Anonymous’ Cyberwar With ISIS And It’s Unintended Consequences.

In the aftermath of the Paris Terrorist Attacks, there is a new target on ISIS: A Declaration of Cyber War. The hacker activist group, Anonymous is using social media to retaliate against ISIS for their reign of terror in the city of light.

In a new YouTube video Anonymous vowed to take out ISIL: “We are tracking down members of the terrorist group responsible for these attacks we will not give up we will not forgive and we’ll do all that is necessary to end their actions.”

Efforts to take down the organization's Web sites and expose its supporters could interfere with carefully planned law enforcement operations. Anonymous’s cyber war with ISIS may have unintended security consequences.

As French police scoured Paris and surrounding areas in search of those responsible for Friday 13th terrorist attacks on the French capital, a group of cyber activists took aim at the Islamic State’s online presence. The computer-hacker federation known as Anonymous claims to have disabled at least 5,500 pro-ISIS Twitter accounts and exposed thousands of the terror group’s supporters who use the social media site.

Anonymous announced its current campaign on November 14, the day after ISIS (the Islamic State in Iraq and Syria) claimed responsibility for murdering at least 129 people and injuring more than 300 in various locations throughout Paris. The hacktivist group released a video that begins with dramatic music and what, appears, to be images of the Paris attacks. Halfway into the video a person wearing Anonymous’s symbolic Guy Fawkes mask announces that the group is tracking down ISIS members and supporters and then proclaims, “We’ll not give up. We will not forgive. And we’ll do all that is necessary to end their actions.”

Law enforcement and cyber counterterrorism experts generally welcome the digital havoc that groups like Anonymous can wreak on terrorist organizations’ online communication and recruiting efforts. That is, as long as these uncoordinated cyber antiterrorism campaigns do not end up scuttling months of undercover investigative police work. 

Anonymous could be the digital equivalent of a renegade cop going to great lengths to catch a bad guy at the expense of ruining a painstakingly organized federal investigation to take down a larger crime ring.

The hacktivist collective does this by exposing its adversaries’ Twitter accounts (and reporting them to the company) or paralyzing opposition Web sites by flooding them with online traffic. The group’s secretive nature gives it a lot of latitude for operating outside the law. 

“This means they can create collateral damage on the Internet without having to answer for it,” says Scott Borg, director and chief economist for The US Cyber Consequences Unit, an independent, nonprofit cybersecurity research institute.

Groups operating outside official law enforcement and intelligence channels can make legitimate communications and business difficult to carry out, or even interfere with the intelligence community's efforts, Borg says. If Anonymous shuts down a terrorist Web site or online forum that government agents have already infiltrated, this could hinder valuable counterterrorism surveillance and data collection. This is especially important because gathering useful information on Islamic State forums is typically difficult. 

The terror group often uses Web-hosting companies unwilling to cooperate with Western governments and regularly switches hosting companies to avoid being shut down. The US has a lot of ways of going after these organizations and can target new communications channels when old ones are blocked, but ISIS’s way of operating in stealth online makes this difficult, Borg adds.

The key to successfully disrupting terrorist organizations online is to shut down their recruiting and propaganda efforts while tapping into the valuable intelligence their forums can provide, according to the executive director of Ghost Security Group, who goes by the name “DigitaShadow” in order to not reveal his true identity. 

His organization formed as a nonprofit counterterrorism network delivering intelligence to US government agencies earlier this year, a few days after terrorists attacked the Parisian paper Charlie Hebdo. They have gained some notoriety in recent months for their role in helping disrupt ISIS’s funding efforts as well as planned attacks in New York City and Tunisia.

Ghost Security Group’s 15 members in the US, Europe and the Middle East have taken down 149 terrorism-related propaganda sites so far, DigitaShadow says. “We leave Islamist-related forum or communication platforms intact for intelligence reasons, waiting for participants to make a mistake,” he adds. “We shut down any propaganda sites that push out videos or graphic or gory pictures because they don’t have any intelligence value.”

