Hello !
| Cyber |
| Kaspersky, the Russian FSB, and the 'digital resistance' |
| 2026-05-12 |
| Direct Translation via Google Translate. Edited Text taken from the Telergam channel of natalya_kasperskaya_channel [ColonelCassad] Natalya Kaspersky on "digital resistance" in Russia. I didn't write yesterday, so as not to spoil the festive atmosphere. In recent days, an article about my humble self from the American publication The Bell (listed as a foreign agent in Russia) has been widely circulated online. This online media outlet is funded by Khodorkovsky and the CIA. The article claims that I allegedly met with the leadership of the FSB's 2nd Service and asked them to stop blocking internet resources, including VPNs. ![]() The "news" then spread through a ton of Telegram channels, and a ton of people commented on it. They expressed opinions, assumptions, judgments, and thoughts. Very useful and interesting, of course. But on a fictitious premise. It's a shame so many letters and emails were wasted. Because I never met with the leadership of the 2nd Service, or even the FSB at all. By the way, why do we in our country so eagerly and immediately embrace foreign-agent media? Hundreds of reposts, thousands of links. Our media, like bison in a thunderstorm, rush in a single direction. It's some amazing flaw in our media industry – this relentless retelling and interpretation of trashy foreign media. But first things first. About a week ago, Masha Kolomychenko, a journalist working for The Bell in the US, wrote to me on Telegram asking for a comment on my alleged meeting with FSB leadership. I've known Masha since her days at Kommersant. Masha is known for hallucinating, like ChatGPT. And anything you don't tell her will be twisted in unpredictable ways. So I chose not to respond at all. But three days later, Masha published these conjectures anyway, citing an "unknown source." Now let's get to the facts: 1. The article says I "suddenly defected" to the anti-blocking camp. That's not true. I didn't "defect." Since 2009, I've advocated for the rights of domestic developers and was one of the founders of the Domestic Software Developers Association. Back then, we were simply defending domestic developers from foreign dominance, and now we're defending them from the fact that their development tools are being blocked, essentially preventing them from doing their jobs. 2. Furthermore, as a professional data protection specialist, I oppose unified registries and all other personal data aggregators, which are guaranteed to leak personal data through government officials and IT professionals with access to it. 3. I haven't met with the FSB. Although, in connection with my statements against the "Unified Registry of Diseases and Conditions" some time ago—in March of this year—I was shown what appeared to be a report from the 2nd Service of the FSB. It was a printed, anonymous letter, unsigned and unmarked, hand-held, accusing me of "activities against the Unified Registry of Diseases, which is important for the country," and the conclusion was that I was deliberately engaging in political activity in the lead-up to the State Duma elections. Frankly, I don't follow political news, and at the time, I didn't even know we were having State Duma elections this year. But reading the anonymous letter made me wonder: why introduce the Unified Registry, which is guaranteed to provoke public backlash, especially in an election year? I certainly didn't lobby for the government order to introduce the Registry on March 1, 2026. 4. After this, I did indeed request a meeting with the Second Service to discuss these claims in person. However, so far no one from this respected agency has contacted me. Although it would be worth talking, especially if the rumors are true that they are now responsible for blocking data in Russia. 5. I discussed this possible meeting privately with colleagues, in a hypothetical format. Perhaps this conversation, poorly relayed through a broken telephone by some informants to Masha Kolomychenko, morphed into the frantic text that spread across the RuNet. In Telegram messages and other online publications, I'm practically described as the head of "Russia's digital resistance," which is rather amusing, because I've always sincerely considered myself a statist and patriot. But if someone in the government is taking obviously technically risky steps, someone has to point them out. As for "digital resistance," it's actually taking hold in the country; it's grassroots, like burning peat bogs, and it's reaching millions of people. I just witnessed a conversation between fruit sellers at a market near Moscow—two women well over sixty were enthusiastically discussing which VPN was best to use. I couldn't believe my ears—the market vendors' IT literacy has really improved! But these conversations aren't a political movement, but rather a habit people have developed with certain mobile services they'd like to keep, which someone has suddenly decided to deprive them of without justification or explanation. Unreasonable digital pressure provokes natural digital resistance—just like the laws of physics. At the same time, we clearly need a strong population resilience, given all the different things that have befallen our country recently – war, massive drone attacks, tax increases, economic problems, and everything else. To withstand all of this, we need strong resilience from our people. Which, in fact, the Russian people (in the broad sense) have, otherwise they wouldn't be so resilient to cataclysms and attacks. But why then do those in power expect these same people, from whom they expect strong resilience in one area, to obediently follow arbitrary restrictions like sheep in another? Fortunately, the Russian digital resistance doesn't yet have any leaders (I’m certainly not). But God forbid, they will appear. It won't be easy for anyone. |
| Link |
| Cyber |
| Kaspersky on Roskomnadzor, Sberbank, and blocking |
| 2026-04-06 |
| Direct Translation via Google Translate. Edited Text taken from the Telegram channel of natalya_kasperskaya_channel Commentary by Russian military journalist Boris Rozhin is in italics. [ColonelCassad] Kaspersky on Roskomnadzor, Sberbank, and blocking. I spoke with A.Yu. Lipov, head of Roskomnadzor, regarding my morning post about yesterday's banking outage. Andrey Yuryevich explained in detail, with examples, why yesterday's outage was not caused specifically by Roskomnadzor. He also explained what Sberbank scenario led to the outages. ![]() Sberbank also confirms in its statements that this was a failure of its internal systems, for example: And since Sberbank is a systemically important bank and other banks are heavily dependent on its infrastructure, its outage led to outages at several other banks, as well as in the Fast Payment System. However, many news reports on this topic speculate that blocking the bank's clients' VPNs may have been the cause of the initial outage. What do I want to say here? First, I'd like to apologize to the esteemed agency for my hasty conclusions. Secondly, it's important to note that citizens desperately need direct communication with the government—with the agencies that make or implement blocking decisions. Neither the Ministry of Digital Development, Communications, or Roskomnadzor have issued public explanations of what happened. Sberbank's explanations are very terse and closed, making