HomeSecurityGrizzly Steppe: FBI, DHS response to Russian Hacking

Grizzly Steppe: FBI, DHS response to Russian Hacking

Grizzly Steppe: As “evidence” and to document the unprecedented act of expelling 35 Russian diplomats and closing two Russian compounds without a significant simultaneous political or diplomatic incident, or any act of war, the Department of Homeland Security (DHS) and the FBI have published a 13-page “report” justifying the above acts “for the breach and exploitation of networks and parameters related to the US elections”, i.e., the hack.

As DHS writes, “this document provides technical details about the tools and infrastructure used by Russian civil and military intelligence services (RIS) to compromise and exploit networks and parameters related to the U.S. election, as well as U.S. government politicians, and private sector sectors. The U.S. government refers to this malicious cyber activity by RIS as GRIZZLY STEPPE.”Grizzly Steppe

From the very beginning of the report, there is a broad disclaimer that everything contained in it may be completely wrong.

“This report is provided for informational purposes only. The Department of Homeland Security (DHS) makes no warranty of any kind regarding the information contained herein. DHS does not endorse any commercial product or service referenced herein.”

The sequel raises questions as there is an allegation that Russia tampered with the election, and the 13-page report purportedly provides technical details regarding the tools and infrastructure used by Russian intelligence services.

Grizzly Steppe:

So, with this useful background in mind, we present some of the most notable excerpts from the report referring to two alleged Russian groups – APT and APT 28.

The US government confirms that two different RIS actors were involved in the US intrusion. The first group, also known as Advanced Persistent Threat (APT) 29, attacked party systems in the summer of 2015, while the second, also known as APT28, operated in the spring of 2016.

Both groups have previously carried out targeted attacks on government organizations, think tanks, universities, and companies around the world. APT29 has been observed conducting targeted spearphishing campaigns using web links that lead to malicious Remote Access Tools (RATs).

APT28 is known for using domains that closely mimic those of targeted organizations and aim to deceive potential victims by stealing legitimate credentials.

Once the two groups APT28 and APT29 gain access to their victims’ data, they collect and analyze the information to gain value for intelligence agencies. These groups use this information to create highly targeted spearphishing campaigns.

The entire report published today is at the end of the publication, and comes as retaliation against Russia for Operation Grizzly Steppe by the Obama administration.

It should be noted that the intelligence community in October officially attributed the attacks to Russia, but provided no evidence to support its assessment. It is unclear whether this DHS report is trying to pass off as “proof” that Russia hacked the US election, because if they do, Putin will be laughing all night.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS