{"id":372,"date":"2024-07-10T07:45:11","date_gmt":"2024-07-10T05:45:11","guid":{"rendered":"https:\/\/cyber-cerber.com\/blog\/?p=372"},"modified":"2024-11-27T18:53:05","modified_gmt":"2024-11-27T16:53:05","slug":"ais-spoofing-in-the-black-sea-a-quick-osint-demo","status":"publish","type":"post","link":"https:\/\/cyber-cerber.com\/blog\/2024\/07\/10\/ais-spoofing-in-the-black-sea-a-quick-osint-demo\/","title":{"rendered":"AIS spoofing in the Black Sea: a quick OSINT demo"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\">As we all are already aware, the Russian invasion of Ukraine started (officially) on February 24th, 2022, and it came along the so-called, classic war, with many other new, developed, and extensive types of warfare: cyber, radio, psychological, financial, etc.<\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\">This time, I will show you a quick and very simple <a href=\"https:\/\/www.sans.org\/blog\/what-is-open-source-intelligence\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>OSINT<\/strong><\/a> demo, of the <a href=\"https:\/\/www.maritime.dot.gov\/msci\/2023-013-various-gps-interference-ais-spoofing\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>AIS spoofing<\/strong><\/a> and GPS jamming in West side of the Black Sea region.<\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\"><a href=\"https:\/\/navcen.uscg.gov\/automatic-identification-system-overview\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>AIS<\/strong><\/a> stands for Automatic Identification System and is digitally broadcasted information data, over <a href=\"https:\/\/icomuk.co.uk\/How-to-use-a-Marine-VHF-Radio\/3995\/3168\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>VHF<\/strong><\/a>, consisting of ship name, course and speed, classification, call sign, registration number, <a href=\"https:\/\/navcen.uscg.gov\/maritime-mobile-service-identity\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>MMSI<\/strong><\/a>, and other information. The Bridge Officers onboard the vessels are then using such information, as an additional tool, for enhancing the ship&#8217;s safety navigation and operations.<\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\">Since navigation (maritime, aero, auto, etc) is mainly based on the <a href=\"https:\/\/www.gps.gov\/systems\/gps\/space\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>GPS constellation<\/strong><\/a>, the obvious target and scope was to interfere with its functionality in certain areas of interest. <a href=\"https:\/\/gpsjam.org\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>GPSJam<\/strong><\/a> is a live source of such activities.<\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\">Other alternative navigation satellite constellations: <a href=\"https:\/\/www.esa.int\/Applications\/Satellite_navigation\/Galileo\/What_is_Galileo\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Galileo<\/strong><\/a> (owned by the European Space Agency), <a href=\"http:\/\/en.beidou.gov.cn\/SYSTEMS\/System\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>BeiDou<\/strong><\/a> (owned by the Chinese state), etc.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"541\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/GPS-.png\" alt=\"GPS Jam\" class=\"wp-image-376\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/GPS-.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/GPS--300x158.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/GPS--768x406.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">Now, returning to our AIS topic, today, 10.07.2024, at 03:20 <strong><a href=\"https:\/\/www.timeanddate.com\/time\/zone\/timezone\/utc\" target=\"_blank\" rel=\"noreferrer noopener\">UTC<\/a><\/strong>, I did a quick research on some publicly available sources, and here is what I&#8217;ve got:<\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\">On <a href=\"https:\/\/www.marinetraffic.com\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Marinetraffic<\/strong><\/a>, on an overall view over the western side of the Black Sea, you may notice some unusual reported positions inside of the Crimea Peninsula, just NE of Sevastopol.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"435\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/marinetraffic-all.png\" alt=\"Marinetraffic Black Sea\" class=\"wp-image-380\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/marinetraffic-all.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/marinetraffic-all-300x127.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/marinetraffic-all-768x326.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">Zooming in a bit, you&#8217;ll observe that there is no &#8220;water&#8221; in the area, sea, lake or river).<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"465\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-1024x465.png\" alt=\"Marinetraffic\" class=\"wp-image-379\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-1024x465.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-300x136.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-768x348.png 768w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-1536x697.png 1536w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-2048x929.png 2048w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-1200x545.png 1200w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-1-1980x898.png 1980w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">Going to <a href=\"https:\/\/www.google.com\/maps\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Google Maps<\/strong><\/a>, and finding the same location, you might wonder (or not), what few ships will do in the area of an airport&#8230; <a href=\"https:\/\/new.sipaero.ru\/en\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Simferopol Airport<\/strong><\/a> (between Rodykove and Ukromnoye area).<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"493\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Maps-Google.png\" alt=\"Google Maps Crimea\" class=\"wp-image-381\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Maps-Google.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Maps-Google-300x144.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Maps-Google-768x370.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">Then, I picked up randomly, an AIS of the bulk carrier, named &#8220;Magic L&#8221;.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"428\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-1024x428.png\" alt=\"Marine Traffic - Magic L\" class=\"wp-image-383\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-1024x428.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-300x125.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-768x321.png 768w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-1536x642.png 1536w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-2048x855.png 2048w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-1200x501.png 1200w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Marinetraffic-Magic-L-1980x827.png 1980w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">To verify the data is accurate, I cheked the same AIS on <a href=\"https:\/\/www.vesselfinder.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Vesselfinder<\/strong><\/a>, and surprise, here the position on the map was correct.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"591\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-1024x591.png\" alt=\"Vesselfinder - Magic L\" class=\"wp-image-384\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-1024x591.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-300x173.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-768x443.png 768w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-1536x886.png 1536w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-2048x1182.png 2048w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-1200x692.png 1200w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Vesselfinder-Magic-L-1980x1143.png 1980w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">As the minimum rule of 3rd, I check on another AIS marine traffic source, <a href=\"https:\/\/www.shiplocation.com\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Shiplocation<\/strong><\/a>, and the confusion increased as pinpointing the ship&#8217;s name and AIS is resulted in double locations&#8230;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"500\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-1024x500.png\" alt=\"Shiplocation Magic L\" class=\"wp-image-385\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-1024x500.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-300x146.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-768x375.png 768w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-1536x750.png 1536w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-2048x999.png 2048w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-1200x586.png 1200w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/07\/Shiplocation-Magic-L-1980x966.png 1980w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p class=\"has-primary-background-color has-background\">The <a href=\"https:\/\/www.flightradar24.com\/blog\/gps-jamming-map\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>air traffic<\/strong><\/a> is affected too due to the shorter response time needed for taking the proper actions, the maritime AIS traffic spoofing is meant to create confusion, traffic jams, chaos or even accidents.<\/p>\n\n\n\n<p class=\"has-primary-background-color has-background\">An extensive OSINT &amp; Radio survey will follow, so stay tuned and safe!<\/p>\n\n\n\n<p class=\"has-accent-color has-subtle-background-background-color has-text-color has-background has-link-color wp-elements-cb2f3162198216715be73b6a9747e539\">Later update: on October 24th, the national TV post, ProTV, confirmed my above statements: <a href=\"https:\/\/stirileprotv.ro\/stiri\/actualitate\/sistemele-de-navigatie-gps-dupa-care-se-ghideaza-avioanele-in-zbor-au-fost-lovite-intens-de-bruiaj-de-unde-vin-interferente.html\" target=\"_blank\" rel=\"noreferrer noopener\">Sistemele de naviga\u021bie GPS dup\u0103 care se ghideaz\u0103 avioanele \u00een zbor au fost lovite intens de bruiaj. De unde vin interferen\u021be.<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/www.omnismares.com\" target=\"_blank\" rel=\"noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"252\" src=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/03\/OmnisMares-logo-1024x252.png\" alt=\"SC OmnisMares SRL\" class=\"wp-image-354\" style=\"width:366px;height:auto\" srcset=\"https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/03\/OmnisMares-logo-1024x252.png 1024w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/03\/OmnisMares-logo-300x74.png 300w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/03\/OmnisMares-logo-768x189.png 768w, https:\/\/cyber-cerber.com\/blog\/wp-content\/uploads\/2024\/03\/OmnisMares-logo.png 1124w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure><\/div>\n\n\n<p class=\"has-text-align-center has-secondary-background-color has-background\">InfoSec &amp; ICT Maritime &amp; SMB\/SOHO:<\/p>\n\n\n\n<p class=\"has-text-align-center has-subtle-background-color has-secondary-background-color has-text-color has-background has-link-color wp-elements-538286a77e7bf8494232b1cd48ccd87d\"><strong><a href=\"https:\/\/www.omnismares.com\">OmnisMares.com<\/a> <\/strong>     <a href=\"https:\/\/www.cyber-cerber.com\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Cyber-Cerber.com<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we all are already aware, the Russian invasion of Ukraine started (officially) on February 24th, 2022, and it came along the so-called, classic war, with many other new, developed, and extensive types of warfare: cyber, radio, psychological, financial, etc. This time, I will show you a quick and very simple OSINT demo, of the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":374,"comment_status":"closed","ping_status":"open","sticky":false,"template":"templates\/template-full-width.php","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[89,88,90,29,82,91,92,93],"class_list":["post-372","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber","tag-ais-maritime-traffic","tag-ais-spoofing","tag-black-sea-warfare","tag-cybersecurity","tag-cyrcomms","tag-gps-jamming","tag-ict-maritime","tag-infosec-maritime"],"_links":{"self":[{"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/posts\/372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/comments?post=372"}],"version-history":[{"count":19,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/posts\/372\/revisions"}],"predecessor-version":[{"id":401,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/posts\/372\/revisions\/401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/media\/374"}],"wp:attachment":[{"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/media?parent=372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/categories?post=372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyber-cerber.com\/blog\/wp-json\/wp\/v2\/tags?post=372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}