Anti-NATO disinformation effort uses coronavirus to poke political tensions
Full article791 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A new report from FireEye does not attribute the effort to the Russian government, though the motives are consistent.
A propaganda campaign is using the coronavirus pandemic to inflame anxieties about NATO troops throughout Eastern Europe, security researchers have determined.
The group, dubbed Ghostwriter, has been focused on amplifying anti-Western narratives in Poland, Latvia and Lithuania since 2017. Operatives have planted fabricated diplomatic documents, tried spreading the false narrative that Canadian soldiers had been spreading COVID-19 through Latvia and leveraged news sites to spread articles that appear to be legitimate, according to a report the security firm FireEye published Tuesday.
While researchers have not attributed the effort to the Russian government, the findings are the latest addition to a growing consensus that pro-Kremlin entities are seizing on COVID-19 to inflame existing political divisions. Russia’s military intelligence agency, the GRU, is using three websites to try to spread disinformation about the U.S. response to the virus, U.S. officials told the Associated Press.
“We believe the assets and operations…are for the first time being collectively tied together and assessed to comprise part of a larger, concerted, and ongoing influence campaign,” the FireEye report noted.
In one case, Ghostwriter personas tried disseminating a fabricated letter that appeared to be written by Jens Stoltenberg, Secretary General of the North Atlantic Treaty Organization, suggesting that Lithuania intended to leave the alliance amid the coronavirus pandemic. They also falsified quotes, apparently taken from an interview with the commanding general of the U.S. Army in Europe, complaining about the state of the Polish and Baltic militaties.
In another case, Ghostwriter personnel authored a letter seemingly from the commander of the Polish War Studies Academy that urged Polish soldiers to rebel against American “occupation forces” stationed there. Polish officials denounced that letter at the time, citing it as an information operation aimed at undercutting relations with the U.S.
The campaign relied on at least 14 inauthentic web personas that have been involved in 15 operations dating back three years. Often, the accounts claim to be journalists, editors or citizens in the targeted countries in an apparent attempt to assume some credibility on the issues they discuss. Some of those accounts then support the work of their counterparts, trying to build engagement and the number of views on a given post.
The tactics closely resemble the work of Operation Secondary Infektion, a suspected Russian effort that’s used more than 300 websites to spread Kremlin talking points on regional blogging websites. John Hultquist, who tracks cyber-espionage at FireEye, cautioned that researchers have not found a link between Ghostwriter and Secondary Infektion.
More Scoops
Mandiant links Belarus to Ghostwriter campaign, which leaked stolen data and pushed disinformation
The effort has boosted anti-NATO messaging and appeared similar to Russian disinformation outfits.
Secondary Infektion, a Russian disinformation outfit, impersonated Swedish lawmaker
Suspected Russian operatives tried to stir far-right outrage about COVID-19 on 4chan
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/russia-disinformation-ghostwriter-secondary-infektion/