Day 8 - Guardians of Peace (Sony Hack, 2014)
By : Maria Corbett, Kaela Fiesta, Kristen Toguchi, and Eamonn Hartmann
Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea
HACKER GROUP - WHO ARE THEY? - The Guardians of Peace are a hacking group that have come to be references to multiple different groups of people. As stated by the Independent News in the article, “Sony Hack : Who Are The Guardians of Peace, and is North Korea Really Behind the Attack”, “it’s entirely possible that the Guardians of Peace name has been used by a number of different groups by now. Though most of the important messages have been released alongside new batches of data - leading some people to speculate that they are coming from the same original person, who has access to the larger haul - the information has probably made its way around file-sharing communities already, and could easily be packaged up and distributed by anyone wanting to take on the name” (The Independent News). Since The Independent News has made this strong claim, further investigation has been done. As one example, according to the US FBI, the Guardians of Peace work for the North Korean government. Additionally, as quoted in an article from The Daily Beast called Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea, “according to a statement issued by the FBI on December 19, which was then echoed by President Obama during his year-end press conference, ‘the North Korean government is responsible’ for hacking Sony’s servers, leaking sensitive company data online, threatening movie theaters that choose to exhibit the satire The Interview, and ultimately succeeding in getting the Kim Jong Un assassination comedy’s release pulled (1).”
How Are They Categorized? - As of now, nobody has a clear idea regarding who exactly this specific group is. However, the US authorities believe the attacks originated from North Korea despite the fact that North Korea has repeatedly denied any involvement in this specific hack attack. Although North Korea is the prime suspect, there is also speculation that this attack is somehow linked to a possible Sony insider, a group of disgruntled former employees or possibly even a marketing campaign orchestrated by Sony itself, that promotes “The Interview.” While keeping all these possibilities in mind, there continues to be uncertainty as to who exactly this mysterious group is.
Who Was Involved? - As quoted by the DEADLINE News in an article covering and discussing this specific topic, “the attack would come to involve the President of the United States, the FBI, the CIA, the State Department, the Department of Homeland Security and Congress, and yet, little more is known about the identity of the hackers today than was known in those first few frantic days after the breach. That’s when blame first began to fall on North Korea, which was suspected of orchestrating the hack in retaliation for the studio’s planned release of The Interview, which ridiculed the Hermit Kingdom’s leader, Kim Jong-un…”
What Was Their Motivation? - This group was possibly driven by the same anarchic philosophy that has been a prime characteristic and marker of the specific group, otherwise known as the “Anonymous”, where many of the hackers came from. Sometimes known as the ‘lulz’, these groups often tended to seek to cause as much damage as possible for little reason other than personal enjoyment. However, it was also taught that there could also potentially be something more political at work and strongly influencing the onset of this specific hack. Because of the predicament that this political involvement caused in relationship to this particular hack, Sony, along with other major distributors, has been increasingly active in fighting against sharing of multiple internet files. Furthermore, Sony has even had its systems taken down by Anonymous in 2011.
What Was The Lead Up? - There were six communiques leading up to and following the Sony hack that have been attributed to the Guardians of Peace. At least one of them is now widely suspected to have been a hoax, and hackers claiming to be from the GOP say that another one is, too. In the three weeks following the attack, the GOP dumped seven huge, but difficult to access, hoards of stolen Sony documents and emails onto online file-sharing hubs, and then quietly disappeared, never to be heard from again.
What Was The Impact? - Stated by John P. Carlin of the Justice Department’s Assistant Attorney General for National Security, “I think the Sony hack and response did more to raise national security cyber awareness than any other single event,” he continued. “The lessons learned from Sony have changed board practices across the country as companies examine whether they are ready to respond in a world where every company in every sector is vulnerable in a way they have not been before.” Also, as stated in the article, “Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea”, ‘technical analysis of the data deletion malware used in this attack revealed links to other malware that the FBI knows North Korean actors previously developed. For example, there were similarities in specific lines of code, encryption algorithms, data deletion methods, and compromised networks. The FBI also observed significant overlap between the infrastructure used in this attack and other malicious cyber activity the U.S. government has previously linked directly to North Korea. For example, the FBI discovered that several Internet protocol (IP) addresses associated with known North Korean infrastructure communicated with IP addresses that were hardcoded into the data deletion malware used in this attack.” Additionally, as quoted from the article, “Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea“, “separately, the tools used in the SPE attack have similarities to a cyber attack in March of last year against South Korean banks and media outlets, which was carried out by North Korea.”
