Hi there, !
Today Sun 09/11/2022 Sat 09/10/2022 Fri 09/09/2022 Thu 09/08/2022 Wed 09/07/2022 Tue 09/06/2022 Mon 09/05/2022 Archives
Rantburg
533674 articles and 1861900 comments are archived on Rantburg.

Today: 61 articles and 274 comments as of 18:25.
Post a news link    Post your own article   
Area: WoT Operations    Non-WoT    Opinion    Local News    Politix   
Queen Elizabeth II dead at 96
Today's Headlines
Headline Comments [Views]
Page 2: WoT Background
7 16:44 magpie [4] 
1 13:11 Abu Uluque [9] 
6 13:32 Skidmark [3] 
0 [4] 
0 [9] 
0 [7] 
5 16:01 Matt [8] 
Page 1: WoT Operations
2 14:32 Ebbilet Dingle8712 [7]
0 [2]
0 [3]
0 [4]
0 [11]
0 [2]
0 [6]
0 [6]
0 [8]
0 [9]
0 [8]
0 [10]
Page 3: Non-WoT
26 22:46 Dron66046 [7]
3 16:59 Skidmark [14]
6 21:44 trailing wife [4]
0 [3]
7 16:53 magpie [3]
4 23:37 Skidmark [6]
9 16:52 DooDahMan [7]
6 13:06 magpie [3]
10 16:49 magpie [4]
9 16:59 magpie [2]
7 08:22 49 Pan [15]
14 17:23 swksvolFF [3]
0 [3]
1 07:49 Procopius2k [2]
3 08:59 M. Murcek [7]
Page 4: Opinion
7 20:00 Silentbrick [13]
12 19:31 Super Hose [4]
4 14:02 swksvolFF [4]
1 11:34 swksvolFF [5]
11 20:00 Super Hose [1]
17 15:52 Deacon Blues [2]
0 [10]
0 [3]
11 19:13 Jefe101 [1]
Page 5: Russia-Former Soviet Union
6 18:51 Nero [5]
27 22:56 Nero [7]
0 [3]
0 [6]
0 [7]
6 19:49 Omineling Forkbeard1962 [5]
0 [10]
9 15:24 swksvolFF [6]
1 12:35 Chris [6]
0 [3]
0 [10]
0 [2]
0 [2]
0 [3]
Page 6: Politix
10 19:24 Super Hose [4]
2 19:19 Super Hose [3]
9 19:17 Super Hose [2]
17 22:03 ruprecht [11]
Africa North
Syrian Military Commander Confirms Use of Child Soldiers in Libya
[PUBLISH.TWITTER]
Posted by: Fred || 09/08/2022 00:00 || Comments || Link || [3 views] Top|| File under: Sublime Porte

#1  Syrian Military Commander Confirms Use of Child Soldiers in Libya

"...It was either this or midnight basketball, and, well....no basketballs."

Mike
Posted by: MikeKozlowski || 09/08/2022 6:51 Comments || Top||

#2  A Syrian recruiter for a Turkish-backed militia stationed in Libya confirmed that they had sent youths, “under the age of 18 with zero military experience to fight in Libya, due to the increased Turkish intelligence request for Syrian mercenaries in Tripoli.”
Posted by: Skidmark || 09/08/2022 11:59 Comments || Top||

#3  Draining somebody's gene pool.
Posted by: M. Murcek || 09/08/2022 12:02 Comments || Top||

#4  Turk mercs pulled from Libya for points north?
Posted by: Skidmark || 09/08/2022 12:15 Comments || Top||

#5  Maybe we could send some of our feral youths there.
Posted by: Chris || 09/08/2022 12:33 Comments || Top||



Libyan Court Rejects Sanalla’s Dismissal Challenge
[PUBLISH.TWITTER]
Posted by: Fred || 09/08/2022 00:00 || Comments || Link || [4 views] Top|| File under: Arab Spring


Caucasus/Russia/Central Asia
Adjamatov's verdict in terrorism financing case approved
Direct Translation via Google Translate. Edited.
[KavkazUzel]\ A military court of appeal upheld the verdict against a Moscow doctor from Dagestan, Alikhan Adzhamatov, who was sentenced to a lengthy term on charges of transferring money to terrorist organizations.

