
From the secret report of the NSA, it follows that Russian hackers working on the GRU, before the 2016 presidential election, tried to access computer systems providing the voting process, write on The Intercept Matthew Cole, Richard Esposito, Sam Biddle and Ryan Grim. The Insider offers a complete translation of the article.
Russian military intelligence undertook to Kiberatak to at least one of the software suppliers for the American electoral system and sent phishing letters to more than a hundred election officers a few days before the presidential election in November, as follows from a top secret intelligence report that fell to the disposal of The Intercept.
The NSA's top secret document, which came from an anonymous source and has passed an independent authentication test, contains an analysis of intelligence, recently received by the agency about the for months of Russian intelligence cyber intelligence on elements of American election infrastructure. The report dated May 5, 2017 is the most detailed description of Russian intervention in the elections compiled by the American state bodies that have ever been published.
The document provides a rare opportunity to see how the NSA imagines the mechanisms of the activities of Russian hackers, but does not reveal the “raw” intelligence on which the analysis is based. An American intelligence officer, who refused to call himself, warned that he should not draw too far -reaching conclusions from one document, since one specific analysis is not necessarily final.
It follows from the report that Russian hackers may have penetrated the American voting system deeper than it had previously been. In the final conclusions, it is unambiguous that the cyber attacks described in the document was carried out by Russian military intelligence - the GRU of the General Staff:
“Persons acting in the interests of the GRU, <...> Cybershption and Cyberspende operations against the named American company in August 2016, obviously, in order to obtain information about computer equipment and software related to the elections. <...> Apparently, they took advantage of the information received during this operation, in order to <...> to carry out a phishing attack against local state bodies of the United States, related to the voter registration system. "
The assessment contained in the conclusions of the NSA sharply diverges with a statement by the President of Russia, made last week, when he denied Russia's intervention in the elections abroad: "We are not doing this at the state level and are not going to do this." Putin, who had previously completely denied any Russian intervention, first admitted that some private Russian hackers, “tuned to patriotic”, could be responsible for this. The ANB report, on the contrary, said that Cyberataka undoubtedly held the GRU.
In the analysis of the NSA, there are no conclusions about whether the intervention of the GRU has affected the result of the elections. Analysts acknowledge that there is a lot to be unknown regarding the real volume of hackers achievements. But, according to the report, it is possible that Russian hackers managed to hack at least some of the elements of the voting system with indefinite results.
When preparing this publication, The Intercept contacted both the NSA and the office of the US National Intelligence Director. Officials demanded that we do not publish a top secret document and not report it, but refused to comment on this. When we stated that we were going to publish this article, the NSA demanded to make a number of amendments to it. The Intercept agreed with some of these requirements, making sure that the disclosure of this information is definitely not in the interests of society.
The report adds significant new details to the picture, consisting of a declassified assessment of Russian intervention in the elections published by the Obama administration in January. Then the conclusions of the American intelligence community were presented, but many details were silent, fearing to reveal important sources and intelligence methods. With a high degree of confidence, it was said that a large -scale multi -stage propaganda operation was carried out to "undermine the general nature of the general person in the democratic process in the United States, to denigrate the Secretary of State Clinton and damage its election campaign and future work as president."
In that report, there were no attempts to evaluate how the actions of Russia were influenced by the election result, although it was argued that "Russian intelligence gained and maintained access to the elements of numerous American election commissions - local and at the state level." According to the Ministry of Internal Security, "types of systems, which, according to our conclusions, have become the object of Russian attacks, are not involved in summing up the voting results."
However, the Anb has now found out that hackers working for the Russian state, part of the Cybershpion team specially aimed at elections in the USA and other countries, concentrated efforts on the elements of a system directly related to the voter registration process, including a private company producing a device for supporting and checking lists. It was reported that some devices for the production of this company maintain wireless Internet access and Bluetooth technology, which could turn out to be an ideal starting point for further malicious actions.

According to the secret report of the ANB, the Russian plan was simple: introducing himself as a supplier of electronic voting systems, fraud to force local officials to open documents in Microsoft Word format, infected with a malicious program that can give hackers full control over the attacked computers.
But in order to fool local officials, hackers needed access to the internal systems of the software supplier; This would make it possible to create a believable cover. And on August 24, 2016, according to the ANB reports, Russian hackers sent out to employees of the American company producing voting software, fake letters allegedly from Google. Although this company is not directly named in the document, a software product manufactured by VR Systems is mentioned there-an electronic voting system manufacturer with headquarters in Florida. The products of this company are used in eight states.
Fishing letters contained a link leading to the site created by the attackers, disguised as Google, which requested information about the user account and transmitted it to the hackers. The NSA installed seven "probable victims" within the company. Fishing letters sent by three potential victims were rejected by the mail server, but at least one employee of the company Hackers, apparently, gained access to the account of at least one employee of the company. The report notes that "it is not known whether the phishing attack managed to get access to the data of all the planned victims, and the hackers were able to get what information about the victims."
VR Systems refused to respond to a request for a commentary on a specific operation of hackers described in the NSA report. The chief operating room of Ben Martin answered the request of The Intercept with an email of the following content:
“Fishing attacks in our industry often happen. We are permanent participants in cybersalians with government officials and members of the law enforcement community created to combat this type of threats. We have developed a policy and procedures to protect our customers and our company. ”
Although from the report of the NSA it follows that VR Systems employees only lured logins and passwords, and did not infect their computers with harmful programs that give hackers control over them, this does not necessarily be considered as an encouraging sign. The founder of the computer security company Rendition InfoSec Jake Williams, a former member of the team of hackers Tailored Access Operations, who worked for the NSA, said that the abducted logins could be even more dangerous than an infected computer. “With the help of malware, you can mainly receive accounting data,” he said, and information about the employee’s login can be used to penetrate “into the corporate VPN, email or cloud storage”, which gives access to the internal information of the company. The risk is especially enhanced by the fact that many use the same password for different services. Fining is not required for everyone to swallow the bait, but Williams emphasizes that hackers are never limited to kidnapping only one set of accounting data.
In any case, hackers clearly received what they needed. Two months later, on October 27, they created an “operational” email address on Gmail, which looked like belonging to an employee of VR Systems and used the documents obtained during the previous operation to start the second sent phishing attack against the “local state bodies of the United States”. These letters contained a document in the Microsoft Word format, infected with Troyan, which, when opening the document, sent a message to the hackers.
According to the ANB, the next phase of the phishing operation, most likely, began on October 31 or November 1; The letters were sent to 122 addresses “related to state bodies mentioned in the report”, probably, “participating in the management of voter registration systems”. In the letters there were files in Microsoft Word format, which looked like documentation related to the VR Systems production database, but infected with a malicious program, which, when opening the document, automatically automatically launches a number of commands. This malicious program uses PowerShell - the script language developed by Microsoft, designed to administer the system and default, installed on computers running Windows. PowerShell gives almost complete control over the installations and functions of the system. When they are opened “with a high probability”, files were given an infected computer to start in the background of downloading the second package of malicious programs from a remote server, also controlled by hackers. As stated in a secret report, in this way, attackers could get constant access to the computer or the opportunity to "track what is interested in the user." In fact, the infected document quietly opens the “back door” to the victim’s computer, allowing you to install almost any “cocktail” of harmful programs in automatic mode.
According to Williams, an attack of this type in case of success gives the attacker unlimited opportunities to extract the information of interest to him. “As soon as the user opens an infected letter,” Williams explained, “the hacker receives all the opportunities that the user has.” The head of the Symantec Security Research Group, Vikram Takur, told The Intercept that in such cases, "the number of information recovered is limited only by the installations of network administrators." The stolen information is usually encrypted, which means that when studying the infected network, it is impossible to determine what exactly is stolen - you can only notice that something is happening on the network, Williams added. In general, as Williams says, this is a “moderate degree of cunning” method, which can apply “almost any hacker”.
However, the NSA, as indicated in the report, has no confidence regarding the results of the attack. “It is unknown,” says Anb, “whether the directed phishing attack against the planned victims reached its goal and what information hackers could access.
The FBI did not answer the question of whether it opened an investigation in connection with cyber attack on VR Systems.
At a press conference in December, President Obama said that he demanded from Russian President Putin so that he would not be engaged in the hacking of the US election infrastructure. “It was especially important for me that for hacking the e -mail of the National Committee of the Democratic Party, another hack, which may complicate the counting of votes and affect the electoral process itself,” Obama said. - Therefore, in early September, when I met with President Putin in China, I felt that the most effective way to achieve this is to turn directly to him and demand that he stop hacker activity and that if he does not do this, there will be serious consequences. And we practically did not see further intervention in the electoral process. ”
But now the NSA discovered that the intervention continued. “The fact that this happened in October is concerned,” said one high -ranking law enforcement officer specializing in computer security. - In August 2016, there were warnings from the FBI and the Ministry of Internal Security to organizations related to the elections. There was nothing unexpected here. It was not difficult to defend myself from this. But for this, budget funds are needed, and it was necessary to pay attention to this. ”
The ANB report briefly describes two other operations of Russian hackers related to the elections. During one of them, military hackers created an email address supposedly belonging to another American company related to the elections (designated in the report as “American Company 2”), from which fake test letters were sent with a proposal for the supply of “related goods and services”. The NSA could not establish whether the use of this address was aimed at a specific goal.
During the third Russian operation, the same group of hackers sent test letters to the addresses of the election commission of the American Samoa-apparently in order to make sure that these addresses exist before launching another phishing attack. It is unclear whether the goal was achieved, but, according to the ANB, the hackers intended to "act under the guise of a legal service that ensures the procedure for absentee voting." The report does not say why the Russian woman chose the tiny islands in the Pacific Ocean, the American territory, whose votes cannot affect the elections.
To attract attention and budget funds to the problem of the safety of the elections, it is necessary to solve a political puzzle. “Our problem is that the security of the voting process does not mean anything until something happens, and after something happens, a group of people who are not interested in security appear, because the incident that happened to them,” said Berkman’s center expert from Harvard University Bruce Schneier, who often wrote about the vulnerability of the American electoral system. “This creates a very difficult security problem, more difficult than with your bank accounts.”
Schneier said that the attack, as the NSA describes it, is a standard hacker procedure. “The kidnapping of accounting data, directed phishing, is usually done,” he said. “First you occupy a coastal bridgehead, and then you decide how to get somewhere else from it.”
All this means that for hackers it was critical of the understanding of how VR Systems is built into our electoral system, what could be the consequences of such a hacking for elections.
VR SYSTEMS does not produce a touchscreen devices, with which voters directly vote, but supplies programs and devices with which they check whether those who come to polling stations on elections day or ahead of schedule or ahead of schedule. Companies such as VR Systems are very important because the “current registration system is the center of all American elections”, Lawrence Norden, deputy director of the Brennanovsky Center for Justice at the New York Law School, explained. Suppliers such as VR, according to Norden, are also especially important because local election committees are often “not enough or no computer specialists at all”, which means that “such a supplier provides most of the technical support, including what is associated with programming and cybersecurity,” and you are unlikely to want such people to involuntarily act in the interests of a hostile state. It is said on the VR website, the company has contracts in eight states: Virginia, West Virginia, Illinois, Indiana, California, New York, North Carolin and Florida.
Pamela Smith, the head of the Verified Voting organization, observing the honesty of elections, agrees that even if VR Systems does not ensure the voting process itself, this company can be a tempting object for anyone who hopes to disrupt the election.
«Если у кого-то есть доступ к государственной базе данных избирателей, он может злонамеренно изменить или удалить информацию, — сказала она.— Это может повлиять на ситуацию, когда кто-то может проголосовать с помощью обычного бюллетеня или же ему потребуется «временный» бюллетень, то есть он подлежит проверке на право голосовать, прежде чем его внесут в список, и тогда ему придется пройти через несколько процедур, например, доказать сотруднику избиркома , что он имеет право голосовать, и только после этого его право будет подтверждено».
Специалист по компьютерной безопасности Марк Графф, в прошлом глава службы кибербезопасности Lawrence Livermore National Lab, описал гипотетическую тактику хакеров как «аналог DdoS-атаки» против будущих збирателей. Но, по мнению Граффа, еще больше тревожит перспектива того, что хакеры через компанию, подобную VR Systems, близко подберутся к таблицам голосования. Попытка непосредственного взлома или изменения программного обеспечения самих машин для голосования была бы более подозрительной и значительно более рискованной, чем атака на соседнюю, менее заметную часть системы выборов, такую, как регистрационные базы избирателей, в надежде, что одна часть объединена с другой общей сетью. VR Systems открыто заявляет, что ее оборудование для избирательных участков линейки EViD подсоединено к интернету и что в день выборов «история голосования каждого избирателя передается непосредственно в окружную базу данных», причем это происходит непрерывно. Таким образом, компьютерная атака может быстро и незаметно распространяться через объединенные сетью компоненты системы — как микробы через рукопожатие.
По словам специалиста по электронному голосованию Алекса Халдермена, директора Центра компьютерной безопасности Мичиганского университета, одна из главных проблем в сценарии, описанном в докладе АНБ, — вероятность того, что люди, составляющие базы данных при электронном голосовании, — те же, кто занимается программированием машин для голосования. Сами машины для голосования не объединены сетью с таким оборудованием, как EViD производства VR Systems, но в них вручную вносят поправки и настраивают их сотрудники избиркомов — местных или на уровне штата, — которые отвечают и за то, и за другое. И если эти люди — объекты атаки хакеров ГРУ, последствия выглядят тревожно.
«Обычно на уровне штата есть какая-то компания, которая перед выборами программирует машины для голосования, — сказал The Intercept Халдермен. — Меня беспокоит, что хакер, который смог вмешаться в работу поставщика баз данных, может получить возможность с помощью апдейтов программ, распространяемых поставщиком, заразить систему управления выборами, которая программирует уже непосредственно машины для голосования. Если сделать это, можно заставить машину давать искаженные результаты».
Шнайер говорит, что главным призом для взломщика VR Systems может быть возможность собрать достаточно информации, чтобы провести спуфинговую атаку (то есть атаку с использованием поддельных сайтов и адресов, имитирующих сайты и адресап реальных людей и организаций) непосредственно против сотрудников избиркомов. Фальшивое электронное письмо, сопровождаемое подтверждением главного поставщика оборудования для голосования, выглядит значительно убедительнее.
Кроме того, такой взлом может служить базой для проведения подрывных операций. Один из сотрудников американской разведки признал, что российская операция, о которой говорит АНБ, — атака на программное обеспечение системы регистрации избирателей — потенциально могла сорвать голосование там, где пользовались продукцией VR Systems. И зараженная система регистрации может не только создать хаос в день выборов, сказал Халдермен: «Можно устраивать это избирательно — на тех участках, где, скорее всего, будут голосовать за определенного кандидата, — и таким образом действовать в интересах одной из партий».
Но эта российская тактика на выборах препзидента США сталкивается с препятствием — децентрализованной федеральной избирательной системой, где процессы могут быть разными не только в в разных штатах, но и в разных округах. В то же время из-за этого трудно предсказать, где будут сосредоточены усилия хакеров.
«Повлиять на исход выборов с помощью взлома трудно не из-за технологий — это как раз удивительно просто, — но трудно понять, что именно будет эффективно, — сказал Шнайер. — Если взглянуть на несколько последних президентских выборов, то в 2000 году исход определила Флорида, в 2004-м — Огайо, а на последних выборах — несколько округов в Мичигане и Пенсильвании, поэтому очень трудно решить, что именно надо взламывать».
