Matthijs R. Koot
banner
cyberwar.nl
Matthijs R. Koot
@cyberwar.nl
IT, privacy, security, democracy. PhD. PGP: 51F9 8FC9 C92A 1165 (http://keybase.io/mrkoot). Employed as IT security specialist.

Mastodon: @[email protected]
LinkedIn: /in/mrkoot
Reposted by Matthijs R. Koot
Now you understand why every pro-Kremlin Twitter bot has spent 90% of its time over the past decade defending or pushing crypto and blockchain tech while randomly publishing some political tweet once in a while?
Illicit cryptocurrency addresses received at least $154 billion in 2025. According to Chainalysis, almost two-thirds of the funds have been linked to sanctions evasion activity. Most came from Russian organizations

www.chainalysis.com/blog/2026-cr...
January 10, 2026 at 4:29 PM
Reposted by Matthijs R. Koot
Germany’s foreign intelligence agency (BND) intercepted phone conversations of former President Barack Obama while he was aboard Air Force One over several years. The interceptions exploited vulnerabilities in the aircraft’s encryption and known frequencies.

www.zeit.de/politik/ausl...
Spionage: BND hörte jahrelang US-Präsident Barack Obama ab
Der deutsche Geheimdienst überwachte regelmäßig Telefonate des damaligen US-Präsidenten an Bord der Air Force One. Erlaubnis von Angela Merkel hatte der BND nicht.
www.zeit.de
January 4, 2026 at 6:25 PM
Reposted by Matthijs R. Koot
New addition

Report: Perceptions Of Counterintelligence In Corporate And Academic Sectors: Risks, Awareness, And Strategic Implications (published 22-11-2025)
https://zenodo.org/records/17681907
Perceptions Of Counterintelligence In Corporate And Academic Sectors: Risks, Awareness, And Strategic Implications
The United States is in the middle of an intelligence war. Foreign adversaries, including their intelligence services and state-sponsored actors, employ increasingly sophisticated technologies and methods to access our most valuable innovations and secrets. The importance of implementing counterintelligence (CI) practices across all sectors of American society has never been greater. As our adversaries increasingly target non-governmental data environments, it has become essential to address security gaps in our nation’s critical industries, supply chains, and academic institutions. While the last two decades have seen the widespread adoption of cybersecurity protocols, malign actors continue to evolve their tactics to exploit both technical and human vulnerabilities. Counterintelligence can and should be a vital tool for corporations and academia which have become increasingly vulnerable targets for foreign espionage, theft, sabotage, and influence operations. By providing strategic insights and actionable practices, counterintelligence enables organizations to effectively and efficiently recognize and respond to threats that fall outside the scope of traditional cybersecurity. This study aims to explore how counterintelligence is perceived in civilian sectors – specifically corporate and academic institutions – in response to escalating intelligence threats. By surveying a diverse range of professionals in the academic and corporate sectors, this study assesses the awareness, attitudes, and institutional barriers to adopting CI practices and seeks to highlight key knowledge gaps and identify opportunities for targeted awareness, training, and investment. The results will inform policy and provide strategic recommendations for building a CI-conscious culture across sectors.
zenodo.org
December 16, 2025 at 10:31 PM
Reposted by Matthijs R. Koot
Resident.NGO has an excellent write-up of a case where a journalist was interrogated by the Belarusian KGB and then had spyware installed on their phone. The recommendations are sensible and practical resident.ngo/lab/writeups...

See also this @rsf.org report rsf.org/en/exclusive...
ResidentBat: Operational Report & Advisory on KGB spyware in Belarus in 2025 - RESIDENT.NGO THREAT LAB
RESIDENT.NGO has helped uncover a malware attack targeted at a Belarus-based journalist by the Belarusian secret service (KGB). This document serves as a short synopsis of the case, offering safety re...
resident.ngo
December 17, 2025 at 9:05 PM
Reposted by Matthijs R. Koot
Belarusian KGB put spyware on phones of detained journalist.

Growing list of cases where authoritarian regimes use detention to implant spyware on phones:

🦠Belarus
🦠Kenya
🦠Serbia

And likely plenty more.

