{"id":9,"date":"2011-03-04T15:35:38","date_gmt":"2011-03-04T23:35:38","guid":{"rendered":"http:\/\/digitaldna.io\/?p=9"},"modified":"2025-01-13T15:35:01","modified_gmt":"2025-01-13T23:35:01","slug":"cyber-jihadists","status":"publish","type":"post","link":"http:\/\/www.digitaldna.io\/?p=9","title":{"rendered":"Cyber Jihadists"},"content":{"rendered":"<blockquote><p>&#8220;<em>We&#8217;re facing a very great threat of loosely-coupled, organizational networks that increasingly rely on IT infrastructure to coordinate their movements and recruit young disenfranchised, apathetic guys as suicidal pawns in a sophisticated, dispersed movement. (&#8230;)<\/em>&#8221; (<a href=\"http:\/\/groups.google.com\/group\/alt.hackers.malicious\/msg\/924e529f06b35307\" target=\"_blank\" rel=\"noopener noreferrer\">AHM, Usenet, September 21, 2001<\/a>)<\/p><\/blockquote>\n<p><!--more--><\/p>\n<p>Although various forms of <a href=\"http:\/\/www.stealth-iss.com\/documents\/pdf\/CYBERTERRORISM.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">cyber terrorism<\/a> and <a href=\"http:\/\/www.wired.com\/culture\/lifestyle\/news\/1998\/12\/17050\" target=\"_blank\" rel=\"noopener noreferrer\">cyber espionage<\/a> have existed as far back as the 1980s, it would not be until the turn of the 21st century that the world at large would be introduced to a new breed of hacker: the cyber jihadist. While the first murmurings of the &#8220;<em>Cyber Jihad<\/em>&#8221; (or <em>e-Jihad<\/em>) came in the form of <a href=\"http:\/\/www.mail-archive.com\/ctrl@listserv.aol.com\/msg58497.html\" target=\"_blank\" rel=\"noopener noreferrer\">a post<\/a> by Cletus Nelson to the Conspiracy Theory Research List (<em>CTRL<\/em>) on December 19, 2000, the e-Jihad movement did not begin to heat up until after the Al Qaeda\u00a0September 11, 2001\u00a0attack.<\/p>\n<p>Much has changed since that time. In both cyberspace and meatspace.<\/p>\n<p>Early cyber jihadists tended to focus upon <a href=\"http:\/\/news.bbc.co.uk\/2\/hi\/technology\/2372209.stm\" target=\"_blank\" rel=\"noopener noreferrer\">web site defacements<\/a>. The &#8220;<a href=\"http:\/\/www.iwar.org.uk\/index.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Information Warfare<\/a>&#8221; site chronicles some of these in a November 2001 article titled, &#8220;<a href=\"http:\/\/www.iwar.org.uk\/cip\/resources\/nipc\/cyberprotestupdate.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Cyber Protests<\/a>.&#8221; Even so, the e-Jihad movement did not seem to be taking root. That is, superficially speaking&#8230; there was little-to-no media coverage and attacks of any real significance seemed few and far between.<\/p>\n<p>The idea of a cyber jihad however persisted. For example, in June of 2002, an apparent Syrian car salesman by day, cyber jihadist by night, attempted to <a href=\"http:\/\/www.google.com\/search?hl=en&amp;source=hp&amp;biw=1920&amp;bih=1085&amp;q=Waed.r%40scs-net.org&amp;btnG=Google+Search&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=\" target=\"_blank\" rel=\"noopener noreferrer\">form a jihad hacker group<\/a>: <a href=\"http:\/\/old.nationalreview.com\/robbins\/robbins073002.asp\" target=\"_blank\" rel=\"noopener noreferrer\">Arab Electronic Jihad Team<\/a>. His was but one of many <a href=\"http:\/\/www.globalsecurity.org\/org\/news\/2004\/040506-virtual-jihad.htm\" target=\"_blank\" rel=\"noopener noreferrer\">self-styled cyber jihadist groups<\/a> that have formed over the past decade.<\/p>\n<p>Notably however, &#8220;<em>One man&#8217;s Cyber Jihadist is another man&#8217;s Hacktivist<\/em>&#8221; simply does not apply.<\/p>\n<p>Why might that be? Or rather, what, exactly, differentiates Cyber Jihadists from Hacktivists (<em>such as Anonymous<\/em>)? After all, both engage in web defacements (<em>cyber graffiti<\/em>), DDoS attacks (<em>cyber vandalism<\/em>), and other illegal cyber activities (<em>worms, keyloggers, etc<\/em>). For starters, consider the <em>Hacker Pyramid<\/em>.