“Almost all disinformation operations are imperfect by design, run not by perfectionists, but pragmatists.”
— Thomas Rid in Active Measures: The Secret History of Disinformation and Political Warfare
As Thomas Rid quips in his book Active Measures, cyber-enabled information operations are more active but less measured. So, it is rare to see the instance of an old-school disinformation operation that seems to have served its purpose quite effectively.
Active Measures, in the general sense of the term, are rarely this successful, so the operation I am going to discuss certainly stands out.
In March 2020, Booz Allen Hamilton released a fascinating dossier analysing the cyber operations of GRU, the Russian military intelligence agency, spanning 15 years. The dossier ran the traditional cyber threat intelligence (CTI) tradecraft through an impressive analytic process, thus credibly gluing the cyber operations of GRU to the doctrinal framework and geopolitical imperatives of the Russian state.
I am having some strange epiphanies as I go knee-deep into SIEM engineering. While the MSSPs have existed in all flavors and sizes, there seems to be a broad consensus that they simply can’t mimic the capabilities of an in-house security operations function – especially when it comes to gaining context, visibility and speed.
In my recent
essay for the Centre for Internet & Society, I surmised that the
current initiatives to derive cyber norms within the ambit of international law
could be incongruous with the technical dynamics of cyber operations. I shed
light on the critical fissures in global attempts to establish normative
frameworks for cyberspace.
I may (or may not) do a series of quick posts highlighting the strategic challenges encountered while investigating a cyberattack like Kudankulam. They would be filed under the ‘lessons-from-kudankulam‘ tag. Since our agencies were literally caught napping, this is a good primer for understanding what nation-state-level cyber capabilities entail:
Some dumbified excerpts from my dispatches to the government: