n this Friday, June 2, 2017, file photo, Russian President Vladimir Putin gestures as he speaks at the St. Petersburg International Economic Forum in St. Petersburg, Russia.

n this Friday, June 2, 2017, file photo, Russian President Vladimir Putin gestures as he speaks at the St. Petersburg International Economic Forum in St. Petersburg, Russia. AP / Dmitry Lovetsky

Vladimir Putin and the Little Green Men of the Internet

The future of Kremlin-backed information operations against Western governments looks a lot like Russia's deceptive campaign against Crimea in 2014.

Russian President Vladimir Putin, in his weekend interview with NBC’s Megyn Kelly, said he was not the culprit behind the U.S. presidential election hacks of 2016 and argued the attacks could have been executed by anyone, even proud Russian patriots committing crimes against the Kremlin’s adversary without his personal knowledge.

The denials are reminiscent of Putin’s assurances during the spring of 2014, when the Russian President claimed the masked soldiers armed with Russian weapons appearing in Eastern Ukraine were simply “local self-defense forces.”  One year later, Putin admitted  Russian soldiers had essentially invaded Ukraine.

With Kelly, Putin appears to have applied a similarly thin denial to the 2016 U.S. election and the global intelligence consensus that there was intentional Kremlin interference, and it was approved personally by the president. Just as in 2014, Putin pushed back on the accusation that the Kremlin ordered the theft and publication of emails stolen from the Democratic National Committee and Clinton advisor John Podesta. But the Russian president surprised many when he offered Kelly a new explanation for the event: the hackers might have come from Russia, but if so, they were acting out of a sense of patriotism.

“Hackers are free people, just like artists who wake up in the morning in a good mood and start painting… The hackers are the same. They would wake up, read about something going on in inter-state relations, and if they feel patriotic they may try to contribute to the fight against those who speak badly about Russia.”

What’s the difference between a patriotic hacker and one that is clearly in the service of the Kremlin? Just like in any criminal case, it comes down to targets selected (motive), and tools used (evidence).

Private cybersecurity company Crowdstrike published last June the first portion of public evidence linking the DNC attackers to the Russian GRU, Russia’s military intelligence service.

“This adversary has a wide range of implants at their disposal, which have been developed over the course of many years and include Sofacy, X-Agent, X-Tunnel, WinIDS, Foozer and DownRange droppers, and even malware for Linux, OSX, IOS, Android and Windows Phones,” notes Crowdstrike in their report.

These are essentially GRU tools that have been left at the scene of various crimes, including phish attacks on France’s TV5 Monde and the German Bundestag in 2015. Crowdstrike’s analysis was corroborated by competing firms such as Fidelis and ThreatConnect.

The U.S. intelligence community eventually came to the same conclusion. In January, the Office of the Director of National Intelligence, or ODNI, released a report stating that the FBI, CIA, and NSA had “high confidence” that “Russian President Vladimir Putin ordered an influence campaign in 2016 aimed at the US presidential election.”

DNI has released multiple reports containing forensic evidence to back that up, one in December, (which was the subject of some criticism for throwing generic malware in with Russian specific malware) and a second one in February, generally described as a great improvement over the first. Both reports reconfirm the “high confidence” assessment the intelligence community first put forward. Both mention X-Agent.

A far more likely explanation than Putin’s patriot-hacker theory is also the more obvious one: they are no different from the brave “volunteers” the Kremlin unleashed on Crimea.

The actual operation to hack the DNC involved not only the GRU but also individuals that the GRU had hired or contracted, such as the so-called Esage Lab, which as Defense One reported in December, found itself on the State Department sanctions list for providing the GRU with “technical research and development.”

The Kremlin also uses criminal gangs for cyber support and “surge capacity” in some instances, such as the December offensive in Ukraine.

Some Russians are reportedly forced to provide the Kremlin with support once law enforcement discovers their other activities, which would make them not so much “patriotic” hackers as indentured.

Putin’s allegation simply does not fit with what observers and Russia experts in the West say they know about Putin’s government and how it operates. “While it's possible for non-RIS (Russian Intelligence Services) controlled hackers to choose their own targets independently, something as big as the DNC hack was certainly approved in the Kremlin,” said Mike Carpenter, senior director at the Biden Center for Diplomacy and Global Engagement at the University of Pennsylvania and a former deputy assistant secretary of defense for Russia, Ukraine, and Eurasia.

Outside of Putin, the overwhelming consensus is Russia’s government is working online against its adversaries in the same way that it succeeded in invading Crimea. They are attacking the enemy’s greatest weaknesses (in the case of democracies, their free and fair elections ) while avoiding direct confrontation. It’s a style of stealth warfare that blends together the hidden and the obvious and that goes by a variety of names such as hybrid war and the Gerasimov Doctrine, after Russian General Staff Gen. Valery Gerasimov who is, today, most closely associated with its ascendance.

Whatever you call it, it works. While NATO in recent years has devoted more attention to cybersecurity, that’s only one tactical portion of what is a much larger campaign with multiple dimensions that play off of the political divisions that dwell in the heart of modern democracies.

“To be blunt, these are tactics that NATO–still, in the final analysis, an alliance designed to deter and resist a mass, tank-led Soviet invasion–finds hard to know how to handle,” Russia researcher Mark Galeotti notes.

In other words, as long as it works, expect Russia’s patriotic (and undeclared) hacking to continue.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.