{"id":96283,"date":"2018-10-04T11:24:00","date_gmt":"2018-10-04T11:24:00","guid":{"rendered":"http:\/\/mostafa.openonline.co.uk\/?guid=4df3fc2f59ada7f782ad89df3de936a6"},"modified":"2018-10-04T11:24:00","modified_gmt":"2018-10-04T11:24:00","slug":"speech-minister-for-europe-statement-attempted-hacking-of-the-opcw-by-russian-military-intelligence","status":"publish","type":"post","link":"https:\/\/mostafa.openonline.co.uk\/?p=96283","title":{"rendered":"Speech: Minister for Europe statement: attempted hacking of the OPCW by Russian military intelligence"},"content":{"rendered":"<div class=\"govspeak\">\n<p>I\u2019d like to thank my Dutch colleagues and to make a few remarks. The United Kingdom and the Netherlands are close security partners, and our presence together today in The Hague underlines that.<\/p>\n<h2 id=\"the-disruption\">The disruption<\/h2>\n<p>The disruption of this attempted attack on the Organisation for the Prohibition of Chemical Weapons (<abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr>) was down to the expertise and professionalism of the Dutch security services, in partnership with the UK. The <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> is a respected international organisation, which is working to rid the world of chemical weapons. Hostile action against it demonstrates complete disregard for its vital mission.<\/p>\n<p>This disruption happened in April. Around that time, the <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> was working to independently verify the UK\u2019s analysis of the chemical used in the poisoning of the Skripals in Salisbury. As we know, the <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> confirmed the UK\u2019s analysis that a Novichok nerve agent was used in the Salisbury attack \u2013 which we now know for certain was carried out by serving <abbr title=\"Russian military intelligence service\">GRU<\/abbr> officers.<\/p>\n<p>The <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> was also due to conduct analysis of the chemical weapons attack in Douma on 7 April. This operation in The Hague by the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> was not an isolated act. The Unit involved,  known in the Russian military as Unit 26165, has sent officers around the world to conduct brazen close access cyber operations.<\/p>\n<p>One of the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> officers who was escorted out of the country by our Dutch colleagues, Yevgeniy Serebriakov, also conducted malign activity in Malaysia. This <abbr title=\"Russian military intelligence service\">GRU<\/abbr> operation there was trying to collect information about the MH17 investigation, and it targeted Malaysian government institutions including the Attorney General\u2019s office and the Royal Malaysian Police.<\/p>\n<p>As the General has just mentioned, we also know that the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> officers who were stopped in The Hague planned to travel on to the <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> designated laboratory in Spiez. This wouldn\u2019t have been the first time they\u2019d travelled to Switzerland. Intelligence collected from a laptop that belonged to one of the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> officers disrupted in The Hague shows that it had connected to WiFi at the Alpha Palmiers Hotel in Lausanne in September 2016 \u2013 where a <abbr title=\"World Anti-Doping Agency\">WADA<\/abbr> conference was taking place.<\/p>\n<p>That conference was attended by officials from the International Olympic Committee and the Canadian Center for Ethics in Sport. They found themselves the victims of a cyber attack. One official from the Canadian Center had their laptop compromised by \u2018APT28\u2019 malware; this was probably deployed by an actor connected to the same hotel WIFI network. Immediately after this laptop was compromised, the Center\u2019s computer systems were infected more broadly by APT28 malware. Subsequently, APT28 actors also compromised the IP addresses of the International Olympic Committee.<\/p>\n<h2 id=\"apt28-sandworm-and-salisbury\">APT28, Sandworm and Salisbury<\/h2>\n<p>Earlier today the British Government has publicly revealed that APT 28 and a number of other cyber actors, widely known to have been conducting cyber attacks around the world, are in fact the <abbr title=\"Russian military intelligence service\">GRU<\/abbr>.<\/p>\n<p>The UK National Cyber Security Centre has made this assessment because of compelling technical evidence that links these actors\u2019 operations to known <abbr title=\"Russian military intelligence service\">GRU<\/abbr> technical infrastructure. This leads them to assess that the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> was almost certainly responsible for these actors\u2019 attacks.<\/p>\n<p>I want to make it completely clear: the officers disrupted in The Hague are part of the same Unit of the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> \u2013 26165 \u2013 which is responsible for APT28. Another of the cyber actors identified as the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> was Sandworm, which was active in the wake of the Salisbury attack.  