The "Caucasian Knot" has reported that a court in Moscow has heard the case of Alikhan Adzhamatov since September 13, 2020. The defendant denied the allegations of financing terrorism, stating that the money transfers were not intended for terrorists. Witness for the prosecution Solikhov in court completely retracted his testimony against Adzhamatov given during the preliminary investigation.

Prosecution witness Parviz Akhmedov stated that evidence against Adjamatov was falsified. Two witnesses for the defense stated that they were pressured to testify against Adzhamatov. In December 2021, the court sentenced Adzhamatov, who was charged with facilitating terrorist activities, to 17 years in prison. This is too harsh a term, given that Adzhamatov's guilt has not been proven, the lawyers said.

In September 2020, a blogger and journalist from Dagestan, Roman Babaev, announced that he was coerced into giving certain evidence in the case of his acquaintance, Alikhan Adzhamatov, who was accused of facilitating terrorist activities. Babaev was detained upon arrival in Moscow, where he flew as a defense witness.

In August 2021, the defense indicated that all 10 episodes in the case are based on the fact that counterparties with whom Adzhamatov had legal business contacts had indirect ties with those convicted in terrorist cases, the defense pointed out.

A military court in Moscow sentenced Alikhan Adzhamatov to 16 years and 9 months in a penal colony for transferring 59 million rubles to members of the international terrorist organizations "Islamic State" and "Al-Qaeda" banned in the Russian Federation for seven years, the press service of the Federal Security Service of Russia for Moscow reported today and Moscow region.

The investigation established that Adjamatov, sharing the ideology of radical Islam, organized the collection of money and their further transfer to support the activities of members of terrorist organizations in Syria. From 2011 to 2017, he made over 100 translations."According to the ruling of the Military Court of Appeal, A.I. Adzhamatov was found guilty and sentenced to imprisonment for a period of 16 years and 9 months in a strict regime colony. The verdict has entered into force," the UFSB quoted TASS as saying.

Posted by: badanov || 09/08/2022 00:00 || Comments || Link || [7 views] Top|| File under: Devout Moslems


Europe
How is Albania's severance of ties with Iran related to Israel?
[Jpost] Albanian Prime Minister Edi Rama said the group that attacked his country also attacked Israel, Saudi Arabia and the UAE.

Albania announced on Wednesday that it was severing ties with Iran and expelling Iranian diplomats due to a cyberattack it says was conducted by Iranians in July in an attempt to destroy Albania's digital infrastructure.

In the announcement, Albania's Prime Minister Edi Rama stated that after thorough investigations, it was confirmed "with indisputable evidence" that the attack was conducted by Iran.

Rama added that the attack was carried out by four hacker groups that acted in concert, including a "notorious international cyber-terrorist group" which he said has carried out attacks against Israel, Saudi Arabia, UAE, Jordan, Kuwait and Cyprus. The prime minister did not name the groups.

In August, the Mandiant cybersecurity company reported that it had linked the cyberattack against Albania to Iranian hackers.

WHO CLAIMED RESPONSIBILITY FOR THE ATTACK?
While Rama did not name the specific groups responsible for the attack, a group calling itself "HomeLand Justice" published statements, screenshots and information on a Telegram channel and a website using a Russian domain linking itself to the cyberattack in July.

"We performed the #CyberAttacks to express our hatred and anger towards the Albanian government. Foreing (sic.) terrorists and moneylaunderes (sic.) do not belong to owr (sic.) sacred land. Our land is in need of pesticide to be cleansed," wrote the group in a Telegram post.