Who Was The Culprit? - At that time, US government officials believed that the attack was tied to the North Korean government, who expressed outrage over the Sony film “The Interview.” On the day of the hack, Sony employees who tried to log onto their computers were greeted with the image shown at the top- a red skeleton with the saying “Hacked by #GOP”. The Guardians of Peace threatened to release data they obtained through hacking. This included personal information of employees and customers, emails, and unreleased movies such as Still Alice, Annie, and To Write Love on Her Arms. As quoted by the DEADLINE NEWS, in the same article, “there were six communiques leading up to and following the Sony hack that have been attributed to the Guardians of Peace. At least one of them is now widely suspected to have been a hoax, and hackers claiming to be from the GOP say that another one is, too.” However, as quoted by the article, “Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea”, “meanwhile, North Korea has maintained their stance that they weren’t involved in the crippling cyber-attack, and have proposed a joint investigation with the U.S. authorities in finding the culprits, warning of “grave consequences” if America continues to blame the Hermit Kingdom for the hacking.” As also stated in the same article from The Daily Beast, “while the FBI, President Obama, and George Clooney seem thoroughly convinced that the Guardians of Peace are the work of Pyongyang—the name “Guardians of Peace” comes from a quote used by former President Richard Nixon describing South Korea—many hackers online have questioned the allocation of blame from Day One, including former Lulzsec hacker turned government information Sabu, who maintains they “don’t have the technical capabilities,” and Anonymous, who wrote, “we all know the hacks didn’t come from North Korea,” and threatened to launch further hacks against Sony if they don’t release the film online. Some of the world’s leading cybersecurity experts have also questioned whether North Korea is responsible for hacking Sony, claiming a decided lack of evidence or that it came from a group posing as North Korea as misdirection, such as Brett Thomas, chief technology officer of Redwood City, California-based online services company Vindicia”
What Was Their Tactic? - The hackers utilized malware which is a type software that is used for hacking attacks. The malware destroyed the hard drive in the Sony system and the hackers also chose Korean as the language on the version of Microsoft Windows that was used for the hack. Again, this points towards the hackers being from North Korea; yet, the computers that were used for the hacking were located in Thailand, Italy, and Poland, not in North Korea. The malware attacked the Windows Management Instrumentation (WMI), which then spread the malware through the whole Sony network. Files concerning “business plans” and “compensation data” were leaked to several websites during the weeks following the attack (Hesseldahl, 2014). Five motion picture files were also leaked to sites, four of them being unreleased (Hesseldahl, 2014).
What Were The Results? - “As quoted by the DEADLINE NEWS, in the same article, “in the three weeks following the attack, the GOP dumped seven huge, but difficult to access, caches of stolen Sony documents and emails onto online file-sharing hubs, and then quietly disappeared, never to be heard from again.” Sony Pictures proceeded to cancel the premier of “The Interview,” because of the allegations that the hackers were from North Korea and that many North Koreans took offense from the movie. Sony also took a letter requesting that the data leakage would be stopped promptly to the Supreme court in the hopes that no more of the hacked data would be leaked; the FBI along with a few anti-hacking companies were enlisted to try and prevent further data leakage (Peterson, 2014). Also, as quoted by The Daily Beast in the article, Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea, it was found that “technical analysis of the data deletion malware used in this attack revealed links to other malware that the FBI knows North Korean actors previously developed. For example, there were similarities in specific lines of code, encryption algorithms, data deletion methods, and compromised networks. The FBI also observed significant overlap between the infrastructure used in this attack and other malicious cyber activity the U.S. government has previously linked directly to North Korea. For example, the FBI discovered that several Internet protocol (IP) addresses associated with known North Korean infrastructure communicated with IP addresses that were hardcoded into the data deletion malware used in this attack.” Through these hacks, it was also discovered that “separately, the tools used in the SPE attack have similarities to a cyber attack in March of last year against South Korean banks and media outlets, which was carried out by North Korea.”
How Did People React? - Many people were disappointed by the cancellation of the release of “The Interview,” but the “cybersecurity community” were much more worried about the “vulnerability” of other technology companies that could be hacked in the future (Peterson, 2014). Another movie studio cancelled their screening of a movie that related to the conflict with North Korea, because of the Sony hacking, so much of the public responded to the hacking as a warning from North Korea (Robb, 2015). As quoted by by The Daily Beast in the article, Sony Hackers Guardians of Peace Troll FBI, Anonymous Convinced Hack Didn’t Come From North Korea, “President Obama, meanwhile, seems quite adamant in believing the narrative that North Korea and its leader, Kim Jong Un, were so offended by the satire The Interview, a Seth Rogen and James Franco flick which portrays the Dear Leader being assassinated, that they launched a cyber-attack on Sony as retribution, and threatened a “proportional” response by the U.S.” Also, as this article goes on to state, “the FBI announced today and we can confirm that North Korea engaged in this attack,” President Obama announced during his year-end presser on Friday. “I think it says something interesting about North Korea that they decided to have the state mount an all-out assault on a movie studio because of a satirical movie starring Seth Rogen and James Flacco [Franco]. I love Seth and I love James, but the notion that that was a threat to them I think gives you some sense of the kind of regime we’re talking about here.’ He added’, “They caused a lot of damage, and we will respond. We will respond proportionally, and we’ll respond in a place and time and manner that we choose. It’s not something that I will announce here today at a press conference.”
