Disclosure Does Little to Dissuade Cyber Spies

Disclosure Does Little to Dissuade Cyber Spies
In the past, outing nation-state cyber espionage groups caused a few to close up shop, but nowadays actors are more likely to switch to new infrastructure and continue operations.

When cybersecurity services firm Mandiant released its APT 1 report in 2013, the Chinese group immediately shut down, and the command-and-control servers that had been used by the group to manage its infrastructure went quiet. 


The incident has driven a naming-and-shaming policy pursued by the United States, which has filed indictments against a number of cyber-espionage actors in Russia, China, and Iran. However, such tactics increasingly appear to fail to have the intended effect, according to a report planning to be published on Nov. 5 by defense giant BAE Systems. While an Iranian group, which BAE Systems calls Operation Cleaver, ceased operations following a report in late 2014, many other Iranian groups continued to operate, including Team Ajax, Shamoon, and others, the analysis said.


It is clear that the Operation Cleaver report just led to a retasking of resources, BAE Systems' analysts concluded in the report.


"A leading theory for the group's disappearance is that Operation Cleaver splintered, and the members dispersed and/or restructured, spent nearly a year retooling and reorganizing, and returned in autumn 2015 as OilRig. However, this remains unconfirmed," the analysis stated. "What is more clear is that Iranian operations which targeted aerospace, defence, and energy didn’t entirely disappear but re-emerged around the same time as OilRig and continued with similar tasking."


The analysis of cyber-espionage groups' activities following being outed by security researchers, government agencies, and non-government organizations (NGOs) does not come to any particular conclusion, but it does show that — aside from a few early, and only purported, successes — outing cyber-e ..

Support the originator by clicking the read the rest link below.