it impossible to understand what happened. Thirdly, the outage coincided with the minister's statements regarding VPN blocking. Therefore, I'm not the only one who has drawn a logical connection between these events. Clearly, Roskomnadzor is the implementing agency. And it's quite possible that it doesn't have the mandate to make independent political statements. Therefore, these statements should be made by representatives of the Ministry of Digital Development, Communications, or the government. People need to be given an explanation of what's happening. Otherwise, there will inevitably be speculation, scary rumors, and a barrage of the worst assumptions. Which is precisely what happened. Unfortunately, dialogue between all IT communities and the relevant ministry has been completely absent lately. All dialogue boils down to the demand, "Keep quiet, and most importantly, don't publish anything." And the technical decisions being made sometimes downright shock me, and I want at least an explanation. The full name of the relevant IT ministry is the Ministry of Digital Development, Communications, and Mass Media of the Russian Federation. I'd like to see more connection with the public and more communication. (c) Natalya Kasperskaya Basically, yesterday it wasn't Roskomnadzor, but Sberbank, that took down some services. It's fair to say that if many things had been explained clearly, many problems simply wouldn't have arisen. |
| Link |
| Cyber |
| Discord has gone too far. The social network for gamers has become a nest of hackers and terrorists |
| 2024-10-05 |
| Direct Translation via Google Translate. Edited. Rantburg.com maintains a Discord server, ostensibly to be used in the event Rantburg.com is down. It should be noted that Discord's primary attraction amongst gamers is its voice applications and its screen sharing applications, both of which I use frequently. Discord also is used by gaming companies to receive feedback on their products and for suggestions for improvements and for debugging. I have yet to see any terrorists on any of the Discord channels I follow. by Pavel Kiselev [REGNUM] Roskomnadzor demanded that the administration of the online platform Discord remove 947 illegal materials, including calls for extremism, propaganda of Nazism, drugs, LGBT and even child pornography. ![]() Since March of this year, the platform has been included in the register of social networks, whose administrators themselves are obliged to search for and remove illegal content published by network users. Discord is a free American online platform that provides the ability to communicate by creating user servers. It was created in 2015 as a platform for gamers, but subsequently gained popularity among a wider audience. This turned Discord into one of the largest social networks for exchanging messages and calls. According to various estimates, the platform's Russian audience ranges from 2.62 million to 4.83 million users. RECRUITMENT - FROM "DEPOSITORS" TO TERRORIST ATTACK PERPETRATORS The social network is most popular among children and teenagers, which is used by criminals, “recruiting minors to ‘stash’ drugs, convincing them that their use is normal,” Roskomnadzor notes. The criminals here are not only running networks selling illegal substances. In the summer of 2022, it became known that a group of hackers was using popular teenage channels on Discord and YouTube and offering them the opportunity to distribute malware through these online platforms. Here, young people are also drawn into extremist cells and into committing terrorist attacks in the country’s regions, department representatives indicated. Thus, in August 2022, the Safe Internet League revealed that messages with false information about the mining of schools and kindergartens in Russia, the purpose of which was to disrupt the start of the school year, were being distributed through Discord and Telegram chats. And this distribution of fakes can still be considered relatively “harmless”. Most recently, on October 1, the FSB reported that its employees, together with representatives of the Ministry of Internal Affairs and the Investigative Committee, detained 39 people aged 14 to 35 during a special operation. Being supporters of Ukrainian terrorist organizations banned in Russia, they incited children and teenagers to attack people. Including nine teenagers preparing attacks on schoolchildren and teachers. One of the detainees prepared a detailed plan for an attack on classmates, selected a possible weapon, and also outlined the sequence of actions. The teenagers received these instructions from Kiev via Discord. THEY CONSIDER LGBT TO BE THE NORM “This network also frequently encounters cases of harassment and the inducement of minors to engage in sexual, including non-traditional, relationships,” Roskomnadzor also states. Discord employees refuse to moderate content with LGBT propaganda and pedophilia because they do not consider LGBT a threat, Andrey Masalovich, president of the Inforus consortium and developer of the Avalanche internet intelligence platform, explained to Regnum. "As for pedophilia, they believe that it is not an 'international concept', since the age of majority is different in different countries. These are such clever tricks," the expert explained. The “free” attitude of the social network’s administration towards the content that circulates there leads to the fact that neo-Nazi symbols, LGBT* pornography, and propaganda of the Ukrainian “Legion of Freedom of Russia”**, which is banned in the Russian Federation, are freely available on Discord. The fact that a platform created with a harmless purpose - as a resource for communication between players - has turned into an extremely toxic and dangerous environment is due to the very “architecture” of Discord. MAGNET FOR CYBERCRIMINALS "Discord is especially convenient due to its mechanics of servers that are accessible only by invitation. This prevents proper content moderation and introduces an element of anonymity, the inappropriateness of which on the Internet has long been obvious," explained State Duma deputy, member of the State Duma Committee on Information Policy, IT and Communications Anton Nemkin. Even if the user is not from a risk group, not one of those who might fall into the networks of drug dealers, pedophiles or Ukrainian recruiters, he is still in danger. Spy Pet, a service that has been operating since April 2024, collects huge amounts of data from Discord, including user messages and their activity. This data is sold to anyone who wants it, including crypto payments, for a small amount. Spy Pet monitors information from more than 14,000 servers and provides access to billions of messages. The discovery revealed that Discord messages may be more vulnerable to surveillance than previously thought. In 2022, Russian antivirus company Kaspersky Lab reported that scammers were deceiving people on the American platform. The extortionists sent out messages about winning free bitcoins and used a network of fake news sites for this scheme. Some hacker groups also use the service to distribute malware and sell stolen information. It should be noted that this is pointed out not only by Russian, but also by Western experts in protection against network threats. In February this year, the American company Intel 471, one of the leading providers of cyber threat analysis solutions, published