Talk about bad ideas

The White House lacks an understanding of how much worse cyber attacks can get

Joe Garifo

8/17/20263 min read

Friday morning I woke up to a few of the content creators I follow discussing a new Presidential Memo allowing for companies to conduct "Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations." Or in short, allowing companies to hack back. It could have been much worse and just opened the gates to allow anyone to conduct these operations but it is shockingly measured for this administration that has thrown the reigns off many industries in the US. I will go over what I understand the goals of the memo are and why it's an issue for cyber defenders.

The stated goal of this memo is to unleash "American Businesses' innovative capabilities" against cybercrime. Companies will register to partner with the government, be vetted, and then directed to counter cybercrime. The Homeland Security Council now has 60 days to establish operating procedures for this program and distribute them so people can start registering and meeting the requirements. Those requirements, at a minimum, are "appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors." When I read this, I think you need former NSA Tailored Access Operations (TAO) operators on staff, how else do you show proven performance of cyber operations? Maybe you'd be someone at Cisco or Red Canary who have worked with law enforcement to help take down cybercrime infrastructure in the past, but I'm not entirely sure. And facility security makes me think that orgs are going to need an onsite location that are secured similar to a Sensitive Compartmented Information Facility (SCIF) where classified information is viewed in US Government buildings. Aside from contractors operating around Fort Meade, I think very few organizations are going to be ready on the first day of registration for this program. Which makes sense, they're already around and working with the US cyber infrastructure, they already take direction from NSA, it is the perfect test group for a program such as this.

Now what is a “Cyber-Enabled Transnational Criminal Organization (CE-TCO)” according to this memo? It's not a foreign group operating under partial or whole operational control by a foreign government. And unless intel existing showing that control, it is assumed to not to be. I think this is an interesting position to take on this. It makes clear that organizations like Salt Typhoon and Cozy Bear are not going to be targets for this memo but is more focused on ShinyHunters. Would Lazarus Group, which is more cyber crime than cyberwarfare, going to be targeted or are they off limit because they seem to be directed by the North Korean government? It'll be interesting to see.

Now that I have gone over the order, I'm going to focus in on what I really wanted to write about and that's how much worse I think things are going to become because of it. The first concern I have is how much more destructive are these campaigns going to become. If you know that a company is going to be set on your tracks, why leave tracks? Once you've gotten paid out, or not, why would you let them get access to the logs that would point to you? It may not be immediately, but I do think there will be an increase in ransoms and destruction from these.

Second concern is going to be an increase of residential proxy usage for these attack pipelines. Section 3 says that if a company discovers they are targeting a system in the US or under control of a US citizen, they need to cease operations and contact the DoJ. We have seen already the rise of malicious smart TV apps that include backdoor proxy access, this is most certainly continue and increase if the point an attack comes from is within the US causes operations to stop. These are well tuned crime machines with at least decent operational security preventing them from getting quickly caught. If that means they just need to gain access to some US systems to launch attacks from, doesn't seem like that difficult step to take.

Lastly, the possibility of misinformation in these campaigns. If the memo only allows targeting of non-state actors, why not leave a couple faked memos or emails indicating direction from Russia, Iran or North Korea? Or hell, make it more interesting an indicate a US ally directed you to do this to stir up some problems? It's really an interesting quirk that I'm not sure how it'll play out or if it'll really be an issue, but I can bet that they already read this memo too and are thinking about the outs for it.

In the end, I don't think this is going to do much to wrangle in cybercrime against US citizens. It may lead to quicker take downs of cybercrime infrastructure, but I think it also leads to more destructive and expensive campaigns to offset the risk they're facing. I am glad they have set the bar high enough for registration that you're not going to get people looking to make a name for themselves signed up, I guess I can look at that positive. But that's it for positives for this memo. And of course with so much else this administration does, it could just go nowhere and be something I look back at and wonder whatever came of it.