Technology

Hacking group that has ties to Africa may be a Russian proxy

A hacking group that has been said to be the cause of a series of outages at Microsoft sometime this month, and had spent the previous months attacking targets in Israel, Sweden and other nations, could be part of an expanding campaign that some cybersecurity researchers have tied to Russia. The group “Anonymous Sudan” defines

Hacking-group-that-has-ties-to-Africa-may-be-a-Russian-proxy

Hacking-group-that-has-ties-to-Africa-may-be-a-Russian-proxy

Share
Picture: BBC
Advertisement

A hacking group that has been said to be the cause of a series of outages at Microsoft sometime this month, and had spent the previous months attacking targets in Israel, Sweden and other nations, could be part of an expanding campaign that some cybersecurity researchers have tied to Russia.

The group “Anonymous Sudan” defines itself as a hacktivist group and says it’s waging cyber strikes out of Africa on behalf of oppressed Muslims worldwide. Claiming its 5 June distributed denial of service, or DDoS, attacks against Microsoft are said to have been a retaliation for US policy regarding Sudan’s military conflict. The US is trying to broker a peace deal between warring factions at this moment.

Experts in cybersecurity came to a conclusion that the group actually operates from Russia and hacks for a completely different purpose: to advance Moscow’s objectives.

Mattias Wåhlén, who is a threat intelligence expert with Stockholm-based Truesec said: “Anonymous Sudan is a Russian information operation that aims to use its Islamic credentials to be an advocate for closer cooperation between Russia and the Islamic world – always claiming that Russia is the Muslims’ friend.”

He led Truesec’s investigation of Anonymous Sudan and the firm’s February report which identified the group as a front for Russia, and that was an assessment that was corroborated by other security experts who studied the group and its activities. In a few short months in existence, the group has repeatedly used cyberattacks as a bludgeon to drive home one narrative: that the West is hostile to Islam, while Moscow is a friend to the Muslim world, he said.

A representative from the from the group denied these allegations but admitted that their intentions were aligned. As part of an online conversation, the group’s representative goes on to write that they go after “everything that is hostile to Islam and all countries that are hostile to Islam are hostile to Russia.” Last weekend, there was a revelation that an extraordinary mutiny in Russia by the mercenary leader of the Wagner Group challenged Russian President Vladimir Putin, and the group took to Telegram in support of the Kremlin.

Advertisement

Microsoft recently stated that in early June it had identified “surges in traffic against some services that temporarily impacted availability”. DDoS attacks are usually directed at junk internet traffic at a target, such as a website or server, temporarily degrading service or shutting it down.

The cyber barrage that was directed at Microsoft caused temporary outages for some of the company’s most popular services, which include Outlook, Teams and OneDrive, and they joined together with what security experts noted were increased hostilities in Russia’s war in Ukraine. All of that tracks with what the experts said was Anonymous Sudan’s pattern of timing its cyberattacks to geopolitical flare-ups in countries that are aligned against Russia to gain greater visibility for its anti-Western messages.

According to Charl van der Walt who is the head of cybersecurity research for Orange Cyberdefense, part of the French telecommunications group Orange, one of the reasons why Anonymous Sudan’s campaigns are effective is that their target is “layer 7”, or the application layer, of victims’ internet infrastructure because that is where web servers receive input from users and, in a computationally draining process, serve content in response.

He mentioned that when executed skilfully, these DDoS events cause web servers to be unable to tell the difference between real and fake requests. These attacks are more work for hackers to set up, but they have a potentially bigger payoff than ordinary denial-of-service assaults, which are easier to block.

The group has all the “technical knowledge on how to execute such a non-trivial attack, and they seem to know how to be effective against one of the biggest cloud infrastructure giants such as Microsoft. From a technical point of view, the attackers are good or have access to resources that they can direct to act on their behalf. This puts them in a league above your average hacker collective.”

Anonymous Sudan came up with a campaign against Sweden in February. The digital onslaught interrupted online programming at Sweden’s national public broadcaster and shut down the websites of the airline SAS, which is a state-owned power company Vattenfall and defence firm Saab.

The group revealed that the strikes were in response to the burning of a Koran in front of the Turkish embassy in Stockholm earlier this year. However, some researchers believe their motivation was to amplify tensions with Sweden’s Muslim minority and pressure Turkey so that they can hold firm in rejecting Sweden’s bid to join the Nato military alliance.

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Process Plant Control
Read nextopinion-analysis

What Happens to Mining Skills When the Equipment Goes Digital?

African mining companies are putting more automation, robotics, artificial intelligence and connected equipment into their operations.

Roy Mulenga · readContinue reading