Restrict Act, Chatcontrol, Modified Elephant Followup: Stan Swami (Strong Encryption Saves Lives)

PeerTube

The first anchored narrative of 2023 has just been released! This time it is quite an explosive one of an in-depth malware forensic follow-up on the famous Bhima Koregaon case, where a nation-state threat actor named #ModifiedElephant planted evidence on the computers of several activists in India and; as a result, have been put in jail. In this anchored narrative, the latest report V from Arsenal Consulting will be covered as well as their #MemoryForensics techniques they applied to reconstruct the uploading of incriminating documents to the computer of an 84-year-old Jesuit Priest, Father Stan Swamy. I was interviewed to review that case by award-winning journalist Niha Masih from The Washington Post. From her, I received court documents detailing the forensics of Mr. Rona Wilson. In those documents, I found an unreported and unidentified piece of malware by the Regional Forensic Science Laboratory in Pune dating back to 2017. This is a horrifying case of poor digital forensics performed by the government and a red flag for our forensic community.

In short, a must-read!

https://anchorednarratives.substack.com/p/the-trojan-solved-the-bhima-koregaon

#DFIR #MemoryForensics #APT #Malware #investigations #Humanrights #innocenceproject #bhimakoregaon @hegel @SentinelLabs @nihamasih @agreenberg @citizenlab @washingtonpost

The Trojan solved the Bhima Koregaon case!

How proper file, malware, and memory forensics techniques were able to catch the ModifiedElephant threat actor planting incriminating evidence on defendants' computers in India.

Anchored Narratives on Threat Intelligence and Geopolitics

When #activists share personal info w/#SocialMedia, they are more open to targeting.

Ex: #ModifiedElephant #India Activists / Journalists Targeted 10yr + Framed For False Assassination Charges.

#Backdoor-free #encryption matters: these individuals had false evidence planted on their devices.

Thankfully #forensics saved their lives (won't always be case)

#activism

https://tube.tchncs.de/w/p3X6RRccMjBmitmXS6tayM

Privacy News: ModifiedElephant APT

PeerTube

Quick post to summarize happenings in the world of 'APTs fabricating evidence to throw people in jail':

This week a new report was released by Arsenal Consulting related to pro bono forensic work they’ve done for defendants in the Bhima Koregaon (aka BK16) case in India. In this report, we’ve learned that a second defendant in the case was framed. The digital evidence of their crimes (domestic terrorism) were documents planted by #malware – specifically a variety of NetWire RAT samples. This framed individual (Stan Swamy) died while incarcerated – he was an 84 year old priest.

@agreenberg at Wired wrote about this news here (definitely read!): https://www.wired.com/story/modified-elephant-stan-swamy-hacked-evidence-frame-bhima-koregaon-16/

Now this confirmation of evidence planting is simply not that surprising to us. Another defendant in the case (Rona Wilson) was confirmed to have evidence planted as well – and we’ve had confidence the same is done to many others. In addition to these two individuals, we know this same threat actor targeted many more individuals – including those not involved in this case at all. This threat actor is working in collusion with the Indian government, plain and simple.

We named this threat actor #ModifiedElephant after profiling an extensive cluster of infrastructure and malware. The IOCs we released are tied to the decade+ life of the group so far.

PDF Report: https://s1.ai/mod-elephant

@jags and I did a BlackHat talk on this actor - a good overview on how they operate: https://youtu.be/zGorOeQS5C8

So, what’s next? The threat actor remains a focus of mine, and new research is ongoing. I hope to have more to share publicly soon. #StayTuned #BestJobIEverHad

Hackers Planted Files to Frame Indian Priest Who Died in Custody

And new evidence suggests those hackers may have collaborated with the police who investigated him.

WIRED
In Indien sitzen zwei Aktivisten seit Jahren in Haft, obwohl Beweismittel auf ihren Computern wohl gefälscht waren. Nun gibt es eine neue, erschreckende Spur.
Indien: Gefälschte Beweise und Hackerangriff – Verbindung zur Polizei gefunden
Indien: Gefälschte Beweise und Hackerangriff – Verbindung zur Polizei gefunden

In Indien sitzen zwei Aktivisten seit Jahren in Haft, obwohl Beweismittel auf ihren Computern wohl gefälscht waren. Nun gibt es eine neue, erschreckende Spur.

heise online
Netzpolitik-Feed with benefits (@[email protected])

Trojaner in Indien: Falsche Beweise untergejubelt – https://netzpolitik.org/2022/trojaner-in-indien-falsche-beweise-untergejubelt/ #StaatlichesHacken #ArsenalComputing #ModifiedElephant #Staatstrojaner #Spearphishing #narendramodi #Überwachung #SentinelOne #RonaWilson #Sidewinder #DarkComet #keylogger #Hangover #Netwire #indien

chaos.social
Privacy News: ModifiedElephant APT

PeerTube
✍️ 📺 How Encryption Protects 🔐 + NEWS: 🐘 "ModifiedElephant" — (RTP) Privacy Tech Tips

(click the image below to watch on decentralized Peertube channel - YT embedded below it)(SHARE the link/video! Help inform others on Telegr...

Buy Me a Coffee

#ModifiedElephant has been framing #HumanRights defenders/activists, #lawyers, and #academics by planting incriminating digital evidence on their devices...

for *over* 10 years now.

Speaks to a high level of motivation, and what could happen if #surveillance goes unchecked.

#News #privacy #humanrights #ModifiedElephant

#ModifiedElephant's main goal is long term #surveillance/spying.

Researchers find they are also planting false evidence on #activist devices: to wrongly incriminate #HumanRights activists. Dirty tricks.

Reminding fighting for #HumanRights: not necessarily safe as it should be.

#privacy + enhancements in #security, even concealment of identity helpful.

#News #India #Activism #Anonymous #Anonymity