17 Apr 2018

Russia accused of global net hack attacks

11:32 am on 17 April 2018

State-sponsored Russian hackers are actively seeking to hijack essential internet hardware, US and UK intelligence agencies say.

no caption.

Photo: AFP

The UK's National Cyber Security Centre (NCSC), the FBI and the US Department of Homeland Security issued a joint alert warning of a global campaign.

The alert details methods used to compromise the networking equipment used to move traffic across the net.

This could be used be used to mount a future offensive, it warned.

In a press conference about the alert, White House cyber-security co-ordinator Rob Joyce said the US and its allies had "high confidence" that Russia was behind the "broad campaign".

Intelligence gathered by the US and UK suggested that millions of machines directing data around the net were being targeted, he said.

Compromised devices were used to look at data passing through them, added Mr Joyce. Attackers also sought to undermine the firewalls and intrusion detection systems organisations used to spot malicious traffic before it reached users.

In addition, Mr Joyce said, many different organisation had come under attacks for months at a time in a bid to scoop up valuable intellectual property, business information or to get at their customers.

"When we see malicious cyber-activity, whether Kremlin or other nation state actors, we are going to push back," said Mr Joyce.

Ciaran Martin, head of the UK's NCSC, said the issuing of the alert marked a "significant moment" as the two powers had never before given joint advice on how to deal with attacks.

"Many of the techniques used by Russia exploit basic weaknesses in network systems," said Mr Martin.

The principal targets of the global campaign were internet service providers, firms running critical infrastructure, government departments and large companies, the alert stated.

And it contained detailed information about attack methods, the signs left when hardware has been compromised, and how networks change when they have been breached.

The advice given to firms has included ways to configure their systems correctly and how to apply patches to address hardware vulnerabilities.

Mr Martin said GCHQ, NCSC's parent organisation, had tracked the threat posed by Russian cyber-gangs for more than 20 years. Further intelligence about the attacks had been added by "multiple" cyber-security organisations and companies, he added.

The UK was working with America, its other allies and the technology industry to "expose Russia's unacceptable cyber-behaviour, so they are held accountable for their actions", said Mr Martin.

- BBC

Get the RNZ app

for ad-free news and current affairs