CLA 1eam 1hreaL 8eporL

1o lnform Lhe Army Lralnlng communlLy of Lhe Syrlan LlecLronlc Army (SLA) cyber aLLack on
CaLarl webslLes.
1o provlde background lnformaLlon on Lhe SLA.
1o descrlbe Lhe general moLlvaLlon behlnd Lhe SLA's aLLacks.

?=.24-08. 34<<>79
1he SLA ls a dlsconnecLed group of Syrlan l1 professlonals who are lnLenL on combaLlng
whaL Lhey vlew as un[usL medla coverage of Lhe Syrlan governmenL and exLernal supporL for
Lhe rebels.
Crganlzed ln 2011, Lhe SLA has aLLacked news agencles, governmenL slLes, unlverslLles, and
oLher organlzaLlons deemed hosLlle Lo Lhe Syrlan governmenL.
ln CcLober 2013, Lhe SLA hacked lnLo a domaln reglsLry conLalnlng lnformaLlon abouL a
number of dlfferenL CaLarl webslLes.
1he SLA polnLed Lo CaLarl supporL for Lhe rebels ln Syrla as Lhe reason for Lhe aLLack.
1he SLA has, Lo daLe, focused on nulsance aLLacks, lncludlng placlng pro-Assad propaganda
on Lhe CaLarl webslLes or dlrecLlng vlslLors Lo oLher slLes.

!"#$% '(")"* +"," -.$/ 01 )($ 21%345 67$8)%"538 9%:1 ;269<=
Figure 1: Map of Qatar

1he recenL medla aLLenLlon glven Lo Lhe naLlonal SecurlLy Agency (nSA) domesLlcally ls puLLlng more
focus on cyber acLlvlLles around Lhe world. 1he nSA's more sophlsLlcaLed operaLlons have
overshadowed Lhe less compllcaLed, buL noneLheless effecLlve, cyber aLLacks conducLed by
organlzaLlons such as Lhe Syrlan LlecLronlc Army (SLA). Slnce lLs lncepLlon ln 2011, Lhe SLA has
conducLed nulsance aLLacks on numerous slLes around Lhe world ln supporL of Lhe Syrlan governmenL.
news agencles, governmenL slLes, unlverslLles, and even Lhe uS Marlne Corps recrulLlng slLe have been
LargeLs of Lhe SLA's cyber aLLacks.
MosL recenLly, Lhe SLA LargeLed CaLarl governmenL mlnlsLry webslLes. 1he CaLarl governmenL galned
conLrol of Lhe onllne slLes wlLhln a few days, buL Lhe evenL underscored Lhe ease wlLh whlch cyber
aLLacks can be waged from anywhere ln Lhe world. 1he SLA's reason for LargeLlng CaLar ls Lhe counLry's
supporL of Lhe lree Syrlan Army and afflllaLed Sunnl lnsurgenLs flghLlng agalnsL Lhe Assad governmenL.
1he SLA has resLralned lLself Lo nulsance aLLacks and noL mallclous assaulLs, however, lL ls noL unreallsLlc
Lo poslL more damaglng aLLacks ln Lhe fuLure. 1he ablllLy Lo wage aLLacks from anywhere ln Lhe world
and operaLe wlLhln dlsparaLe and dlsconnecLed cells allows cyber lnsurgenLs Lo conducL operaLlons more
easlly Lhan LradlLlonal lnsurgenLs.
3970>, ?/.2-76,02 $7<9 :3?$;
1he SLA ls a dlsparaLe group of compuLer hackers boLh lnslde and ouLslde Syrla who supporL Lhe Assad
governmenL. 1he purporLed goal of Lhe SLA ls Lo counLer whaL lL percelves ls unfalr coverage of Lhe
Syrlan governmenL ln Lhe WesLern and Arablc press and supporL of governmenLs for rebels flghLlng
agalnsL Lhe Syrlan governmenL. CperaLlng onllne vla soclal medla plaLforms such as lacebook and
1wlLLer, Lhe SLA has launched organlzed nulsance aLLacks such as spammlng campalgns and denlal of
servlce aLLacks on lndlvldual, group, and organlzaLlon webslLes LhaL lL belleves undermlne Lhe Syrlan
governmenL's leglLlmacy.
1he SLA lacebook page clalms LhaL lL ls noL an offlclal pollLlcal parLy and ls
only assoclaLed wlLh Lhe Syrlan governmenL Lhrough lLs supporL of Lhe governmenL agalnsL an
lnsurgency supporLed by oLher counLrles.

