Showing posts with label Russia. Show all posts
Showing posts with label Russia. Show all posts

October 9, 2018

The GRU close access operation against the OPCW in perspective

(Updated: December 2, 2018)

Last Thursday, October 4, the Dutch Ministry of Defence held a press conference about how its Military Intelligence and Security Service MIVD had disrupted a spying operation by the Russian military intelligence agency GRU last April.

Four Russian operatives were caught red-handed when they tried to hack into the Wi-Fi network of the headquarters of the Organisation for the Prohibition of Chemical Weapons (OPCW) in The Hague. Meanwhile, the US Department of Justice (DoJ) published a formal indictment against seven GRU officers, including the four from the Netherlands.

Here, the failed GRU operation will be compared to close access operations of the NSA, which learns us more about the methods for hacking wireless networks. There are also some answers to frequent questions about the disruption by the MIVD.



Press conference with from left to right: MIVD director Onno Eichelsheim, Defence
minister Ank Bijleveld, British ambassador Peter Wilson
(photo: Bart Maat/ANP - click to enlarge)


MIVD presentation

During the press conference, the director of MIVD, major general Onno Eichelsheim, explained the case using a 35-page powerpoint presentation with an unprecedented amount of photos and details of what had been discovered about the Russian operation.

This makes the presentation very similar to the ones from the Snowden-revelations, although they were highly classified and for internal use only, while the MIVD presentation is unclassified (in Dutch: ongerubriceerd) and, although marked as For Official Use Only, made for the general public.



Front slide of the MIVD presentation about the disrupted GRU close access operation
(click to download the full presentation)



Close Access operations

MIVD director Eichelsheim revealed that the GRU officers planned a "close access" operation. Such an operation can range from simply setting up a microphone to listen into what is said in a nearby building, to the highly sophisticated collection of unintentional emanations from computer equipment by exploiting so-called TEMPEST vulnarabilities.

In this case it was an effort to gain access to the internal Wi-Fi network of the OPCW headquarters building by using an interception system hidden in a car at a nearby parking lot. It was described as high-end equipment capable of hacking Wi-Fi connections from a distance, identifying the users and intercepting their login credentials.

This sounds very similar to an IMSI-catcher (also known as a Stingray), a very expensive device that functions like a fake cell tower. It's used by law enforcement and intelligence agencies either to identify the nearby active phone numbers, or to actually intercept the calls of a particular cell phone.



The equipment found in the car of the GRU officers, clarified by a diagram
(source: MIVD - click to enlarge)


WiFi Pineapple

Besides the equipment in the car, the backpack of GRU officer Serebriakov also contained some antennas, a WLAN Booster, a WiFi Signal Booster and a WiFi Pineapple model NANO. These Pineapples, with a cost of just around 100,- US Dollar, can mimic the functions of a Wi-Fi server. They are not only used by law enforcement and penetration testers, but are also popular among criminals who use them to spoof Wi-Fi networks so that victims connect to them rather than the intended legitimate server.

As explained in the DoJ indictment, it's likely that the GRU already tried to get access to the OPCW computer network through remote hacking methods, like spear fishing e-mails. Only after that failed to result in the desired access, the agency apparently decided to sent a team to break in through close access methods. Had they succeeded, then the hacking team back in Moscow would have taken over again to exploit the access through remote means.


NSA equivalent

The GRU officers clearly planned to hack the OPCW network and infect it, a technique that wasn't yet known to the MIVD, according to director Eichelsheim. The latter sounds intruiging, but wasn't explained any further.

For an indication of what that mysterious Russian method might be, we can look at the techniques used by the NSA to hack into WiFi networks, which are also referenced to as 802.11 networks. The Snowden-trove provided several documents about this, some of which were published in August 2016 by the website The Intercept.

The NSA equivalent of the set-up found in the car of the GRU officers seems to be a mobile antenna system running software codenamed BLINDDATE. This software can also be attached to a drone to be positioned within the range ofa wireless network of interest:



The NSA's BLINDDATE Wi-Fi hacking system, depicted in the field in Afghanistan
(click to enlarge)


One of the components of BLINDDATE is a "man-in-the-middle" attack method codenamed BADDECISION, which redirects the target's wireless web traffic to a FOXACID server of the NSA. Such a server is then able to infect the target's computer with various kinds of spying malware. This method even seems to work when the wireless connection is WPA or WPA2 encrypted.



Slide from an 2010 NSA presentation of the BADDECISION Wi-Fi hacking method
(click for the full presentation)


SCS units

Such close access operations for American intelligence are usually conducted by units of the Special Collection Service (SCS). They operate covertly from inside US diplomatic facilites around the world and consist of specialized officers from both CIA (for getting physical or HUMINT access) and NSA (for the SIGINT interception equipment).

Interestingly, the GRU team had a similar composition with Aleksei Morenets and Evgenii Serebriakov as cyber operators and Oleg Sotnikov and Alexey Minin for HUMINT support.



