Categories
Michael Novakhov's favorite articles

Was Vladimir Putin a German Agent?


gettyimages-961037694-594x594

Russian President Vladimir Putin visits Sochi, Russia. Putin served as an officer in the KGB, the Soviet-era intelligence services, in the East German city of Dresden until 1990.
Mikhail Svetlov/Getty Images

Russian President Vladimir Putin once owned an ID card for East Germany’s Stasi, the Soviet-era secret police, according to a German publication.

The Stasi identification card, which was first reported on by the German newspaper Bild on Tuesday, was valid until 1989 and bore the name “Major Vladimir Putin.” It also had Putin’s photograph and signature.

The ID was discovered by historical archivists handling Stasi personnel files.

Putin served as an officer of the KGB in the East German city of Dresden until 1990. Fluent in German, he adopted the cover of a translator.

German officials told Bild that the Stasi ID card would have allowed Putin to enter East German government buildings without having to identify himself as a KGB agent. He also would have been able to recruit members of the Stasi to work for the KGB. Kremlin spokesperson Dmitry Peskov noted that the Stasi and the KGB worked closely together and may have exchanged documents.

“My guess is that in the Soviet era, the KGB and the Stasi were partners and for this reason one should not rule out they might have exchanged identification papers and passes,” Peskov told reporters, directing any further questions about the report to Russia’s foreign intelligence services.

gettyimages-961037694-594x594

Russian President Vladimir Putin visits Sochi, Russia. Putin served as an officer in the KGB, the Soviet-era intelligence services, in the East German city of Dresden until 1990.
Mikhail Svetlov/Getty Images

Researchers have noted that the two agencies worked closely together until the collapse of communism and the fall of the Berlin Wall in 1989.

“The East German Ministry for State Security (MfS or Stasi) was established and developed under the strict control of the Soviet secret services (the NKVD, the MGB, and finally the KGB). Up until the very end of its existence, the MfS worked closely together with the KGB,” a report from the Cold War International History Project and the Office of the Federal Commissioner for the Stasi Records said.

“Established in February 1950, the East German Ministry for State Security (MfS) never overcame its subordination to the Soviet secret service. [German communist official Erich] Mielke himself characterized the Stasi as ‘a fighting division of the renowned Soviet Cheka’– a general term for the Soviet secret police,” the report continued.

Putin began working for the KGB in St. Petersburg, Russia, after he finished his law degree in the mid-1970s. East Germany was his first foreign posting. He began his career when then KGB chairman Yuri Andropov was pushing to hire new young recruits. Still, he had a lifelong interest in espionage even before he began his career in the secret service, according to his biographers.

Newsweek is committed to challenging conventional wisdom and finding connections in the search for common ground.

Newsweek is committed to challenging conventional wisdom and finding connections in the search for common ground.


Cristina Maza

Cristina Maza is an award-winning journalist who has reported from countries such as Cambodia, Kyrgyzstan, India, Lithuania, Serbia, and Turkey. She previously worked as a reporter for the Phnom Penh Post in Cambodia, and as a reporting fellow covering energy and cybersecurity for the Christian Science Monitor in Washington D.C. She writes frequently about international affairs, politics, global development, religion, defense, and cybersecurity. 

Cristina Maza is an award-winning journalist who has reported from countries such as Cambodia, Kyrgyzstan, India, Lithuania, Serbia, and Turkey. …
Read more

To read how Newsweek uses AI as a newsroom tool, Click here.


Categories
(@mikenov) / Twitter

@GlasnostGone: RT by @mikenov: “Who is Orban working for? Answer: Putin. And why is the EU doing nothing to stop him?” #Hungary should be stopped from “…



Categories
(@mikenov) / Twitter

@mikenov: Is Putin a German agent?



Categories
Michael Novakhov's favorite articles

Mandiant Unveils Russian GRU’s Cyber Playbook Against Ukraine


Drawing on its tracking of Russia-backed disruptive operations against Ukraine since the country’s invasion of its neighbor in February 2022, Mandiant observed that multiple distinct Russian threat clusters have been persistently using the same, repeatable playbook throughout the war to pursue Russia’s information confrontation objectives.

The cybersecurity firm, now part of Google Cloud, presented its findings in a blog post published on July 12, 2023.

This playbook, crafted by the Russian military intelligence service (GRU), contains the following five operational phases:

  1. Living on the Edge: Leveraging hard-to-detect compromised edge infrastructure such as routers, VPNs, firewalls and email servers to gain and regain initial access into targets
  2. Living off the Land: Using built-in tools such as operating system components or pre-installed software for reconnaissance, lateral movement and information theft on target networks, likely aiming to limit their malware footprint and evade detection
  3. Going for the GPO: Creating persistent, privileged access from which wipers can be deployed via group policy objects (GPO) using a tried-and-true PowerShell script
  4. Disrupt and Deny: Deploying ‘pure’ wipers and other low-equity disruptive tools such as ransomware to fit a variety of contexts and scenarios
  5. Telegraphing ‘Success’: Amplifying the narrative of successful disruption via a series of hacktivist personas on Telegram, regardless of the actual impact of the operation

The GRU’s Disruptive Playbook. Source: MandiantThe GRU’s Disruptive Playbook. Source: Mandiant

Typically, after an initial reconnaissance, Russian cyber operations since the beginning of the war in Ukraine would start compromising systems with the ‘living on the edge’ phase. Then, the adversary would establish a foothold in the system, maintain its presence and escalate privileges with ‘living off the land’ methods. It would then combine these methods with group policy objects to move laterally and conduct further reconnaissance within the internal systems. Finally, it would deploy the malware (wipers, ransomware…) and launch a Telegram campaign to amplify the operation’s success at the same time.

