{"id":24846,"date":"2019-01-31T17:03:56","date_gmt":"2019-01-31T17:03:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/29772\/Inside-The-UAEs-Secret-Hacking-Team-Of-US-Mercenaries.html"},"modified":"2019-01-31T17:03:56","modified_gmt":"2019-01-31T17:03:56","slug":"inside-the-uaes-secret-hacking-team-of-us-mercenaries","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/","title":{"rendered":"Inside The UAE&#8217;s Secret Hacking Team Of US Mercenaries"},"content":{"rendered":"<p>WASHINGTON (Reuters) &#8211; Two weeks after leaving her position as an intelligence analyst for the U.S. National Security Agency in 2014, Lori Stroud was in the Middle East working as a hacker for an Arab monarchy.<\/p>\n<p>She had joined Project Raven, a clandestine team that included more than a dozen former U.S. intelligence operatives recruited to help the United Arab Emirates engage in surveillance of other governments, militants and human rights activists critical of the monarchy.<\/p>\n<p>Stroud and her team, working from a converted mansion in Abu Dhabi known internally as \u201cthe Villa,\u201d would use methods learned from a decade in the U.S intelligence community to help the UAE hack into the phones and computers of its enemies.<\/p>\n<p>Stroud had been recruited by a Maryland cyber security contractor to help the Emiratis launch hacking operations, and for three years, she thrived in the job. But in 2016, the Emiratis moved Project Raven to a UAE cyber security firm named DarkMatter. Before long, Stroud and other Americans involved in the effort say they saw the mission cross a red line: targeting fellow Americans for surveillance.<\/p>\n<p>\u201cI am working for a foreign intelligence agency who is targeting U.S. persons,\u201d she told Reuters. \u201cI am officially the bad kind of spy.\u201d<\/p>\n<p>The story of Project Raven reveals how former U.S. government hackers have employed state-of-the-art cyber-espionage tools on behalf of a foreign intelligence service that spies on human rights activists, journalists and political rivals.<\/p>\n<p>Interviews with nine former Raven operatives, along with a review of thousands of pages of project documents and emails, show that surveillance techniques taught by the NSA were central to the UAE\u2019s efforts to monitor opponents. The sources interviewed by Reuters were not Emirati citizens.<\/p>\n<p>The operatives utilized an arsenal of cyber tools, including a cutting-edge espionage platform known as Karma, in which Raven operatives say they hacked into the iPhones of hundreds of activists, political leaders and suspected terrorists. Details of the Karma hack were described in a separate Reuters article today.<\/p>\n<p>An NSA spokesman declined to comment on Raven. An Apple spokeswoman declined to comment. A spokeswoman for UAE\u2019s Ministry of Foreign Affairs declined to comment. The UAE\u2019s Embassy in Washington and a spokesman for its National Media Council did not respond to requests for comment.<\/p>\n<p>The UAE has said it faces a real threat from violent extremist groups and that it is cooperating with the United States on counter-terrorism efforts. Former Raven operatives say the project helped NESA break up an ISIS network within the Emirates. When an ISIS-inspired militant stabbed to death a teacher in Abu Dhabi in 2014, the operatives say, Raven spearheaded the UAE effort to assess if other attacks were imminent.<\/p>\n<p>Various reports have highlighted the ongoing cyber arms race in the Middle East, as the Emirates and other nations attempt to sweep up hacking weapons and personnel faster than their rivals. The Reuters investigation is the first to reveal the existence of Project Raven, providing a rare inside account of state hacking operations usually shrouded in secrecy and denials.<\/p>\n<p>The Raven story also provides new insight into the role former American cyberspies play in foreign hacking operations. Within the U.S. intelligence community, leaving to work as an operative for another country is seen by some as a betrayal. \u201cThere\u2019s a moral obligation if you\u2019re a former intelligence officer from becoming effectively a mercenary for a foreign government,\u201d said Bob Anderson, who served as executive assistant director of the Federal Bureau of Investigation until 2015.