The GRU team arrives at Schiphol Airport on April 10, 2018. From left to right: Serebriakov
(cyber), Minin (HUMINT), Sotnikov (HUMINT), Morenets (cyber), Russian embassy official.
(source: MIVD presentation - click to enlarge)


Traveling team

According to the DoJ indictment, Serebriakov and Morenets are both members of Unit 26165, also known as the GRU 85 Main Special Service Center, traveling to foreign countries to conduct on-site hacking operations. Evidence for that was provided by Serebriakov's laptop, from which the MIVD recovered the earlier Wi-Fi connections.

It appeared that they had also been in Rio de Janeiro, Brazil in August 2016 and in Lausanne, Switzerland in September 2016, where they targeted the anti-doping agencies WADA and USADA. In December 2017 the laptop connected to a Wi-Fi network in Kuala Lumpur, Malaysia, which related to the Flight MH17 investigation. After the OPCW in The Hague, their next assignment should have been the Spiez chemical laboratory in Switzerland.

Note that Serebriakov and Morenets traveled to targets related to some of the most controversial issues of Russian politics, which indicates their importance for GRU operations.


Embassy facilities

The fact that the four men were flown in, indicates that the GRU doesn't have such a team permanently stationed inside the Russian embassy in The Hague - just like there's also no SCS unit within the American embassy, according to a 2010 slide from the NSA.

The SCS units became notorious after it was revealed that one of them had been assigned to eavesdrop on German chancellor Angela Merkel and subsequently SCS "spying sheds" were discovered on the rooftops of a number of US embassy buildings.

The Russian embassy in The Hague, which is not very far from both the prime minister's residence as well as from the OPCW building, doesn't have visible spying structures on its roof.



The Russian embassy in The Hague. About 1/3 of the diplomatic personnel can
be considered working for Russian intelligence agencies.
(photo: OmroepWest.nl - click to enlarge)


Update:

On November 30, 2018, the Dutch newspaper NRC came with a long piece about espionage by military officials from the Russian embassy in The Hague, a facility which includes six historic villas, a school, a tennis court and a range of satellite dishes, on a fenced area of ​​almost one hectare.

NRC journalists were able to identify several GRU employees working under diplomatic cover who were involved in various kinds of espionage activities. Most notable was Anton Naoemkin, who's official job at the embassy was Head of Protocol. He appeared to be the man who accompanied the GRU team at Schiphol airport as can be seen in one of the photos released in the MIVD presentation.

Naoemkin brought them to the embassy, where they were awaited by Konstantin Bachtin, who was also involved in the hacking attack, but who may also compromised the operation by constantly calling with Moscow - which may have been intercepted. NRC also mentioned that one month after the failed close access operation, the GRU conducted fishing mail attacks against the OPCW.


Questions

Referencing the "alibi" for the two Russians accused of poisoning Sergei Skripal, MIVD director Eichelsheim noted that the four GRU officers were clearly not on a holiday: they carried spying equipment, multiple cell and smartphones as well as 20.000,- US Dollar and the same amount of Euros in cash.

Also things like how Morenets tried to destroy a smartphone, several traces leading back to the GRU headquarters and the list of earlier Wi-Fi connections still stored on the laptop make the operation look sloppy and unprofessional. Actually it shows that the GRU didn't consider these kind of close access operations to be very risky, and the risk of being caught in the Netherlands not very high.


Plausible deniability

The presumed sloppiness is therefore no reason to lay back, but rather to be more alert. In hostile countries or high risk places, intelligence officers would make sure not to use and carry things that could to identify them or their mission so they can plausibly deny any accusations.

The cover story that the Russian foreign ministry came up with in this case is that there was nothing secret about trip of the four technical experts, as it was allegedly their job to test the cyber security of Russian diplomatic missions.


Prevention instead of monitoring

There were also some questions about how the Dutch services operated. Someone wondered for example why the MIVD didn't monitor the Russian hacking attempt for a short period of time in order to learn what kind of targets they were looking for - a common practice in cyber security.

During the press conference, MIVD director Eichelsheim said that the Russian equipment did not provide information about why the OPCW was targeted. We can assume that field operatives have no "need to know" for the actual purpose of the operation, which may also be classified differently. Maybe it was also already known that this particular GRU method is just used to get a general access to a network, instead of to particular users or files.

Another reason could be that the MIVD simply wanted to prevent any kind of attack on the network of an international organization like the OPCW - Dutch secret services can be quite strict when it comes to their legal tasks. This might have been different when the target had been a Dutch government agency, in which case it may be allowed to monitor a network intrusion for intelligence and prevention purposes.


Expelled instead of arrested

Another frequent question is why the Dutch authorities didn't arrest the GRU officers given the fact that they were caught red-handed. Instead, the four men had been immediately "escorted to a plane to Moscow" - not even formally expelled as some press reports suggest.

Here the most likely reason is that it's the usual practice in espionage to expel spies, especially when they operate under diplomatic cover. This not only prevents that a court case would attract public attention to intelligence failures and successes, but also that we can expect our own intelligence officials to be sent home instead of thrown in jail.