Analysis - Geeks are the New Guardians of Our Civil Liberties Hacker Politics & Publics-In this article, Gabriella Coleman compares the principles and politics of geeks and hackers in the modern era. Two companies that leak hacked content, Anonymous and WikiLeaks, are associated with each other, because of their political agenda and operation, which is to expose corruption at the corporate level. Coleman also addresses the emphasis on free speech among hackers and geeks. Liberalism is a common trait among hackers and geeks who wish to give the public a clean view of possibly fuzzy information covered up by corporations or other powerful groups. As we have previously learned, hacking is a form of protest at the digital level and it can be compared with any other kind of opinionated insurgency. The increase in hacking activity in this day and age could be a sign of transition towards a different form of protest that presents the public with fraud or corrupt information and allows the public to fight for change.
TED Talk- Hackers: The Internet’s Immune System- Keren Elazari, a cybersecurity expert, explains how “we need hackers” because “they might be the immune system for the information age”. They find hidden threats in our world and force us to fix it. Hackers practice full disclosure, which is when they make vulnerabilities known to the public. Some hackers do what they do to grab our attention and bring people together. Anonymous, the leading brand of hacktivism, has uncovered corruption and abuse. The Telecomix group has helped Egyptians bypass censorship and also opened up 300 Internet lines. Hackers are a force for social, political and military influence. The same people who demonize hacking also utilize it. Overall, hackers have impacted civil liberties, innovation and Internet freedom.
Geeks are the New Guardians of Our Civil Liberties - Comparison - This article is comparing how hackers and geeks are similar to terrorists; dangerous criminals on the web. The author proves this by explaining what hackers do. More specifically speaking, like terrorists, hackers often associate with each other and work together as a means of meeting their same goal of terrorism that they share. Building off of this specific point, an article from ars technica, Sony Pictures Hackers Release List of Stolen Corporate Files, states that “In an effort to reveal the true actions and associations that hackers tend to associate themselves with as well as be involved with, he writes, “some hackers are part of a transgressive, law-breaking tradition, their activities opaque and below the radar.” Also, he says that in our society today, hacking on the web is useful skill for jobs (Ex: FBI, Google). This skill is able to create movements and control what we see on the internet, thus has a lot of power. Through this specific article, this author has voiced the strong opinion and notion that while hacking has its obvious flaws and detrimental drawbacks, this practice has also gained a significant amount of power, and is therefore able to enhance the practice of various different occupations. Drawing from this, one way of looking at this particular practice is that it has the potential of acting as a positive influence on many different occupations in the work force.
What themes from previous sessions do these draw on? How are these significant in the context of hacking & hacktivism? - The themes that this article relate to include how our internet is being regulated at various levels. This theme extends to put across the integral point and is very much centered around the idea that among all of these different hackers, different levels of hacking as well as various types of hacking are being performed. For example, there are hackers who work for large companies whose purpose is to protect the companies for whom they work. These are some hackers who hack for the pure pleasure of hacking. There are other hacktivists who hack to protest corporate or political policy. These themes are significant, especially in relationship to the context of hacking and hactivism in the sense that it puts across the point that there is clearly different levels of security displayed over different aspects of the internet. Furthermore, while some components of the internet is very much secured and guarded over, other aspects of the internet is not as regulated, thus leading to hacks. In other words, the fact that some aspects of the internet has more exposure and less security than other aspects of the internet is in significant to understanding the void in our digital world that allows room for hacking and for hacktivists to have much more access to hacking.
Bibliography Griffin, Andrew. 2014. “Sony Hack: Who Are the Guardians of Peace, and Is North Korea Really behind the Attack?” The Independent. Retrieved January 21, 2016 (http://www.independent.co.uk/life-style/gadgets-and-tech/news/sony-hack-who-are-the-guardians-of-peace-and-is-north-korea-really-behind-the-attack-9931282.html). Grisham, Lori. 2015. “Timeline: North Korea And the Sony Pictures Hack.” USA Today. Retrieved January 21, 2016 (http://www.usatoday.com/story/news/nation-now/2014/12/18/sony-hack-timeline-interview-north-korea/20601645/). Hesseldahl, Arik. 2014. “Details Emerge On Malware Used in Sony Hacking Attack.” Recode. Retrieved January 21, 2016 (http://recode.net/2014/12/02/details-emerge-on-malware-used-in-sony-hacking-attack/). Peterson, Andrea. 2014. “The Sony Pictures Hack, Explained.” Washington Post. Retrieved January 21, 2016 (https://www.washingtonpost.com/news/the-switch/wp/2014/12/18/the-sony-pictures-hack-explained/). Robb, David. 2015. “The Sony Hack One Year Later: Just Who Are The Guardians Of Peace?” Deadline. Retrieved January 21, 2016 (http://deadline.com/2015/11/sony-hack-guardians-of-peace-one-year-anniversary-1201636491/).









