)
● Tor Browser
● Aviator Browser
● Opera Mini Browser
● Photo GPS Editor (iOS app, remove geolocation data from photos)
● Cryptophone (encrypted phones)
● BlackPhone (encrypted phones)
● FireChat (IM client, connectivity issues)
● Tin-Can (connectivity issues)
● The Serval Mesh (connectivity issues)
● Freedome (VPN)
● Avast SecureLine! (VPN)
● TrueCrypt (on-the-fly data/disk encryption)
● VeraCrypt (on-the-fly data/disk encryption)
● BitLocker (Windows built-in, on-the-fly data/disk encryption)
● Hushmail (email provider)
● ProtonMail (email provider)
● Tutanota (email provider)
● Threema (encrypted IM client)
● Telegram (encrypted IM client)
● Surespot (encrypted IM client)
● Wickr (encrypted IM client)
● Cryptocat (encrypted IM client)
● PQChat (encrypted IM client)
● Sicher (encrypted IM client)
● iMessage (encrypted IM client)
● Linphone (encrypted VoIP)
● Swisscom (encrypted VoIP)
● Silent Circle (encrypted VoIP)
● RedPhone (encrypted VoIP)
● Signal (encrypted VoIP)
● Apple FaceTime (encrypted VoIP, audio & video)
● MEGA (cloud storage)
● SpiderOak (cloud storage)
● SugarSync (cloud storage)
● Copy.com (cloud storage)

In the blacklist, the manual mentions apps and services such as Facebook, Instagram, WhatsApp, and Dropbox.

The manual is complemented by a 24-hour help desk via Telegram. The help desk closed a few days ago.

IS-Encryption-Guide

IS Encryption Guide by AlyssaBereznak

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS