08/14/20

Epic Relations Agreement Between Israel and UAE

By: Denise Simon | Founders Code

© Mandel Ngan Image: Secretary of State Mike Pompeo meets with Abu Dhabi Crown Prince Mohamed bin Zayed al-Nahyan (Mandel Ngan / Pool via AFP – Getty Images)

The agreement, to be known as the Abraham Accord.

While the election(s) of Prime Minister Netanyahu of Israel has been contentious for years, and there is a convoluted shared leadership role with Benny Gantz, this new agreement launched by President Trump 3 years ago and now completed is a significant achievement for Netanyahu. The relation agreement continues to reshape the Middle East. Israel had signed peace agreements with Egypt in 1979 and Jordan in 1994.

Arab nations merely by history are not supposed to work with or have relations with the Jewish nation but some Gulf States in the Middle East are moderating including the United Arab Emirates. This relations agreement does put other nations on notice including Qatar, Iran, and Turkey. The UAE has been a great ally of the United States in the war against al Qaeda and Islamic State. There is at least one stipulation however to the agreement and that is any new or additional housing construction in certain areas of the West Bank are again put on hold. Still, Palestinian leaders, apparently taken by surprise, denounced it as a “stab in the back” to their cause.

The UAE, which has never fought Israel and has quietly been improving ties for years. Israel, the UAE and other Gulf countries that view Iran as a regional menace have been cultivating closer ties in recent years. Turkey has had diplomatic relations with Israel for decades, but under President Recep Tayyip Erdogan has positioned itself as a champion of the Palestinians. Turkey and the UAE support rival camps in the conflict in Libya.

Israel and the UAE are expected soon to exchange ambassadors and embassies. A signing ceremony is due to be held at the White House.

Israel-UAE reached very close to full normalization of ...

Delegations from Israel and the United Arab Emirates will meet in the coming weeks to sign agreements regarding investment, tourism, direct flights, security, telecommunications, and other issues, the joint statement said.

“Everybody said this would be impossible,” Trump said.

“Now that the ice has been broken, I expect more Arab and Muslim countries will follow the United Arab Emirates’ lead,” Trump added.

***

Read the statement here:

President Donald J. Trump, Prime Minister Benjamin Netanyahu of Israel, and Sheikh Mohammed Bin Zayed, Crown Prince of Abu Dhabi and Deputy Supreme Commander of the United Arab Emirates spoke today and agreed to the full normalization of relations between Israel and the United Arab Emirates.

This historic diplomatic breakthrough will advance peace in the Middle East region and is a testament to the bold diplomacy and vision of the three leaders and the courage of the United Arab Emirates and Israel to chart a new path that will unlock the great potential in the region. All three countries face many common challenges and will mutually benefit from today’s historic achievement.

Delegations from Israel and the United Arab Emirates will meet in the coming weeks to sign bilateral agreements regarding investment, tourism, direct flights, security, telecommunications, technology, energy, healthcare, culture, the environment, the establishment of reciprocal embassies, and other areas of mutual benefit. Opening direct ties between two of the Middle East’s most dynamic societies and advanced economies will transform the region by spurring economic growth, enhancing technological innovation, and forging closer people-to-people relations.

As a result of this diplomatic breakthrough and at the request of President Trump with the support of the United Arab Emirates, Israel will suspend declaring sovereignty over areas outlined in the President’s Vision for Peace and focus its efforts now on expanding ties with other countries in the Arab and Muslim world. The United States, Israel, and the United Arab Emirates are confident that additional diplomatic breakthroughs with other nations are possible, and will work together to achieve this goal.

The United Arab Emirates and Israel will immediately expand and accelerate cooperation regarding the treatment of and the development of a vaccine for the coronavirus. Working together, these efforts will help save Muslim, Jewish, and Christian lives throughout the region.

This normalization of relations and peaceful diplomacy will bring together two of America’s most reliable and capable regional partners. Israel and the United Arab Emirates will join with the United States to launch a Strategic Agenda for the Middle East to expand diplomatic, trade, and security cooperation. Along with the United States, Israel and the United Arab Emirates share a similar outlook regarding the threats and opportunities in the region, as well as a shared commitment to promoting stability through diplomatic engagement, increased economic integration, and closer security coordination. Today’s agreement will lead to better lives for the peoples of the United Arab Emirates, Israel, and the region.

The United States and Israel recall with gratitude the appearance of the United Arab Emirates at the White House reception held on January 28, 2020, at which President Trump presented his Vision for Peace, and express their appreciation for United Arab Emirates’ related supportive statements. The parties will continue their efforts in this regard to achieve a just, comprehensive, and enduring resolution to the Israeli-Palestinian conflict. As set forth in the Vision for Peace, all Muslims who come in peace may visit and pray at the Al Aqsa Mosque, and Jerusalem’s other holy sites should remain open for peaceful worshippers of all faiths.