The group, which presented itself as Albanian, referenced the Mujahedin-e-Khalq (MEK) Iranian-opposition group throughout its messages, complaining that the Albanian government was supporting the MEK.

HomeLand Justice also published files it said contained data from the inboxes of Albanian government officials and offices.

HOW IS HOMELAND JUSTICE LINKED TO IRAN?
According to Mandiant, a ransomware called ROADSWEEP displayed a ransom note reading "Why should our taxes be spent on the benefit of DURRES terrorists?" on computers it infected in the attack. The MEK's Free Iran World Summit was set to be held in July in the town of Manëz in Durrës County.

The HomeLand Justice group's logo appeared identical to the wallpaper used by the ROADSWEEP ransomware. The graphic shows a circle containing lines that look like circuits and the outline of a Star of David, as well as an eagle with its talons pointed towards the star.

It is unclear why the Star of David was used in the logo as the group did not make any references to Jews or the State of Israel in its messaging.

Mandiant found that the attack also used a backdoor called CHIMNEYSWEEP which has likely been used in attacks against Farsi and Arabic speakers since 2012. CHIMNEYSWEEP and ROADSWEEP have a number of pieces of code in common.

CHIMNEYSWEEP operates through a self-extracting archive that contains it and a decoy Excel, Word or video file.

A tool called ZEROCLEARE which corrupts file systems may have also been used in the attack, according to Mandiant.

ZEROCLEARE has been used by Iranian hackers multiple times in recent years, according to multiple reports. Another wiper called Dustman, which has been identified as a very similar offshoot of ZEROCLEARE, was used in an attack on the Bahraini Bapco national oil company in 2019. Although they're very similar, it is unclear if Dustman was made and used by the same groups using ZEROCLEARE.

Mandiant estimated that one or multiple threat actors working for Iran were involved in the cyberattack against Albania due to the timing of the attack ahead of the planned MEK conference, the content of the Telegram group focusing on the MEK and the long history of CHIMNEYSWEEP being used to target Farsi and Arabic speakers.

The cyber security company stressed that the attack was, however, "significantly more complex" than prior CHIMNEYSWEEP operations, adding that this could indicate a cross-team collaboration or other scenarios.

"The use of ransomware to conduct a politically motivated disruptive operation against the government websites and citizen services of a NATO member state in the same week an Iranian opposition groups’ conference was set to take place would be a notably brazen operation by Iran-nexus threat actors," said Mandiant in the report.

"As negotiations surrounding the Iran nuclear deal continue to stall, this activity indicates Iran may feel less restraint in conducting cyber network attack operations going forward. This activity is also a geographic expansion of Iranian disruptive cyber operations, conducted against a NATO member state. It may indicate an increased tolerance of risk when employing disruptive tools against countries perceived to be working against Iranian interests."

So what does this have to do with Israel and other Middle Eastern countries?

According to a report by IBM's X-Force IRIS, ZEROCLEARE was used in a destructive cyberattack in the Middle East. X-Force IRIS estimated that an Iranian group known as the ITG13 threat group or APT34/OilRig and at least one other group likely based out of Iran collaborated on that attack.

Attacks by APT34 have also used decoy Word documents to infect computer systems in past attacks, according to the Israeli CheckPoint cybersecurity company.

A Russian threat actor called ITG12 or Turla also has access to tools used by APT34, according to X-Force IRIS. Turla has used APT34's infrastructure to carry out its own attacks, seemingly without explicit cooperation or agreement by the Iranian group, according to the US National Security Agency (NSA) and GCHQ's National Cyber Security Centre.

While it is still unclear if APT34 was the group behind the attack against Albania, tools it is has been linked to were used in the attack which has been linked to Iran.

APT34 has attacked targets in a number of countries, including Lebanon, Jordan and Israel, among others, according to a multitude of reports by cybersecurity companies.

The countries targeted by ZEROCLEARE and APT34 in the past seems to largely line up with the list of targeted countries stated by the Armenian prime minister, although no publicly reported attacks in Cyprus have been linked to APT34 or ZEROCLEARE.