Important investigation & reminder that dictators don't always need zero-days.
rsf.org RSF @rsf.org · 26d
#Belarus: RSF reveals the existence of a previously unknown spyware tool, used since at least 2021 by the KGB against journalists. Installed after the physical confiscation of phones, #ResidentBat constitutes a grave violation of press freedom. RSF calls for a ban on these surveillance technologies.
Exclusive: RSF uncovers new spyware from Belarus
Reporters Without Borders (RSF)’s Digital Security Lab (DSL), working with the Eastern European organisation RESIDENT.NGO, has uncovered a previously unknown spyware tool used by the State Security Co...
rsf.org
December 17, 2025 at 3:45 PM
Reposted by Matthijs R. Koot
The Pope involves himself in Italy's spy scandal and asks intel officials to respect people's privacy and not leak data and smear people with hacked data

www.reuters.com/world/pope-t...
Pope tells Italian spies not to smear politicians or journalists
Pope Leo on Friday urged Italy's intelligence services to avoid smearing public figures and journalists, saying abuse of confidential material risked undermining democracy and public trust.
www.reuters.com
December 14, 2025 at 5:56 PM
Reposted by Matthijs R. Koot
The "upgraded" Age Assurance system has essentially locked everyone out of the @ddosecrets.com account while we wait for @support.bsky.team to explain what a "birthdate" is for an organization, and whether we're supposed to submit made-up information or have the organization's account restricted.
v1.111 is live today!

We've upgraded our Age Assurance system to comply with upcoming laws in Australia and other regions, and to restore access to people over 18 in Mississippi.

Plus, we fixed some bugs and laid the groundwork for improved "who to follow" suggestions in the near future.
December 9, 2025 at 5:33 PM
US DOJ: Fiber laser expert convicted by a federal jury of economic espionage and theft of trade secrets (5 November 2025) www.justice.gov/usao-wdny/pr...

“ […] On or about July 1, 2016, Wang stole hundreds of files that contained non-public data generated during the DARPA project […]”
Fiber laser expert convicted by a federal jury of economic espionage and theft of trade secrets
A federal jury has convicted Ji Wang, 63, of Painted Post, NY, of two counts of economic espionage, one count of theft of trade secrets, one count of attempted economic espionage, and one count of att...
www.justice.gov
December 7, 2025 at 11:56 AM
Reposted by Matthijs R. Koot
I'm especially pleased to see X fined for not providing researchers access to their platform.

This is something we @citizenlab.ca have called for, and it's essential for protection of the public interest by independent watchdogs 2)
December 5, 2025 at 1:26 PM
Reposted by Matthijs R. Koot
Did the EU top court (it is a binding judgment) just prohibit anonymity on the internet? Posting without showing an ID (like the new EU ID Wallet) could be made mandatory?
December 5, 2025 at 9:12 AM
Reposted by Matthijs R. Koot
Sweden scrambled Gripen fighters to identify and shadow a group of Russian long-range aircraft flying over the Baltic Sea on Thursday, after radar picked up multiple Tu-22M3 bombers travelling with escorting Su-35 fighters.

ukdefencejournal.org.uk/nato-interce...
NATO intercepts Russian bombers armed with cruise missiles
Sweden scrambled Gripen fighters on Thursday to shadow a group of Russian Tu-22M3 bombers and Su-35 escorts flying over the Baltic Sea after the formation was detected on radar.
ukdefencejournal.org.uk
November 30, 2025 at 6:02 PM
Reposted by Matthijs R. Koot
For the first time in its history, a woman will be head of the Dutch secret service AIVD. Simone Smit will replace Erik Akerboom on 1 March next year. Since February 2021, she is his #2 as deputy Director General. Before that, she was Director Counter-Terrorism at the NCTV.
November 28, 2025 at 2:02 PM
Reposted by Matthijs R. Koot
The Commission’s new “intelligence cell” could backfire, pulling analysis into a political space and making EU states share less, not more. Our Euractiv piece explains why trust, not expansion, is the real bottleneck. @dvanp.bsky.social @evamichaels.bsky.social
www.euractiv.com/opinion/von-...
Von der Leyen’s 'intelligence cell' will only fuel fragmentation and mistrust | Euractiv
The need to improve intelligence capacity is undeniable. But von der Leyen’s chosen method reflects a familiar instinct: using crisis logic to expand the Commission’s authority
www.euractiv.com
November 25, 2025 at 10:25 AM
Reposted by Matthijs R. Koot
Epstein emails (2.5 GB)

Approximately 20,900 unredacted emails and file attachments sent and received by Jeffrey Epstein's [email protected] email address over nineteen years.

ddosecrets.com/article/epst...

Help us keep publishing: donorbox.org/ddosecrets
November 24, 2025 at 10:14 AM
“The MI5 alert cited LinkedIn profiles of two women, Amanda Qiu and Shirly Shen, and said other similar recruiters’ profiles were acting as fronts for espionage.”
Chinese spies are trying to reach UK lawmakers via LinkedIn, MI5 warns (18 Nov 2025) www.pbs.org/newshour/wor...