I can reveal that they were behind the following attempted intrusions:<\/p>\n<ul>\n<li>in March, straight after the Salisbury attack, the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> attempted to compromise UK Foreign and Commonwealth Office computer systems via a spear phishing attack<\/li>\n<li>in April, <abbr title=\"Russian military intelligence service\">GRU<\/abbr> intrusions targeted both the computers of the UK Defence and Science Technology Laboratory, as well as the Organisation for the Prohibition of Chemical Weapons<\/li>\n<li>in May, <abbr title=\"Russian military intelligence service\">GRU<\/abbr> hackers sent spear phishing emails which impersonated Swiss federal authorities to target <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> employees directly, and thus <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr> computer systems.<\/li>\n<\/ul>\n<p>These cyber-attacks were carried out remotely \u2013 by <abbr title=\"Russian military intelligence service\">GRU<\/abbr> teams based within Russia.<\/p>\n<h2 id=\"pattern-of-behaviour-the-gru\">Pattern of behaviour: the <abbr title=\"Russian military intelligence service\">GRU<\/abbr><br \/>\n<\/h2>\n<p>Alongside our allies, the United Kingdom is committed to confronting, exposing and disrupting the <abbr title=\"Russian military intelligence service\">GRU<\/abbr>\u2019s activity.<br \/>\nTheir pattern of behaviour is exemplified by the reckless attempted operation against the <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr>\u2019s headquarters here in The Hague, which was brilliantly disrupted by the Dutch security services. But its wider implications bear repeating.<\/p>\n<p>As our attributions today have made clear, the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> has interfered in free elections and pursued a hostile campaign of cyber-attacks against state and civilian targets.<\/p>\n<h2 id=\"conclusion\">Conclusion<\/h2>\n<p>The <abbr title=\"Russian military intelligence service\">GRU<\/abbr> is an aggressive, well-funded, official body of the Russian State. It can no longer be allowed to act aggressively across the world, and against vital international organisations, with apparent impunity.<\/p>\n<p>I should repeat that this is a real and multi-faceted threat, conducted by both remote and proximate means. <abbr title=\"Russian military intelligence service\">GRU<\/abbr> officers do not just attempt to compromise our computer systems from their barracks in Moscow. As we have shown today:<\/p>\n<ul>\n<li>they have operated on the streets of the Netherlands to target the <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr>\n<\/li>\n<li>they travelled across the world under diplomatic cover to target the MH17 investigation in Malaysia and a <abbr title=\"World Anti-Doping Agency\">WADA<\/abbr> conference in Switzerland<\/li>\n<li>and they operated in a quiet British city to apply a banned nerve agent to a door handle<\/li>\n<\/ul>\n<p>With its aggressive cyber campaigns, we see the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> trying to clean up Russia\u2019s own mess \u2013 be it the doping uncovered by <abbr title=\"World Anti-Doping Agency\">WADA<\/abbr> or the nerve agent identified by the <abbr title=\"Organisation for the Prohibition of Chemical Weapons\">OPCW<\/abbr>.<\/p>\n<p>Our world-leading intelligence partnership and outstanding professionalism from the Dutch, British and allied security and intelligence communities have allowed us to disrupt and expose them.<\/p>\n<p>On the basis of what we have learnt in the Salisbury investigation \u2013 and what we know about this organisation more broadly \u2013 we are now stepping up our collective efforts against malign activity, and specifically against the <abbr title=\"Russian military intelligence service\">GRU<\/abbr>.<\/p>\n<p>We will increase further our understanding of what the <abbr title=\"Russian military intelligence service\">GRU<\/abbr> is doing, and attempting to do, in our countries. We will shine a light on their activities. We will expose their methods and we will share this with our allies. This includes strengthening international organisations, and working to protect other potential targets from further harm.<\/p>\n<p>Through our institutions, including the EU, we will work with allies to update sanctions regimes to deter and respond to the use of chemical weapons, we will combat hostile activity in cyberspace, and we will punish human rights abuse.<\/p>\n<p>The <abbr title=\"Russian military intelligence service\">GRU<\/abbr> can only succeed in the shadows. We all agree that where we see their malign activity, we must expose it together.  And we will.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>UK Ambassador to The Netherlands Peter Wilson delivered a statement on behalf of Europe Minister Alan Duncan on the attempted hacking of the OPCW by the GRU.<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"_links":{"self":[{"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/96283"}],"collection":[{"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=96283"}],"version-history":[{"count":0,"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/96283\/revisions"}],"wp:attachment":[{"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=96283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=96283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mostafa.openonline.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=96283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}