Iranian cyber attacks have repeatedly targeted civilian facilities in the past.

In 2020, Iran-backed hackers reportedly attempted to attack and sabotage Israeli water and sewage facilities. Attacks attributed to Iran-backed hackers have also targeted medical facilities in Israel.
Posted by: Skidmark || 09/08/2022 07:07 || Comments || Link || [9 views] Top|| File under: Govt of Iran

#1  CHIMNEYSWEEP operates through a self-extracting archive that contains it and a decoy Excel, Word or video file.

Tempting for morons who think they can get Excel and Word for free.
Posted by: Abu Uluque || 09/08/2022 13:11 Comments || Top||


Home Front: Politix
White House DEFENDS Homeland Security following damning [IG] report that vetting 'flaws' may have allowed national security threats into the US after they were evacuated from Afghanistan
  • Follows report that DHS had 'inaccurate, incomplete, or missing' to vet evacuees

  • Report focuses on procedures to settle Afghan evacuees after fall of Kabul govt

  • Karine Jean-Pierre said report didn't take into account 'multi-layered process and screening process' by other US agencies

  • DHS said the IG lacked 'comprehensive understanding of the extensive details related to the numerous facts and nuances' of the vetting process
Posted by: Skidmark || 09/08/2022 11:30 || Comments || Link || [4 views] Top|| File under: Devout Moslems

#1  Incompetence at the White House and Pentagon is a national security threat.
Posted by: Abu Uluque || 09/08/2022 12:55 Comments || Top||

#2  'Vetting flaws' my ass - more likely there was no 'vetting'.
Posted by: Raj || 09/08/2022 13:20 Comments || Top||

#3  The important thing was to contaminate our country with these people. All other considerations were secondary.
Posted by: Sonny de Medici5342 || 09/08/2022 14:33 Comments || Top||

#4  #2 ..and that a program comperable to Visa Express made sure that desired "assets" made into the US.
Posted by: Rex Mundi || 09/08/2022 16:14 Comments || Top||

#5  Not making roll-call or answering their pager?

Whoopsies! Ooopsies! Vetting fall down!
Posted by: swksvolFF || 09/08/2022 16:22 Comments || Top||

#6  Or a real clincher, they've been tasked.
Posted by: swksvolFF || 09/08/2022 16:24 Comments || Top||

#7  Departments of Defense and Homeland Security -- bureaucracy not solutions
Posted by: magpie || 09/08/2022 16:44 Comments || Top||


Israel-Palestine-Jordan
Standing next to an F-35 fighter jet, Lapid issues warning to Iran: ‘Don’t test us'
Posted by: Fred || 09/08/2022 00:00 || Comments || Link || [9 views] Top|| File under: Govt of Iraq


Syria-Lebanon-Iran
International Atomic Energy Agency: Iran's nuclear program might not be exclusively peaceful
[FoxNews] The UN's International Atomic Energy Agency released a report outlining the progress Iran's nuclear program has made, warning that the agency cannot determine that the country's nuclear aims are "exclusively peaceful."

"The Agency is not in a position to provide assurance that Iran's nuclear programme is exclusively peaceful," said the report released Wednesday, according to Reuters.

The report comes as the Biden administration reportedly closed in on a renewed nuclear deal with Iran in recent weeks, though talks have stalled in the last 24 hours and the European Union's chief negotiator has attempted to downplay speculation that a deal could be close.


