Showing posts with label Cyber Attack. Show all posts
Showing posts with label Cyber Attack. Show all posts

Saturday, April 13, 2019

US tried to coax Iranian expat into sabotaging Iran’s power grid

An Iranian-American engineer was reportedly approached by the US State Department with an offer of cash for sabotage of Iran’s power grid, says journalist Sharmine Narwani in her article, titled: “US Tried to Coax Iranian Expat into Sabotaging Iran’s Power Grid”.
It took a country-wide power outage in Venezuela, whispers of a cyberattack, and smug tweets from US officials to make me suddenly recall the cloak-and-dagger story of a close Iranian-American friend nine years ago.
My friend, an engineer — who I will not name for obvious reasons and who I will call ‘Kourosh’ for the purpose of this article — revealed to me in 2010 that he was approached by two “State Department employees” who offered him $250,000 to “do something very simple” during his upcoming trip to Tehran.
Kourosh was freaking out because he didn’t know how these guys knew he was going to Iran in the first place, and how they knew he was “cash-strapped,” in the second.
He wasn’t a particularly political person. He was just one of the thousands of Iranian-American engineers in the Washington-Maryland-Virginia technology belt looking to make a decent living.
Kourosh told the US officials that he was not interested, that if Iran needed to make changes, Iranians inside the country were the only ones who should do it.
I begged him to let me write this story, but he was very nervous and declined. Over the next year or two, I pushed some more and he gave me further information, but wouldn’t budge on its publication.
Here is what he revealed: The State Department guys had since approached him a second time. They offered him further details about the job. They wanted him to disable Tehran’s power grid in exchange for the $250k. They needed someone with technical skills but said the job was a simple one. He would have to go to a specific location in the Tehran area with a laptop or similar communication device and punch in a code.
Kourosh even told me the code. Said he had memorized it and could recite it in his sleep. Here it is: 32-B6-B10–40-E (symbol for epsilon).
Okay, that’s not the actual code, but it looks exactly like that — same format, same sequence and amount of numbers and letters. I don’t feel comfortable publishing the code in case it is still relevant — sorry. If anyone knows what this code could be, please comment below.
A colleague with an engineering background has this to say about it: “This could be a password for power grids or any equipment that is governed by an electronic or computer system. Manufacturers have codes they use for de-bugging or resetting a system. Control systems are all electronic and sometimes for any reason (like an earthquake) something is triggered and the system goes off. And then you reset it within the vicinity of the system usually and feed in the new code. You don’t have to physically be there if you can hack into it, but that’s of course harder. If they (the Americans) needed to have someone physically there during the sabotage attempt, it probably means they didn’t have remote access to the system.”
I don’t actually know why Kourosh received that level of detail unless he was willing to go through with this act of sabotage on behalf of the US government, but he assured me he would never consider it — that he was just “curious” during the second meeting. “No way,” he told me.
Imagine if I did it and someone’s grandmother or father died because their life support machine switched off.”
I remember these details because I discussed it with a number of people in and around 2010, without disclosing Kourosh’s name. Today, I dug up the old Facebook message I sent to Iranian-American author and activist Trita Parsi of the DC-based National Iranian-American Council (NIAC), a fellow Huffington Post blogger at the time. Trita gave me permission to post screenshots.
Disclosure: My Iranian-American husband and I ran an internet company in the telecommunications industry in Washington years ago and I was a founding member of the Iranian-American Technology Council, so I knew a lot of engineers and technology folks from that very background.
I recall writing to Trita precisely because he was so keyed into the political heart of this community. It would be extremely dangerous for myself and colleagues in my industry if the US government was recruiting Iranian-American civilian engineers as saboteurs in third countries.
This deep-dive by investigative journalist Whitney Webb into Venezuela’s power outage reveals some interesting details about a Bush administration cyberattack plan against Iran. Exposed by the New York Times in 2016, the “Nitro Zeus” plan — which involved the US Cyber Command — would, among other things, target crucial parts of Iran’s electricity grid.
