Statecraft and Cyberwar

When states entered the field the stakes changed. The 2007 disruption of Estonian services, Stuxnet and the damage to centrifuges at Natanz in 2010, and NotPetya in June 2017, which escaped its target and cost shipping and logistics firms hundreds of millions.

Part of Cybersecurity

23 moments in this segment.

  1. Riots over the Bronze Soldier, Tallinn, 26 April 2007. Night-time protests in Tallinn over the relocation of the Bronze Soldier war memorial, 26 April 2007. Within hours Estonia's banks, ministries, parliament and newspapers were knocked offline by three weeks of distributed denial-of-service traffic. It is generally treated as the first case of a nation-state-scale cyber attack against a whole country, and led directly to NATO siting its cyber defence centre in Tallinn.
  2. The Natanz enrichment facility, Iran. The Natanz fuel enrichment plant, the target of Stuxnet. Roughly a thousand IR-1 centrifuges were destroyed or replaced in 2009-2010. Photographed in 2022, so this is a modern view of the site rather than a period image. The subject dates from 2010; the photograph itself is later.
  3. A Siemens Simatic S7-300 PLC, Stuxnet's target. The Siemens Simatic S7-300 programmable logic controller, the class of industrial device Stuxnet was built to reprogram. Stuxnet altered centrifuge motor speeds at Natanz while replaying normal readings to the operators. This is the moment malware stopped being about data and started breaking physical machinery. The subject dates from 2010; the photograph itself is later.
  4. Global distribution of Stuxnet infections. A map of where Stuxnet was actually found, overwhelmingly concentrated in Iran. The distribution was one of the first public clues that this was a targeted weapon rather than criminal malware.
  5. How Stuxnet hid its own code from the operator. A contemporaneous technical diagram showing Stuxnet intercepting the engineering workstation's view of the PLC so its injected STL code stayed invisible. This rootkit-for-industrial-control behaviour is what made Stuxnet a decade ahead of anything else in 2010.
  6. Zero Days, Alex Gibney's Stuxnet documentary. Alex Gibney's feature documentary on Stuxnet, the self-replicating malware that damaged centrifuges at Iran's Natanz enrichment plant and then escaped onto the wider internet. It draws on intelligence-community sources to argue that a new category of weapon had been used without public debate.
  7. Moonlight Maze traced to a modern threat actor. Kaspersky Lab and King's College London researchers describe recovering samples, logs and artefacts from Moonlight Maze, the intrusions that targeted the Pentagon, NASA and others in the late 1990s, and the link they found to a later backdoor. Research that reached back to one of the first documented targeted campaigns.
  8. The original Petya ransomware splash screen. The skull-and-crossbones splash screen of the original Petya ransomware, which encrypted the master file table rather than individual files. NotPetya borrowed its look, which is why the 2017 attack got the wrong name and kept it.
  9. Cliff Stoll on three decades of computer security. Cliff Stoll's keynote at the SANS Cyber Threat Intelligence Summit, returning to the intrusion he tracked and chronicled in The Cuckoo's Egg and setting it against how the field looks decades later. First-hand account from the person who did the original hunt.
  10. ITV News interview after the NotPetya attack. A short ITV News interview recorded in the immediate aftermath of the NotPetya attack of June 2017, which spread rapidly through corporate networks and destroyed data on affected machines. Contemporaneous comment while the incident was still developing.
  11. The NotPetya ransom screen, 27 June 2017. The message shown to machines hit by NotPetya on 27 June 2017. It demanded a ransom but had no working decryption path: it was a destructive wiper disguised as ransomware, seeded through a Ukrainian tax-software update and spread worldwide. Maersk, Merck and FedEx's TNT each lost hundreds of millions; total damage is estimated at around ten billion dollars.
  12. Maersk on the lessons of NotPetya at Black Hat Europe. Maersk CISO Andy Powell's Black Hat Europe briefing on how the shipping group rebuilt after the June 2017 NotPetya attack and what it changed afterwards. A first-hand account from inside one of the worst-hit organisations.
  13. German documentary on NotPetya. A German-language breakdown of the 2017 NotPetya outbreak, which spread out of Ukraine and caused enormous collateral damage to companies worldwide. Retrospective rather than period coverage.
  14. What went wrong in the SolarWinds compromise. A former CIA information security official explains how the compromise of SolarWinds' Orion build process gave intruders access to thousands of downstream government and corporate networks, and why supply-chain attacks are so hard to prevent. Recorded days after the intrusion became public.
  15. CNBC on SolarWinds and cyber espionage. CNBC's report on the SolarWinds compromise discovered by FireEye in December 2020, which reached more than eighteen thousand of the company's customers, and on the US government's response. Contemporary business-news coverage.
  16. Google on Operation Aurora. The opening episode of Google's own documentary series on the 2009 intrusion into its network, in which attackers went after the accounts of human rights activists. Google's account of an attack that changed how the company and the industry talked about state-linked intrusions.
  17. Documentary on Titan Rain. A documentary on the Titan Rain intrusions against US defence networks in the mid-2000s, and on Shawn Carpenter, the analyst who followed the intruders and lost his job for it. Covers one of the first publicly discussed campaigns of sustained network espionage.
  18. A retired Windows engineer explains Stuxnet. Dave Plummer walks through the technical construction of Stuxnet: the chained zero-days, the stolen code-signing certificates, and the payload that manipulated centrifuge frequency converters while replaying normal readings to operators. Told from the perspective of an engineer who worked on the operating system it abused.
  19. Cybernews on the 2007 attacks that knocked Estonia offline. A detailed account of the three weeks in April and May 2007 when sustained denial-of-service traffic took down Estonian ministries, banks and newspapers. The episode covers how a small, heavily digitised state responded, and why the incident pushed NATO to open its cyber defence centre in Tallinn.
  20. Cybernews on NotPetya. An account of the 27 June 2017 NotPetya outbreak, which spread from a compromised update to the Ukrainian accounting package M.E.Doc and destroyed data across Ukraine and then worldwide. Presented as ransomware, it had no working recovery path, and the damage ran into billions of dollars.
  21. CBS Mornings on Anthropic's report of an AI-run espionage campaign. CBS covers Anthropic's disclosure that a group it assessed as Chinese state-sponsored used its AI tools to run an espionage campaign against technology firms, financial institutions and government agencies with little human involvement. Former CISA director Chris Krebs discusses what it means for defenders.
  22. Cybernews on the SolarWinds supply-chain compromise. How a backdoor inserted into SolarWinds' Orion network-management updates reached thousands of customers, including US federal agencies, before the intrusion was found in December 2020. The episode explains why compromising a trusted software vendor is more efficient than attacking each target.
  23. Titan Rain and the discovery of long-running network espionage. Titan Rain was the US government codename for a series of coordinated intrusions into defence and government networks detected in the early 2000s. The episode covers how investigators came to see persistent, patient network espionage as a standing condition rather than isolated break-ins.
V1SFULBN
MOMENTS0000
VIEWS0000
LIKES0000
TIME0000
Search moments...