New strategy

A final question is why the MIVD came with such a unusually detailed presentation about a recent operation, given how extremely secretive the Dutch intelligence services are. But internationally there were precedents:

Last July, the US Department of Justice issued an indictment in which 12 Russian intelligence officials (mostly from the GRU) were identified and accused of hacking the Democratic National Committee (DNC) and the Clinton presidential campaign and subsequently releasing the stolen files using platforms like DC Leaks, Wikileaks and Guccifer 2.0.

In September, the British government also identified two GRU officers ("Alexander Petrov" and "Ruslan Boshirov") as the suspects in the case of the poisoning of former GRU officer and double agent Sergei Skripal in Salisbury in March 2018.

And just before the press conference in the Netherlands, the UK National Cyber Security Centre (NCSC) came with a statement in which the GRU was accused of "indiscriminate and reckless cyber attacks" including disrupting the Kyiv metro, Odessa airport, Russia’s central bank and two Russian media outlets, hacking a small UK-based TV station and cyber attacks on Ukrainian financial, energy and government sectors.

This makes clear that "naming and shaming" Russian intelligence officials is a new deterrance strategy of the Western allies in the hybrid cyber and information war that Russia inflamed a few years ago.



Links and sources
- Clingendael.org: Hoe de Russen (waarschijnlijk) probeerden de OPCW te hacken
- Clingendael.org: Heads rolling at the GRU? Blundering Russian intelligence
- Spiegel.de: The Rise of Russia's GRU Military Intelligence Service
- Wired.com: How Russian Spies Infiltrated Hotel Wi-Fi to Hack Victims
- Emptywheel.net: A Tale of Two GRU Indictments
- RTLNieuws.nl: Waarom de MIVD de Russische spionnen niet liet vastzetten

June 8, 2017

Dutch-Russian cyber crime case reveals how the police taps the internet

(Updated: August 26, 2017)

About how signals intelligence agencies, like NSA and GCHQ, are intercepting communications, we learned a lot from the Snowden revelations and the German parliamentary inquiry, but also from new legislation in France, the Netherlands and the United Kingdom.

Much less is known about the practice of tapping by law enforcement, like for example the FBI and police forces. Now, a case from the Netherlands provides some interesting insights in how Dutch police intercepts internet communications - in a way that comes remarkably close to the bulk collection by intelligence agencies.





Office of the Team High Tech Crime (THTC) of the Dutch police in Driebergen
(photo: NRC/Merlin Daleman)
 

Cooperation with the Russians

On Saturday, May 27, the Dutch newspaper De Volkskrant came with a surprising story about the cooperation between the Team High Tech Crime (THTC) of the Dutch police and officials from the Russian federal security service FSB, which is the main successor to the notorious KGB.

Since 2009, regular meetings are held in the Netherlands, in which also officials from the FBI participate. The aim is to cooperate in tracking down and eventually arresting cyber criminals. The Volkskrant's front page report is accompanied by an extensive background story, which contains some more worrying details, but is only available in Dutch.

The cooperation with the Russians dates back to September 2007, when the head of THTC attended a conference in the Russian city of Khabarovsk, at which CIA, FBI, Mossad, BND and other agencies were present. The head of THTC was able to create a connection to the FSB and their deputy head of the Center for Information Security (TsIB), Sergei Mikhailov, became the liaison for the Dutch police and would regularly visit the Netherlands.


Meetings in Driebergen

Initially, the meetings with the Russians were held in the Dutch village of Driebergen, where the Team High Tech Crime has its offices. The Dutch security service AIVD was apparently not very fond of this, so every visit of for example Mikhailov had to be reported, and since 2012, every police officer who had contact with someone from the FSB was briefed by the AIVD before and after every meeting.

The FSB, much like the FBI, isn't just responsible for law enforcement, but is also Russia's secret service for domestic security. This made AIVD worried that FSB officers could use their visits to the Netherlands for spying - although strictly spoken, collecting foreign intelligence is the task of another Russian agency, the SVR.

The police compound in Driebergen started as highway patrol station, but nowadays houses some of the most sensitive units of the Dutch police, including the national criminal investigation branch and the Unit Landelijke Interceptie (or Lawful Interception, ULI; nowadays: Interceptie & Sensing, I&S), which was created in 2005 as the central facility for internet tapping, as well as for telephone tapping on behalf of all the smaller police districts.*



The police compound in the village of Driebergen
(photo via Flickr)


Security incident

There was at least one security incident in Driebergen: De Volkskrant describes that during a meeting with FBI and FSB, a Russian official came to a member of the Dutch police team, pointed at someone from the FBI and said "he is copying your data". An investigator went looking and saw that indeed the American had a thumb drive in a police laptop and was copying Dutch information. Whether this had any consequences was not reported.