Prime Minister Netanyahu and Crown Prince Sheikh Mohammed bin Zayed Al Nahyan express their deep appreciation to President Trump for his dedication to peace in the region and to the pragmatic and unique approach he has taken to achieve it.

08/14/20

4 Tankers Headed to Venezuela, Stopped by US

By: Denise Simon | Founders Code

MIAMI — The Trump administration has seized the cargo of four tankers it was targeting for transporting Iranian fuel to Venezuela, U.S. officials said Thursday, as it steps up its campaign of maximum pressure against the two heavily sanctioned allies.

Last month, federal prosecutors in Washington filed a civil forfeiture complaint alleging that the sale was arranged by a businessman, Mahmoud Madanipour, with ties to Iran‘s Revolutionary Guard Corps, a U.S.-designated foreign terrorist organization. At the time, sanctions experts thought it would be impossible to enforce the U.S. court order in international waters.

A senior U.S. official told The Associated Press that no military force was used in the seizures and that the ships weren’t physically confiscated. Rather, U.S. officials threatened ship owners, insurers, and captains with sanction to force them to hand over their cargo, which now becomes U.S. property, the official said.

Prosecutors alleged the four ships were transporting to Venezuela 1.1 million barrels of gasoline. But the tankers never arrived at the South American country and then went missing. Two of the ships later reappeared near Cape Verde, a second U.S. official said.

Both officials agreed to discuss the sensitive diplomatic and judicial offensive only if granted anonymity.

Iran’s ambassador to Venezuela, Hojad Soltani, pushed back on what would appear a victory for the U.S. sanctions campaign, saying Thursday on Twitter that neither the ships nor their owners were Iranian.

“This is another lie and act of psychological warfare perpetrated by the U.S. propaganda machine,” Soltani said. “The terrorist #Trump cannot compensate for his humiliation and defeat by Iran using false propaganda.”

It is not clear where the vessels — the Bella, Bering, Pandi, and Luna — or their cargoes currently are. But the ship captains weeks ago turned off their tracking devices to hide their locations, said Russ Dallen, a Miami-based partner at brokerage Caracas Capital Markets, who follows ship movements.

The Bering went dark on May 11 in the Mediterranean near Greece and has not turned on its transponder since, while the Bella did the same July 2 in the Philippines, Dallen said. The Luna and Pandi were last spotted when they were together in the Gulf of Oman on July 10 when the U.S. seizure order came. Shipping data shows that the Pandi, which also goes by Andy, is reporting that it has been “broken up,” or sold as scrap, Dallen said.

As commercial traders increasingly shun Venezuela, Nicolás Maduro’s socialist government has been increasingly turning to Iran.

In May, Maduro celebrated the arrival of five Iranian tankers delivering badly needed fuel to alleviate shortages that have led to days-long gas lines even in the capital, Caracas, which is normally spared such hardships.

Despite sitting atop the world’s largest crude reserves, Venezuela doesn’t produce enough domestically refined gasoline and has seen its overall crude production plunged to the lowest in over seven decades amid its economic crisis and fallout from U.S. sanctions.

The Trump administration has been stepping up pressure on ship owners to abide by sanctions against U.S. adversaries like Iran, Venezuela, and North Korea. In May, it issued an advisory urging the global maritime industry to be on the lookout for tactics to evade sanctions like dangerous ship-to-ship transfers and the turning off of mandatory tracking devices — both techniques used in recent oil deliveries to and from both Iran and Venezuela.

One of the companies involved in the shipment to Venezuela, the Avantgarde Group, was previously linked to the Revolutionary Guard and attempts to evade U.S. sanctions, according to prosecutors.

An affiliate of Avantgarde facilitated the purchase for the Revolutionary Guard of the Grace 1, a ship seized last year by Britain on U.S. accusations that it was transporting oil to Syria. Iran denied the charges and the Grace 1 was eventually released. But the seizure nonetheless triggered an international standoff in which Iran retaliated by seizing a British-flagged vessel.

According to the asset forfeiture complaint, an unnamed company in February invoiced Avantgarde for a $14.9 million cash payment for the sale of the gasoline aboard the Pandi. Nonetheless, a text message between Madanipour and an unnamed co-conspirator suggested the voyage had encountered difficulties.

“The shipowner doesn’t want to go because of the American threat, but we want him to go, and we even agreed We will also buy the ship,” according to the message, an excerpt of which was included in the complaint.

08/14/20

Hat tip to NSA FBI for Cracking Drovorub

By: Denise Simon | Founders Code

The National Security Agency and the FBI are jointly exposing malware that they say Russian military hackers use in cyber-espionage operations.

