EXCHANGE RATES (MIDDLE RATES)
US DOLLAR: RS. 331.89 UK POUND: RS. 443.87 EURO: RS. 380.31 JAPANESE YEN: RS. 2.12 INDIAN RUPEE: RS. 3.45 AUSTRALIAN DOLLAR: RS. 235.47
CURRENT AFFAIRS

DIGITAL WARFARE

VIEWPOINTS

CYBERWAR IN A DIGITALLY DIVIDED WORLD

Sunera Bandara explores AI, cryptocurrency and state backed actors shaping global espionage – and Sri Lanka’s need to strengthen cyber defences

The intelligence portfolio of the 21st century looks very different from that of the previous century. Cold War or not, one thing is apparent: the US has been engaged in a geopolitical turnabout with Russia, China and Iran, and the stakes have intensified along digital lines.

Compared to the 20th century, where spooks – popularly known as spies – would duke it out using bugs, transmitters, poisoned umbrella tips and dead drops, this conflict has suddenly become a phenomenon relegated to the digital world.

Back then, it was a race for nuclear power. Joseph Stalin stole the blueprints through assets such as the Rosenbergs in the 1950s, enabling the USSR to create its own nuclear arsenal. The argument for nuclear sovereignty is irrelevant here; however, it does have its merits as it also applies to cyberwarfare.

Attorney and former United States senator Elizabeth Hanford wrote in the Loyola Public Interest Law Reporter in 2014 that “criminals are difficult to find in cyberspace because ‘there is no equivalent of a DNA sample or fingerprint to identify the perpetrator of a specific cybercrime.’”

That was 12 years ago. And the playing field has since changed.

Today, the real blueprints are AI, digital ecosystems, fintech and the global domination of information as a currency. Blockchain based currencies exist as intangible assets, unlike gold and silver. However, they carry considerable weight when considering the investments pooling into Bitcoin, especially as cryptocurrency is used to fund terrorist organisations such as ISIS.

With the deepening of AI, terror groups are finding tools that can rapidly enhance their cyberattack playbooks. On 16 July, it was discovered that threat actors linked to Iran were using artificial intelligence to enhance their cyber and information warfare capabilities.

A report compiled by Recorded Futures, a cyber threat intelligence company, found that threat actors closely associated with Iran had used generative AI and large language models in various ways – including for malware development, research into industrial control systems and exploitation of software vulnerabilities.

A group tracked as ‘Ababil of Minab’ used ChatGPT in April against Vyncs, a firm based in the United States that provides GPS technology for tracking vehicles. According to analysts, Iran has worked closely with Russia and China – the latter being a heavyweight in the current AI cold war – and developed its capabilities in concert with these superpowers.

With Bitcoin ledgers and tracing options available to government intelligence agencies and private intelligence firms, which are coining the new frontier of cyber threat intelligence, tracking these is becoming less harder though not easier.

The Office of Foreign Assets Control (OFAC) of the U.S. Department of the Treasury designated three individuals and six entities in June for facilitating ISIS financial flows.

Bitcoin Xchange is among these parties; it is a Syria based money services business that vendor intelligence analysts are tracking. Syria based cryptocurrency exchangers, including third party or informal hawala operators, have long served as an integral part of ISIS fundraising campaigns.

Pooling and conversion networks for ISIS donation campaigns target members, detainees, and families held in camps such as Al-Hol and Roj, converting donated cryptocurrency into cash for a fee.

OFAC designated these parties across Europe, the Middle East and West Africa. The investment model – as described by vendor intelli­gence analysts – states that donors send cryptocurrency through the popular messaging app Telegram, where ISIS affiliated channels and supporters of the terrorist organisation circulate their campaigns.

State sponsored terror is evidenced by the existence of threat actors such as APT29, also known as ‘Cozy Bear,’ which has a record complete with spear phishing, credential harvesting and custom malware development.

Supply chain attacks have also been carried out by the likes of the Winnti Group, which is described as a prolific Chinese state sponsored cyber threat actor with a unique blend of operations affiliated with espionage and financially motivated cybercrime.

All of this is relevant to Sri Lanka, especially as the country positions itself as a digital economy hub.

Lest we forget, A$ 2.5 million was ‘lost’ following a botched repayment transaction, for which the opposition laid blame not merely to incompetence. Sri Lanka’s venture into the digital economy may precede a slew of attacks.

The ransomware attack on Cargill’s identity database, which compromised 1.1 million files, marked a stark difference from the cyberattacks of the previous decade. Before the current government took office, many cyberattacks that occurred were defacements of websites to little more than cyber graffiti – such as the attack on the Ministry of Health website.

So the extent of cybersecurity defacement, direct attacks on economic infrastructure and the erosion of international credibility call for Sri Lanka to strengthen its own cybersecurity considerations on a seismic scale, especially as it balances competing geopolitical interests in the region and globally.

Related Articles

Back to top button