In 2014, the cooperation with Russia came under pressure: in July, there was the Russian annexation of the Crimea and shortly aftwerwards, flight MH17 was shot down, killing 193 Dutch citizens. The criminal investigation of this case also takes place in Driebergen, so the police decided to move to meetings with FSB officials from Driebergen to police stations in Amsterdam and Rotterdam.

 

Intercepting at Leaseweb

The first case in which Dutch police and Russian FSB cooperated started in 2008, when Russian criminals used the ZeuS trojan horse malware to spoof the login screen of banks in order to capture user credentials, and steal the money from bank accounts without a trace.

Often these criminals used servers of the Dutch hosting company Leaseweb, which offers relatively anonymous and cheap services as well as high-speed connections, as it is close to the large Amsterdam internet exchange AMS-IX. To communicate with eachother, the criminals used the messenger service ICQ, which is still popular in Russia and Eastern Europe, but doesn't use encryption.

To catch the criminals behind the ZeuS malware, the Dutch police team set up operation Roerdomp (the Dutch name for the Eurasian bittern) and in October 2008, they asked other countries for the ICQ numbers of known cyber criminals. Within 3 months, authorities from the US, Germany, Britain, the Ukraine and Russia provided a total of 436 ICQ numbers. In January 2009, the public prosecutor and an examining judge approved the interception of communications associated with these numbers.



ICQ logo and interface

DPI filtering

To acquire these ICQ communications, the police had decided to intercept all ICQ traffic from Russia that went through the Leaseweb servers. For that purpose they bought equipment for deep-packet inspection (DPI) worth 600.000,- euro.

DPI devices are able to examine the packets that make up internet traffic and filter them according to predefined criteria, usually to prevent viruses and spam, but in this case for intercepting communications.

High-end DPI equipment, from manufacturers like Narus (now part of Symantec) and Verint, can also recreate ("sessionize") the communication sessions in order to filter complete files and messages out - which is also one of the main features of NSA's XKEYSCORE system.

The Volkskrant reports that after the interception was approved, the new equipment was connected to the servers of Leaseweb, but actually, Leaseweb will have splitted the traffic on its main backbone cable, creating a copy of all the data, which was then directed to the police computer - telecom and internet companies really don't like outsiders to install equipment onto their actual networks.

Next, all the copied Leaseweb traffic, some 50 Gigabit per second for 4 to 10 million websites, went through the DPI machine. First the police filtered out all ICQ traffic, and then the ICQ traffic associated with the list of the 436 selected numbers. This went on for 3 months, so the warrant was apparently renewed a few times, as an approval for targeted interception is initially limited to a period of 4 weeks.

Update: On July 5, 2017, it was reported that in the brand new Equinix AM4 data center in Amsterdam (with over 120.000 servers, connected to 150 networks), there's a highly secure section which is used by the Dutch government - could that be intended for intercepting the servers that (foreign) companies are hosting there?



Leaseweb headquarters in Amsterdam
(click to enlarge)
 

Some questions

The description of the tapping operation by De Volkskrant raises some questions. Government filtering systems having access to all the internet traffic of a company is the way that (signals) intelligence agencies are conducting bulk collection, not the way that law enforcement is supposed to do targeted interception.

In western countries, the police is generally only allowed to tap communications associated with individually identified suspects or specific communication identifiers, like phone numbers and e-mail addresses. In the ZeuS case, it was probably argued that it was targeted interception because there were 436 specific identifiers: the ICQ numbers of known cyber criminals.


Foreign selectors

First, this case immediately reminds of the selector affair that came to light through the German parliamentary inquiry into the cooperation between NSA and BND. For years, NSA provided the Germans with millions of internet identifiers, which they entered into their satellite collection system, without being able to see to whom these identifiers belonged.


Could that have happened to the Dutch police too? Were they able to verify that each one of the 436 ICQ numbers was used by a cyber criminal, or did they just trusted the foreign authority that provided them?

For this kind of international cooperation, it's often inevitable that you have to trust your foreign partners, but then you should also try to make sure that the data collection is as careful and targeted as possible.


Dutch internet tapping

One way to assure that is through technical means. For telephone tapping this is relatively easy, because telephone switches have built-in tapping capabilities based upon international standards. For internet tapping this is different and external devices have to be used to pick out the communications of interest.

In the Netherlands, the interception of internet data uses the Transport of Intercepted IP Traffic (TIIT) protocol, which ensures that the police only gets the internet data associated with an IP or e-mail address for which there's a warrant (managed through the Warrant Management System, WMS).



Overview of the TIIT protocol for IP and e-mail interception
(click to enlarge)


First, an Internet Service Provider (ISP) copies all its traffic and leads the copy to a secured interception network on its own premises. There, a sniffer machine (S1) filters out the data that have to be intercepted, and encrypts these with a key that is associated with a particular warrant.

Then, these data go to the ISP collector machine (S2), which sets up a connection, through an encrypted tunnel over a regular internet link, to a government collector machine (T1), which receives the data from one or more S2 machines.

