Google Inadvertently Stopped A Government Counterterrorism Operation, Report Said

In privacy perspective, cyberattacks are always bad, simply because they involve software and other methods to infiltrate targets by exploiting weaknesses in their systems, in order to compromise them.

However, in the eyes of the governments at least, cyberattacks can be good.

But that is as long as they are the ones who are doing them, like for things that include intelligence, espionage or counterterrorism.

And this time, it happened that one government-backed campaign has been inadvertently and unilaterally blocked by Google.

Google's top security team at Project Zero managed to find a sophisticated hacking campaign that targeted security flaws in Android, Windows and iOS devices. The campaign was made public in January by the team, and was then reported as a campaign where a “highly sophisticated” group, likely staffed by “teams of experts,” was responsible for targeting numerous zero-day vulnerabilities.

But later, it was realized that the campaign was actually the work of “Western government operatives” conducting a “counterterrorism operation.”

Google

That according to a report from MIT Technology Review:

"Google runs some of the most venerated cybersecurity operations on the planet: its Project Zero team, for example, finds powerful undiscovered security vulnerabilities, while its Threat Analysis Group directly counters hacking backed by governments, including North Korea, China, and Russia. And those two teams caught an unexpectedly big fish recently: an 'expert' hacking group exploiting 11 powerful vulnerabilities to compromise devices running iOS, Android, and Windows."

"But MIT Technology Review has learned that the hackers in question were actually Western government operatives actively conducting a counterterrorism operation. The company’s decision to stop and publicize the attack caused internal division at Google and raised questions inside the intelligence communities of the United States and its allies."

This hacking campaign, is said to have been going on for at least nine months, and was using the so-called “watering hole” method.

What it does, is injecting malicious code into a website to effectively “booby trap” it. As a result, visitors of the website can be infected with malware.

Due to its scope, it was suggested that some government should be behind the campaign. But as MIT realized, it was actually the Westerns' doing.

At the time of finding, it is unclear what government is actually responsible for the attacks, who its targets were, or what the so-called “counterterrorism” operation related to all of this entailed.

MIT itself has not detailed how it managed to discover this information.

[block:block=87]

But whatever is real behind this campaign, Google has certainly derailed the hacking operation.

MIT wrote that Google in publicly disclosing what the hacking campaign did, has effectively shut down a “live counterterrorism” cyber mission, while adding that it “is not clear whether Google gave advance notice to government officials that they would be publicizing and shutting down” the attacks.

It should be noted that the team at Google Project Zero apparently knows who the hackers are, but refuses to disclose who they are.

As per the MIT report, the incident has spurred a debate at the company over whether counterterrorism operations like this should be considered “out of bounds” for public disclosure, or whether it was well within their purview to disclose the vulnerabilities to “protect users and make the internet more secure.”

The reason things like this can happen, is because government-backed campaigns are usually opaque.

Government-backed hackers can be supplied with some of the best a government can supply, simply because they work for the government. But while resourceful and sitting on huge resources, these hackers work in the shadows because their work tends to involve intelligence, espionage or counterterrorism.

And this campaign is most often, target rival countries.

This is why parties that aren't part of the campaign, are never notified.

US flag

“The level of oversight even in Western democracies about what their national security agencies are actually doing is, in many cases, a lot less than we have in the United States,” said Michael Daniel, who was previously a White House cybersecurity coordinator for the Obama administration.

“The degree of parliamentary oversight is much less. These countries do not have the robust inter-agency processes the US has. I’m not normally one to brag about the US—we’ve got a lot of problems—but this is one area where we have robust processes that other Western democracies just don’t.”

While campaigns like this in the eyes of privacy are a violation, the fact that the campaign was discovered so rapidly could indicate a problematic imbalance.

Some worry about the effectiveness of counterterrorism cyber operations after being shut down at potentially decisive moments without the ability to quickly start up again.

And Google’s ability to shut down such an operation can actually be a source of conflict within the U.S. and its allies.

“US allies don’t all have the ability to regenerate entire operations as quickly as some other players,” the former senior US intelligence official said.

By suddenly being blocked, Google is essentially stopping a counterterrorism mission during “periods of incredible exposure,” when a lot of exploitation is taking place, the official explained.

“This is still something that hasn’t been well addressed,” the official said.

“The idea that someone like Google can destroy that much capability that quickly is slowly dawning on folks.”