Posted by: NoMoreBS || 09/08/2022 00:00 || Comments || Link || [8 views] Top|| File under: Govt of Iran

#1  Sorta like "mostly peaceful" riots...
Posted by: M. Murcek || 09/08/2022 8:31 Comments || Top||

#2  Gotta go find my shocked face.
Posted by: AlanC || 09/08/2022 9:09 Comments || Top||

#3  That is British, no, Olympian levels of understatement.
Posted by: magpie || 09/08/2022 12:59 Comments || Top||

#4  That is British

Nope. Fox News.
Posted by: Skidmark || 09/08/2022 13:33 Comments || Top||

#5  When there's a leaked report that DJT had some nuclear documents, it's maximum vapors and all hands to the pump. But it's quiet as a mouse as the Mad Mullahs progress toward getting actual nukes.
Posted by: Matt || 09/08/2022 16:01 Comments || Top||



Who's in the News
40[untagged]
5Govt of Iran
3Islamic State
2Arab Spring
2Devout Moslems
1Govt of Pakistain Proxies
1Hayat Tahrir al-Sham (al-Nusra)
1Sublime Porte
1Tin Hat Dictators, Presidents for Life, & Kleptocrats
1[untagged]
1al-Qaeda in the Arabian Peninsula
1Commies
1Govt of Iran Proxies
1Govt of Iraq

Bookmark
E-Mail Me

The Classics
The O Club
Rantburg Store
The Bloids
The Never-ending Story
Thugburg
Gulf War I
The Way We Were
Bio

Merry-Go-Blog











On Sale now!


A multi-volume chronology and reference guide set detailing three years of the Mexican Drug War between 2010 and 2012.

Rantburg.com and borderlandbeat.com correspondent and author Chris Covert presents his first non-fiction work detailing the drug and gang related violence in Mexico.

Chris gives us Mexican press dispatches of drug and gang war violence over three years, presented in a multi volume set intended to chronicle the death, violence and mayhem which has dominated Mexico for six years.
Click here for more information

Meet the Mods
In no particular order...
Steve White
Seafarious
tu3031
badanov
sherry
ryuge
GolfBravoUSMC
Bright Pebbles
trailing wife
Gloria
Fred
Besoeker
Glenmore
Frank G
3dc
Skidmark

Two weeks of WOT
Thu 2022-09-08
  Queen Elizabeth II dead at 96
Wed 2022-09-07
  Scores of Nigeria Jihadists Drown Fleeing Air Strikes: Sources
Tue 2022-09-06
  Arizona troopers discover 46 pounds of fentanyl pills during traffic stop
Mon 2022-09-05
  West Bank: Shooting at Israeli soldiers' bus leaves seven wounded; 3 miscreants all one family
Sun 2022-09-04
  At least 33 people have been killed following an attack on a town in the eastern Democratic Republic of Congo
Sat 2022-09-03
  Explosion at oil refinery in Iran’s Abadan
Fri 2022-09-02
  Nigerian Fighter Jets Reportedly Kill 49 Boko Haram Fighters In Separate Camps
Thu 2022-09-01
  Border officials in Texas make largest cocaine bust in 20 years inside baby wipe shipment
Wed 2022-08-31
  ‘This Is Not a Revolution': Shiite Cleric Tells Iraqi Rioters to Stop After 30 Deaths, 400 Wounded
Tue 2022-08-30
  32 Killed, 159 Injured in Libya Clashes; Death Toll Continues to Rise
Mon 2022-08-29
  Iraq Presidential Palace Stormed, US Embassy Helicopter Evacuation
Sun 2022-08-28
  Jewelry designer unmasked as Russian spy luring NATO chiefs into honeytraps
Sat 2022-08-27
  Five people shot dead in the center of Canada's capital
Fri 2022-08-26
  The Russians unsuccessfully advanced in the Avdiiv, Slavyan and Bakhmut directions
Thu 2022-08-25
  At least 15 killed, 50 more injured after the Russian missile strike on the railway station in Chaplyne near Dnipro


Rantburg was assembled from recycled algorithms in the United States of America. No trees were destroyed in the production of this weblog. We did hurt some, though. Sorry.
18.117.196.184
Help keep the Burg running! Paypal:
WoT Operations (12)    Non-WoT (15)    Opinion (9)    Local News (14)    Politix (4)