Slnce 2011, Lhe SLA has conducLed whaL can be deflned as nulsance aLLacks on numerous slLes, buL mosL
organlzaLlons LargeLed regalned conLrol of Lhelr webslLes wlLhln a few hours Lo a few days. Cne self-
descrlbed member of Lhe SLA neLwork sLaLed LhaL hls lnLenL was noL Lo desLroy, buL Lo publlsh messages
or arLlcles of supporL for Lhe Syrlan governmenL. A velled LhreaL, however, followed when Lhe hacker
sald LhaL lf Lhe unlLed SLaLes aLLacked Syrla, more mallclous and damaglng aLLacks could resulL.
1he SLA
has Lhree years of successful experlence problng a large number of webslLes. lLs collecLlve skllls aL LhaL
level are sharp, yeL lL ls unllkely LhaL Lhe SLA wlll be able Lo progress much furLher lnLo more
compllcaLed cyber aLLacks wlLhouL slgnlflcanL help from allles. 1hose capable of hlgher-level Lechnology
aLLacks are noL llkely Lo share Lhose resources wlLh Lhe SLA, as lL would creaLe vulnerablllLy for Lhe
sharlng enLlLy.
Figure 2: Now defunct SEA website calling for volunteers

1he SLA ls noL a monollLhlc organlzaLlon, buL operaLes ln a decenLrallzed fashlon, ln a manner slmllar Lo
lnsurgenL cells. Loosely-allgned afflllaLlons allow hackers Lo conLrlbuLe Lo muLual goals, buL wlLhouL a
hlerarchlcal sLrucLure. Cn Lhe SLA's now-defuncL webslLe, lL llsLed a number of hackers who had an
ldenLlLy under Lhe SLA's umbrella organlzaLlon, buL were able Lo operaLe lndependenLly. 1he webslLe
shown ln llgure 2, recenLly Laken down by lLs domaln reglsLerlng hosL, recrulLed anyone lnLeresLed ln
furLherlng Lhe Syrlan governmenL cause. 1he LexL ln Lhe upper lefL asked for volunLeers ln less Lhan
perfecL prose:
º1o conLrlbuLe wlLh us ln supporLlng Lhe cause of Lhe Syrlan Arab people by armamenLs wlLh
sclence and knowledge agalnsL Lhe campalgns led by Lhe Arab medla and WesLern on our
8epubllc by broadcasLlng fabrlcaLed news abouL whaL ls happenlng ln Syrla. ?ou can [oln our
page vla soclal neLworklng slLes: lacebook - 1wlLLer or by publlshlng vldeos LhaL dlsplay on our
page on ?ou 1ube. [oln Lo our pages by cllcklng on Lhe llnks below Lo be one of Lhe Syrlan
ln Lhe lower lefL corner of llgure 2, SLA ouLllned Lhe procedure for becomlng an afflllaLe and Lhe
procedure for havlng an anonymous presence on Lhe SLA webslLe:
º?ou can now geL a membershlp card ln Lhe Syrlan LlecLronlc Army by reglsLraLlng Lhe daLa LhaL
you wlsh Lo be shown, you musL reglsLer as a membershlp on Lhe slLe flrsL, lL wlll express your
elecLronlc ldenLlLy card and lLs daLa can'L be modlfled wlLhouL approval of managemenL, Lo
creaLe your own card now Cllck Pere."
3970>, ?/.2-76,02 $7<9 '9E.7 $-->2FC
1hls llsL of Lhe SLA's aLLacks ls noL all lncluslve, buL provldes a sense of Lhe number and scope of Lhelr
+,-. %&''/ 012345627. 89 :;-298512; <86 =1>4-46 - webslLe defaced by SLA hacker known as "1he Þro"

?4@74AB45 %&''/ C;53;5D 012345627. - homepage was replaced wlLh an lmage of Syrlan presldenL
8ashar al-Assad, wlLh a message sLaLlng, "Syrlan LlecLronlc Army Were [slc] Pere"

=@52- %&'%/ <21E4DF1 - Look down Lhe offlclal blog slLe and redlrecLed vlslLors Lo a slLe supporLlng 8ashar

=,>,67 %&'%/ G4,7456 !4H6 =>41I. - LwenLy-Lwo 1wlLLer accounL LweeLs were senL wlLh false
lnformaLlon on Lhe confllcL ln Syrla and a false reporL was posLed Lo a 8euLers [ournallsL's blog on Lhe
news webslLe

J4B5,;5. %&'(/ ?E. !4H6 =5;B2; K pro-Syrlan governmenL commenLs were wrlLLen on Lhe maln 1wlLLer
accounL [skynewsarbla, used for culLural and enLerLalnmenL news, and lLs lacebook page,

=@52- %&'(/ =668I2;74D L5466 - Lhrough 1wlLLer accounL, falsely clalmed Lhe WhlLe Pouse had been
bombed and ÞresldenL 8arack Cbama was ln[ured. 1he LweeL was re-LweeLed Lhousands of Llmes wlLhln
mlnuLes and caused Lhe uow !ones lndusLrlal Average lndex Lo drop sharply before qulckly recoverlng

M;. %&'(/ NO4 "1281 - 1wlLLer accounL was hacked by phlshlng Coogle app accounLs of 1he Cnlon's

M;. %&'(/ NO4 FN# !4H6 <81D81 - 1wlLLer accounL was hacked.

M;. %&'(/ ?E. !4H6 - compromlsed several Sky news Androld appllcaLlons, requlrlng users Lo reload
Lhe apps.

+,-. %&'(/ N5,4I;--45 (a global phone dlrecLory appllcaLlon for smarLphones and feaLure phones) - SLA
clalmed lL hacked lnLo servers and sLole seven daLabases and released 1rueCaller's daLabase hosL lu,
username, and password vla a LweeL. Cn 18 !uly 2013, 1ruecaller lssued a sLaLemenL on lLs blog sLaLlng
LhaL lLs servers were lndeed hacked, buL clalmlng LhaL Lhe aLLack dld noL dlsclose any passwords or
credlL card lnformaLlon.

"I78B45 %&'(/ 0? L5462D417 Q;5;IE "B;A; - 1wlLLer and lacebook accounLs were hacked lnLo,
dlverLlng slLe vlslLors Lo a Syrlan propaganda vldeo

+,-. %&'(/ #2B45 (proprleLary cross-plaLform lnsLanL messaglng volce-over-lnLerneL proLocol appllcaLlon
for smarLphones developed by vlber Medla) - accessed Lwo mlnor sysLems: a cusLomer supporL panel
and a supporL admlnlsLraLlon sysLem, accordlng Lo Lhe company's offlclal response, no senslLlve user
daLa was exposed and vlber's daLabases were noL hacked

=,>,67 %&'(/ ",7B5;21 (adverLlslng servlce) - hacked vla a spearphlshlng aLLack, allowlng placemenL of
redlrecLs lnLo Lhe webslLes of 1he WashlngLon ÞosL, 1lme, and Cnn

=,>,67 %&'(/ !RN2A46SI8A - domaln name reglsLraLlon (unS) was hacked, causlng redlrecLlon from Lhe
webslLe Lo a page LhaL dlsplayed Lhe message "Packed by SLA," 1wlLLer's domaln reglsLrar was also

=,>,67 %&'(/ NH27745 - unS reglsLraLlon hacked Lo show Lhe SLA as lLs admln and Lech conLacLs

=,>,67 %&'(/ NO4 !4H R85E N2A46T C,9921>781 L867T ;1D NH27745 - Look conLrol of medla webslLe

?4@74AB45 %&'(/ 0? M;5214 :85@6 G4I5,2721> - hacked lnLo Lhe lnLerneL recrulLlng slLe for Lhe uS
Marlne Corps, posLlng a message LhaL urged uS Soldlers Lo refuse orders lf WashlngLon decldes Lo
launch a sLrlke agalnsL Lhe Syrlan governmenL

