Who really takes advantage of the operations of Anonymous?

I desire to tribute another article to the group that catch the  worldwide attention of security community, Anonymous. Few years to consolidate its image become one of the most debated phenomenon on internet, many consider the collective a threat, many other the expression of a dissent to listen. Both interpretations are correct, but let’s think for a moment to the misuse of the name Anonymous, who and why can bring in the fame of the famous group of hackers?

Are we really able to fight against the hacktivism and do we desire do it?

It’s true that the raise of hacktivism in the last 4 years has created several problems to governments and private firms, but it also true that many figures have benefited of the operation promoted by Anonymous.

First of all many security firms have had the opportunity to promote their services and solutions to protect companies from the attacks of collective, for example DDoS attacks have become famous after the first attacks made by Anonymous, with their popularity is increased the sold for network appliances able to secure prevent the destruction of web services or data breach.

Again we can consider the intelligence services provided to prevent the clamorous operation of the hackers and to expose the identities of members of the collective, several private agencies have sold their reports and advices to law enforcement and private businesses, we speak of flourishing business!

But in many cases the reality exceed fiction, the governments seems to be the entities that can most benefit of the hacktivism. Last year I wrote on the possible usage of Anonymous as cyber weapon trying to explain how foreign government could conduct covert operations, such as cyber attacks or cyber espionage in the name of the group or influencing the choices of the Anonymous.

Several operations of Anonymous have attacked networks and web site belonging to governments, it’s happened for example with #OpChina and #opJapan, when the hackers have targeted the two countries to officially protest against censorship and web monitoring.

This offensive scenarios could advantage a state sponsored attacks, attackers could benefit of the rumors of the attacks to bypass security protection stressed by the events.  In this case group of hackers could follow the organization of an event that represents for them a diversion option, a lapse time in which the adversary protection are engaged against attacks coming from other sources.

Well this in in my opinion the most plausible scenario, but not the only one.

In other situation governments could be in interested to put the blame on Anonymous while they remain hidden, we are living in the era of cyber war and the operations in cyberspace are joining more and more frequently conventional military operations.

For example some experts believe that the #opChina could be also be supported by foreign governments like US or other western countries, Rob Rachwald, directory of security strategy at Imperva, doesn’t exclude the participation of governments in the attack declaring:

“It was a pretty extensive campaign. Could it be the US government helping out? I don’t know, [but] I wouldn’t rule it out. Could it be German, UK hackers sponsored by the government? I don’t know.”

Many skeptics may argue then why the collective Anonymous in these case leaves governments to act with impunity. Possible explanations could be the intent to don’t be catch in a potential trap set for to come forward them, we have also hypothesize that the same Anonymous benefits in terms of media exposure in a time where its operations have triggered a process of habituation, but the most plausible thesis is in the inability of a central collective to validate and monitor attacks made by various groups all over the world.

The common trend to underestimate Anonymous groups may conceal other intentions, the desire of governments to be able to infiltrate the hacktivists influencing their policies and strategies. The governments know well the potential of their cyber threats, despite they represent a serious danger, they prefer to avoid a direct confrontation, there are no serious offensives of intelligence against the collective operations that have not been a response to an attack. Yes we often read of sporadic arrests that actually represent a sop to the collectivity, Anonymous must continue to operate, there are too much conveniences to stop them.

Nobody really know identities of these individuals that fight for freedom and internet rights, but what is indisputable is their offensive power. I’m not speaking of DDoS attacks but the effected related to various data breach they conducted.

China taught the world the importance of cyber espionage, discovery the enemy secrets, to steal their intellectual property, well all this attacks could benefit of the Anonymous brand. Governments can masquerade their identities hacking foreign networks, they could infiltrate groups of hacktivists acquiring sensible information, in many cases in fact following data breach the disclosed data have been used for further attacks such as APT and other targeted offensive.

In light of all the above reflection are we really sure that there is imminent need to eradicate Anonymous?

Pierluigi Paganini

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Operation ENDGAME disrupted global ransomware infrastructure

Operation ENDGAME dismantled key ransomware infrastructure, taking down 300 servers, 650 domains, and seizing €21.2M…

2 hours ago

Silent Ransom Group targeting law firms, the FBI warns

FBI warns Silent Ransom Group has targeted U.S. law firms for 2 years using callback…

20 hours ago

Leader of Qakbot cybercrime network indicted in U.S. crackdown

The U.S. indicted Russian Rustam Gallyamov for leading the Qakbot botnet, which infected 700K+ devices…

1 day ago

Operation RapTor led to the arrest of 270 dark web vendors and buyers

Law enforcement operation codenamed 'Operation RapTor' led to the arrest of 270 dark web vendors…

2 days ago

Chinese threat actors exploited Trimble Cityworks flaw to breach U.S. local government networks

A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy…

2 days ago

U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Samsung MagicINFO 9 Server vulnerability to its…

3 days ago