Posts

The (un)Usual Suspects: Tracking America's Next Adversaries (2025-2045)

Framing the Future Disclaimer : This research project uses data derived from open-source materials like public intelligence assessments, government publications, and think tank reports. This report is based solely on my personal insights, hypothetical scenarios, and independent analysis. It does not contain any sensitive or classified information and does not reflect the views of my employer. This report's purpose is to serve as an exercise in research, analysis, and critical thinking. As the global security environment grows increasingly complex, United States (US) national defense strategies need to evolve beyond traditional threat frameworks. While Russia (RU), China (CN), Iran (IR), and North Korea (NK) - the "Big Four" - remain primary national security concerns, they don't represent the full spectrum of emerging kinetic threats the US may face over the next two decades. A range of other state and non-state threat actors are developing the capabilities and intent...

Russian Intelligence Impersonates Multiple Organizations to Target Ukraine Sympathizers in New Phishing Campaign

On March 14, 2024, Silent Push published a report [1] detailing a targeted phishing campaign suspected to be linked to Russian intelligence services , possibly associated with GRU Unit 29155 —a unit previously implicated in influence operations, assassinations, and destabilization campaigns across Europe [2]. The campaign appears to target individuals who are sympathetic to Ukraine or opposed to the Russian government , with the likely objective of collecting intelligence on opposition-aligned Russians , identifying potential defectors , and monitoring foreign sympathizers . Silent Push identified four distinct phishing clusters impersonating: The CIA – Websites masquerading as legitimate CIA communication portals, likely intended to trick users into self-identifying as informants or opposition supporters. Russian Volunteer Corps (RVC) – Fake sites spoofing this anti-Putin militia made up of Russian nationals fighting alongside Ukraine. Legion "Liberty" (Legion Svo...

Ukraine halts natural gas transit to Europe citing national security concerns

" Kyiv took the step on Jan. 1st to cut off revenue helping to fund Russia's war on Ukraine, having given time for alternative suppliers to be found, and supplies have been maintained in the EU " - Reuters Very interesting development today. Seems like this would have some profound implications for the geopolitical landscape, affecting alliances, economic policies, security strategies, etc. Slovakia considering retaliation against Ukraine according to Reuters on Thursday, Jan. 9th citing Slovakian Prime Minister Robert Fico: " ... threatened to cut emergency electricity supplies to Ukraine as Russia attacks its power grid, or reduce aid for Ukrainian refugees ". The move aims to reduce or remove Russia's leverage on Western European countries through the use of energy as a geopolitical tool, which affects Europe's energy security. European countries will face increased pressure to further diversify their energy sources to reduce their vulnerability to an...

Russian GRU Unit 29155 recent operations

Image
Background Russian GRU military intelligence Unit 29155 (aka Cadet Blizzard, Ember Bear, FrozenVista, UNC2589) is a covert subunit of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), primarily tasked with conducting high-stakes and clandestine operations abroad. Established under the GRU, Unit 29155 gained public attention due to its involvement in activities that align with Russia's asymmetric warfare objectives, particularly in Europe, Ukraine, and NATO-affiliated regions. Unit 29155 operates in several domains, from traditional espionage and sabotage to cyber operations. Figure 1 WANTED: GRU Unit 29155 [1] Unit 29155 has significantly intensified operations since 2020, pivoting from covert actions in Europe toward a greater emphasis on cyber operations with a focus on undermining Ukraine and NATO allies through espionage, data manipulation, and sabotage. Primary TTPs Espionage and Data Theft Unit 29155 conducts extensive espionage ca...
Image
ESET's APT Activity Report Q4 2023-Q1 2024 summarizes observations of various advanced persistent threat (APT) groups documented by ESET researchers between October 2023 and March 2024. Their observations highlight the broader threat landscape investigated during this period of time and details trends, developments and tooling used by these threat actors. The public report proclaims to contain a fraction of what private ESET customers receive. China Chinese-aligned cyber espionage groups have traditionally targeted public facing applications for obtaining initial access on a target network. In many campaigns investigated by ESET and others, the groups leveraged one-day vulnerabilities against a range of appliances and software including VPNs, firewalls, Confluence, Exchange, and others. See ESETs report linked below for their detailed analysis on Chinese threat activity.  Middle East According to ESET's research, a potentially Iranian-aligned threat group BladedFeline continued...
Image
Microsoft recently released their findings after a lengthy investigation into activity conducted by the Russian state-sponsored APT28 group using a unique tool for privilege escalation and credential harvesting on victim networks. Microsoft refers to the custom tool as GooseEgg and claim that the group has been observed leveraging this tool since at least June 2020. GooseEgg The custom toolset leverages CVE-2023-38208 in the Windows Print Spooler service which changes a JavaScript constraints file and executes it with SYSTEM permissions. Based on their findings, Microsoft believes GooseEgg is deployed after initial access to elevate access to targeted systems with the end goal of harvesting credentials and data. Unsurprisingly, targeting includes Ukrainian, Western European and North American entities across several sectors including government, non-government, education and transportation. After initial access of victim device, researchers observed APT28 deploying GooseEgg to escalate...
Image
 Mandiant Identifies Novel OT Malware: COSMICENERGY Researchers at Mandiant recently provided the public with an analysis of a recently discovered OT malware they've dubbed COSMICENERGY. The malware was uploaded to a public malware scanner in December of 2021 by someone in Russia. They believe that the malware may have been developed by a contractor for red teaming purposes for simulation of power disruption exercises hosted by Rostelecom-Solar, a Russian cybersecurity consultant company. In their blog post, Mandiant draws comparisons between this new malware and previous OT malwares like INDUSTROYER, like both malwares being deployed to impact electricity transmission and distribution through IEC-104. COSMICENERGY contains two derivative components: PIEHOP and LIGHTWORK. PIEHOP is a disruption tool written in Python that is able to connect to remote MSSQL servers for file upload and sending remote commands to a remote terminal unit (RTU). PIEHOPE uses LIGHTWORK to issue "ON...