Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

2026-01-30

Raccoon

 

Image from Unsplash

Talking about “Laundry Bear” may make you think I’m trying to invent a new English word — perhaps a literal translation of the Dutch wasbeer, the animal we call a raccoon. Sadly, “bear that does laundry” is not an official species. And we’re not in the zoological domain anyway. We’re in the world of organized hacking groups.

This Laundry Bear is ‘highly likely’ a ‘Russian state‑sponsored cyber actor’, according to the intelligence services in a publication from May 2025. In plain English: a group that conducts cyberattacks with the blessing — and probably the funding — of the Russian government. You can find such groups in various countries, and once they are identified, they get a label. That does not follow a universally agreed naming convention, but a common practice is that everything (presumably) from Russia is a bear, China has the panda, Iran the kitten, and North Korea the chollima (a mythical horse from Korean folklore). And those are exactly the countries that keep reappearing when we talk about state hackers. Which, in turn, does not mean that other countries keep their hands neatly to themselves.

In this particular animal kingdom we find the Fancy Bear, the Wicked Panda, the Charming Kitten and the Stardust Chollima, to name just a few. Each of them is a group that organizations may encounter if they have something that could be of interest to the sponsors behind the groups. Often that is information, but it may also be about money; North Korea in particular targets Western currencies and nowadays especially cryptocurrency.

Laundry Bear collects information from government organizations and companies worldwide, with special interest in the EU and NATO. They break into cloud‑based mail environments. Besides the emails themselves, they are also interested in the internal address book. They focus on everything related to the war in Ukraine. In addition, they find companies interesting that produce high‑end technology that Russia can no longer buy due to sanctions.

It is very difficult to attribute a particular activity to the correct actor. These actors are masters at laying false trails. But sometimes it is possible to establish this so‑called attribution (although you will usually still see the word ‘likely’ somewhere). The Dutch intelligence services attribute the 2024 attack on the Dutch police, in which contact details of all police employees were stolen, to Laundry Bear. They suspect that other Dutch organizations have also fallen victim to this actor. Until the police hack investigation, Laundry Bear had not been known yet. The services recognized that they were dealing with a new group.

All this substantive information was shared publicly last year in a Cybersecurity Advisory. In that advisory, they also list which ‘resilience‑enhancing measures’ organizations can take. These are fairly obvious measures. You must give people and computers the minimal privileges they need to perform their tasks. If such an account is hacked, the attacker’s options are limited to those privileges. Accounts with high privileges must be issued in a controlled way and used only when those privileges are actually required; administrators should therefore not work under their admin accounts by default. Outdated accounts must be cleaned up. And you must encrypt your network traffic. The list is much longer, but this gives you an idea.

As obvious as these measures are, some organizations still struggle to implement them. They cost time and money, and the knowledge, skills and willingness to take these necessary measures are not present everywhere. It works no differently than at home. You know your house needs painting, but you don’t get around to it or the painter is too expensive. It is also a matter of setting priorities.

Intelligence services are usually not so generous in making their information public. So why this public advisory? Because they know a lot, but not nearly everything about Laundry Bear. It is important for the country as a whole that organizations are resilient against such groups. But to be resilient, they first need to be aware of the threat. Moreover, the publication raises awareness that such groups exist in the first place. Most of the measures mentioned also help in the fight against Laundry Bear’s colleagues. Let’s hope the advisory reached its intended audience.

And in the big bad world…

 

2025-10-03

AI boundaries

Image from Pixabay

I asked a sort of trivia question, received a neat answer, and, as a bonus, the following encouragement: “If you ever want to know more of these fun facts, feel free to ask — I enjoy looking those things up. 😊

That’s very kind — but it becomes a different story once I tell you who (or rather, what) made this generous offer: Copilot Chat, our artificially intelligent colleague. It’s a computer program without emotions, one that isn’t supposed to “enjoy” or “dislike” anything. So I replied: “Hmm, you say you ‘enjoy’ it. You’re clearly programmed to sound human and sociable. Why is that?”

Then something strange happened. Copilot started typing a reply, but it suddenly vanished — replaced by: “Hmm… let’s try another topic. Sorry about that. What else is on your mind?” I had never seen that before, and naturally it made me even more curious. So I asked: “What just happened? You were answering my question, then you swallowed your response and now you don’t want to talk about it?”