DigitaShadow’s organization had acted as part of Anonymous for a few months after forming but is no longer affiliated with them. “They’ve attacked quite a few forums that had high-value Islamic State militants transmitting propaganda, trying to recruit young people and in some cases addressing weapons-manufacturing and ground movements,” he says. “It’s caused quite a disruption for intelligence.”

Borg contends, however, that Anonymous and the hacker community in general do more good than harm. Given the brutality of ISIS’s attacks, and its successful Internet recruitment efforts, the hacker collective’s latest rally against the terrorist organization is an acceptable risk. 

Anonymous launched a similar campaign against ISIS following its attack on Charlie Hebdo, claiming to disrupt tens of thousands of Twitter accounts connected to the terrorist organization.

Anonymous also claims to be spamming ISIS hashtags with “rickrolls,” messages that appear to be relevant but instead include a link to the music video for the 1987 Rick Astley hit song “Never Gonna Give You Up.” 
The cyber scuffle has not been entirely one-sided though. Anonymous tweeted recently that it had to take down its own site for reporting on Islamic State activity due to a high level of spam, although it is unclear whether the terror group was responsible. 
Ein News:http://http://bit.ly/1RmbtVX
Scientific American: http://bit.ly/1NFKlvj

« Bitwalking: Digital Currency Pays People to Walk
N. Korea Employs Grads for Cyber Warfare »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

CERT Polska

CERT Polska

CERT Polska is the first Polish computer emergency response team and operates within the structures of NASK (Research and Academic Computer Network) research institute.

Cleafy

Cleafy

Cleafy protects web and mobile applications from tampering attempts and deploys countermeasures to guarantee data and content integrity at scale.

Verlingue

Verlingue

Verlingue (formerly ICB Group) is a leading corporate insurance broker providing Insurance, Risk Management and related advice to businesses and private clients.

TitanHQ

TitanHQ

TitanHQ offers ultimate protection from internet based threats and powerful Web filtering functionalities to SMBs, Service Providers and Education sectors around the World.

Idaptive

Idaptive

Idaptive delivers Next-Gen Access through a zero trust approach. Idaptive secures access everywhere with single sign-on, adaptive MFA, EMM and analytics.

Sigma IT

Sigma IT

SIGMA IT is one of the largest IT services organizations in EMEA region providing a full range of solutions and services including cybersecurity, data protection and business continuity.

Octane OC

Octane OC

OCTANe is building the SoCal of tomorrow. We drive innovation and growth by connecting people, resources and capital. Our Incubator focus is FinTech, Data Analytics and Cybersecurity.

Intel

Intel

Intel products are engineered with built-in security technologies to help protect potential attack surfaces.

SecurityGen

SecurityGen

SecurityGen is a global cybersecurity start-up focused on telecom security, with a focus on 5G networks.

Cloud4C

Cloud4C

Cloud4C is a leading automation-driven, application focused cloud Managed Services Provider.

KATIM

KATIM

KATIM is a leader in the development of innovative secure communication products and solutions for governments and businesses.

Daisy Corporate Services

Daisy Corporate Services

Daisy is one of the largest providers of communications and IT solutions across the UK, with a portfolio spanning unified communications, cloud, cyber security and resilience.

SeQure

SeQure

SeQure is a cutting-edge startup specializing in the development of advanced security infrastructure for artificial intelligence and blockchain.

Vector Choice Technologies

Vector Choice Technologies

Vector Choice Technology Solutions has a long standing reputation in cyber security consulting since 2008.

Google Safety Engineering Center (GSEC)

Google Safety Engineering Center (GSEC)

GSEC Málaga is an international cybersecurity hub where Google experts work to understand the cyber threat landscape and to create tools that keep users around the world safer online.

CyAmast

CyAmast

CyAmast is an IoT Network security and analytics company that is changing the way enterprise and governments detect and protect networks from the pervasive threat of cyber attacks.