Take note, however, that US officials asked Kourosh to sabotage Tehran’s power grid during the Obama administration. Obviously, aspects of the Nitro Zeus plan remained on the table despite a switch in government, political parties and policies.
Now back to Venezuela. It’s been a grueling week for Venezuelans dealing with the nationwide blackout that has brought the country to a standstill. Recently, a supposed “accident” at the Guri Dam power plant in Bolivar state — which generates around 80% of the country’s electricity — left at least 20 out of 23 Venezuelan states without electricity.
As power started to flood back to central states, a second “cyberattack” on Saturday plunged the country back into darkness. Government authorities have charged US officials with launching the attack on Venezuela’s electricity infrastructure and say they will present evidence of this to the United Nations and other international organizations.
The US has countered, blaming the power outage on corruption and infrastructure neglect by the government of President Nicolás Maduro — against whom Washington has been staging a rather unsuccessful coup effort these past months.
US Secretary of State, the gangster-looking Mike Pompeo tweeted: “No food. No medicine. Now, no power. Next, no Maduro.”
But in the midst of this to-and-fro between longtime adversaries, insightful news reports and analysis are starting to emerge, suggesting that a US cyberattack against Venezuela’s power grid is actually a very possible — even likely — scenario.
Says Forbes Magazine‘s Kalev Leetaru: “In the case of Venezuela, the idea of a government like the United States remotely interfering with its power grid is actually quite realistic. Remote cyber operations rarely require a significant ground presence, making them the ideal deniable influence operation.”
Widespread power and connectivity outages like the one Venezuela experienced last week are also straight from the modern cyber playbook. Cutting power at rush hour, ensuring maximal impact on civilian society and plenty of mediagenic post-apocalyptic imagery, fits squarely into the mold of a traditional influence operation,” he continues.
For those of us who have spent years covering US irregular warfare in West Asia, infrastructure targets are part and parcel of these wars — sometimes via direct strikes, other times via proxies and sabotage operations.
I’m not just talking about cyberattacks of the US and the Israelis.
In Syria, for instance, the US military specifically targeted major economic infrastructure under the guise of ‘fighting Daesh.’ These include but are not limited to oilfields, wells and facilities, electrical transformer stations, gas plants, bridges, canals, a number of vital dams and reservoirs in the country’s northern agricultural belt — and power generation facilities.
And US-backed proxies — part of the Pentagon and CIA’s ‘irregular army’ in Syria — targeted bread factories, wheat silos and flour mills to deprive a population of basic food staples.
As opposed to conventional wars, US irregular warfare seeks to covertly use influence ops to turn the largest part of a country’s population, the “uncommitted middle,” into supporting regime-change. Destroying infrastructure, creating shortages, unleashing political violence, propaganda dissemination — these are all steps outlined in the US military’s Special Forces Unconventional Warfare manual to create a disgruntled population that will turn on its government.
And cyber warfare is the newest theater of engagement for the Pentagon, which is now openly ramping up its investment in “lethal cyber weapons,” regardless of the civilian casualties these attacks will leave in their wake.
So far in Venezuela, around 20 people are reported dead due to the blackouts, though I’ve seen some opposition sources place that number north of 70.
Is Venezuela’s blackout part of US cyber warfare against a Latin American adversary? Has the US engaged in cyberwarfare against Iranian infrastructure?
Does a duck quack?

Wednesday, March 13, 2019

Lights out! Did Trump and his Neocons recycle Bush-era plan to knock out Venezuela’s power grid?

Whitney Webb
Even as the Venezuelan government held the US responsible for the recent power outage, calling it “sabotage,” and saying the US has long had a plan on the books for targeting the civilian power grid of adversarial nations.
These were the remarks of Chile-based US journalist Whitney Webb in her report for MintPress, titled: Lights out! Did Trump and his Neocons recycle Bush-era plan to knock out Venezuela’s power grid?
For nearly four days, much of Venezuela has been without power, bringing the country’s embattled economy to a near standstill. Though power is now returning, the outage saw US officials and politicians blame the Venezuelan government for the crisis while officials in Caracas charged the US with conducting “sabotage” and launching cyberattacks that targeted its civilian power grid as well as of employing saboteurs within Venezuela.