“Their aim is to collect information and lay the groundwork for long-term relationships, using professional networking sites, recruitment agents and consultants acting on their behalf.”
Chinese spies are trying to reach UK lawmakers via LinkedIn, MI5 warns
Chinese spies are reaching out to U.K. lawmakers them recruitment headhunters or cover companies, Britain’s domestic intelligence agency has warned.
www.pbs.org
November 19, 2025 at 8:14 AM
Chinese spies are trying to reach UK lawmakers via LinkedIn, MI5 warns (18 Nov 2025) www.pbs.org/newshour/wor...

“Their aim is to collect information and lay the groundwork for long-term relationships, using professional networking sites, recruitment agents and consultants acting on their behalf.”
Chinese spies are trying to reach UK lawmakers via LinkedIn, MI5 warns
Chinese spies are reaching out to U.K. lawmakers them recruitment headhunters or cover companies, Britain’s domestic intelligence agency has warned.
www.pbs.org
November 19, 2025 at 8:13 AM
Reposted by Matthijs R. Koot
There's a Russian disinformation network operating from Mastodon to push content into BlueSky, it's a few hundred active accounts (they also exist directly on BlueSky natively too).

It probably costs more to run than the value it provides to whoever runs it, tbh.

cyberplace.social/@GossiTheDog...
Kevin Beaumont (@[email protected])
I dunno if anybody has done a write up of it but there’s a pretty big Russian disinformation operation that runs on the Fediverse If you search on Mastodon for t.me/RussianBaZa you’ll find some of i...
cyberplace.social
November 15, 2025 at 11:46 AM
Reposted by Matthijs R. Koot
After years of blocking Tor users from accessing essential government websites, Mexico has finally reversed course. At least in part. @globalvoices.org breaks down the story on our blog🗞️📰: blog.torproject.org/mexican-gove...
@jacobonajera.bsky.social
Mexican government partially unblocks secure internet | Tor Project
Mexico blocked Tor access to government websites citing security concerns. The current administration lifted the main block earlier this year, though some sites appear to remain restricted. Ironically...
blog.torproject.org
November 18, 2025 at 3:23 PM
Reposted by Matthijs R. Koot
The Friesland-based Dutch Certification Institute, which certifies shipping and yacht-related products, was taken over by a Chinese company in 2019. Now, it has suddenly closed down and its customers are stuck without necessary paperwork and with no clue where their dossiers have gone.
Chinese eigenaar doekt ineens Fries bedrijf op. Waar zijn de bedrijfs­geheimen van klanten? – Follow the Money: „DCI, dat productcertificaten leverde aan jachtbouwers, kreeg zes jaar geleden een omstreden Chinese eigenaar. Van de ene op de andere dag heeft het dit jaar alle activiteiten gestaakt.”
Chinese eigenaar doekt ineens Fries bedrijf op. Waar zijn de bedrijfs­geheimen van klanten?
Het Friese DCI, een keuringsclub voor de scheepvaart- en jachtbouwsector, kreeg eind 2019 een nieuw, Chinees moederbedrijf. De nieuwe eigenaar vertrok dit jaar met de noorderzon. Niemand weet nu waar ...
www.ftm.nl
November 17, 2025 at 9:20 AM
Reposted by Matthijs R. Koot
Russia handed Roskomnadzor the keys to the entire internet on October 27, letting the agency reroute traffic, flip the censorship switch and isolate the Russian web at will starting March 1. Officials insist it's all for "Russians' online safety".
November 8, 2025 at 6:46 PM
Reposted by Matthijs R. Koot
US Defense Secretary Pete Hegseth said that Washington and Beijing would establish (additional) military-to-military communications channels:
www.militarytimes.com/news/pentago...
US, China reportedly agree to set up military communication channels
Defense Secretary Pete Hegseth spoke with his Chinese counterpart, Admiral Dong Jun, late Saturday on the sidelines of a regional security meeting.
www.militarytimes.com
November 6, 2025 at 5:58 PM
Reposted by Matthijs R. Koot
Vital piece of investigative reporting from Sky. They've uncovered the X algorithm which feeds users extremist right wing material from the moment they join the site. It is a far-right radicalisation engine, by design.

news.sky.com/story/the-x-...
Elon Musk is boosting the British right - and this shows how
Elon Musk is boosting the British right - and this shows how
news.sky.com
November 6, 2025 at 7:23 AM
Reposted by Matthijs R. Koot
NEW: Peter Williams, the former head of Western zero-day and spyware maker Trenchant, pleaded guilty to selling eight exploits to a broker that resells to the Russian government.

The DOJ said Williams was promised millions of dollars in exchange for "national-security focused software."
Former L3Harris Trenchant boss pleads guilty to selling zero-day exploits to Russian broker | TechCrunch
Prosecutors confirmed Peter Williams, the former Trenchant boss, sold eight exploits to a Russian buyer. TechCrunch exclusively reported that the Trenchant division was investigating a leak of its hac...
techcrunch.com
October 29, 2025 at 5:42 PM