{"id":3868,"date":"2024-06-03T15:47:50","date_gmt":"2024-06-03T20:47:50","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/russia-cyber-operations-summer-olympics"},"modified":"2024-06-03T15:47:50","modified_gmt":"2024-06-03T20:47:50","slug":"russia-aims-cyber-operations-at-summer-olympics","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/03\/russia-aims-cyber-operations-at-summer-olympics\/","title":{"rendered":"Russia Aims Cyber Operations at Summer Olympics"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt13bed7ea27f0a660\/665e2c4b208c11f9d5387a29\/olympics_JuergenHasenkopf_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Two Russian state-aligned threat actors have been carrying out online influence operations designed to undermine the upcoming Olympic Games in Paris.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For a year now, Storm-1679 and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/openai-disrupts-5-ai-powered-state-backed-influence-ops\" rel=\"noopener\">the recently disrupted Storm-1099<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (aka &#8220;Doppelganger&#8221;) have been spreading fake news, doctored images, and artificial intelligence (AI)-aided videos about the Olympics on social media. According to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cdn-dynmedia-1.microsoft.com\/is\/content\/microsoftcorp\/microsoft\/final\/en-us\/microsoft-brand\/documents\/MTAC_Report_Russian_Influence_and_Paris_2024.pdf\" rel=\"noopener\">Microsoft report this week<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the goal seems to be twofold: harm the reputation of the International Olympic Committee (IOC) (which has banned Russia in the past), and stoke fears around potential violence at the Summer Games.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Time will tell whether these operations are a precursor to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/paris-olympics-cybersecurity-at-risk-via-attack-surface-gaps\" rel=\"noopener\">more direct cyberattacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> during the Games themselves.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Russia vs. the Olympics\">Russia vs. the Olympics<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Russia&#8217;s influence campaigns against the 2024 Olympics began with a bang.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last June, Storm-1679 published to Telegram a full feature-length movie titled &#8220;Olympics Has Fallen,&#8221; a play on the popular 2013 blockbuster &#8220;Olympus Has Fallen.&#8221; It came with all the bells and whistles: a fake Netflix intro, fake five-star reviews from major US newspapers, slick special effects, and narration from an AI-generated voice resembling Tom Cruise. The group spread its masterpiece on social media, even commissioning celebrities on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cameo.com\/\" rel=\"noopener\">Cameo<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to unwittingly help promote it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In months since, Storm-1679 has developed as an auteur with videos pretending to come from the CIA, France&#8217;s General Directorate for Internal Security (DGSI), French broadcaster France24, and the Belgium-based Euro News. All of these videos carried the same theme: warning viewers about terrorist threats to the summer games, in one creative way or another.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In comparison, Storm-1099 has taken a relatively more straightforward approach to fake Olympics-themed content. Particularly in the last couple of months, the group has been using 15 French-language fake news websites to spread rumors about corruption in the IOC, fears about purported violence to come in July, and criticisms of French president Emmanuel Macron.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Concerns About Physical Attacks on Paris Olympics\">Concerns About Physical Attacks on Paris Olympics<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Russia&#8217;s recent history with the Olympics has not been defined by sporting achievement and medals.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides a highly publicized doping scandal, it&#8217;s best known for sponsoring a major <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cyberattack-aimed-to-disrupt-opening-of-winter-olympics\" rel=\"noopener\">cyberattack during the 2018 Winter Games<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in PyeongChang, South Korea. That attack, dubbed Olympic Destroyer, temporarily disabled IT systems \u2014 including Wi-Fi at the stadium, IOC worker monitors, and the event&#8217;s ticketing website \u2014 during the opening ceremony to the events, and was cleverly designed to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/olympic-destroyer-s-false-flag-changes-the-game\" rel=\"noopener\">pin the blame on North Korea&#8217;s Lazarus group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So while influence operations have their place in defenders&#8217; thoughts, &#8220;the first and largest fear on everyone&#8217;s mind would be that attackers stop the Games \u2014 that they interfere with critical infrastructure such as power or networking, which prevent events from executing or from being watched,&#8221; says Sean McNee, head of research for DomainTools.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The unique nature of the Olympic IT infrastructure increases its vulnerability, offering an extensive and unique surface area to attack,&#8221; he notes. For this reason, securing the games will require immense international coordination and planning, with an emphasis on physical security, and training staff for potential cyberattack scenarios.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The Games will need a fully operational security operations center (SOC) with trained personnel to monitor for possible attacks. Because they only happen every four years, the staff will need to be ready for the unexpected, as the attack and defense landscape has changed dramatically since the last Games,&#8221; he warns.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/russia-cyber-operations-summer-olympics\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two Russian state-aligned threat actors have been carrying out online<\/p>\n","protected":false},"author":12,"featured_media":3869,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3868","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/russia-aims-cyber-operations-at-summer-olympics.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3868","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3868"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3868\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3869"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}