<\/p>\n<p>While this activity raises ethical dilemmas, U.S. national security lawyers say the laws guiding what American intelligence contractors can do abroad are murky. Though it\u2019s illegal to share classified information, there is no specific law that bars contractors from sharing more general spycraft knowhow, such as how to bait a target with a virus-laden email.<\/p>\n<p>The rules, however, are clear on hacking U.S. networks or stealing the communications of Americans. \u201cIt would be very illegal,\u201d said Rhea Siers, former NSA deputy assistant director for policy.<\/p>\n<p>The hacking of Americans was a tightly held secret even within Raven, with those operations led by Emiratis instead. Stroud\u2019s account of the targeting of Americans was confirmed by four other former operatives and in emails reviewed by Reuters.<\/p>\n<p>The FBI is now investigating whether Raven\u2019s American staff leaked classified U.S. surveillance techniques and if they illegally targeted American computer networks, according to former Raven employees interviewed by federal law enforcement agents. Stroud said she is cooperating with that investigation. No charges have been filed and it is possible none will emerge from the inquiry. An FBI spokeswoman declined to comment.<\/p>\n<h3>PURPLE BRIEFING, BLACK BRIEFING<\/h3>\n<p>Stroud is the only former Raven operative willing to be named in this story; eight others who described their experiences would do so only on condition of anonymity. She spent a decade at the NSA, first as a military service member from 2003 to 2009 and later as a contractor in the agency for the giant technology consultant Booz Allen Hamilton from 2009 to 2014. Her specialty was hunting for vulnerabilities in the computer systems of foreign governments, such as China, and analyzing what data should be stolen.<\/p>\n<p>In 2013, her world changed. While stationed at NSA Hawaii, Stroud says, she made the fateful recommendation to bring a Dell technician already working in the building onto her team. That contractor was Edward Snowden.<\/p>\n<p>\u201cHe\u2019s former CIA, he\u2019s local, he\u2019s already cleared,\u201d Stroud, 37, recalled. \u201cHe\u2019s perfect!\u201d Booz and the NSA would later approve Snowden\u2019s transfer, providing him with even greater access to classified material.<\/p>\n<p>Two months after joining Stroud\u2019s group, Snowden fled the United States and passed on thousands of pages of top secret program files to journalists, detailing the agency\u2019s massive data collection programs. In the maelstrom that followed, Stroud said her Booz team was vilified for unwittingly enabling the largest security breach in agency history.<\/p>\n<p>\u201cOur brand was ruined,\u201d she said of her team.<\/p>\n<p>In the wake of the scandal, Marc Baier, a former colleague at NSA Hawaii, offered her the chance to work for a contractor in Abu Dhabi called CyberPoint. In May 2014, Stroud jumped at the opportunity and left Booz Allen.<\/p>\n<p>CyberPoint, a small cyber security contractor headquartered in Baltimore, was founded by an entrepreneur named Karl Gumtow in 2009. Its clients have included the U.S. Department of Defense, and its UAE business has gained media attention.<\/p>\n<p>In an interview, Gumtow said his company was not involved in any improper actions.<\/p>\n<p>Stroud had already made the switch from government employee to Booz Allen contractor, essentially performing the same NSA job at higher pay. Taking a job with CyberPoint would fulfill a lifelong dream of deploying to the Middle East and doing so at a lucrative salary. Many analysts, like Stroud, were paid more than $200,000 a year, and some managers received salaries and compensation above $400,000.<\/p>\n<p>She understood her new job would involve a counterterrorism mission in cooperation with the Emiratis, a close U.S. ally in the fight against ISIS, but little else. Baier and other Raven managers assured her the project was approved by the NSA, she said. With Baier\u2019s impressive resume, including time in an elite NSA hacking unit known as Tailored Access Operations, the pledge was convincing. Baier did not respond to multiple phone calls, text messages, emails, and messages on social media.<\/p>\n<p>In the highly secretive, compartmentalized world of intelligence contracting, it isn\u2019t unusual for recruiters to keep the mission and client from potential hires until they sign non-disclosure documents and go through a briefing process.<\/p>\n<p>When Stroud was brought into the Villa for the first time, in May 2014, Raven management gave her two separate briefings, back-to-back.<\/p>\n<p>In the first, known internally as the \u201cPurple briefing,\u201d she said she was told Raven would pursue a purely defensive mission, protecting the government of the UAE from hackers and other threats. Right after the briefing ended, she said she was told she had just received a cover story.<\/p>\n<p>She then received the \u201cBlack briefing,\u201d a copy of which was reviewed by Reuters. Raven is \u201cthe offensive, operational division of NESA and will never be acknowledged to the general public,\u201d the Black memo says. The NESA, or National Electronic Security Authority, was the UAE\u2019s version of the NSA.<\/p>\n<p>Stroud would be part of Raven\u2019s analysis and target-development shop, tasked with helping the government profile its enemies online, hack them and collect data. Those targets were provided by the client, NESA, now called the Signals Intelligence Agency.<\/p>\n<p>The language and secrecy of the briefings closely mirrored her experience at the NSA, Stroud said, giving her a level of comfort.<\/p>\n<p>The information scooped up by Raven was feeding a security apparatus that has drawn international criticism. The Emirates, a wealthy federation of seven Arab sheikhdoms with a population of 9 million, is an ally of neighbor Saudi Arabia and rival of Iran.<\/p>\n<p>Like those two regional powers, the UAE has been accused of suppressing free speech, detaining dissidents and other abuses by groups such as Human Rights Watch. The UAE says it is working closely with Washington to fight extremism \u201cbeyond the battlefield\u201d and is promoting efforts to counter the \u201croot causes\u201d of radical violence.<\/p>\n<p>Raven\u2019s targets eventually would include militants in Yemen, foreign adversaries such as Iran, Qatar and Turkey, and individuals who criticized the monarchy, said Stroud and eight other former Raven operatives. Their accounts were confirmed by hundreds of Raven program documents reviewed by Reuters.<\/p>\n<p>Under orders from the UAE government, former operatives said, Raven would monitor social media and target people who security forces felt had insulted the government.<\/p>\n<p>\u201cSome days it was hard to swallow, like [when you target] a 16-year-old kid on Twitter,\u201d she said. \u201cBut it\u2019s an intelligence mission, you are an intelligence operative. I never made it personal.\u201d<\/p>\n<p>The Americans identified vulnerabilities in selected targets, developed or procured software to carry out the intrusions and assisted in monitoring them, former Raven employees said. But an Emirati operative would usually press the button on an attack. This arrangement was intended to give the Americans \u201cplausible deniability\u201d about the nature of the work, said former Raven members.<\/p>\n<h3>TARGETING \u2018GYRO\u2019 AND \u2018EGRET\u2019<\/h3>\n<p>Stroud discovered that the program took aim not just at terrorists and foreign government agencies, but also dissidents and human rights activists. The Emiratis categorized them as national security targets.<\/p>\n<p>Following the Arab Spring protests and the ousting of Egyptian President Hosni Mubarak in 2011, Emirati security forces viewed human rights advocates as a major threat to \u201cnational stability,\u201d records and interviews show.<\/p>\n<p>One of the program\u2019s key targets in 2012 was Rori Donaghy, according to former Raven operatives and program documents. Donaghy, then 25, was a British journalist and activist who authored articles critical of the country\u2019s human rights record. In 2012, he wrote an opinion piece for the Guardian criticizing the UAE government\u2019s activist crackdown and warning that, if it continued, \u201cthose in power face an uncertain future.\u201d<\/p>\n<p>Before 2012, the former operatives said, the nascent UAE intelligence-gathering operation largely relied on Emirati agents breaking into the homes of targets while they were away and physically placing spyware on computers. But as the Americans built up Raven, the remote hacking of Donaghy offered the contractors a tantalizing win they could present to the client.<\/p>\n<p>Because of sensitivity over human rights violations and press freedom in the West, the operation against a journalist-activist was a gamble. \u201cThe potential risk to the UAE Government and diplomatic relations with Western powers is great if the operation can be traced back to UAE,\u201d 2012 program documents said.<\/p>\n<p>To get close to Donaghy, a Raven operative should attempt to \u201cingratiate himself to the target by espousing similar beliefs,\u201d the cyber-mercenaries wrote. Donaghy would be \u201cunable to resist an overture of this nature,\u201d they believed.<\/p>\n<p>Posing as a single human rights activist, Raven operatives emailed Donaghy asking for his help to \u201cbring hope to those who are long suffering,\u201d the email message said.<\/p>\n<p>The operative convinced Donaghy to download software he claimed would make messages \u201cdifficult to trace.\u201d In reality, the malware allowed the Emiratis to continuously monitor Donaghy\u2019s email account and Internet browsing. The surveillance against Donaghy, who was given the codename Gyro, continued under Stroud and remained a top priority for the Emirates for years, Stroud said.<\/p>\n<p>Donaghy eventually became aware that his email had been hacked. In 2015, after receiving another suspicious email, he contacted a security researcher at Citizen Lab, a Canadian human rights and digital privacy group, who discovered hackers had been attempting for years to breach his computer.<\/p>\n<p>Reached by phone in London, Donaghy, now a graduate student pursuing Arab studies, expressed surprise he was considered a top national security target for five years. Donaghy confirmed he was targeted using the techniques described in the documents.<\/p>\n<p>\u201cI\u2019m glad my partner is sitting here as I talk on the phone because she wouldn\u2019t believe it,\u201d he said. Told the hackers were American mercenaries working for the UAE, Donaghy, a British citizen, expressed surprise and disgust. \u201cIt feels like a betrayal of the alliance we have,\u201d he said.<\/p>\n<p>Stroud said her background as an intelligence operative made her comfortable with human rights targets as long as they weren\u2019t Americans. \u201cWe\u2019re working on behalf of this country\u2019s government, and they have specific intelligence objectives which differ from the U.S., and understandably so,\u201d Stroud said. \u201cYou live with it.\u201d<\/p>\n<p>Prominent Emirati activist Ahmed Mansoor, given the code name Egret, was another target, former Raven operatives say. For years, Mansoor publicly criticized the country\u2019s war in Yemen, treatment of migrant workers and detention of political opponents.<\/p>\n<p>In September 2013, Raven presented senior NESA officials with material taken from Mansoor\u2019s computer, boasting of the successful collection of evidence against him. It contained screenshots of emails in which Mansoor discussed an upcoming demonstration in front of the UAE\u2019s Federal Supreme Court with family members of imprisoned dissidents.<\/p>\n<div class=\"Image_container\" tabindex=\"-1\">\n<div class=\"LazyImage_container LazyImage_dark\"><img decoding=\"async\" src=\"https:\/\/s2.reutersmedia.net\/resources\/r\/?m=02&amp;d=20190130&amp;t=2&amp;i=1351405010&amp;r=LYNXNPEF0T0RE&amp;w=20\" aria-label=\"FILE PHOTO: Edward Snowden speaks via video link during a news conference in New York , U.S., September 14, 2016. REUTERS\/Brendan McDermid\/File Photo\"\/>\n<\/div>\n<div class=\"Image_caption\"> <span>FILE PHOTO: Edward Snowden speaks via video link during a news conference in New York , U.S., September 14, 2016. REUTERS\/Brendan McDermid\/File Photo<\/span><\/div>\n<\/div>\n<p>Raven told UAE security forces Mansoor had photographed a prisoner he visited in jail, against prison policy, \u201cand then attempted to destroy the evidence on his computer,\u201d said a Powerpoint presentation reviewed by Reuters.<\/p>\n<p>Citizen Lab published research in 2016 showing that Mansoor and Donaghy were targeted by hackers \u2014 with researchers speculating that the UAE government was the most likely culprit. Concrete evidence of who was responsible, details on the use of American operatives, and first-hand accounts from the hacking team are reported here for the first time.<\/p>\n<p>Mansoor was convicted in a secret trial in 2017 of damaging the country\u2019s unity and sentenced to 10 years in jail. He is now held in solitary confinement, his health declining, a person familiar with the matter said.<\/p>\n<p>Mansoor\u2019s wife, Nadia, has lived in social isolation in Abu Dhabi. Neighbors are avoiding her out of fear security forces are watching.<\/p>\n<p>They are correct. By June 2017 Raven had tapped into her mobile device and given her the code name Purple Egret, program documents reviewed by Reuters show.<\/p>\n<p>To do so, Raven utilized a powerful new hacking tool called Karma, which allowed operatives to break into the iPhones of users around the world.<\/p>\n<p>Karma allowed Raven to obtain emails, location, text messages and photographs from iPhones simply by uploading lists of numbers into a preconfigured system, five former project employees said. Reuters had no contact with Mansoor\u2019s wife.<\/p>\n<p>Karma was particularly potent because it did not require a target to click on any link to download malicious software. The operatives understood the hacking tool to rely on an undisclosed vulnerability in Apple\u2019s iMessage text messaging software.<\/p>\n<p>In 2016 and 2017, it would be used against hundreds of targets across the Middle East and Europe, including governments of Qatar, Yemen, Iran and Turkey, documents show. Raven used Karma to hack an iPhone used by the Emir of Qatar, Sheikh Tamim bin Hamad al-Thani, as well as the phones of close associates and his brother. The embassy of Qatar in Washington did not respond to requests for comment.<\/p>\n<h3>WHAT WASHINGTON KNEW<\/h3>\n<p>Former Raven operatives believed they were on the right side of the law because, they said, supervisors told them the mission was blessed by the U.S. government.<\/p>\n<p>Although the NSA wasn\u2019t involved in day-to-day operations, the agency approved of and was regularly briefed on Raven\u2019s activities, they said Baier told them.<\/p>\n<p>CyberPoint founder Gumtow said his company was not involved in hacking operations.<\/p>\n<p>\u201cWe were not doing offensive operations. Period,\u201d Gumtow said in a phone interview. \u201cIf someone was doing something rogue, then that\u2019s painful for me to think they would do that under our banner.\u201d<\/p>\n<p>Instead, he said, the company trained Emiratis to defend themselves through a program with the country\u2019s Ministry of Interior.<\/p>\n<p>A review of internal Raven documents shows Gumtow\u2019s description of the program as advising the Interior Ministry on cyber defense matches an \u201cunclassified cover story\u201d Raven operatives were instructed to give when asked about the project. Raven employees were told to say they worked for the Information Technology and Interoperability Office, the program document said.<\/p>\n<p>Providing sensitive defense technologies or services to a foreign government generally requires special licenses from the U.S. State and Commerce Departments. Both agencies declined to comment on whether they issued such licenses to CyberPoint for its operations in the UAE. They added that human rights considerations figure into any such approvals.<\/p>\n<p>But a 2014 State Department agreement with CyberPoint showed Washington understood the contractors were helping launch cyber surveillance operations for the UAE. The approval document explains CyberPoint\u2019s contract is to work alongside NESA in the \u201cprotection of UAE sovereignty\u201d through \u201ccollection of information from communications systems inside and outside the UAE\u201d and \u201csurveillance analysis.\u201d<\/p>\n<p>One section of the State Department approval states CyberPoint must receive specific approval from the NSA before giving any presentations pertaining to \u201ccomputer network exploitation or attack.\u201d Reuters identified dozens of such presentations Raven gave to NESA describing attacks against Donaghy, Mansoor and others. It\u2019s unclear whether the NSA approved Raven\u2019s operations against specific targets.<\/p>\n<p>The agreement clearly forbade CyberPoint employees from targeting American citizens or companies. As part of the agreement, CyberPoint promised that its own staff and even Emirati personnel supporting the program \u201cwill not be used to Exploit U.S. Persons, (i.e. U.S. citizens, permanent resident aliens, or U.S. companies.)\u201d Sharing classified U.S. information, controlled military technology, or the intelligence collection methods of U.S. agencies was also prohibited.<\/p>\n<p>Gumtow declined to discuss the specifics of the agreement. \u201cTo the best of my ability and to the best of my knowledge, we did everything as requested when it came to U.S. rules and regulations,\u201d he said. \u201cAnd we provided a mechanism for people to come to me if they thought that something that was done was wrong.\u201d<\/p>\n<p>An NSA spokesman declined to comment on Project Raven.<\/p>\n<p>A State Department spokesman declined to comment on the agreement but said such licenses do not authorize people to engage in human rights abuses.<\/p>\n<p>By late 2015, some Raven operatives said their missions became more audacious.<\/p>\n<p>For instance, instead of being asked to hack into individual users of an Islamist Internet forum, as before, the American contractors were called on to create computer viruses that would infect every person visiting a flagged site. Such wholesale collection efforts risked sweeping in the communications of American citizens, stepping over a line the operators knew well from their NSA days.<\/p>\n<p>U.S. law generally forbids the NSA, CIA and other U.S. intelligence agencies from monitoring U.S. citizens.<\/p>\n<p>Working together with managers, Stroud helped create a policy for what to do when Raven swept up personal data belonging to Americans. The former NSA employees were instructed to mark that material for deletion. Other Raven operatives would also be notified so the American victims could be removed from future collection.<\/p>\n<p>As time went on, Stroud noticed American data flagged for removal show up again and again in Raven\u2019s NESA-controlled data stores.<\/p>\n<p>Still, she found the work exhilarating. \u201cIt was incredible because there weren\u2019t these limitations like there was at the NSA. There wasn\u2019t that bullshit red tape,\u201d she said. \u201cI feel like we did a lot of good work on counterterrorism.\u201d<\/p>\n<h3>DARKMATTER AND DEPARTURES<\/h3>\n<p>When Raven was created in 2009, Abu Dhabi had little cyber expertise. The original idea was for Americans to develop and run the program for five to 10 years until Emirati intelligence officers were skilled enough to take over, documents show. By 2013, the American contingent at Raven numbered between a dozen and 20 members at any time, accounting for the majority of the staff.<\/p>\n<p>In late 2015, the power dynamic at the Villa shifted as the UAE grew more uncomfortable with a core national security program being controlled by foreigners, former staff said. Emirati defense officials told Gumtow they wanted Project Raven to be run through a domestic company, named DarkMatter.<\/p>\n<p>Raven\u2019s American creators were given two options: Join DarkMatter or go home.<\/p>\n<p>At least eight operatives left Raven during this transition period. Some said they left after feeling unsettled about the vague explanations Raven managers provided when pressed on potential surveillance against other Americans.<\/p>\n<p>DarkMatter was founded in 2014 by Faisal Al Bannai, who also created Axiom, one of the largest sellers of mobile devices in the region. DarkMatter markets itself as an innovative developer of defensive cyber technology. A 2016 Intercept article reported the company assisted UAE\u2019s security forces in surveillance efforts and was attempting to recruit foreign cyber experts.<\/p>\n<p>The Emirati company of more than 650 employees publicly acknowledges its close business relationship to the UAE government, but denies involvement in state-backed hacking efforts.<\/p>\n<p>Project Raven\u2019s true purpose was kept secret from most executives at DarkMatter, former operatives said.<\/p>\n<p>DarkMatter did not respond to requests for comment. Al Bannai and the company\u2019s current chief executive, Karim Sabbagh, did not respond to interview requests. A spokeswoman for the UAE Ministry of Foreign Affairs declined to comment.<\/p>\n<p>Under DarkMatter, Project Raven continued to operate in Abu Dhabi from the Villa, but pressure escalated for the program to become more aggressive.<\/p>\n<p>Before long, senior NESA officers were given more control over daily functions, former Raven operatives said, often leaving American managers out of the loop. By mid-2016, the Emirates had begun making an increasing number of sections of Raven hidden from the Americans still managing day-to-day operations. Soon, an \u201cEmirate-eyes only\u201d designation appeared for some hacking targets.