<\/p>\n<p><a href=\"http:\/\/digitaldna.io\/wp-content\/uploads\/2011\/03\/HackerPyramid.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-597\" src=\"http:\/\/digitaldna.io\/wp-content\/uploads\/2011\/03\/HackerPyramid.jpg\" alt=\"\" width=\"312\" height=\"346\" srcset=\"http:\/\/www.digitaldna.io\/wp-content\/uploads\/2011\/03\/HackerPyramid.jpg 312w, http:\/\/www.digitaldna.io\/wp-content\/uploads\/2011\/03\/HackerPyramid-271x300.jpg 271w\" sizes=\"auto, (max-width: 312px) 100vw, 312px\" \/><\/a><\/p>\n<p>While the above is but a parody, it does convey some inherent truths within &#8220;<em>Hackerdom<\/em>&#8221; and especially in context of this article. For example, Cyber Jihadists are largely comprised of <em>Cyber Terrorists<\/em> whereas Hacktivists are largely comprised of <em>Ankle Biters<\/em> and <em>Script Kiddies<\/em>. The <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Stuxnet\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">Stuxnet<\/a> virus (<em>a <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Computer_worm\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">worm<\/a> designed to target <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Seimens\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">Seimens<\/a> <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/SCADA\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">SCADA<\/a>, carrying a <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Programmable_logic_controller\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">PLC<\/a> payload<\/em>) vs. <a href=\"http:\/\/arstechnica.com\/tech-policy\/news\/2011\/02\/anonymous-speaks-the-inside-story-of-the-hbgary-hack.ars\/\" target=\"_blank\" rel=\"noopener noreferrer\">Anonops attack against HBGary<\/a> (<em><a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Social_engineering_(security)\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">social engineering<\/a> and <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/SQL injection\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">SQL injection<\/a><\/em>) epitomize this.<\/p>\n<p>Furthermore, Cyber Jihadists hack to further extremist terrorist agendas as well as provide a means to network and train potential recruits. Take, <a href=\"http:\/\/www.memri.org\/report\/en\/0\/0\/0\/0\/0\/0\/4801.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Ansar Al Jihad<\/a>.<\/p>\n<blockquote><p><em>&#8220;Ansar Al Jihad Network\u2019s website is another popular jihadi website that is accessible in Pakistan. The forum has been closed for membership, but features videos, press releases and discussions about the war in Afghanistan and Pakistan. While one could not see the discussion on the forums, it is astounding to see the sheer number of videos that have been produced by the As-Sahab Foundation for Islamic Media Publication, Al-Qaeda\u2019s media cell, featuring members of the Taliban that have been killed, or messages from current Taliban leaders fighting in Afghanistan and Pakistan.<\/em><\/p><\/blockquote>\n<p>The site listed in the aforementioned article was registered in 2010. The original site and its mirrors were registered within five months of the United States invasion of Iraq. Original videos began to appear on the wayback machine as early as 2004, though they have since been scrubbed. However many can still be found in both the google video archives as well as on youtube such as the notorious &#8220;<em>Bush Assassination<\/em>&#8221; mock-up, white phosphorus attack footage, and Juba sniper footage.<\/p>\n<p>Videos that did not make it to google or youtube include but are not limited to various Iraqi resistance and training videos, and the &#8220;<em>wlakinallahrama<\/em>&#8221; video. The latter was uploaded to the main Ansar Al Jihad site in 2004 and contained, among other things, a shot of a handwritten note asking viewers to call in the U.S. 39th BCT in the event a certain individual was detained by US forces.