a report that showed that hackers use the Discord platform to coordinate their actions, share stolen data, and teach each other new hacking methods. Discord’s anonymity and convenience, including the ability to easily restore communities, make it attractive to criminals, which poses a serious threat to users and organizations. "The Discord platform has long since become a real magnet for cybercriminals. It is easy to find malware, phishing attacks and other threats here. Users regularly become victims of fraud, and the platform does not take active measures to protect them," says Ilya Gogua, an expert at the Regional Public Center for Internet Technologies (ROCIT). There is no protection from either attackers or destructive content, the distribution of which is difficult to control due to the very principle of the platform. In other words, security in Discord is an illusion, the expert concluded. FINES DON'T HELP At the same time, the owners and management of Discord either completely ignore the requirements of Russian legislation, or comply with them extremely selectively, reminds journalist Alexander Malkevich, head of the department of social communications at the Azov State Pedagogical University (Zaporizhia region). In November 2021, Roskomnadzor included Discord Inc. in the List of Foreign Persons Operating in the Russian Segment of the Internet. The company was required to create a branch, register a personal account on the Roskomnadzor website, and post an electronic form for sending requests from Russian citizens and legal entities. None of the requirements were met. Therefore, since August 2021, search engines operating in Russia, on the instructions of Roskomnadzor, have been informing: Discord is a violator of our legislation. Discord continues to ignore demands to stop distributing illegal content. In July 2023, a Moscow court fined the company 6 million rubles for failing to remove pornographic content featuring minors. The platform has been subject to sanctions for failing to remove prohibited content, including extremist content and drug-making instructions. Yes, sometimes the company meets the authorities' demands halfway - for example, the year before last, 55 million users were blocked for sending spam or engaging in pedophilia. According to Roskomnadzor's demands, 933 links with prohibited materials were removed. But this is rather an exception to the rule. Discord continues to spread a large amount of prohibited information, which for some reason the management is in no hurry to block. Thus, just recently, on September 30, the Tagansky Court of Moscow fined the platform 3.5 million rubles for failure to comply with requirements to remove prohibited content. “When a company refuses to comply with laws and remove fakes and destructive content, this is always an alarming signal,” emphasizes Rifat Sabitov, head of the commission for the development of the information community, media and mass communications of the Public Chamber of Russia. In such cases, the authorities still strive to move the dialogue into a constructive direction and do not try to solve the problem with multi-million dollar fines, following the example of their European colleagues, noted a member of the Public Chamber. But when the law is violated systematically, and administrative cases continue to accumulate, then the only logical action is a thorough inspection of the platform’s activities – and then appropriate decisions are made, Sabitov added. "Please note that no one asked Discord for anything supernatural - the discussion included materials related to pedophilia and 18+ content. It is difficult to understand the principled refusal to remove even such content," the public figure emphasized. It should be noted that it is not only the Russian authorities who have accumulated claims against Discord. This year, the French National Commission on Information Technology and Human Rights fined the platform 800 thousand euros for violating the General Data Protection Regulation (GDPR). Secret documents from the Pentagon and US intelligence in 2023 also leaked through Discord - the company is currently cooperating with the US authorities in investigating this incident. But "the deed is already done." We could say that the problems of our Western "non-partners" do not concern us, if the freedom in Discord did not threaten Russians as well. Discord has become a toxic and, moreover, unnecessary platform for Russian users. This is also pointed out by "specialized" legislators. "How can Discord continue to operate if the messenger constantly violates Russian laws and does not protect its users? Destructive content remains, fraud flourishes, and the company does not even try to comply with the requirements for removing prohibited information," notes State Duma deputy Anton Nemkin. Naturally, after all the warnings and attempts to establish a dialogue, a thorough inspection of the messenger by Roskomnadzor is a logical decision, the parliamentarian emphasized. “Roskomnadzor is doing everything right by stretching sanctions against Discord over several stages: first a warning, then a fine, and soon a possible slowdown and blocking,” notes Andrey Masalovich, president of the Inforus consortium and developer of the Avalanche internet intelligence platform. NO GREAT LOSS Calls to block Discord, as has already been done with other Western Internet resources, are already spreading in RuNet. This opinion is shared, for example, by popular blogger Dmitry "Goblin" Puchkov. "There is such a simple concept in the Russian language - "has played itself out". It is fully applicable to Discord, which took the warnings of the authorities and the desire to speak like humans for weakness," Puchkov believes. He is sure that in its current form, this platform is a real breeding ground for fakes and destructiveness. "I don't know what censored word can be used to describe moderation that turns a blind eye to materials related to pornography and pedophilia," the blogger noted. And everything positive that is in Discord is easily replaced by Russian analogues, Puchkov explained. "Want to play with friends? Call them in any domestic messenger. Want to conduct an online lesson? Try the same calls or specialized services. I definitely do not see a problem in the absence of Discord in Russia, if the messenger is suddenly blocked," the blogger emphasized. Rifat Sabitov, head of the OP commission for the development of the information community, media and mass communications, shares a similar opinion. He is confident that the possible blocking of Discord in Russia will not be a loss for users. It is quite easy to replace the functionality of Discord. Voice communication and group calls can be arranged in many domestic messengers, so choosing a suitable alternative will not be difficult, the head of the relevant commission of the OP noted. Deputy Nemkin also points to this. "Even if the only way out of the situation is to block the service, Russians have nothing to worry about. Among domestic platforms, it is easy to find a solution for communicating with friends during the game, as well as a program for group calls and distance learning," the parliamentarian said. So many public figures are either neutral or positive about the closure of Discord. Perhaps this will be the only way out if the company continues to ignore the urgent requests and demands of Roskomnadzor and "not notice" how the resource has turned into a comfortable environment for extremists, perverts and cyber fraudsters. "Discord is an example of a major threat to Russian society. Firstly, because it is popular among young people, and this is the most pliable audience that the enemy can influence. Secondly, it is dangerous because it spreads hacker infection and through it you can easily hack users' computers," summarizes Andrey Masalovich, developer of the Avalanche Internet intelligence platform. Finally, - adds the interlocutor of IA Regnum, - Discord moderators are not friends with the Russian authorities, which is why they have ignored calls to remove illegal content for so long. |
| Link |
| Europe |
| 'Darkness over the Free World': How Pavel Durov Fell into the Trap of Principles |
| 2024-08-26 |
| Direct Translation via Google Translate. Edited. See also here. Responding to that and this story from yesterday. by Kirill Velesov [REGNUM] The arrest of billionaire Pavel Durov in France has once again raised questions about the methods by which various states gain control over media platforms. Durov owns the Telegram messenger, which is used by about 900 million people per month. This platform ranks 8th in the ranking of the most popular social networks in the world. India leads in the number of users of this resource. Telegram has over 1.4 million channels and 140,000 chats, through which over 167 billion messages are sent daily. The company is valued at $30 billion, and its Dubai office employs 30 people. The passenger of his own private jet Embraer Legacy 600 fell into the hands of French justice at the Paris Le Bourget airport, at about nine o'clock in the evening Moscow time. The French TV channel TF1 told the world about Durov's arrest. According to him, the warrant was issued by the National Directorate of the French Judicial Police. The bracelets on the arrested man's wrists were snapped by the air transport gendarmerie. Interestingly, Flightradar24 claims that Durov's plane attempted to change course and head south of the country. The businessman was put on the wanted list shortly before landing at the Paris airport, so it is unclear whether this was a failed escape attempt or Durov decided to go all in, realizing that he would not be able to escape. The Telegram cryptocurrency reacted sensitively to the arrest: the Toncoin rate fell by 20% in the first hours after the news from the Paris airport appeared. Among the crimes incriminated to Durov are complicity in terrorism, fraud and pedophilia. According to French law, a judge can imprison a defendant in these criminal proceedings for a term of 20 to 25 years. Durov, by the way, will celebrate his 40th birthday on October 10. It is doubtful that this will happen at large: apparently, he is facing a lengthy trial. VERSION NUMBER ONE The thing is that the brainchild of the Durov brothers - and Nikolai, the elder brother of the detainee, played the first violin in the development of the platform code - turned out to be too tough for cyber policemen around the world. The secret of users' correspondence is not available to third parties. This is where the leading version of the arrest comes from: Western liberal elites want to take control of an independent digital platform. The attitude towards what is happening was formulated in an indicative way by the American journalist and one of the main enemies of the liberal establishment, Tucker Carlson : “Tonight Pavel Durov will spend the night in a French prison, this is a living warning to all platform owners who do not want to censor the truth. <…> The darkness is quickly gathering over the former free world.” Russian Foreign Ministry spokesperson Maria Zakharova recalled how Western NGOs called on Russian authorities to stop creating obstacles to Telegram’s work after the adoption of the “Yarovaya Law” on July 1, 2018. Moreover, Durov remained at large while Russian authorities restricted the platform’s operation in Russia. "Do you think this time they will appeal to Paris and demand Durov's release or will they swallow their tongues?" Zakharova wrote. According to Deputy Chairman of the Russian Security Council Dmitry Medvedev, Durov remains Russian, and therefore unpredictable and dangerous. That is, there are no "good" Russians for the West and there never will be. Medvedev warned Pavel about problems with the law in any country due to his refusal to cooperate with the authorities. Durov called his refusal a "principled" position. How far his principled stand will extend now in the face of a long prison term is not yet known. In general, Russian politicians condemned Durov's arrest, seeing political motives in the actions of the French authorities. And State Duma Deputy Speaker Vyacheslav Davankov called on Russian Foreign Minister Sergey Lavrov to seek the release of the newly-minted political prisoner. But will this stir up the remnants of patriotism in the libertarian Durov, who declared back in 2014 that he had no intention of returning to Russia, but ended up in a clash with the West? SEARCHING FOR CONNECTIONS WITH RUSSIA Another version has appeared in the community of Russian military experts. Supporters of this version claim that it was the secure Telegram that became the main messenger during the special military operation, since Russian military personnel exchange information there. "You shouldn't fly to France when most of the combat command of the Russian Armed Forces is sitting in your midst. They might ask for cooperation," says military historian Ilya Kramnik. However, this version still seems secondary, since the military has other communication channels. The plane from which the hero of Sunday's news agenda stepped off had arrived from Baku. This gave rise to speculation about his possible meeting there with Russian President Vladimir Putin. Then the interest of Western intelligence services in checking Durov's possible connections with the Russian military-political leadership becomes understandable. And, of course, despite all the accusatory pathos about the actions of the world behind the scenes, it must be acknowledged that the messenger has more than once become a tool in the hands of those whose intentions were predatory and disgusting. It is enough to recall the role of the Telegram channel in recruiting terrorists who carried out the massacre in Crocus City. The resource's moderators were members of the Islamic State of Khorasan, which is banned in Russia. Then, the lives of 143 people were tragically cut short. However, there is no answer to the question of what extent the owner of Telegram is responsible. Perhaps he will be offered to sacrifice the principles of an independent "man of peace" and cooperate with those who organized this arrest by changing the messenger's program code. And it may well be that Durov's team foresaw this development of events and will make any manipulation of the messenger impossible. Related: Pavel Durov 08/25/2024 CEO of Telegram Messaging App Arrested in France For a 'Lack of Moderators' on the Russian Messaging Site Pavel Durov 08/06/2024 Kaspersky Lab has discovered an Android Trojan that spies on Russians Pavel Durov 06/12/2024 South African court seizes Google assets for discrimination against Orthodox TV channel |
| Link |
| Europe | |
| Telegram app founder Pavel Durov, detained in France, placed in custody | |
| 2024-08-26 | |
Direct Translation via Google Translate. Edited.
![]() A source close to the investigation told the TV channel that the founder of Telegram allegedly committed countless offenses and crimes on the platform. It is specified that encrypted messages have become one of the main complaints of the authorities of the EU countries against Telegram. As reported by the Regnum news agency, the arrest of Pavel Durov at the airport of the Paris suburb of Le Bourget became known on the evening of August 24. It is alleged that the corresponding warrant was issued by the National Office of the Judicial Police of France (OFMIN) based on a preliminary investigation. More from regnum.ru Arrest warrant activated upon Durov's arrival in France The search warrant issued by the French authorities against Telegram founder Pavel Durov was activated only after the entrepreneur arrived in France. This was reported on August 25 by the newspaper Le Parisien. Journalists claim that this was the condition stipulated in the document. The warrant was issued on the basis of a preliminary investigation conducted by the juvenile affairs department of the French National Judicial Police Office (OFMI). The said unit is engaged in combating violence against minors. As reported by the Regnum news agency, it was previously reported that Pavel Durov was detained at Le Bourget Airport (a suburb of Paris) on the evening of August 24. The businessman was placed under arrest. A hearing is scheduled for August 25, at which he will appear in court. Journalists have disseminated information according to which Durov may be charged with several charges related to Telegram's activities, including terrorism and drug trafficking. The French authorities' claims against the businessman are that the messages in this messenger were encrypted and he did not cooperate with law enforcement agencies. Because of this situation, he began to be suspected of complicity in countless offenses and crimes. The Russian Foreign Ministry stated that the Russian Embassy in Paris did not wait for inquiries from Durov’s representatives and immediately began work to clarify the situation with him. Related: Pavel Durov 08/25/2024 CEO of Telegram Messaging App Arrested in France For a 'Lack of Moderators' on the Russian Messaging Site Pavel Durov 08/06/2024 Kaspersky Lab has discovered an Android Trojan that spies on Russians Pavel Durov 06/12/2024 South African court seizes Google assets for discrimination against Orthodox TV channel | |
| Link |
| Europe |
| CEO of Telegram Messaging App Arrested in France For a 'Lack of Moderators' on the Russian Messaging Site |
| 2024-08-25 |
| [PJMedia] The Russian messaging App Telegram could be the last relic from a time when the internet was the wild, wild west. Anyone can use the encrypted messaging app, including terrorists, drug dealers, and low lifes of all sorts. But Telegram has also served as one of the only sources of uncensored news in Russia where many of their 900 million users reside. It's also available in Ukraine and oppressive societies around the world. The CEO of Telegram, Pavel Durov, has been a marked man in Western Europe for allowing all of this freedom to go on without a sufficient number of moderators. The French struck first, arresting Durov when he landed in France on his private jet. French authorities are being very tight-lipped about their special prisoner. Aside from vague references to the lack of moderators and non-cooperation with authorities, specific charges have not been filed against Durov. He may be indicted as early as Sunday. Elon Musk referred to Durov's arrest, sarcastically calling it an "ad for the First Amendment." A poster on X gave a thumbnail bio of Durov. Pavel reminds me of you. He is not bought. In an interview with Tucker Carlson earlier this year, Durov spoke of the interest shown in Telegram by U.S. law enforcement. 🚨 PAVEL DUROV: THE U.S. WANTED TO CONTROL TELEGRAM BETTER “I would rather be free than to take orders from anyone,” Durov told U.S. journalist Tucker Carlson in April about his exit from Russia and search for a home for his company. Durov ended up in the United Arab Emirates. NBC News: Durov, whose fortune was estimated by Forbes at $15.5 billion, said some governments had sought to pressure him but the app should remain a “neutral platform” and not a “player in geopolitics”. What I know of Durov, he's not the kind of person to take this lying down. If they want to hold a trial on freedom of speech, he will embrace it and expose the authorities as the jack-booted thugs they are. Related: Telegram 08/24/2024 Current information on the situation on the front line: August 23 (updated) Telegram 08/24/2024 First verdict handed down to participants in riots at Makhachkala airport Telegram 08/24/2024 Composition of the Ukrainian Armed Forces group that attacked Kursk region Related: Pavel Durov 08/06/2024 Kaspersky Lab has discovered an Android Trojan that spies on Russians Pavel Durov 06/12/2024 South African court seizes Google assets for discrimination against Orthodox TV channel Pavel Durov 11/15/2023 Ministry of Internal Affairs puts Abakar Abakarov on the wanted list |
| Link |
| Cyber |
| Kaspersky Lab has discovered an Android Trojan that spies on Russians |
| 2024-08-06 |
| Direct Translation via Google Translate. Edited. [Regnum] Kaspersky Lab experts have identified a Trojan-type virus that can be used by attackers to spy on Android device owners in Russia. The company reported this on August 5. "It's unusual in that it's not one of ours" "LianSpy disguises itself as system applications and financial services. The malware's functionality includes collecting and transmitting to attackers a list of contacts from an infected device, as well as call log data, a list of installed applications," Izvestia quoted Kaspersky Lab cybersecurity expert Dmitry Kalinin as saying. It is noted that the virus can also record the smartphone screen when opening individual applications, primarily instant messengers, however, most often, the attackers are not interested in the financial information of the victims. The company added that when launched, the Trojan runs in the background and begins to fully control the device, for example, without showing the owner a notification about turning on the camera or microphone. As reported by Regnum News Agency, American businessman and billionaire Elon Musk warned on July 7 about the dangers of using the WhatsApp messenger from Meta Platforms Corporation (an organization whose activities are recognized as extremist and banned in the Russian Federation). The entrepreneur was referring to the protection of user data. Co-founder of the Telegram messenger and the VKontakte social network Pavel Durov said on April 17 that he does not believe in the security of American Internet platforms. In his opinion, any devices used by users can be hacked. Related: Kaspersky 06/22/2024 BRICS Games hit by major DDoS attack Kaspersky 06/03/2024 Expert Golovanov calls Russia the most attacked country in the world by hackers Kaspersky 06/02/2023 Apple iPhone News Round Up |