<\/p>\n<h3>FBI QUESTIONS<\/h3>\n<p>By 2016, FBI agents began approaching DarkMatter employees reentering the United States to ask about Project Raven, three former operatives said.<\/p>\n<p>The FBI wanted to know: Had they been asked to spy on Americans? Did classified information on U.S. intelligence collection techniques and technologies end up in the hands of the Emiratis?<\/p>\n<p>Two agents approached Stroud in 2016 at Virginia\u2019s Dulles airport as she was returning to the UAE after a trip home. Stroud, afraid she might be under surveillance by the UAE herself, said she brushed off the FBI investigators. \u201cI\u2019m not telling you guys jack,\u201d she recounted.<\/p>\n<p>Stroud had been promoted and given even more access to internal Raven databases the previous year. A lead analyst, her job was to probe the accounts of potential Raven targets and learn what vulnerabilities could be used to penetrate their email or messaging systems.<\/p>\n<p>Targets were listed in various categories, by country. Yemeni targets were in the \u201cbrown category,\u201d for example. Iran was gray.<\/p>\n<p>One morning in spring 2017, after she finished her own list of targets, Stroud said she began working on a backlog of other assignments intended for a NESA officer. She noticed that a passport page of an American was in the system. When Stroud emailed supervisors to complain, she was told the data had been collected by mistake and would be deleted, according to an email reviewed by Reuters.<\/p>\n<p>Concerned, Stroud began searching a targeting request list usually limited to Raven\u2019s Emirati staff, which she was still able to access because of her role as lead analyst. She saw that security forces had sought surveillance against two other Americans.<\/p>\n<p>When she questioned the apparent targeting of Americans, she received a rebuke from an Emirati colleague for accessing the targeting list, the emails show. The target requests she viewed were to be processed by \u201ccertain people. You are not one of them,\u201d the Emirati officer wrote.<\/p>\n<p>Days later, Stroud said she came upon three more American names on the hidden targeting queue.<\/p>\n<p>Those names were in a category she hadn\u2019t seen before: the \u201cwhite category\u201d \u2014 for Americans. This time, she said, the occupations were listed: journalist.<\/p>\n<p>\u201cI was sick to my stomach,\u201d she said. \u201cIt kind of hit me at that macro level realizing there was a whole category for U.S. persons on this program.\u201d<\/p>\n<p>Once more, she said she turned to manager Baier. He attempted to downplay the concern and asked her to drop the issue, she said. But he also indicated that any targeting of Americans was supposed to be done by Raven\u2019s Emirate staff, said Stroud and two other people familiar with the discussion.<\/p>\n<p>Stroud\u2019s account of the incidents was confirmed by four other former employees and emails reviewed by Reuters.<\/p>\n<div class=\"Slideshow_container Slideshow_small Slideshow_standard\">\n<div class=\"Slideshow_preview-container\">\n<div class=\"LazyImage_container LazyImage_dark\"><img decoding=\"async\" src=\"https:\/\/s2.reutersmedia.net\/resources\/r\/?m=02&amp;d=20190130&amp;t=2&amp;i=1351405013&amp;r=LYNXNPEF0T0RC\"\/>\n<\/div>\n<p> Slideshow <span class=\"Slideshow_count\">(12 Images)<\/span><\/div>\n<\/div>\n<p>When Stroud kept raising questions, she said, she was put on leave by superiors, her phones and passport were taken, and she was escorted from the building. Stroud said it all happened so quickly she was unable to recall the names of the three U.S. journalists or other Americans she came across in the files. \u201cI felt like one of those national security targets,\u201d she said. \u201cI\u2019m stuck in the country, I\u2019m being surveilled, I can\u2019t leave.\u201d<\/p>\n<p>After two months, Stroud was allowed to return to America. Soon after, she fished out the business card of the FBI agents who had confronted her at the airport.<\/p>\n<p>\u201cI don\u2019t think Americans should be doing this to other Americans,\u201d she told Reuters. \u201cI\u2019m a spy, I get that. I\u2019m an intelligence officer, but I\u2019m not a bad one.