?4@74AB45 %&'(/ U-8B;- L867 - LargeLed lLs offlclal LwlLLer accounL and webslLe (globalposL.com). SLA
offlclally announced Lhe hack Lhrough lLs LwlLLer accounL, sLaLlng: "1hlnk Lwlce before you publlsh
unLrusLed lnformaLlons [slc] abouL Syrlan LlecLronlc Army" and, "1hls Llme we hacked your webslLe and
your 1wlLLer accounL, Lhe nexL Llme you wlll sLarL searchlng for new [ob"

"I78B45 %&'(/ V;7;5 U83451A417 - hacked Lhe CaLarl domalns reglsLry (reglsLry.qa), lmpacLlng Lhe .qa
domaln webslLes of Coogle, vodafone, lacebook, al !azeera, CaLar 1elecom, Shelkha Mozah, CaLar
MlnlsLry of lorelgn Affalrs, Lhe CaLar governmenL porLal, Lhe Lmlr's Þalace, Lhe CaLar Armed lorces, and
Lhe CaLar MlnlsLry of Lhe lnLerlor
"I78B45 %&'(/ 0? L5462D417 Q;5;IE "B;A; - Lhrough aL leasL one sLaff member's Cmall accounL,
hacked 1wlLLer and lacebook accounLs, redlrecLlng vlslLors Lo a graphlc 24-mlnuLe propaganda vldeo on
?ou1ube (subsequenLly removed)
"A. G>->7 $-->2F
uomaln reglsLraLlon ls Lhe process by whlch a company or lndlvldual can obLaln a webslLe domaln, such
as www.yourslLe.com. 1he lnLerneL CorporaLlon for Asslgned names and numbers (lCAnn)
Lhe lnLernaLlonal uomaln name Server (unS) daLabase. lCAnn ensures LhaL all reglsLered names are
unlque and map properly Lo a unlque lnLerneL ÞroLocol (lÞ) address. 1he lÞ address ls Lhe numerlcal
address of Lhe webslLe LhaL Lells oLher compuLers on Lhe lnLerneL where Lo flnd Lhe server hosL and
domaln. uomaln reglsLraLlon ls avallable Lo Lhe publlc vla a reglsLrar. 8efore a domaln reglsLraLlon can be
approved, Lhe new name musL be checked agalnsL exlsLlng names ln Lhe unS daLabase. Calnlng access
Lo Lhe reglsLrar's daLabase allows a hacker, such as SLA, Lo alLer Lhe names of domalns and galn access
Lo webslLes. 1hls ls how SLA galned access Lo CaLarl webslLes ln CcLober 2013.
1here are a number of ways Lo galn access Lo an organlzaLlon's webslLe. llgure 3 below lllusLraLes a
slmpllfled way ln whlch SLA mlghL have galned access Lo Lhe CaLarl domaln reglsLry, whlch gave lL access
Lo a number of webslLes. (A deLalled conslderaLlon of hacklng Lechnlques and sofLware ls beyond Lhe
scope of Lhls 1hreaL 8eporL.) llgure 3 also lllusLraLes Lhe vulnerablllLy organlzaLlons face as Lhey exlsL ln
a dlglLal world, parLlcularly wlLh Lhe readlly avallable and free-flowlng lnformaLlon on lnLerneL soclal
medla slLes.
A hacker flrsL uses blogs, soclal neLwork slLes, webslLes, eLc. Lo flnd emall addresses of people wlLhln an
organlzaLlon. uslng LhaL lnformaLlon, Lhe hacker sends an emall Lo Lhe address wlLh a downloadable flle,
acLlng as a 1ro[an horse, LhaL conLalns an embedded remoLe access Lool (8A1). Cnce Lhe emall reclplenL
ls enLlced Lo open Lhe aLLached flle, Lhe 8A1 ls acLlvaLed and able Lo send password and oLher senslLlve
lnformaLlon back Lo Lhe hacker. WlLh Lhe acqulred lnformaLlon, Lhe hacker can enLer Lhe domaln
reglsLry. Cnce ln Lhe domaln reglsLry, Lhe hacker can change domaln names and modlfy webslLes.