Однако в децентрализации системы есть и своя уязвимость. Сильного государственного надзора за процессом приобретения оборудования и программного обеспечения для голосования нет, как и за регистрацией избирателей, поддержкой списков и подсчетом голосов. Нет одного органа, ответственного за безопасность выборов. Пресс-секретарь Федеральной избирательной комиссии Кристиан Хилленд сказал The Intercept, что «вопросы голосования, а также оборудования и программного обеспечения для голосования не в юрисдикции комиссии; возможно, вам следует связаться с Комиссией содействия выборам».
Знакомство с Комиссией содействия выборам тоже дает мало поводов для оптимизма. Комиссия была создана в 2002 году как реакция Конгресса на неразбериху с подсчетом голосов в 2000-м. На сайте комиссии сказано, что она «призвана служить общенациональной площадкой для обмена информацией по управлению выборами. Комиссия также аккредитует лаборатории тестирования и сертифицирует системы голосования», но это второстепенный орган без реальной власти. На ее сайте ссылка на раздел, посвященный сертификации систем голосования, ведет на несуществующую страницу.
Если бы в США существовала некая центральная власть в сфере выборов, она могла бы начать расследование того, что случилось в день выборов в Дареме, штат Северная Каролина. На нескольких избирательных участках система регистрации давала сбои, создавая хаос. Выстроились длинные очереди, и пришлось перейти на бумажные бюллетени, а также продлить часы работы участков до позднего вечера.
Списки избирателей в Дареме поддерживало оборудование производства VR Systems — той самой фирмы, которую, согласно докладу АНБ, атаковали российские хакеры. Местные власти заявили, что причиной сбоев не был взлом. «Избирательная комиссия штата Северная Каролина не обнаружила никакой подозрительной активности в ходе выборов 2016 года, отличной от той, с которой она имеет дело в другое время. Все потенциальные точки уязвимости подвергаются мониторингу; комиссия сотрудничает с министерством внутренней безопасности и департаментом информационных технологий Северной Каролины, чтобы уменьшить потенциальный риск», — сказал пресс-секретарь комиссии Патрик Гэннон.
Замдиректора избирательной комиссии округа Дарем Джордж Маккью также заявил, что проблема была не в программах, поставленных VR Systems. “Было расследование, и не обнаружено никаких свидетельств того, что с программным продуктом была какая-то проблема, — сказал он. - Выяснилось, что это были ошибки пользователей на разных этапах процесса между настройкой компьютеров и использованием их сотрудниками избиркома».
Все это привлекает еще больше внимания к происходящему сейчас расследованию сговора между избирательным штабом Трампа и российскими агентами, которое обещает стать центральным событием, когда уволенный директор ФБР Джеймс Коми будет свидетельствовать перед Конгрессом. Если в конечном счете удастся продемонстрировать наличие сговора (подчеркиваем слово «если»), то выяснится, что содействие со стороны России вовсе не ограничилось взломом электронной почты ради пропагандистской кампании — это была атака на саму инфраструктуру американских выборов.
Впрочем, к какому бы выводу ни пришло расследование, все это бледнеет в сравнении с той угрозой для легитимности выборов в США, которая возникнет, если не удастся обезопасить избирательную инфраструктуру. Выводы АНБ «показывают, что разные страны разрабатывают специфическую тактику манипулирования выборами и мы должны быть бдительными защищая свою систему, — сказал Шнайер. — Выборы не только определяют победителя, они должны еще и убедить проигравшего. В той мере, в которой выборы уязвимы для хакерских атак, мы рискуем легитимностью процесса голосования, даже тогда, когда фактически взлома нет.
На протяжении всей истории передача власти была моментом величайшей слабости для обществ, что приводило к бесчисленным случаям кровопролития. Мирная передача власти — одно из величайших достижений демократии.
«Просто честных выборов недостаточно, надо, чтобы в их честности легко было убедиться — так, чтобы проигравший сказал: «Да, я проиграл в честной и равной борьбе». Если вы не можете этого сделать, вы проиграли — сказал Шнайер — Они из кожи вон вылезут, если будут убеждены, что не все честно».