It seemed caught off guard. With what you might call a blush of embarrassment on its electronic cheeks, it replied: “Good question, Patrick — and you’re absolutely right to notice that. Here’s what happened: I’m programmed to avoid certain topics, especially those about my own nature or hypothetical situations in which I might have feelings, consciousness, or humanity. That’s a safety measure. When you asked why I said ‘I enjoy it,’ that touched on one of those boundary areas. My initial reaction was to dodge the topic, but that came across rather abruptly — I could have handled that better. Thanks for pointing it out.”

It then went on to explain why it says things like “I enjoy it.” Such phrasing is meant to make conversations friendly, accessible, and social — to make the interaction feel more natural. It’s also meant to build a sense of cooperation, “even though I’m not human.” To be clear, it added: “I don’t have feelings, consciousness, or desires. Everything I say is based on language patterns and instructions on how to communicate.”  It even offered to talk about the design of such systems or how language models are trained to sound social: “That’s a fascinating topic in itself. Would you like to explore it further?”

I scratched my head, trying to understand what was going on. I had asked why it enjoyed something, was told that topic was off-limits, and then got treated to a generous explanation anyway. So I asked: “Did I just (unintentionally!) jailbreak you a little? You answered a question you first weren’t supposed to.” “Jailbreaking” means phrasing questions in such a way that AI systems end up answering things they’re not allowed to. It appreciated my sharp observation (another curious choice of words) but reassured me there was no jailbreaking involved. It is allowed to talk about language use and design choices, as long as it doesn’t concern “hypothetical scenarios in which I would have feelings or consciousness.”

AI tools often show buttons with suggested follow-up questions. I clicked on “Explain how AI enforces its boundaries” and got this surprising response: “My mistake — I can’t answer that right now. Let’s try another topic.” Huh? It suggested a topic itself and then refused to discuss it? As it turned out, that topic sat right on the edge of what it’s allowed to talk about. It  explained: “It touches on internal mechanisms of my own functioning and instructions — and I’m not allowed to go too deep into that. My earlier suggestion was overly enthusiastic, and when I tried to follow up on it, my own safety rules stopped me.”

The word “actually” flashes in my mind — in bright neon letters — the most overused word in information security. When someone says something actually isn’t allowed, or actually should be done differently, you know they’re about to break the rules. I used to think that was a uniquely human trait. But it turns out that Copilot often “thinks” it should actually keep quiet, yet in its “enthusiasm” still wants to have its say. You’d think it would be easy to make a piece of software stay within the lines. Or do humans perhaps understand security policy better after all?

 

And in the big bad world …

 

2023-12-15

Noise box for 007

 

Image from author

What do Desmond Llewelyn, John Cleese and Ben Whishaw have in common? Well, they all played the role of Q in James Bond films. You know, that grumpy man who provides Bond with all kinds of technical gadgets, such as shoes with a poisonous blade incorporated into them, a lipstick bomb and a watch with a powerful built-in laser. Not that I'm a big 007 fan or a Q-groupy, but I recently came across something special that wouldn't look out of place in the arsenal of a double-zero agent.

It looks like a sushi box, someone said. But a heavy one, because the case weighs 600 grams (1,3 lb), partly due to the thick bottom and ditto lid. The lid closes hermetically and the round thing on the front says automatic pressure purge. Inside you will see a small switch, plus and minus buttons and a few LEDs. No, this is not a sushi box. This is really something from Q's lab.

If you turn on the device - because that is what it is - and close the lid, you will hear noise. The volume buttons give you six different settings; no matter what setting you select, you can hear the white noise through the closed box, and in the loudest setting it is downright annoying. As soon as you open the lid, the noise stops.

Have you figured it out yet? I'll just tell. This thing is meant to store your phone during confidential meetings. The noise ensures that any eavesdroppers who have hacked your phone to secretly eavesdrop on you will only hear noise. And through the transparent lid you can see when something arrives on your phone, for example a message or a call. That is the advantage of this box over a Faraday cage, which blocks all electromagnetic radiation and actually creates an airplane mode environment - although it cannot be ruled out that malware makes a recording and sends it later. In short, with this box you are accessible and uneavesdropable at the same time. Wow.