Although many mainstream media outlets have echoed the official US government response, some journalists have strayed from the pack. One notable example is Kalev Leetaru, who wrote at Forbes that “the United States remotely interfering with its [Venezuela’s] power grid is actually quite realistic.”
Leetaru also noted that “timing such an outage to occur at a moment of societal upheaval in a way that delegitimizes the current government, exactly as a government-in-waiting has presented itself as a ready alternative, is actually one of the tactics” he had previously explored in a 2015 article detailing US government hybrid warfare tactics “to weaken an adversary prior to conventional invasion or to forcibly and deniably effect a transition in a foreign government.”
In addition to Leetaru’s claims, others have asserted US government involvement after US Senator Marco Rubio (Republican - Florida), who is deeply involved in Trump’s Venezuela policy, appeared to have prior knowledge that the blackouts would occur when he tweeted about them only three minutes after they had begun.
While several journalists have pointed out that the probability that the Trump administration was responsible for the blackout is highly likely, few — if any — pointed out that the US has long had highly developed plans involving the use of cyberattacks to attack critical power-grid infrastructure in countries targeted for regime change by Washington.
Indeed, the most well-known plan of this type, known by its codename “Nitro Zeus,” was originally created under the George W. Bush administration and was aimed at Iran. With so many former Bush officials now calling the shots in the Trump administration, particularly its Venezuela policy, the potential return of a “Nitro Zeus” virus, this time tailored to Venezuela, seems increasingly likely.
It is could be called a little hammer to use when big hammers have been nixed.
The “Nitro Zeus” plan first came to light in a November 2016 exposé published in the New York Times, which described it as an “elaborate plan” that was created for use against Iran were negotiations over its nuclear program to fail.
That program intended to target “Iran’s air defenses, communications systems and crucial parts of its power grid. At its height it “involved thousands of American military and intelligence personnel” and is believed to have cost tens of millions of dollars. The program intimately involved both the National Security Agency’s Tailored Access Operations unit and the US Cyber Command.
The program was shelved when the Joint Comprehensive Plan of Action (JCPOA) was established, though the Trump administration’s decision to unilaterally withdraw from the deal has led some to ask whether the Trump administration has been considering reviving the program. While they may not have revived it for use against Iran – because of Iran’s potential and mastery of sophisticated technology to cripple the system in the US itself – they instead may have done so in Venezuela, if Venezuelan government assertions that a US cyberattack is to blame for much of the country’s recent power outage are to be believed.
Indeed, Leetaru noted in his recent Forbes article that “given the US government’s longstanding concern with Venezuela’s government, it is likely that the US already maintains a deep presence within the country’s national infrastructure grid,” much as it did with Iran in connection with the Nitro Zeus program prior to its public revelation three years ago.
The Nitro Zeus program is not nearly as well known as its relative, the Stuxnet virus, which was co-developed by the US and Israel. Yet Nitro Zeus, despite its relative lack of infamy, is notable for several reasons. First, it “took it [US cyberwarfare] to a new level,” according to a former official involved in the project cited by the Times. This was because, prior to Nitro Zeus, “the US had never assembled a combined cyber and kinetic attack plan on this scale,” and also because executing the program would have “significant effects on civilians, particularly if the United States had to cut vast swaths of the country’s electrical grid and communications networks.”
Another reason Nitro Zeus is notable, particularly in light of US efforts to meddle in Venezuela, is the motive for its creation. Indeed, although Nitro Zeus became the “enormous, and enormously complex” program detailed by the Times during the Obama administration, work on the program had actually begun during the George W. Bush administration. According to a report in the Daily Beast, Bush had considered Nitro Zeus “a necessary tactical alternative after the Iraq War sabotaged his chances of starting another Middle East invasion.” In other words, after the Iraq War debacle made it more difficult for the US to launch unilateral military interventions, the Bush administration opted to develop “non-kinetic” military tools that would avoid angering the US public and US allies abroad.