The T1 devices are managed by the central interception unit in Driebergen and from there, the intercepted data are distributed to computers (T2) at the tapping rooms (tapkamers, nowadays: BOB-kamers) of the police districts. There, they are stored and decrypted so the intercepted communications become available in plain text.


Intercepting hosting providers

With the TIIT protocol, the police doesn't get access to the copy of an ISP's entire traffic: it's the ISP that controls the sniffer machine that filters out the communications that belong to a particular suspect. But at Leaseweb it was apparently the police that controlled the sniffer (in the form of DPI equipment) where all the traffic passed through.

The most likely reason for this is that Leaseweb is a hosting provider and it's considered that such companies don't have to comply with the Dutch Telecommunications Law that says that public communication networks or services have to be interceptable. Therefore, hosting providers were not required to install the tapping facilities like the telephone and internet access companies have.

But the hosting companies can of course cooperate voluntarily when the police presents them a warrant. However, when the new Secret Services Act comes into force, such non-public communication providers do have to tolerate interception on behalf of AIVD and MIVD, but they don't need to have pre-installed tapping equipment.

This means that in both cases, even for targeted interception, the government will control the sniffer equipment for filtering up to a company's entire traffic - something that digital rights groups like the ACLU already consider to be unlawful "bulk surveillance."




Oversight

Another question is how to make sure that the police doesn't misuse it's power when for example a hosting provider voluntarily provides access to their entire traffic. Maybe the police has internal protocols for that, but while interception conducted by the secret services is subject to independent oversight, police tapping is not.

It's considered that in criminal cases, a judge will eventually decide whether certain police methods are lawful or not, but in practice, judges often lack the necessary technical knowledge, while police and public prosecutors try to hide these sensitive techniques. It's not clear whether any suspect in the ZeuS case was tried before a Dutch court.


Untargeted interception

The ZeuS case shows that not only the networks of telecommunications and internet service providers can be useful to intercept, but also hosting providers like Leaseweb, especially when their servers are used by foreign companies to host their internet (communication) services - useful, not only for the police, but also for the secret services AIVD and MIVD.

Soon, both services can even go a step further, as the new Secret Services Act will also allow them to conduct untargeted cable interception. That means that they may not only filter out communications that are associated with already known identifiers, but also (temporarily) store all the metadata and a lot of content in order to search for data that belong to yet unknown targets.

In the public debate about the new law, there was a lot of speculation about how the new untargeted cable access will be implemented, but the interception at Leaseweb, as described by De Volkskrant, gives a very concrete example of what can be expected.



National watch center of the Royal Marechaussee in Driebergen
with a large dark gray Philips PNVX crypto telephone
(photo: AmberAlert.nl)
 

The end of ZeuS

After collecting the messages associated with the 436 ICQ numbers and subsequently analysing them, it came out that one particular ICQ number acted as the leader of the cyber crime network. In one of the intercepted conversations this person even admitted to be the designer of the ZeuS malware.

The police gave him the codename "Umbro", but he himself used aliasses like Lucky12345, Monstr, Slavik, IOO, Pollingsoon, and Nu11. De Volkskrant story doesn't tell how the police found out the real identity of "Umbro" and it was only in 2014, under the international law enforcement Operation Tovar, that he was identified as Evgeniy Mikhailovich Bogachev, born October 28, 1983.

Already in 2013, investigators noticed that the ZeuS virus wasn't just used for stealing money anymore, but also for finding out very specific information about government officials of Russia's neighbours. Dutch police and the FBI became convinced that "Umbro" (Bogachev) had started working for Russian intelligence too.


To be or not to be arrested

The latter seems to be one of the reasons that, after the hack of the Democratic National Committee (DNC) in 2016, the US government put Bogachev on a list of sanctioned individuals. Besides that, his malware was also responsible for stealing over 100 million USD from American organizations. However, Bogachev is still at large, probably because he is useful for Russian intelligence operations.

For the Dutch police team there was another unpleasant surprise: Sergei Mikhailov, the FSB officer who had become such a familiar face for them, was suddenly arrested in December 2016 - according to Russian press reports because he and Kaspersky expert Ruslan Stojanov had leaked information to US intelligence.

Nobody knows whether this is true or where Mikhailov is now, but the cooperation between Dutch police and the Russian FSB continues.

Update:
In August 2017, Russian media reported that Sergei Mikhailov and his deputy Dmitry Dokuchaev were charged with treason after they were found to have helped the CIA catch two notorious Russian hackers: Roman Seleznev, who was arrested in 2014 on the Maldives, and Yevgeniy Nikulin, who was arrested in the Czech Republic in 2016.



