GCHQ reportedly infiltrated and attacked hacktivist groups

Leaked documents suggest the agency used denial-of-service tactics and assisted law enforcement in identifying Anonymous members

By Lucian Constantin, IDG News Service |  IT Management

British intelligence agency Government Communications Headquarters (GCHQ) has reportedly infiltrated hacktivist groups and used denial-of-service and other techniques to disrupt their online activities.

A PowerPoint presentation that GCHQ prepared for a 2012 conference organized by the U.S. National Security Agency reveals that one of the agency's units, called the Joint Threat Research Intelligence Group (JTRIG), collected information on "hacktivists" -- politically motivated hackers -- and shared it with law enforcement agencies. The unit also used denial-of-service techniques to disrupt the hacktivists' communication channels.

The slides were among the documents leaked by former NSA contractor Edward Snowden and were published Wednesday by NBC News. JTRIG used human intelligence techniques to gather information about members of Anonymous and LulzSec, two related groups of hacktivists that attacked the websites of various companies, organizations and governments, NBC News reported.

The leaked slides provide two examples of JTRIG intelligence gathering that targeted two hackers using the online handles GZero and p0ke.

In one IRC (Internet Relay Chat) log included in a slide, an undercover JTRIG agent responds to a request from a hacker looking to buy access to a website with 10,000 or more unique daily visitors. The discussion suggests the hacker intended to install an exploit on the site to infect the computers of visitors with botnet malware so they could be used to support Operation Payback, a large-scale DDoS (distributed denial-of-service) campaign launched by Anonymous in 2010 against pro-copyright organizations and a variety of companies including PayPal, MoneyBookers, Visa, Mastercard and Amazon.

In another chat log, the agent is contacted by a user named GZero who says the first hacker works with him and who also expresses interest in buying traffic for use with an exploit pack.

JTRIG's reporting on GZero led to his identification and arrest, one of the slides says. Edward Pearson, a 23 year old from York, England, was identified by law enforcement as GZero. He was sentenced in 2012 to two years in prison for using Trojan programs like Zeus and SpyEye to steal credit card details and PayPal credentials.

Another chat log in the GCHQ slides shows a user named p0ke telling another one, named Topiary, that he hacked into a government database and extracted the names, email addresses and phone numbers of 700 U.S. Federal Bureau of Investigation employees. In a later private chat with a JTRIG agent p0ke says that he compromised usda.gov, the website of the U.S. Department of Agriculture.

Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Spotlight on ...
Online Training

    Upgrade your skills and earn higher pay

    Readers to share their best tips for maximizing training dollars and getting the most out self-directed learning. Here’s what they said.

     

    Learn more

IT ManagementWhite Papers & Webcasts

See more White Papers | Webcasts

Answers - Powered by ITworld

ITworld Answers helps you solve problems and share expertise. Ask a question or take a crack at answering the new questions below.

Ask a Question
randomness