<\/p>\n<p><a href=\"http:\/\/digitaldna.io\/wp-content\/uploads\/2011\/03\/39thBCT.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-598\" src=\"http:\/\/digitaldna.io\/wp-content\/uploads\/2011\/03\/39thBCT.jpg\" alt=\"\" width=\"395\" height=\"250\" srcset=\"http:\/\/www.digitaldna.io\/wp-content\/uploads\/2011\/03\/39thBCT.jpg 395w, http:\/\/www.digitaldna.io\/wp-content\/uploads\/2011\/03\/39thBCT-300x190.jpg 300w\" sizes=\"auto, (max-width: 395px) 100vw, 395px\" \/><\/a><\/p>\n<p>The above is but one example of cyber jihadist activities and why both local and foreign government bodies have not only been monitoring these individuals but have set up elaborate stings, as well. Whether via the CIA&#8217;s, since closed, <a href=\"http:\/\/www.washingtonpost.com\/wp-dyn\/content\/article\/2010\/03\/18\/AR2010031805464.html\" target=\"_blank\" rel=\"noopener noreferrer\">jihad honeypot<\/a> or the USAF&#8217;s recent\u00a0<a href=\"https:\/\/www.fbo.gov\/index?s=opportunity&amp;mode=form&amp;id=d88e9d660336be91552fe8c1a51bacb2\" target=\"_blank\" rel=\"noopener noreferrer\">RFP<\/a> for acquiring\u00a0<em>persona management software.<\/em><\/p>\n<p>Some opine the latter is for <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/astroturfing\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">astroturfing<\/a>. Doutful. Historically speaking, that is. The government&#8217;s approach to combating terrorism on the cyber front makes it abundantlly clear, at least to this writer, that they have other things in mind&#8230; a <a href=\"http:\/\/www.pcworld.com\/article\/220142\/your_new_facebook_friend_might_be_a_spy.html\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook honeypot<\/a>, for example.<\/p>\n<p>The idea of persona management is a new word for an old hacker mainstay: <a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Sockpuppet_(Internet)\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">sockpuppets<\/a>. Though, the goal in the case of government entities, involves infiltrating cyber jihadist groups to identify and collect information in relation to terrorist threat. In fact, this approach has garnered <a href=\"http:\/\/www.economist.com\/node\/9472498\" target=\"_blank\" rel=\"noopener noreferrer\">numerous arrests<\/a> over the past decade.<\/p>\n<p>Arrests include but are not limited to 15 year-old Mirsad Bektasevic (aka &#8220;<em>Maximus<\/em>&#8220;), who was caught up in a <a href=\"http:\/\/query.nytimes.com\/gst\/fullpage.html?res=9E03E3DB1231F930A35751C1A9639C8B63\" target=\"_blank\" rel=\"noopener noreferrer\">2005 Danish raid<\/a>. 22 year-old West Londoner, <a href=\"http:\/\/www.washingtonpost.com\/wp-dyn\/content\/article\/2006\/03\/25\/AR2006032500020.html\" target=\"_blank\" rel=\"noopener noreferrer\">Younis Tsouli<\/a> (<em>aka Irhabi 007<\/em>) in 2007. 26 year old Moroccan, <a href=\"http:\/\/www.morocconewsline.com\/index.php?option=com_content&amp;task=view&amp;id=461&amp;Itemid=44\" target=\"_blank\" rel=\"noopener noreferrer\">Faical Errai<\/a> in 2010. 46 year-old <a href=\"http:\/\/abcnews.go.com\/GMA\/Politics\/jihad-jane-arrest-colleen-larose-raises-fears-homegrown\/story?id=10056187\" target=\"_blank\" rel=\"noopener noreferrer\">Colleen LaRose<\/a> (aka &#8220;<em>Jihad Jane<\/em>&#8221; and &#8220;<em>Fatima Rose<\/em>&#8220;) and 31 year-old Jamie Paulin-Ramirez (&#8220;<em>Jihad Jamie<\/em>&#8220;) in 2010. LaRose <a href=\"http:\/\/philadelphiacriminallawnews.com\/2011\/02\/colleen-larose-pleads-guilty-to-murder-plot-and-helping-terrorists.html\" target=\"_blank\" rel=\"noopener noreferrer\">plead guilty<\/a> on February 1, 2011 and it is yet unknown whether Paulin-Ramirez will change her &#8220;<em>not guilty<\/em>&#8221; plea for the upcoming <a href=\"http:\/\/www.google.com\/hostednews\/ap\/article\/ALeqM5iJYY7jky2YeUtjkvw8k0IfqbM3-g?docId=25b6c054a2c64ad3853ff10a2ba904b9\" target=\"_blank\" rel=\"noopener noreferrer\">May trial<\/a>.