lCAnn ls a non-proflL corporaLlon locaLed ln Marlna uel 8ey, Callfornla Lasked wlLh managlng lnLerneL ÞroLocol
(lÞ) addresses and domaln names.
Figure 3: Cyber attack

$,>/9C- $CC.CC<.,-
1he SLA ls a loosely-allgned group of compuLer hackers lnLenL on rlghLlng whaL Lhey percelve Lo be
unfalr LreaLmenL of Lhe Syrlan reglme by WesLern and Arab medla and governmenLs. lL ls currenLly
capable of nulsance aLLacks on mosL lnLerneL webslLes, lncludlng lacebook and 1wlLLer. 1he SLA aLLacks
have been successful due Lo Lhe group's ablllLy Lo explolL lnnaLe weaknesses ln Lhe securlLy of lnLerneL
slLes. uesplLe LhreaLs LhaL lL would be forced Lo resorL Lo more damaglng aLLacks lf provoked by an
aLLack by ouLslde forces, Lhere ls no evldence Lhe SLA could acLually carry ouL such an aLLack wlLhouL
help from Syrlan allles such as 8ussla, Chlna, or lran. lL ls hlghly unllkely LhaL any of Lhese counLrles
would enLrusL any klnd of more sophlsLlcaLed Lools or resources Lo Lhe SLA.
ConLlnulng successful nulsance aLLacks, however, wlll have an effecL. 1lme losL ln regalnlng conLrol of a
webslLe and loss of cusLomer confldence ln Lhe ablllLy of an organlzaLlon Lo proLecL senslLlve daLa wlll
have an economlc lmpacL. lL ls posslble LhaL Lhe SLA has Lhe capablllLy Lo hack lnLo sysLems LhaL hold
credlL card and oLher senslLlve lnformaLlon. 1hese klnds of crlmlnal aLLacks have been successfully
performed by oLher groups wlLh devasLaLlng effecLs on consumer confldence. 1he SLA has only shown
an lnLeresL ln presslng a propaganda agenda Lo daLe, buL shlfLs ln pollcles or coverage mlghL cause Lhe
SLA Lo up Lhe dlglLal anLe.
1here ls no evldence, however, LhaL Lhese aLLacks are swaylng anyone Lo Lhe slde of Syrla. lndeed, Lhere
ls evldence LhaL conLlnued aLLacks may compllcaLe Lhe SLA's cause. ln Lhe afLermaLh of an aLLack on Lhe
new ?ork 1lmes, Lhe SLA's webpage was Laken down by Lhe lnLerneL reglsLrar hosLlng Lhe slLe. Cne of
Lhe more blzarre and lnLeresLlng resulLs of Lhe SLA's growlng promlnence ls lLs challenge Lo one of Lhe
mosL noLorlous and lnfamous lnLernaLlonal hacker groups. ln whaL resembled cyber gangs flghLlng over
LerrlLory, Anonymous and Lhe SLA faced off on opposlng sldes of Lhe Syrlan confllcL beglnnlng ln 2011.
ALLacks have been accompanled by Lhe Lough Lalk Lyplcal of Lwo gangs, each Lrylng Lo one-up Lhe oLher.
ln SepLember 2013, Lhe SLA denled clalms by Anonymous LhaL lL had hacked lnLo SLA's sysLem.
SLA ls clearly a force of dlsrupLlon, and Lhe long-Lerm lmpllcaLlons of lLs conLlnued presence mlghL very
well remaln whaL Lhey are Loday - prlmarlly a nulsance - or Lhe lmpllcaLlons mlghL become more serlous
lf Lhe SLA's message galns greaLer lnfluence.
"7>0,0,1 +<5/02>-06,C
All lnLerneL-based slLes are vulnerable Lo cyber aLLacks.
lnformaLlon galned from soclal medla and oLher lnLerneL slLes can be used Lo faclllLaLe
successful cyber aLLacks.
Packers are able Lo operaLe wlLhln dlsconnecLed organlzaLlons, each wlLh slmllar goals and
operaLlng lndependenLly under a larger umbrella.
All susplclous emalls should be vlewed as a LhreaL.
#./>-.@ B76@42-C
and Army knowledge Cnllne (AkC): hLLps://www.us.army.mll/sulLe/porLal/lndex.[sp