Hackers working for Russia’s General Staff Main Intelligence Directorate’s 85th Main Special Service Center, military unit 26165, use the malware, which the Russians themselves call “Drovorub,” to target Linux systems, the NSA and FBI said Thursday in a detailed report.

The hackers, also known as APT28 or Fancy Bear, allegedly hacked the Democratic National Committee in 2016 and frequently target defense, government, and aerospace entities. The Russian military agency is also known as the GRU.

FBI e NSA descobrem novo malware Linux chamado Drovorub ...

While the alert does not include specific details about Drovorub victims, U.S. officials did say they published the alert Thursday to raise awareness about state-sponsored Russian hacking and possible defense sector vulnerabilities. The disclosure comes just months before American voters will conduct a presidential election.

“Information in this Cybersecurity Advisory is being disclosed publicly to assist National Security System owners and the public to counter the capabilities of the GRU, an organization which continues to threaten the United States and U.S. allies as part of its rogue behavior, including their interference in the 2016 U.S. Presidential Election,” the NSA and FBI said in the report.

The U.S. intelligence community has assessed that multiple foreign governments may “seek to compromise our election infrastructure.” It was not clear if the Russian hackers were using Drovorub malware in any ongoing interference efforts related to the 2020 presidential elections.

The NSA and FBI urged national security personnel, including the U.S. Department of Defense, to be on the alert for Drovorub attacks.

“The malware represents a threat because Linux systems are used pervasively throughout National Security Systems, Department of Defense, and the Defense Industrial Base,” the statement said. “All stakeholders should take action as appropriate.”

The announcement comes nearly one year after the NSA stood up a new cybersecurity directorate aimed at sharing more adversary threat intelligence with the public, and in recent weeks the NSA has worked to expose a spate of Russian campaigns, including Russian hackers’ efforts to target coronavirus research.

Senior Vice President of Intelligence at CrowdStrike, Adam Meyers, told CyberScoop the release shows these hackers are not easily deterred.

“Most importantly it demonstrates that FANCY BEAR has more tools and capabilities that are still being identified. This actor didn’t pack up and go home, they still have tricks up their sleeve,” Meyers told CyberScoop, adding that the news should raise alarm bells about Linux security. “Another important take away is that Linux is an area that organizations need to keep in mind from a malware perspective, many have not invested in similar security tools for this platform as they have for user platforms.”

Attacks employing Drovorub may be linked with previous Russian military efforts against connected devices, according to the NSA and the FBI. An APT28 attack that Microsoft security researchers identified last year against devices such as an office printer or a VOIP phone, for instance, was linked with an IP address that has also been used to access the Drovorub command and control IP address, the NSA and FBI said.

In such attacks, the hackers appeared interested in exploiting the so-called internet of things devices in order to gain access to broader networks, other insecure accounts, and sensitive data, according to Microsoft.

The joint NSA and FBI release also has the effect of alerting the Russian government that U.S. officials are capable of tracking some of their work. The 780th Military Intelligence Brigade, which currently works with the Pentagon’s offensive cyber arm, Cyber Command, tweeted information out about the malware, and tagged a state-funded media outlet, RT, to flag the news for them.

The Drovorub malware consists of several components, the NSA and the FBI said, including an implant, a kernel module rootlet, a file transfer tool, and an attacker-controlled command and control server.

“When deployed on a victim machine, the Drovorub implant (client) provides the capability for direct communications with actor-controlled C2 infrastructure; file download and upload capabilities; execution of arbitrary commands as ‘root’; and port forwarding of network traffic to other hosts on the network,” the NSA and FBI said.

More detail from ZDNet:

“Technical details released today by the NSA and FBI on APT28’s Drovorub toolset are highly valuable to cyber defenders across the United States.”

To prevent attacks, the agency recommends that US organizations update any Linux system to a version running kernel version 3.7 or later, “in order to take full advantage of kernel signing enforcement,” a security feature that would prevent APT28 hackers from installing Drovorub’s rootkit.

The joint security alert [PDF] contains guidance for running Volatility, probing for file hiding behavior, Snort rules, and Yara rules — all helpful for deploying proper detection measures.

Some interesting details we gathered from the 45-page-long security alert:

  • The name Drovorub is the name that APT28 uses for the malware, and not one assigned by the NSA or FBI.
  • The name comes from drovo [дрово], which translates to “firewood”, or “wood” and rub [руб], which translates to “to fell”, or “to chop.”
  • The FBI and NSA said they were able to link Drovorub to APT28 after the Russian hackers reused servers across different operations. For example, the two agencies claim Drovorub connected to a C&C server that was previously used in the past for APT28 operations targeting IoT devices in the spring of 2019. The IP address had been previously documented by Microsoft.