A Deliberate Effort from the GRU to Go Quick and Dirty

Mandiant has observed that this same playbook has been used by various threat actors throughout the six phases of the war identified by Mandiant researchers – five of which were outlined in Google Threat Analysis Group’s (TAG) February analysis, reported by Infosecurity.

This led Mandiant to confirm the GRU’s “central role in standardizing operations across multiple subteams in an attempt to deliver more repeatable, consistent effects,” the report reads.

Phases of Russian Cyber Operations during the war in Ukraine. Source: MandiantPhases of Russian Cyber Operations during the war in Ukraine. Source: Mandiant

As most phases aim to deploy and execute disruptive malware quickly while avoiding detection, Mandiant noted that the playbook is “notably suited for a fast-paced and highly contested operating environment, indicating that Russia’s wartime goals have likely guided the GRU’s chosen tactical courses of action.”   

The company also assessed “with moderate confidence that this standard concept of operations highly likely represents a deliberate effort to increase the speed, scale and intensity at which the GRU could conduct offensive cyber operations while minimizing the odds of detection.”

A Shift from Previous GRU Methods

Dan Black and Gabby Roncone, the report’s authors, also noted that while the general intent of the GRU is aligned with previous Russia-aligned cyber campaigns – “to irreversibly destroy data and disrupt the ability of target systems to function as intended” – the design of the disruptive malware the GRU has chosen to use during the war is substantively different from what was previously observed.

Read more on Mandiant’s 2023 M-Trends report

First, since the beginning of the war in Ukraine, Russian threat actors have shifted from deploying pure, sometimes pre-packaged, disruptive tools that can be used immediately – but that were usually not reused much – to multifunctional and highly reusable ones.

Second, the GRU has extended its use of “noteworthy political actors and hacktivist identities” in its disruptive playbook. From 2014 to 2018, Mandiant saw the emergence of several ‘personas’ (CyberBerkut, CyberCaliphate, Guccifer 2.0…) that allowed the GRU “to misdirect attribution and generate second-order psychological effects from their cyber operations.”

Since the beginning of the war in Ukraine, some new, self-proclaimed hacktivist groups have started appearing (CyberArmyofRussia_Reborn, XakNet Team,  Infoccentr…). These took a more active role than the previous category of personas: besides supporting the Russian regime, they actively amplified and exaggerated the impact of the cyber-attacks conducted by Russian hackers, and some were even observed to leak data from victims who were also affected by wiper attacks. All this primarily happened on Telegram, “which has emerged as a critical source of sensemaking, war-related information operations, and a key recruitment platform for volunteer cyber “armies” in the conflict,” wrote Mandiant researchers.

UNC3810 and CyberArmyofRussia_Reborn’s Links to the GRU

One notable example highlighted by Mandiant is the deployment of CaddyWiper in October 2022 by a threat group the cybersecurity firm tracks as UNC3810.

The researchers wrote: “In the final stage of the playbook, data from the victim of UNC3810’s wiper attack was staged and advertised on Telegram by ‘CyberArmyofRussia_Reborn,’ […] that claimed responsibility for the wiper attack. However, technical artifacts from the UNC3810’s intrusion indicate that the ‘CyberArmyofRussia_Reborn’ persona severely exaggerated the success of the wiper attack. Due to a series of operator errors, UNC3810 was unable to complete the wiper attack before the Telegram post boasting of the disrupted network. Instead, the Telegram post preceded CADDYWIPER’s execution by 35 minutes, undermining CyberArmyofRussia_Reborn’s repeated claims of independence from the GRU.”

According to Dan Black on Twitter, this operation failure shows the two groups’ “integrated forward planning and the Telegram channel’s high confidence links to the GRU.”

alt pitch: come for the Playbook, stay for the “oopsies” https://t.co/TfEFLV6eay

— Gabby Roncone 🌻 @gabr.bsky.social (@gabby_roncone) July 12, 2023

In its conclusion, Mandiant said it “anticipates that similar operational approaches, or ‘playbooks,’ may be mirrored in future crises and conflict scenarios where requirements to support high volumes of disruptive cyber operations are present.”


Categories
(@mikenov) / Twitter

@mikenov: IV Железнодорожный съезд • Президент России https://t.co/XjVY6hqsaT https://t.co/8o0XRExOv9



Categories
(@mikenov) / Twitter

@dw_russian: RT by @mikenov: Поддержка Украины дешево обходится Европе, считает немецкий эксперт Бенджамин Таллис. Он и более 20 экспертов подписали обр…



Categories
(@mikenov) / Twitter

@haaretzcom: RT by @mikenov: Britain, and more than a dozen partner countries, including Australia, Canada and France, have called on Israel to take imm…



Categories
(@mikenov) / Twitter

@mikenov: IV Железнодорожный съезд • Президент России https://t.co/GHwhcZnjwE https://t.co/1XORcClhOq



Categories
(@mikenov) / Twitter

@mikenov: Встреча с руководителями фракций Государственной Думы • Президент России https://t.co/Ra9jlqFcX8 https://t.co/qJn7ZtOSEl



Categories
(@mikenov) / Twitter

@dw_russian: RT by @mikenov: СБУ объявила в розыск патриарха Кирилла. Согласно информации, размещенной на сайте украинского МВД, патриарх Московский раз…