Links and sources
- Meduza.io: Moscow's cyber-defense How the Russian government plans to protect the country from the coming cyberwar (2017)
- Volkskrant.nl: Dutch police works together with Russia's FSB, despite political tensions (2017)
- Netkwesties.nl: Russen schakelden contactpersoon van Nederlandse cyberpolitie uit (2017)
- Inspectie V en J: Meldkamer Landelijke Eenheid Politie (.pdf) (2014)
- Ars Technica: Deep packet inspection meets ‘Net neutrality, CALEA (2007)
- Dialogic.nl: Aftapbaarheid van telecommunicatie (.pdf) (2005)
- Rijkspolitie.org: Geschiedenis AVD Driebergen (2002)

November 26, 2012

Bilateral Hotlines Worldwide

(Updated: February 21, 2026)

In a previous article we discussed the Washington-Moscow Hotline, being the most famous bilateral hotline. It was soon followed by direct communication links between a number of other countries with nuclear capabilities.

In general these hotlines started as a teletype connection, being upgraded with facsimile units in the eighties and were eventually turned into dedicated secure computer networks. An exception is the hotline between Washington and London, which was a phone line already since 1943.




Overview of the top level bilateral hotlines worldwide
(Click to enlarge)


The hotlines between the heads of governments, are meant to prevent (nuclear) war in times of severe crisis. For preventing misunderstandings and miscommunications in less critical situations, countries have also set up lower level telephone hotlines between their defense or foreign ministers. For example, the United States has so called Defense Telephone Links with at least 23 other states.



Overview of the lower level bilateral hotlines worldwide
reflecting political and military relationships between countries
(Click to enlarge)



UNITED STATES - RUSSIA

- In 1963 the United States and the Soviet Union established the Direct Communications Link (DCL) or Washington-Moscow Hotline. This highly secured connection originally used teletype machines, which were replaced by facsimile units in 1988 and is using e-mail since 2008.


- In 1990 both countries agreed to establish a direct, secure telephone link between Washington and Moscow, which is officially called the Direct Voice Link (DVL) and is maintained by the White House Communications Agency.

- In 2008, Russia and the United States agreed to set up a Direct Secure Communications System, which is an encrypted computer network for both the original Hotline and the Direct Voice Link. Since 2013 this network is also used for a voice link to manage cybersecurity incidents and in December 2021, for a secure video call between the Russian and the American presidents.



The Washington-Moscow Hotline terminal room at the Pentagon in 2013
(photo: www.army.mil)



Between the United States and Russia there are also the following lower level communication links:

- In 1988 the Nuclear Risk Reduction Center (NRRC) was established at the US Department of State, which is used to exchange information in support of arms control treaties. After the split-up of the Soviet Union this secure data exchange connection, called Government-to-Government Communication Link (GGCL), was extended to Ukraine, Belarus, and Kazakhstan. Since 2013, the NRRC also maintains a communications link with Russia for the exchange of information about cybersecurity risks.

- In 2000 the US and Russia signed an agreement for the establishement of a Joint Data Exchange Center (JDEC) to share early warning information on missile and space launches to reduce the risk that a test launch could be misread as a missile attack. It's not clear whether this center has already been realized or not.

- In 2013, a direct secure voice line was set up between the US Cybersecurity Coordinator and the deputy secretary of the Russian Security Council in order to manage crisis situations arising from cybersecurity incidents.

- In 2015, the American and the Russian military created a back-channel after Russia entered Syria's multi-sided civil war. This de-confliction line consisted of a non-secure telephone line and a Google e-mail account, which proved useful in avoiding serious accidents.

- On March 1, 2022, a military de-confliction 'hotline' was established in order to prevent an accidental clash between Russia and the US during the Russian invasion of Ukraine. This link is basically an exchange of phone numbers between both sides for quick access. The US side will be run out of the US European Command's operations center in Stuttgart, Germany, while the Russian side is expected to be coordinated out of the Ministry of Defense in Moscow.


Besides these bilateral hotlines with Russia, the United States also has the following lower level communication links with other nations:

- There is a secure telephone line called Foreign Affairs Link (FAL) between the US Department of State and Russia (since 1999), Japan, Mexico, Germany and Israel.

- There is or was a Defense Telephone Link (DTL) between the US Department of Defense and Russia (since 1994), China (since 2008), Albania, Oman, Qatar, Latvia, Lithuania, Slovenia, Saudi Arabia, Ukraine, Bulgaria, Kuwait, Estonia, Slovakia, Kazakhstan, Macedonia, Bahrain, Israel (since 1996), United Arab Emirates, Poland, Romania, Czech Republic and Austria.

In March 2022, US defense secretary Llyod Austin and Joint Chiefs of Staff chairman Mark A. Milley tried to set up phone calls, most likely through the Defense Telephone Link (DTL), with their Russian counterparts, but the Russians declined to answer the calls.

- In September 2011, the United States proposed opening a direct military hotline with Iran to avoid a possible conflict erupting over the Iranian nuclear program. Tehran declined the offer.


UNITED STATES - UKRAINE

- Already before Russian armed forces invade Ukraine on February 24, 2022, the United States provided Ukrainian president Volodymyr Zelensky with a secure satellite phone that can put him into an encrypted call with US president Biden. On March 5, 2022, Zelensky used it for a 35-minute call with his American counterpart on what more the US could do to support Ukraine without entering into direct combat with Russian forces. A similar satellite phone was provided to Ukrainian foreign minister Dmytro Kuleba.




