News: 1596182130

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

EU tries to get serious on cybercrime with first sanctions against Wannacry, NotPetya, CloudHopper crews

(2020/07/31)


The European Union has, for the first time ever, slapped sanctions on hacking crews.

The EU's Council of Ministers has [1]cracked down on six individuals and three companies in China, North Korea, and Russia for breaking into computer networks, stealing information, and spreading malware.

"Sanctions are one of the options available in the EU’s cyber diplomacy toolbox to prevent, deter and respond to malicious cyber activities directed against the EU or its member states, and today is the first time the EU has used this tool," the [2]EU said of the decision. "The legal framework for targeted restrictive measures against cyber-attacks was adopted in May 2019 and recently renewed."

The sanctions will take the form of asset freezes and travel bans, as well as blocks on any EU person or company doing business with any of those listed. Many of those sanctioned already face charges or restrictions in other countries, such as America.

One group on the receiving end of Europe's ire is the miscreants behind [3]Operation Cloud Hopper . As the name suggests, this gang hacked cloud providers who were hosting systems for European companies, and in some cases made off with those customers' intellectual property and trade secrets, mainly in the defense and aerospace sectors. IBM and HPE were said to be among Cloud Hopper's victims.

The EU said two individuals involved in the operation, Gao Qiang and Zhang Shilong ( [4]also wanted by the FBI), will now face sanctions, as will the company that served as their base of operations, Huaying Haitai. All are based out of Tianjin, China.

FYI Russia is totally hacking the West's labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies [5]READ MORE

Sanctions were next imposed on Russian miscreants behind the [6]2018 intrusion into the Wi-Fi network of a Dutch chemical-weapons watchdog, the Organisation for the Prohibition of Chemical Weapons (OPCW) in the Netherlands. Alexey Valeryevich Minin, Aleksei Sergeyvich Morenets, Evgenii Mikhaylovich Serebriakov, and Oleg Mikhaylovich Sotnikov are accused of renting a car and going war-driving by the OPCW to infiltrate the agency's wireless network and steal data.

At the time, OPCW was among the labs investigating the Kremlin-linked Novichok poisonings in England, and chemical weapons attacks in Syria.

Meanwhile, a Moscow-based team tied to GRU, the Russian military intelligence service, was sanctioned for its role in a pair of high-profile malware outbreaks: the GRU's Main Center for Special Technologies (GTsST) was said by the council to have been the source of the infamous [7]NotPetya malware. The 2017 outbreak of the ransomware crippled the machines of a number of large corporations and topped a billion dollars worth of damage in what was [8]called at the time the most expensive malware pandemic in history.

GTsST was also blamed for attacks on Ukranian power companies over the winter months spanning 2015 and 2016.

Finally, there's the Chosun Expo business, a North Korean financial operation that is said to have bankrolled the development and outbreak of the [9]WannaCry ransomware.

"WannaCry disrupted information systems around the world by targeting information systems with ransomware and blocking access to data," the council said. "It affected information systems of companies in the Union, including information systems relating to services necessary for the maintenance of essential services and economic activities within Member States."

Chosun Expo is also believed to be backing [10]Lazarus Group , a long-running North Korean hacking crew that boasts an impressive arsenal of hacking tools and largely targets financial institutions with its attacks. ®

Get our [11]Tech Resources



[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32020D1127&from=EN

[2] https://www.consilium.europa.eu/en/press/press-releases/2020/07/30/eu-imposes-the-first-ever-sanctions-against-cyber-attacks/

[3] https://www.theregister.com/2018/12/20/two_alleged_chinese_hackers/

[4] https://www.fbi.gov/wanted/cyber/zhang-shilong

[5] https://www.theregister.com/2020/07/16/russia_coronavirus_hacking/

[6] https://www.theregister.com/2018/10/04/gru_opcw_hack_bust/

[7] https://www.theregister.com/2017/06/28/petya_notpetya_ransomware/

[8] https://www.theregister.com/2018/06/27/notpetya_anniversary/

[9] https://www.theregister.com/2019/09/19/wannacry_analysis_sophos/

[10] https://www.theregister.com/2020/01/08/applejeus_malware_returns/

[11] https://whitepapers.theregister.com/

The Nation State seeks to maintain its Monopoly on Hacking

Anonymous Coward

as well as Violence.

Re: The Nation State seeks to maintain its Monopoly on Hacking

Gordon 10

I might suggest a small modification. The *western* Nation States would desire a Monopoly on Hacking

Also how out of date is this. No mention of anything released in the last couple of years. If you cant move faster than this its pretty pointless. any vunerable assets will be long gone/aliased.

Re: The Nation State seeks to maintain its Monopoly on Hacking

Anonymous Coward

The joke is that the Russian individuals hacking the Organisation for the Prohibitation of Chemical Weapons would very clearly have been doing so at the behest of the Russian state to find out what we knew about the high ranking Russian special operations types that supposedly came to the UK to enjoy the sights and then took a tourist stroll through a housing estate, smeared a weapon of mass destruction on the door of a house and then went back to Russia without seeing any of those sights.

Logically one would expect a strong response against Russia for the hacking attempt as well as the WMD usage.

Geopolitically though several EU states are dependent on Russia; Germany for instance since closing down their nuclear power plants has needed huge quantities of Russian gas to make up for the lost generating capacity that the green retoric said would be generated by Solar & Wind. Obviously it isin't being, and Germany's CO2 emissions have soared in proportion to their Russian gas imports. This which forces their foreign policy being to appease Russia or diversify suppliers. Russian gas is slightly cheaper precisely so Russia can use it as a political lever, so they (short shortsightedly and idiotically) go with the appeasement policy.

Since Germany has disproportionate influence in the EU they will therefore be blocking the EU sanctioning Russia in case upsetting them results in their gas getting more expensive, which means that you end up with an insanity of random sanctions of Russian shell companies and individuals instead of their bosses or the organisations actually responsible.

Sanctions?

Phil O'Sophical

if these people have been tried & convicted, then just confiscate their assets & jail them.

If they haven't yet been convicted, wouldn't this be an illegal extra-judicial punishment under the various human rights laws?

Re: Sanctions?

I ain't Spartacus

They can't be tried and convicted, because they can't be extradited. Unless they turn up voluntarily.

However I'd imagine that the decisions to put them on the sanctions list are challengeable in court - so there'll have to be some evidence - which is probably one reason the sanctions take so long to put in place. Also in the EU's case, all governments have to agree to sanctions, so that usually adds a few months while they negotiate.

The OPCW hacking was investigated by Dutch police, after a tip-off from the UK I think. From memory, they caught the guys red handed - but they were under diplomatic passports, so presumably had to be released.

Looks Like Too Little Far Too Late

Richard Jones 1

Not only have the horses bolted, they lived their lives and became someone's lunch before this action was taken.

Don't make a big deal out of everything; just deal with everything.