Summary: A Website is a collection of related web pages hosted on a server and accessible via a web browser. Websites have an associated Domain and can host various types of content, such as text, images, videos, and interactive features.
When a Website is fleshed out, it Presents a Persona to site visitors. For example, the Domain “bbc.co.uk/news” hosts a Website which uses the News Outlet Persona.
Tactic: TA07 Select Channels and Affordances
Parent Technique: T0152 Digital Content Hosting Asset
| Associated Technique | Description |
|---|
| Incident | Descriptions given for this incident |
|---|---|
| I00066 The online war between Qatar and Saudi Arabia | In the early hours of 24 May 2017, a news story appeared on the website of Qatar's official news agency, QNA, reporting that the country's emir, Sheikh Tamim bin Hamad al-Thani, had made an astonishing speech (T0152.004: Website Asset, T0150.005: Compromised Asset, T0097.202: News Outlet Persona, T0145.005: Compromised Persona). The quotes then appeared on the QNA's social media accounts (T0146: Account Asset, T0150.005: Compromised Asset, T0097.202: News Outlet Persona, T0145.005: Compromised Persona) and on the news ticker running along the bottom of the screen on videos uploaded to the agency's YouTube channel (T0162.002: Edits Made to News Report which Reframe Context). The emir was quoted praising Islamist groups Hamas, Hezbollah and the Muslim Brotherhood. And perhaps most controversially of all, Iran, Saudi Arabia's arch-rival (T0161.002: Statement Incorrectly Presented as Made by Individual or Institution). But the story soon disappeared from the QNA website, and Qatar's foreign ministry issued a statement denying the speech had ever taken place. No video footage has ever emerged of the emir actually saying the words supposedly attributed to him. Qatar claimed that the QNA had been hacked. And they said the hack was designed to deliberately spread fake news about the country's leader and its foreign policies. The Qataris specifically blamed UAE, an allegation later repeated by a Washington Post report which cited US intelligence sources. The UAE categorically denied those reports. But the story of the emir's speech unleashed a media free-for-all. Within minutes, Saudi and UAE-owned TV networks - Al Arabiya and Sky News Arabia - picked up on the comments attributed to al-Thani. Both networks accused Qatar of funding extremist groups and of destabilising the region. |
| I00099 More Women Are Facing The Reality Of Deepfakes, And They’re Ruining Lives | “The creator of Geopolitika[.]ru is Aleksandr Dugin, who was sanctioned by the United States Department of Treasury in 2015 for his role in the Eurasian Youth Union “for being responsible for or complicit in actions or policies that threaten the peace, security, stability, or sovereignty or territorial integrity of Ukraine.” [...] “Currently, the website geopolika[.]ru redirects directly to another partner website, Katehon. “Katehon poses itself as a think tank focused on geopolitics in an English edition of its website. In contrast, in Russian, it states its aim to develop “ideological, political, diplomatic, economic and military strategy for Russia of the future” with a special role of religion. The president of Katehon’s supervisory board is Konstantin Malofeev, a Russian millionaire with connections to the Russian orthodox church and presidential administration, who founded Tsargrad TV, a known source of disinformation. Malofeev was sanctioned by the U.S. Department of Treasury and the European Union in 2014 for material support and financial backing of Russian-backed separatists in eastern Ukraine. Another known figure from the board is Sergei Glaziev, former advisor to Putin in 2012–2019. Dugin is also on the board in the Russian edition of the website, whereas he is omitted in English.” In this example a domain managed by an actor previously sanctioned by the US department of treasury has been reconfigured to redirect to another website; Katehon (T0149.004: Redirecting Domain Asset, T0150.004: Repurposed Asset). Katehon presents itself as a geopolitical think tank in English, but does not maintain this persona when presenting itself to a Russian speaking audience (T0097.204: Think Tank Persona, T0152.004: Website Asset, T0155.004: Geoblocked Asset). |