| Link |
| Cyber |
| BRICS Games hit by major DDoS attack |
| 2024-06-22 |
| Direct Translation via Google Translate. Edited. [Regnum] The BRICS Games platforms suffered a major DDoS attack on June 21. Hackers used tens of thousands of IP addresses to stop the operation of digital resources at the event sites, said Vladimir Dryukov, head of the Solar JSOC cyberattack countermeasure center of the Solar Group. According to him, the cyber attacks began at approximately 12:00 Moscow time. “We have already repelled three waves of cyber attacks, which involved almost all known types of DDoS, which is rare. Malicious requests were sent from tens of thousands of IP addresses from various countries; the attack power at its peak reached 400 Gbit/s,” Dryukov told reporters. The head of a cybersecurity company added that hackers attacked nine BRICS Games venues. Employees of the cyberattack countermeasures center were required to immediately respond to what was happening and reconfigure defense mechanisms taking into account hacker attack vectors, Dryukov concluded. The BRICS Games are taking place in Kazan from June 12 to 24. About 5 thousand athletes from more than 90 countries are participating in the competition, they will compete for 387 sets of medals. After the seventh day, the Russian team took first place in the medal standings of the Games, the athletes won 173 gold, 94 silver and 65 bronze medals. As Regnum reported, Russia is the country most attacked by hackers in the world, said Sergei Golovanov, chief expert at Kaspersky Lab, on May 2. Before the coronavirus pandemic, these chances were 30–35%; during the pandemic they rose to 40–50% and now they are over 70%, he clarified. Russian President Vladimir Putin instructed the FSB to strengthen the protection of information infrastructure, as well as expand preventive response measures against the backdrop of an increase in the number of cyber attacks. The head of state proposed that the special services actively cooperate with scientists involved in digital development, business, and use domestic achievements in quantum technologies and the development of artificial intelligence to solve cyber defense problems. Related: DDoS attack 06/06/2024 Ukrainian Perspective: Invasion of Ukraine: June 5, 2024 DDoS attack 04/01/2024 Der Tagesspiegel: Germany is not ready for large-scale cyber attacks DDoS attack 03/22/2024 More than 12 million DDoS attacks carried out on Central Election Commission resources during the presidential election |
| Link |
| Cyber |
| Expert Golovanov calls Russia the most attacked country in the world by hackers |
| 2024-06-03 |
| Direct Translation via Google Translate. Edited. [Regnum] Russia is by far the most hacked country in the world. This was announced on May 2 on the eve of SPIEF 2024 by the chief expert of Kaspersky Lab, Sergey Golovanov. ![]() “Russia has the largest number of information security incidents in 2023 in the world, and moreover, the chances that you will now encounter phishing or other fraud just by going online are 73-75%,” quoted his words from the Prime agency. |
| Link |
| Caucasus/Russia/Central Asia |
| Apple iPhone News Round Up |
| 2023-06-02 |
| Direct Translation via Google Translate. Edited. [Regnum] The Federal Security Service, together with the Federal Security Service, uncovered an intelligence operation by American intelligence agencies using Apple technology, the FSB Public Relations Center reported on June 1. “In the course of ensuring the security of the Russian telecommunications infrastructure, anomalies were identified that are specific only to users of Apple mobile phones and are caused by the operation of previously unknown malicious software (VPO) that uses software vulnerabilities provided by the manufacturer,” the department informed . As the FSB found out, several thousand Apple mobile devices were infected with viruses. Malicious software, in addition to domestic subscribers, was found on equipment registered with the diplomatic missions of NATO member countries, the CIS, Israel, Syria and China in Russia. The information received indicates close cooperation between Apple and the US National Security Agency and contradicts the company's stated privacy policy, the FSB stressed. The department added that Apple provides American intelligence services with great opportunities for surveillance and control of any persons, including allies of the States and its own citizens. This is not the first time that the United States has been caught in espionage, which targets not only Washington's declared opponents, but also allies. So, for example, in April, IA Regnum reported with reference to the German media that the US intelligence report leaked to the Network contained data on surveillance by American intelligence services of representatives of the defense departments of Germany and China during a meeting on February 20 in Berlin. Washington did not respond to requests from publications asking them to confirm the authenticity of excerpts from the reports. Berlin also did not respond to information about surveillance of German officials. More from regnum.ru Peskov announces a ban on the use of iPhones for official purposes in the Presidential Administration The use of iPhones for official purposes in the Presidential Administration is unacceptable. This was announced at a briefing on June 1 by the press secretary of the President of Russia Dmitry Peskov. “The use of them [gadgets] for official purposes is unacceptable and prohibited,” Peskov said. The Kremlin spokesman added that for personal purposes, many continue to use iPhones - about 20-30%. Peskov added that this information deserves attention. In addition, whether or not to impose a ban on the use of iPhones for personal purposes will depend on the recommendations of the security services. According to the press secretary, what additional restrictions are needed are better known to the special