UNITED STATES - UNITED KINGDOM

- During World War II, more than two decades before the hotline between Washington and Moscow was established, British prime minister Churchill and US president Roosevelt held phone calls over a commercial radiotelephone network, operated by AT&T. Conversations over this network were secured by the A-3 speech privacy system. The phone calls between Churchill and Roosevelt were intercepted and decoded by nazi-Germany.
- Since 1943, the direct telephone link between the Cabinet War Room bunker under Downing Street and the Pentagon with an extension to the White House was secured by the very first digital voice encryption machine, codenamed SIGSALY.
- In the 1950s and 1960s the Washington-London hotline was secured by the KY-9, probably succeeded by the KY-3 voice encryption devices. In the 1980s, the STU-I system was used, to be replaced by a small version of the IST red phone.


British prime minister Margaret Thatcher in her office at Nr. 10 Downing Street in 1987
At the far right we see the beige STU-I telephone for the hotline with the US
(photo: Tim Graham/Getty Images - click to enlarge)


UNITED STATES - GERMANY

- In 1962, a hotline was established between the White House and the German chancellor's office. Initially, this was non-secure, standard telephone line. In 1969 it was probably replaced by a secure teletype link and since the late 1970s it consisted of secure STU-I telephone sets. Somewhere in the 1990s these were replaced by a small version of the IST red phone.



UNITED STATES - SPAIN

- The Spanish prime minister José Maria Aznar (1996-2004) was so often in contact with US president George W. Bush, that a special phone line was installed in his office in the Moncloa palace, exclusively for phone calls to the White House. One of those phone calls was just before the war in Iraq and both leaders also talked about developments in South America.*



UNITED STATES - CHINA

- In October 1997, US president Clinton and Chinese president Jiang Zemin agreed to "connect a presidential hotline to make it easier to confer at a moment's notice." On April 29, 1998 the United States and China signed an agreement to set up such a direct telephone link between both heads of state. However, this hotline was not used when in 2001 an American EP-3E electronic surveillance aircraft was forced to land on Hainan Island.

- In the Summer of 2021, the Biden administration examined the possibility of setting up an emergency hotline with the office of China's president Xi Jinping in order to avoid accidental escalation at a time of heightening bilateral tensions. However, it was believed that China views hotlines as tools to manipulate rather than to solve crises by de-escalating and communicating between forces like the US does. According to remarks by president Biden in July 2024, it seemed that the hotline between him and Xi had been established. Biden eventually had several phone calls with Xi Jinping and president Trump did so on June 5 and September 19, 2025.

- On February 29, 2008, China and the United States had already agreed to set up a Defense Telephone Link (DTL) between the US Department of Defense and China’s Ministry of National Defense, which became operational in April 2008. Until 2011 this hotline was used only four times, but later it was used somewhat more often and in 2014, the US proposed to upgrade the DTL to video teleconference. In 2020, the DTL was used on a regular basis by various defense officials.


UNITED STATES - INDIA

- During a visit of US president Obama to India in January 2015, it was decided to set up a secure hotline between the White House and the Indian prime minister. The link became operational in August 2015 and was said to be established with the help of the US military.



RUSSIA - CHINA

- A hotline connection between Moscow and Bejing was used during the 1969 frontier confrontation between the two countries. The Chinese however refused the Russian peace attempts, and informed Moscow that the direct communications link "was no longer "advantageous" and normal diplomatic channels would suffice". After a reconciliation between the former enemies, the hotline between China and Russia was revived in 1996.* It's not clear whether this hotline is for record or voice communications.
- A telephone hotline between the defence ministries of Russia and China became operational on March 14, 2008.



RUSSIA - NORTH KOREA

- Apparently there was a facsimile-hotline between Moscow and Pyongyang, which was used in 1968, when North Korea captured the American spy ship USS Pueblo.*



RUSSIA - FRANCE

- Since 1966 there was a direct teletype connection between the French president and the Kremlin. In 1989 the teletype equipment was replaced by high speed facsimile units.*


RUSSIA - UNITED KINGDOM

- Since 1967 there was a direct teletype connection between the British prime minister and the Kremlin. In 1990 it was proposed to install a telephone line between London and Moscow, but British government officials considered it too costly to secure this line through encryption. It seems that this hotline was eventually upgraded with encryption in 2011.


RUSSIA - GERMANY

- In 1989 a facsimile connection was established between the West-German capital Bonn and Moscow.* In 1990 there was also a non-secure telephone line between both capitals.
- The Soviet Union also had a hotline with Erich Honecker as leader of the former East-German Republic (DDR). During a short period before East and West Germany were united in 1991, there was a telephone hotline between Honecker and the West-German Bundeskanzler Helmut Kohl.*


RUSSIA - NATO

- There's a direct telephone link between the headquarters of the Supreme Allied Commander Europe (SACEUR) and the headquarters of the Chief of the General Staff of the Russian Armed Forces. This line is being tested daily for technical purposes by a corporal at each side. In 2025, the Russian Chief of the General Staff Valery Gerasimov didn't respond to calls from his NATO counterpart anymore.*



ISRAEL - EGYPT

- In 2009 Israeli prime minister Ehud Olmert and Egyptian president Hosni Mubarak agreed to pass on relevant intelligence information immediately using a hotline, primarily to combat smuggling from Sinai into the Gaza Strip.