| I00109 Coordinated Facebook Pages Designed to Fund a White Supremacist Agenda | In this report, researchers look at online platforms commonly used by people who play videogames, looking at how these platforms can contribute to radicalisation of gamers: Indie DB [is a platform that serves] to present indie games, which are titles from independent, small developer teams, which can be discussed and downloaded [Indie DB]. [...] [On Indie DB we] found antisemitic, Islamist, sexist and other discriminatory content during the exploration. Both games and comments were located that made positive references to National Socialism. Radicalised users seem to use the opportunities to network, create groups, and communicate in forums. In addition, a number of member profiles with graphic propaganda content could be located. We found several games with propagandistic content advertised on the platform, which caused apparently radicalised users to form a fan community around those games. For example, there are titles such as the antisemitic Fursan Al-Aqsa: The Knights of the Al-Aqsa Mosque, which has won the Best Hardcore Game award at the Game Connection America 2024 Game Development Awards and which has received antisemitic praise on its review page. In the game, players need to target members of the Israeli Defence Forces, and attacks by Palestinian terrorist groups such as Hamas or Lions’ Den can be re-enacted. These include bomb attacks, beheadings and the re-enactment of the terrorist attack in Israel on 7 October 2023. We, therefore, deem Indie DB to be relevant for further analyses of extremist activities in digital gaming spaces. Indie DB is an online software delivery platform on which users can create groups, and participate in discussion forums (T0152.009: Software Delivery Platform, T0151.002: Online Community Group, T0151.009: Legacy Online Forum Platform). The platform hosted games which allowed players to reenact terrorist attacks (T0147.001: Game Asset). |
| I00128 #TrollTracker: Outward Influence Operation From Iran | ISD conducted an investigation into the usage of social groups on Steam. Steam is an online platform used to buy and sell digital games, and includes the Steam community feature, which “allows users to find friends and join groups and discussion forums, while also offering in-game voice and text chat”. Actors have used Steam’s social capabilities to enable online harm campaigns: A number of groups were observed encouraging members to join conversations on outside platforms. These include links to Telegram channels connected to white supremacist marches, and media outlets, forums and Discord servers run by neo-Nazis. [...] This off-ramping activity demonstrates how rather than sitting in isolation, Steam fits into the wider extreme right wing online ecosystem, with Steam groups acting as hubs for communities and organizations which span multiple platforms. Accordingly, although the platform appears to fill a specific role in the building and strengthening of communities with similar hobbies and interests, it is suggested that analysis seeking to determine the risk of these communities should focus on their activity across platforms Social Groups on Steam were used to drive new people to other neo-Nazi controlled community assets (T0122: Direct Users to Alternative Platforms, T0152.009: Software Delivery Platform, T0151.002: Online Community Group). |
| I00244 Hackers publish fake story about Ukrainians attempting to assassinate Slovak president | An unidentified attacker hacked a Czech news service's website and published a fake story on Tuesday claiming that an assassination attempt had been made against the newly elected Slovak president, Peter Pellegrini (T0152.004: Website Asset, T0150.005: Compromised Asset, T0097.202: News Outlet Persona, T0145.005: Compromised Persona, T0161.002: Statement Incorrectly Presented as Made by Individual or Institution). According to the government-owned public service Czech News Agency (CTK), the attacker posted the false article directly to its website, meaning the story was not distributed to the service’s clients. The article has since been retracted, with CTK declaring it to be a fake and announcing that it had informed the country’s intelligence agencies and cybersecurity authority about the breach. The headline of the fake story claimed that Slovakia’s domestic intelligence agency, the Security Information Service (BIS), “prevented an assassination attempt on the newly elected Slovak President Petr Pelligrini.” Readers noted that the story misspelled Peter Pellegrini’s name. Pellegrini was elected earlier this month (T0068: Respond to Breaking News Event or Active Crisis), providing what Reuters reported was a boost to Slovakia’s pro-Russian prime minister Robert Fico. Despite Slovakia’s NATO membership, Pellegrini has said he would oppose sending the country’s armed forces to assist a member state if it were attacked by Russia. The false story published on Tuesday in both Czech and English said that the fictitious attempted assassination of Pellegrini was planned by Ukrainian nationals. It named Vitaliy Usatyy, Kyiv’s charge d’affaires in Prague, as one of the perpetrators. CTK described the incident as an act of disinformation. No evidence has yet been published tying the hack to a particular actor, and the news agency said it would not be releasing further information. |
| Counters | Response types |
|---|
DO NOT EDIT ABOVE THIS LINE - PLEASE ADD NOTES BELOW