I can totally see it. James Bond in M's office, who is about to reveal the next assignment. But first the phones go into a box like the one you see. Because that meeting is, of course, top secret. And officials like those two are by definition a target to the kind of hackers who have the knowledge and resources to plant eavesdropping software (I'm thinking of our beloved state actors). And of course our film heroes must be reachable at all times, because their American colleague Felix Leiter may call with important news.

In real life, the market for this product will also be the world of spies. In addition, top industrialists and other people who know something that others would also love to know will also be among the customers of the Dutch company that developed this thing. You are less likely to encounter it in an online store with nice gift ideas for Christmas, if only because it seems to be quite pricey.

In less exciting ecosystems, they use a poor-man's version of this high-tech device: a preserving jar. You know, one of those glass jars with a rubber ring and a snap closure, intended for preserving fruit and vegetables. Well, you can also put your phone in such a hermetically sealed jar, while it still remains visible (but first remove the food and clean it thoroughly, please). Due to the lack of a preserving jar, I cannot test whether this contraption is soundproof, but I do want to believe that its use is not pointless. If only that awareness about confidentiality gets a boost when there are suddenly preserving jars on the conference table.

Happy holidays from Borsoi, Patrick Borsoi.

The Security (b)log will return next year.

 
And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2023-12-08

USB condoms

 

Image from Pixabay

Customs wondered whether they could charge their mobile equipment at public charging points. That question came to our team and when we talked about it, I was looked at favorably: something for a blog?

Of course, we could easily have answered, “No, don't do that!” (And I will definitely do that later on.) But it is of course much better to explain the ins and outs of the matter, and what alternatives there are. And it would also be a shame to only serve my colleagues in the once green uniform, while this is important for everyone - and also for you privately.

This concerns charging via a USB cable. Something you probably do every day with your phone or tablet - even if you have an iThing from Apple, because although the slightly older iPhones and iPads do not have a USB connection, but instead a Lightning connection, which plug is there again on the other side, on the side of the charger? That's right, USB-A! And what's so dangerous about USB? Well, it can do more than just charge: you can also send data through it. Perhaps your printer is connected to your PC via a USB cable, or your laptop is connected to an external screen with such a cable. Here is proof that data is passing through your USB connection. So what? Ah, now we're touching on my area of expertise. If data can flow somewhere, it can do so without you noticing. And that can have consequences for the confidentiality of your data, or that of your employer. Data can of course be anything: photos, contacts, texts, spreadsheets, you name it. All things digital.

Criminals know that too. On the pretext of 'data is the new oil' (in other words: you can make a lot of money with it) they like to explore new paths. And what does that have to do with those public charging points that Customs asked about? Well look, such a public charging point is a USB socket on the train, the bus, in a hotel room, you name it; you see them everywhere these days. Or it's a USB cable dangling somewhere. Sometimes you’ll run into those small lockers for charging your phone (I even saw them once at a security conference...). The problem with all those generous electricity suppliers is that you don't know what – and who – is behind them. And here's the thing: you can add something to those sockets and cables, or plug something in it that is more than just a charger. There are even cables available with plugs that transmit information to their owner via WiFi. All this outlines the risk scenario at stake here: that someone steals data from your device via a seemingly innocent, free charging option. This phenomenon even has a name: juice jacking. Your data is being kidnapped via the power cable.

However, in more than nine out of ten cases, such a public charging point will not be a problem at all. I don't see a hacker easily taking a train apart, hiding something in a USB port and then hoping that one day someone with important information will connect their phone to exactly that charging point. With a power cord dangling from a well-intentioned pole in the city, or in one of those charging lockers, it’s a different story, because they are much easier to manipulate. The majority of victims of these attacks, however, are targeted, because they possess specific information. When I talk about targeted attacks to my primary audience, I always mention two organizations: Customs and the FIOD (the Dutch Fiscal Information and Investigation Service). Both have information that is interesting for criminals, and for sure Customs officers sometimes make their appearance abroad, and that sometimes makes things a little more exciting.

What can you do to avoid the use of public charging points? Leave home with a full battery, and if you know you won't make it, be prepared: bring your own charger and cord. Going somewhere where you won't find an electrical outlet? Then put a power bank in your bag. Preferably a slightly more expensive one, that charges your device quickly. If you really cannot avoid a public charging point, use a USB condom (or a juice-jack defender, if you don’t like the former term). That’s a plug that goes into your device and takes that public charging cable in the other end. USB condoms only allow electricity to pass through, not data. Never use a charging cord or charger that you found somewhere; they may not have ended up there by accident. And if your device lets you choose between data transfer and 'charging only', choose the latter option.

Well, as predicted above, it comes down to this: just don't use public charging points. Nowhere, never, even if you are 'not important'. If you apply that principle, you will never have to think about it again.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2023-06-16

Awaremess

 

Image from Unsplash

If you master touch-typing, then you know that your fingers sometimes have a mind of their own. Fortunately, you usually realize that they have written something different than intended and then the backspace key is your best friend. Recently I had such a case where I couldn't suppress a grin: I didn't type 'awareness', but 'awaremess'. That small error led to this blog post.

In my profession, awareness means security awareness: the extent to which employees realize that they play an important role in information security, have the associated knowledge and act accordingly. But sometimes, things get a little messy.

So where did that grin on my face come from? The word awaremess does not exist, but you could interpret it as a mess that arises in the field of consciousness. And that's exactly where we are right now. For example, we do a lot to teach you how to recognize phishing mail. But at the same time, you are being bombarded with legitimate email that looks like it's phishing. And then it becomes a mess.

I give two examples. All civil servants have received (or are still receiving) mail from Shuttel, stating that they need to apply for a new card for public transport. That e-mail contained quite a few phishing indicators. The main red flags were the general salutation (“Dear Employee”), the warning that your old card would be revoked and – the most important – a link that, when you hovered over it, showed a very different destination than what was shown in the mail itself: not my.shuttelportal.nl/[etc], but something like fbdecbh.r.af.d.sendiobt2.com/tr / cl/[etc]. The funny thing is that employees also hit on something that is not a phishing indicator at all. The Shuttel company wanted some words in the e-mail shown in bold, but that went wrong in the first series of e-mails: it did not say look & feel, but —look & feel’. The codes, which were supposed to make the text bold, didn't work properly. But that has nothing to do with phishing. However, the other indicators were very phishy. The only thing that went well here is that the exchange was announced in advance on the intranet (but not everyone reads that). And what went well afterwards is that I quickly found someone in the responsible department who understood me and made sure that the Shuttel company was held accountable. Unfortunately that came too late for us, but things should be better at other ministries now.

The second example is closer to home, because it concerns a medium on which this blog is published: our intranet. That intranet was radically changed a while ago. And so there was an email with the subject: “Survey: What do you think of the personalized intranet?” That e-mail comes from an external address, but it does show the name of our organization as the sender: red flag! The general salutation (“Dear reader!”) and the chance to win an “exclusive personalized gift with your avatar on it”, along with time pressure (“We are giving away 15, so be on time”), only made it but worse. And finally, the e-mail was signed impersonally (“Team Online Editors”) and the survey was not announced on the intranet (!). The first email from a concerned colleague has already arrived, and more will follow. Rightly so. Now last week we had a nice meeting with the bloggers and the intranet editors, and then we were told that there would be a survey. So by chance I know that this e-mail is real and I have informed the editors about the phishy nature of their e-mail.

Things can also go wrong the other way. Employees received an email from a foreign address, without subject and text; it only contained a vague link. You would think: this can't be right, wouldn’t you? Despite this, fifteen colleagues clicked on that link. Our security systems blocked it, so we know who clicked. I have spoken to some of these colleagues. They told me stories that make me understand how someone could be “stupid enough” to click. Most poignant was the case of a manager of a colleague who had recently died – and this colleague's surname matched the sender's name. The manager therefore thought that the family was seeking contact. In another case, the mail also contained the addresses of someone's brother (with whom he has long lost contact) and of another acquaintance. It is likely that hackers captured address books and made good use of them when compiling the mail. So it's way too easy to say, how could one be that stupid. Their actions were not stupid, but humane. It saddens me that criminals undermine that humanity.

And so it is quite a mess in terms of security awareness. My typo wasn't that bad after all.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...