services. As IA Regnum reported , the FSB, together with the FSO, uncovered the intelligence operation of the US special services with the help of electronics from the American company Apple. Several thousand iPhones have been infected with viruses intended for surveillance. The Russian Foreign Ministry reported on June 1 that US intelligence agencies have been using IT corporations for decades to collect data on Internet users without the knowledge of the latter. Evidence of such illegal activity appears every year, the Russian diplomatic department clarified. At the same time, it is noted that Russia has repeatedly raised the issue of restoring order in this area and developing universal norms of behavior in the digital space at all specialized international platforms. More, again from regnum.ru Experts explained how US intelligence agencies managed to infect iPhone with dangerous software US intelligence agencies have developed malicious software (software) and introduced it into the iPhone in order to circumvent the measures taken by Russian law enforcement agencies to ensure the security of data of domestic telecom operators. This was told to a correspondent of IA Regnum by a professor of the Department of Security in the Digital World of Moscow State Technical University. N. E. Bauman, an expert in the field of information security Vitaly Vekhov . He also told what is important to pay attention to in order to secure your gadget. PROFESSOR VEKHOV TOLD HOW APPLE USERS CAN SECURE THEIR GADGETS Earlier, the FSB of Russia reported that counterintelligence had uncovered an operation by US intelligence agencies to infect thousands of Apple smartphones with malware , which also belonged to foreign diplomats in Moscow. Russian subscribers were infected, as well as foreign numbers and subscribers using SIM cards registered with diplomatic missions and embassies in the Russian Federation, including NATO and post-Soviet member countries, as well as Israel, Syria and China. The report notes that mobile devices worked with abnormal failures that were caused by malware. The FSB said that the information received indicates that Apple is working closely with the US national intelligence community. Professor of Moscow State Technical University Vekhov explained the situation by the fact that American legislation regarding the protection of personal data is extraterritorial. "They set the rules and distribute their current legislation in violation of all other national laws of other countries. At the factory stage, they solder a microchip onto the motherboard, on which a code is pre-embedded, which is transferred to the security agency in order to remotely conduct reconnaissance and illegally download data without the permission of the subscriber. This has been happening for a long time," says Vekhov. According to him, it is not surprising that the Americans needed the introduction of malware. "Viruses were developed to overcome the blocks, the protection that our law enforcement officers demanded some time ago from telecom operators to ensure the security of user data," the expert explains. Vekhov noted that when a smartphone requests an operating system update, the process of the same data transfer to the US National Security Agency starts. The specialist recommended that users of foreign smartphones and gadgets, especially the Apple brand, download the standard - the security certificate of the Ministry of Digital Development of the Russian Federation in order to protect themselves and their personal data under Russian law. The opinion of the professor of Moscow State Technical University. N. E. Bauman is also shared by Denis Kuskov, CEO of the information and analytical agency TelecomDaily . He also drew attention to the information, which had previously been actively advertised, about special chips built into imported smartphones directly at manufacturing plants. "Smartphone is a possibility to receive data. Now there is a lot of information about smartphone security issues. Before that, it was said that a certain amount of equipment was equipped with malware directly at the factories. But while we do not have our own telecommunications equipment, our analogues, we use American developments," Kuskov emphasizes. However, both experts do not think that FSB reports about infected smartphones will somehow affect the use of foreign equipment. According to Kuskov, the sale of Apple branded equipment has already decreased. But this is a situation that does not depend on the information of the FSB, but a consequence of the difficulty in executing parallel imports. The Russian Foreign Ministry responded to reports from the Security Service about American malware. The agency noted that the intelligence services of the United States have been using IT corporations for decades to collect data on Internet users without the knowledge of the latter. Press Secretary of the President of Russia Dmitry Peskov said at a briefing on June 1 that the use of iPhones for official purposes in the Presidential Administration is unacceptable. As IA Regnum reported with reference to the German media, earlier in the US intelligence report leaked to the Network there was data on the surveillance of American intelligence agencies over representatives of the defense departments of Germany and China during a meeting on February 20 in Berlin. Washington did not respond to requests from publications asking them to confirm the authenticity of excerpts from the reports. Yet more again, from regnum.ru Kaspersky Lab discovered an attack on employees' Apple devices Kaspersky Lab has detected a targeted cyberattack on Apple devices of its employees, the press service of the organization said . Kaspersky Lab has detected a cyberattack on Apple devices of its employees “The purpose of the attack was to quietly introduce a spyware module into the iPhone of company employees ,” the report says. It turned out that several dozen iPhone owners among the company's employees were found to have a new, technologically sophisticated spyware called "Triangulation". The company said that the attack was carried out using an invisible message with a virus, which, using vulnerabilities in the iOS operating system, installs spyware on the device. At the same time, the implementation of the program was completely covert. The spyware program itself transmits recordings from a microphone, photos from instant messengers, location and other personal information of the owner to remote services. It is noted that the investigation of the spy operation "Triangulation" has just begun. As IA Regnum reported , the FSB, together with the FSO, uncovered an intelligence operation by the US special services using electronics from the American company Apple. Several thousand iPhones have been infected with viruses. At the same time, the Russian Foreign Ministry reported that US intelligence services have been using IT corporations for decades to collect data on Internet users without the knowledge of the latter. Presidential spokesman Dmitry Peskov also commented on this situation. According to a Kremlin spokesman, the use of iPhones for official purposes in the Presidential Administration is prohibited and unacceptable. He added that for personal purposes, many continue to use iPhones - about 20-30%. Yet again, more from regnum.ru Prosecutor General of the Russian Federation urged to initiate a case of espionage against Apple employees On June 1, Vitaly Borodin, head of the Federal Project for Security and Combating Corruption, wrote an appeal to Prosecutor General Igor Krasnov with a request to open a criminal case on espionage against Apple employees and US intelligence. The corresponding letter appeared at the disposal of the editors of IA Regnum. Borodin called for a response to the FSB report about the disclosed operation of American intelligence services using Apple smartphones. Malicious spyware has been detected on several thousand devices. They were on the gadgets of Russian citizens, as well as employees of the diplomatic departments of China, Syria, Israel, the CIS and NATO member countries. “The actions of unidentified persons who are employees of the American company Apple, as well as employees of American intelligence organizations, contain signs of crimes under Art. 272, 272 and 276 of the Criminal Code of the Russian Federation, namely: “Illegal access to computer information”, “Creation, use and distribution of malicious computer programs” and “Espionage”, wrote Borodin. He noted that the FSB assessed the information received as confirmation of Apple's cooperation with US intelligence, although this is contrary to the privacy policy declared by the company. As IA Regnum reported , on June 1, Kaspersky Lab announced a targeted cyberattack on Apple devices of its employees. The purpose of the attack was the covert introduction of spyware. It was found on dozens of iPhone devices. Attackers sent invisible messages with viruses to gadgets. The spyware sent personal information about the owner to remote services. |
| Link |
| Cyber |
| Never-before-seen malware is nuking data in Russia's courts and mayors' offices |
| 2022-12-03 |
| [ArsTechnica] CryWiper masquerades as ransomware, but its real purpose is to permanently destroy data. Mayors' offices and courts in Russia are under attack by never-before-seen malware that poses as ransomware but is actually a wiper that permanently destroys data on an infected system, according to security company Kaspersky and the Izvestia news service. Kaspersky researchers have named the wiper CryWiper, a nod to the extension .cry that gets appended to destroyed files. Kaspersky says its team has seen the malware launch “pinpoint attacks” on targets in Russia. Izvestia, meanwhile, reported that the targets are Russian mayors' offices and courts. Additional details, including how many organizations have been hit and whether the malware successfully wiped data, weren’t immediately known. Wiper malware has grown increasingly common over the past decade. In 2012, a wiper known as Shamoon wreaked havoc on Saudi Arabia's Saudi Aramco and Qatar's RasGas. Four years later, a new variant of Shamoon returned and struck multiple organizations in Saudi Arabia. In 2017, self-replicating malware dubbed NotPetya spread across the globe in a matter of hours and caused an estimated $10 billion in damage. In the past year, a flurry of new wipers appeared. They include DoubleZero, IsaacWiper, HermeticWiper, CaddyWiper, WhisperGate, AcidRain, Industroyer2, and RuRansom. Kaspersky said it discovered the attack attempts by CryWiper in the last few months. After infecting a target, the malware left a note demanding, according to Izvestia, 0.5 bitcoin and including a wallet address where the payment could be made. “After examining a sample of malware, we found out that this Trojan, although it masquerades as a ransomware and extorts money from the victim for ‘decrypting’ data, does not actually encrypt, but purposefully destroys data in the affected system,” Kaspersky’s report stated. “Moreover, an analysis of the Trojan's program code showed that this was not a developer's mistake, but his original intention.” CryWiper bears some resemblance to IsaacWiper, which targeted organizations in Ukraine. Both wipers use the same algorithm for generating pseudo-random numbers that go on to corrupt targeted files by overwriting the data inside of them. The name of the algorithm is the Mersenne Vortex PRNG. The algorithm is rarely used, so the commonality stuck out. CryWiper shares a separate commonality with ransomware families known as Trojan-Ransom.Win32.Xorist and Trojan-Ransom.MSIL.Agent. Specifically, the email address in the ransom note of all three is the same. The CryWiper sample Kaspersky analyzed is a 64-bit executable file for Windows. It was written in C++ and compiled using the MinGW-w64 toolkit and the GCC compiler. That’s an unusual choice since it’s more common for malware written in C++ to use Microsoft’s Visual Studio. One possible reason for this choice is that it gives the developers the option of porting their code to Linux. Given the number of specific calls CryWiper makes to Windows programming interfaces, this reason seems unlikely. The more likely reason is that the developer writing the code was using a non-Windows device. Successful wiper attacks often take advantage of poor network security. Kaspersky advised network engineers to take precautions by using:
Given Russia’s invasion of Ukraine and other geopolitical conflicts raging around the globe, the pace of wiper malware isn’t likely to slow in the coming months. “In many cases, wiper and ransomware incidents are caused by insufficient network security, and it is the strengthening of protection that should be paid attention to,” Friday’s Kaspersky report stated. “We assume that the number of cyberattacks, including those using wipers, will grow, largely due to the unstable situation in the world.” |
| Link |