Can the ransomware crisis force action against Russia?

[ad_1]

At the same time, the Kremlin usually resolutely resists international efforts so that hackers will follow suit, simply throwing the blame back to the rest of the world, refusing to admit that there is a problem, and refuse to provide help.

For example, on May 11, shortly after Biden’s statement, Kremlin spokesman Dmitry Preskov publicly denied Russian intervention. On the contrary, he criticized the United States for “refusing to cooperate with us in any way to deal with cyber threats.”

Russia’s calculus is difficult to measure clearly, but there are several variables that are amazing: ransomware attacks have destabilized Moscow’s opponents and transferred wealth to Moscow’s friends-all without many negative consequences.

Now, observers want to know whether high-profile events such as pipe closures will change the mathematics.

“For the United States and the West, the question is,’If Russia doesn’t cooperate, how much are you willing to do with Russia?” said James Lewis, a cyber security expert at the Center for Strategic and International Studies. What the West has been reluctant to do is to take strong action against Russia. How will you impose the consequences when people ignore the agreed international standards? “

“I do think we need to put pressure on Russia to start dealing with cybercriminals,” Alperovitch thinks. “Not only the people directly responsible for the colony, but also a group of people who have been carrying out ransomware attacks, financial fraud and other activities for decades. Not only did Russia fail to do so, but we also asked for the arrest of individuals and provide sufficient evidence to Russian law enforcement agencies. At that time, they strongly opposed it, and they did nothing. They are at least completely obstructive. They do not help investigations, arrests, and hold accountable. At least, we need to ask them to take action.”

“Russia has at least been a complete obstructionist. It has not helped investigations, made no arrests, and has not been accountable to the people.”

Dmitri Alperovitch, Silverado Policy Accelerator

There are countless examples of cybercriminals entangled with Russian intelligence services. The huge hack against Yahoo in 2014 resulted in toll Oppose Russian intelligence personnel and cybercriminal accomplices. Hacker Evgeniy Bogachev, who was once the most prolific bank hacker in the world Linked Espionage against Russia. And in rare cases, when hackers were arrested and extradited, Russia accused the United States of “Kidnapping“Its citizens: the Americans oppose the Kremlin is protection By preventing investigations and arresting their own criminals.

For example, the United States has accused Bogachev of establishing a criminal hacker network responsible for stealing hundreds of millions of dollars from bank hackers. His current residence in a resort in southern Russia is no secret. The most important thing is that the Russian authorities initially cooperated with the US-led investigation against him, but ultimately rejected the deal. Like many of his contemporaries, he is out of reach because of Moscow’s protection.

To be clear: There is no evidence that Moscow led the colonial pipeline hacking operation. Security and intelligence experts believe that the Russian government’s long-term tolerance of cybercriminals and incidental direct relationships are at the core of the ransomware crisis. Allowing the criminal economy to develop unrestricted will almost inevitably hit critical infrastructure targets such as hospitals and pipelines. But the rewards are high, and the risks so far have been low, so the problem has increased.

What are the options?

A few days before the pipeline was hacked, a landmark “fighting against ransomware” report Published by the Institute of Security Technology. It is composed of a task force composed of representatives of the government, academia, and the largest companies in the US technology industry, and is one of the most comprehensive works on this issue. Its main recommendation is to establish a coordinated process to prioritize ransomware defenses throughout the US government. It believes that the next stage will require real international efforts to deal with the multi-billion dollar ransomware problem.

Phil Reiner, who led the report, said: “The previous government did not consider this issue to be a priority.” “They did not take coordinated action. In fact, the previous government was completely disharmonized in terms of cyber security. They did not gather. It’s no surprise that they didn’t establish a cross-departmental process to solve this problem, and they did nothing.

Today, the standard menu of options for responding to hacking incidents in the United States includes sending obnoxious notes or personal indictments, to state-level sanctions and offensive cyber operations against ransomware groups.

[ad_2]

Source link