<\/p>\n<p>Persona management is however an extremely slow and arduous process. After all, the socks must not only be aged but a robust cyber profile must be developed. And the sock must interact on a regular (<em>yet, not too regular<\/em>) basis. One that only hints at routine while not looking&#8230; well&#8230; botty. After all, people are creatures of habit.<\/p>\n<p>In other words, the sock must believable.\u00a0Persona management software may (<em>or not<\/em>) help this process along.<\/p>\n<p>At the very least, it can utilize\u00a0cyber profiling to\u00a0automate the sock&#8217;s interaction (<em>i.e., posting to people&#8217;s facebook walls, clicking like\/dislike buttons, commenting in various forums and on various blogs that are congruent to the sock&#8217;s published interests<\/em>). At best, it can also &#8220;<em>scrape data<\/em>&#8221; which can then be fed to the great heuristic analyzer in the sky&#8230; or in this case, within the bowels of the government&#8217;s think tanks. With the goal of not only alerting them to potential terrorist threats but generating dossiers for tracking down potential terrorists. At worst, it can be construed as a gross breach of privacy that could result in inadmissible evidence in a court of law.\u00a0That is, where social networking sites, such as Facebook, are concerned.<\/p>\n<p>Regardless of the very real threat of terrorism, we remain faced with important issues, among which include identifying and defining how to protect ourselves from hacker jihadists without compromising ethical values. While some of these protections can certainly come from hardening the infrastructure (<a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Intrusion_detection_system\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">IDS<\/a>,\u00a0<a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Anti-virus\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">AVS<\/a>,\u00a0<a class=\"wiki\" href=\"http:\/\/en.wikipedia.org\/wiki\/Firewall_(computing)\" target=\"_blank\" rel=\"tag\" title=\"wikipedia\">Sofware &amp; Hardware firewalls<\/a>) and even implementing some form of persona management software, a great deal is really no different than every day living.<\/p>\n<p>That is, our safety is also dependent upon education with regard to everything from safe surfing practices and implementing new social rules that are specific to cyberspace to codifying rules of engagement within the context of &#8220;<em>cyber war<\/em>.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;We&#8217;re facing a very great threat of loosely-coupled, organizational networks that increasingly rely on IT infrastructure to coordinate their movements and recruit young disenfranchised, apathetic guys as suicidal pawns in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":836,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,5,31,1],"tags":[],"class_list":["post-9","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto","category-hacks-n-cracks","category-showcase","category-hackpocalypse"],"_links":{"self":[{"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/posts\/9","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9"}],"version-history":[{"count":3,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/posts\/9\/revisions"}],"predecessor-version":[{"id":750,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/posts\/9\/revisions\/750"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=\/wp\/v2\/media\/836"}],"wp:attachment":[{"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.digitaldna.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}