\u201d<\/p>\n<div class=\"Attribution_container\" readability=\"7\">\n<div class=\"Attribution_attribution\" readability=\"9\">\n<p class=\"Attribution_content\">By Christopher Bing and Joel Schectman in Washington. Editing by Ronnie Greene, Jonathan Weber and Michael Williams<\/p>\n<\/div>\n<\/div>\n<div class=\"StandardArticleBody_trustBadgeContainer\"><span class=\"StandardArticleBody_trustBadgeTitle\">Our Standards:<\/span><span class=\"trustBadgeUrl\"><a href=\"http:\/\/thomsonreuters.com\/en\/about-us\/trust-principles.html\">The Thomson Reuters Trust Principles.<\/a><\/span><\/div>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/29772\/Inside-The-UAEs-Secret-Hacking-Team-Of-US-Mercenaries.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":24847,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[5681],"class_list":["post-24846","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinegovernmentusaphonecyberwarspyware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Inside The UAE&#039;s Secret Hacking Team Of US Mercenaries 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Inside The UAE&#039;s Secret Hacking Team Of US Mercenaries 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-01-31T17:03:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1\" \/>\n\t<meta property=\"og:image:height\" content=\"1\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"22 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Inside The UAE&#8217;s Secret Hacking Team Of US Mercenaries\",\"datePublished\":\"2019-01-31T17:03:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/\"},\"wordCount\":4426,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png\",\"keywords\":[\"headline,government,usa,phone,cyberwar,spyware\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/\",\"name\":\"Inside The UAE's Secret Hacking Team Of US Mercenaries 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png\",\"datePublished\":\"2019-01-31T17:03:56+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png\",\"width\":1,\"height\":1},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,government,usa,phone,cyberwar,spyware\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinegovernmentusaphonecyberwarspyware\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Inside The UAE&#8217;s Secret Hacking Team Of US Mercenaries\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Inside The UAE's Secret Hacking Team Of US Mercenaries 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/","og_locale":"en_US","og_type":"article","og_title":"Inside The UAE's Secret Hacking Team Of US Mercenaries 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-01-31T17:03:56+00:00","og_image":[{"width":1,"height":1,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"22 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Inside The UAE&#8217;s Secret Hacking Team Of US Mercenaries","datePublished":"2019-01-31T17:03:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/"},"wordCount":4426,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png","keywords":["headline,government,usa,phone,cyberwar,spyware"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/","url":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/","name":"Inside The UAE's Secret Hacking Team Of US Mercenaries 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png","datePublished":"2019-01-31T17:03:56+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/inside-the-uaes-secret-hacking-team-of-us-mercenaries.png","width":1,"height":1},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/inside-the-uaes-secret-hacking-team-of-us-mercenaries\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,government,usa,phone,cyberwar,spyware","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinegovernmentusaphonecyberwarspyware\/"},{"@type":"ListItem","position":3,"name":"Inside The UAE&#8217;s Secret Hacking Team Of US Mercenaries"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/24846","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=24846"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/24846\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/24847"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=24846"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=24846"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=24846"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}