ISRAEL - RUSSIA

- In 2015, Russian armed forces in Syria had set up a hotline with the Israeli military to avoid accidental clashes in the Syrian sky: "Mutual information-sharing on the actions of aircraft has been established through a hotline between the Russian aviation command center at the Hmeimim air base and a command post of the Israeli Air Force."



INDIA - PAKISTAN

- After the 1971 war between India and Pakistan, a secure communications link between the Prime Minister Secretariat in Islamabad and the Secretariat Building in New Delhi was established, but it was seldom used until the 1990s.
- In 2004, both countries agreed to set up an additional secure hotline between their foreign ministers, aimed at preventing nuclear risks.
- In 2011, India and Pakistan agreed to set up a 24/7 non-encrypted hotline between their interior ministers, that will facilitate real-time information sharing on terrorist threats.


INDIA - CHINA

- Since 2005 there's a non-encrypted hotline between the foreign ministers of India and China for building "mutual political trust".
- In 2009 both countries agreed to set up a direct, secure telephone link between the Chinese premier and Indian prime minister, which was meant as a confidence building measure and to maintain regular contacts at the highest level. The agreement for this hotline was signed in April 2010.


INDIA - RUSSIA

- There's also a non-encrypted hotline between Delhi and Moscow, which was established before 2009.



SOUTH KOREA - NORTH KOREA

- A first telephone hotline between North and South Korea became operational on September 22, 1971. Many low-level phone lines between both countries followed, until there were 33 lines through Pamnumjom and 15 lines outside that border town. A top-level telephone hotline between the presidents of North and South Korea was established on April 20, 2018, in preparation of a summit between both leaders.



A South Korean liaison officer speaks with his North Korean counterpart over the
inter-Korean communications channel at Panmunjom, January 3, 2018
(photo: Unification Ministry - click to enlarge)


CHINA - SOUTH KOREA

- In September 2012, China and South Korea agreed to set up a consular hotline between their defense ministries to protect rights of their citizens who are staying in the other country. In April 2013 both countries agreed to set up a second, 24-hour hotline to deal with the rising tension over North Korea.


CHINA - VIETNAM

- In June 2013, China and Vietnam agreed to set up a naval hotline between their defense departments, in order to keep a peaceful and secure maritime environment in the South China Sea, amid escalating maritime tensions over disputed South China Sea islands.


CHINA - PHILIPPINES

- In January 2023, an emergency telephone hotline was established after Philippine President Ferdinand Marcos Jr. met Chinese President Xi Jinping in Beijing. However, during a confrontation between Chinese and Philippine forces in August 2023, the Philippine government said it was unable to reach Chinese officials through this "maritime communication mechanism" for several hours.
- On July 2, 2024, both countries agreed to set up three new lines of communication to improve their handling of maritime disputes regarding the South China Sea:
1. for "representatives to be designated by their leaders";
2. for the respective foreign ministries at ministerial or vice-ministerial level;
3. for their respective coast guards.
It is not clear whether a direct line of communication between the Philippine and Chinese presidential offices was established as well.


In 2010, China and Japan agreed to establish a hotline between their political leaders, following a series of naval incidents, but the plan wasn't realized. Defence officials of the two countries also agreed in 2011 to set up a military-to-military hotline by the end of 2012, but the talks stalled due to heightened tensions over the territorial row. In February 2013, Japan again suggested to establish a China-Japan hotline, and reiterated this once again in January 2014.


In September 2016, China and the Southeast Asian countries decided to set up hotlines and adopt communications protocols to avoid potential naval clashes in the disputed waters of the South China Sea.


When more information about these hotlines becomes available, it will be added here. Some of the most notable bilateral hotlines will be discussed later on this weblog.



Links and Sources
- Concil on Foreign Relations: Trump, Xi, and the Making of a Presidential Phone Call, September 2025
- The Rand Blog: Another 'Hotline' with China Isn't the Answer, July 2022
- Politico: Pentagon wants Moscow back channels to prevent nuclear escalation, February 2022
- National Communications System, Forty Years of Service to the Nation: 1963-2003, 2003
- Haraldur Þór Egilsson, The Origins, Use and Development of Hot Line Diplomacy, Institute Clingendael, 2003
- US Department of State, Bureau of Information Resource Management (IRM), 2011

Some older articles on this weblog that are of current interest:
In Dutch: Volg de actuele ontwikkelingen rond de Wet op de inlichtingen- en veiligheidsdiensten via het Dossier herziening Wiv 2017