Every accusation is also an admission with these guys.
There isn’t always a claim to their attacks, but the evidence frames them very easily… Most always cover the same modus operandi, so much so that I consider it their signature.
Five Eyes Nations can eat a dick for all I care. They’ll warn of their adversaries actions but insist that they operate under an absurd amount of secrecy with enormous budgets.
5/9/14 eyes is some 1984 bullshit.
Yes, no one is truly holy, we know that. Mass surveillance is undertaken by all states, some in less invasive ways and some in outright abuse. But you also have to consider states that rely on cybercrime to attack an adversary and those that defend their citizens/customers only with ito… That’s the difference in a nutshell.
The university I work for had a flood of phishing right after Russia started attacking Ukraine. It’s hard to know who was behind the attacks, but our best guess was criminals harbored and directed by the Russian state. We are a university, we’re not out to hurt anyone. This is just yet more innocent civilians getting hurt because Russia got angry that Ukraine turned out to be a tougher pill to swallow than it thought.
Yes, according to my sources, a phishing campaign has been going on since the beginning of the invasion. The problem that knowing exactly who is behind it is a bit difficult, it starts from almost all over the world, and pointing the finger at someone is just unethical: until proven otherwise it can also be the Ukrainians themselves or even criminal groups that are exploiting the situation, not necessarily the Russians.
Removed by mod
Dude you’re getting confused, those are the Russians doing propaganda about the Ukrainians.
Removed by mod
Doesn’t make any sense! Does Russia have any incentive at phishing your university? Why would they waste their scarce resources in time of hardships just to phish some university website?
Nation states and criminal organizations have considered universities a valuable target for a long time now. Easier than financial institutions and military targets, campus-wide networks, sensitive data on thousands and thousands of students, often lots of powerful hardware and even research equipment to botnet or abuse for processing/mining coing. Lots of value in owning them.
It could be a very important university to even be considered strategic for an opposing state, you also have to consider the fact that at the level of military strategy it can be a target to prevent culturally growing people… That’s why I’m not surprised. Then it is not only the university, it is the whole country that is affected.
Unless you wanted to make a strategic strike on the US’s urban planning & policy capabilities, I’m afraid it wouldn’t do much. We’re a fairly large university, but we don’t have a whole lot of mind share among the general population.
Everything you do is probably always an ulterior motive for your country, rest assured that every state makes money on it for everything you produce. Now it may be that the “phishing” that hit your university may actually be an isolated thing, but it may be hiding behind a plan that probably no one can know about.
I just learned that we do have at least one government grant that could mean sensitive information going through our systems. It’s fully a defensive/hardening grant, but it could still make us a target.
You may have discovered one of the possible reasons why they attempted phishing. And I can confirm that most universities, as well as private companies, work with their country’s government… So I’m not even surprised.
It’s just retribution and harassment. From what I understand, the way it works is that the Russian state harbors criminals as long as they don’t attack Russian targets. So in some cases, the malware they used literally checked for a Russian language pack on Windows and left the computer alone if it found that. They are essentially modern day privateers, harassing soft targets of an adversary.
I wouldn’t be confident assuming “it’s just retribution”, it’s tactically useful. More detail in https://lemmy.ml/post/239272/comment/165414
May I ask for which university?
I’m not sure that I should say (though it’s not exactly a secret if you do some work).
Removed by mod
People started upvoting me and downvoting him/her. But my question was legit. I wasn’t trying falsify his arguments. I was just curious because I have heard of similar things near me.
Nation states and criminal organizations have been doing that for years it’s not a new thing that just started happening.
In fact the method of phishing if exploited really properly for a state can be a really powerful weapon, more for the fact that it can involve so many people and less that it can cause damage to be legally actionable.
I don’t trust anything that comes out of Five Eyes spies.
Removed by mod