Furthermore, as Tyler Rogoway wrote at Foxtrot Alpha: “[Programs like Nitro Zeus] can be paired for synergistic effect, leaving its target country’s military blind and deaf and its population suffering. And all this can be had without ever dropping a bomb and even under the veil of plausible deniability.”
This, according to Rogoway, has led such programs to become “more and more a viable alternative to traditional forms of attack,” given that the US can deny its involvement, avoiding potential diplomatic blowback, and because it can wreak havoc not just on a country’s military but its civilian population.
The logic behind the likelihood of US cyber sabotage is obvious.
While “Nitro Zeus” was never unleashed upon Iran – because of obvious reasons, especially the Islamic Republic’s ability to retaliate in like manner – it’s likely that the program spawned similar attack plans on the power grids of other adversarial nations given the precedent it set. As the Times pointed out in its Nitro Zeus exposé: “The United States military develops contingency plans for all kinds of possible conflicts, such as a North Korean attack on the South, loose nuclear weapons in South Asia or uprisings in Africa or Latin America. Most sit on the shelf, and are updated every few years.”
This point was expanded upon by Rogoway, who noted: “Nitro Zeus is most likely one of a whole slew of plans to attack potential enemies via cyber weaponry. Plans surely exist for all of America’s potential adversaries, and some are likely to be far more elaborate and deadly than anything that has been disclosed to date.”
There are more than a few indications that many of the more aggressive “contingency plans” have moved to the top of the toolbox under the Trump administration. For instance, key former Bush officials that are now in the Trump administration, particularly John Bolton and Elliot Abrams, are known for their aggressive stances and willingness to promote extreme policies targeting adversaries, even those policies that harm or kill scores of innocent civilians. Thus, voices like those in the Obama State Department and National Security Council, who had warned of the potential adverse effects on civilians that a Nitro Zeus blackout could cause, are unlikely to influence the likes of Bolton and Abrams — who have an outsized role in creating the administration’s Venezuela policy.
Furthermore, such a plan would be considered valuable by Bolton and Abrams in the same way that Bush valued Nitro Zeus after his “hands were tied” following the Iraq War disaster. In regard to Venezuela, Bolton and Abrams similarly have their hands tied when it comes to military action, given that military intervention of any type has been resoundingly rejected by the US allies in Latin America and elsewhere. Not only that but Abrams’ favored tactic of providing arms disguised as “humanitarian aid” to insurgents has also failed, limiting the aggressive actions that can be taken by the administration.
Unable to launch a military intervention — either overt or covert — a Nitro Zeus cyberattack would likely have been a top contender for a next step following the failed “humanitarian aid” stunt and the rejection of any type of military intervention by the US’ Latin American allies.
In addition, many of those responsible for the creation of the Nitro Zeus program share connections with neoconservatives who are influential in the Trump administration. For instance, Keith Alexander — who was NSA director at the time the Nitro Zeus program began and for much of its development — is now the CEO of his new cybersecurity consultancy, IronNet Cybersecurity. Sitting on IronNet’s board of directors alongside Alexander is Jack Keane, a zealously pro-war retired general whom Trump valued enough to offer the position of Secretary of Defense, an offer Keane declined. Keane is a close associate of the neoconservative Kagan family and is currently chairman of the Institute for the Study of War, founded by Kimberly Kagan and financed by top US weapons companies.
With Bush-era warmongers now dominating Trump’s Venezuela policy, it seems increasingly likely that efforts to revive the Bush/Obama-era Nitro Zeus program have taken place. Indeed, with such an enormous and complex program already on the books and the likely existence of spin-off programs that have developed over the past decade, it was likely the easiest route for another “aggressive” US-backed measure targeting the Venezuelan government.
However, if the US did conduct a cyberattack on Venezuela’s power grid, it would not be powerful neoconservatives in the administration who would ultimately be to blame, as only the US president can authorize an offensive cyberattack. Thus, if any part of Venezuela’s current blackout was indeed US-directed sabotage, it was President Donald Trump who gave the order to attack Venezuela’s civilian power infrastructure, a strange thing to do for someone who professes to care so much for the Venezuelan people.