The last day of June set the agenda for all of July. On 30 June 2014 Symantec published a report on a group it named Dragonfly, and the finding that mattered was not that energy companies in the United States and Europe had been compromised but how. Three European industrial suppliers had had installers on their own websites quietly swapped for copies carrying a remote-access tool. One was eWON, a Belgian firm whose eCatcher client gives engineers remote access to programmable logic controllers; the trojanised setup file was on the site in January 2014 and, Symantec said, had already been downloaded roughly 250 times by the time the vendor caught it. Nobody was tricked into anything. The engineers who took it were doing exactly what their vendor told them to do.
The tool had a name before it had a story. F-Secure and Symantec called the backdoor Havex — Symantec's own label was Backdoor.Oldrea — and a second family, Trojan.Karagany, travelled alongside. ICS-CERT had issued an alert on 25 June describing malware aimed at industrial control systems, saying it had learned the identities of the three affected vendors from Symantec and F-Secure but withholding them from the public document. What made Havex unusual was a module that used Windows DCOM to hunt for OPC servers — the middleware through which control software talks to plant equipment — and to inventory the tags it found. ICS-CERT's own testing found the scan made several common OPC platforms crash intermittently. It was reconnaissance rather than sabotage, but reconnaissance of a factory floor.
Symantec had reasoned from compilation timestamps: work concentrated Monday to Friday inside a nine-hour window consistent with UTC+4, which it read as Eastern Europe, and it called the operation state-sponsored. On 31 July Kaspersky Lab published its own account and declined to follow. It counted more than 2,800 victims worldwide and identified 101 organisations among them, the heaviest concentrations in the United States, Spain, Japan, Germany, France, Italy, Turkey, Ireland, Poland and China. Industrial and machinery firms led its victim list, then manufacturing, pharmaceuticals, construction, education and information technology — an industrial campaign more than an energy one. Nothing in the data settled the actor's origin, Kaspersky said, and it renamed the group Crouching Yeti. Two vendors, a month apart, agreed on the malware and disagreed about everything else.
The ending took eight years. On 24 March 2022 the United States Department of Justice unsealed an indictment returned in Kansas on 26 August 2021 against three officers of the Russian Federal Security Service's Military Unit 71330 — known to researchers as Center 16, Energetic Bear and Dragonfly. They were Pavel Aleksandrovich Akulov, then 36, Mikhail Mikhailovich Gavrilov, 42, and Marat Valeryevich Tyukov, 39. The department described the technique precisely: Havex concealed inside legitimate vendor updates, alongside spearphishing and watering holes, on more than 17,000 devices and at entities in more than 135 countries between 2012 and 2014. A later phase, it said, reached the business network of the Wolf Creek nuclear plant in Burlington, Kansas. The State Department offered $10 million for information. None of the three has been arrested.
A talk pulled, an attack found
On 21 July 2014 Black Hat pulled a briefing from its Las Vegas schedule — "You Don't Have to be the NSA to Break Tor: Deanonymizing Users on a Budget", by Alexander Volynkin and Michael McCord of the CERT division at Carnegie Mellon University's Software Engineering Institute. The material, the conference said, had not been cleared for release by the university. Nine days later the Tor Project published an advisory. About 115 relays, some 6.4 per cent of the network's guard capacity, had joined on 30 January and were removed on 4 July, encoding hidden-service names for one another by alternating ordinary relay cells with relay-early cells — a traffic-confirmation attack. Anyone who ran or looked up a hidden service between early February and 4 July should assume they were affected. Tor thought it likely, without proof, that the relays and the pulled talk were the same work. The rest emerged slowly. In November 2015 Tor alleged the FBI had paid the university at least $1 million; the university denied any such payment, noting it is served with subpoenas from time to time. In February 2016 Judge Richard A. Jones, in the Silk Road 2.0 prosecution of Brian Farrell in Seattle, wrote that the institute's Tor research had been funded by the Department of Defense, that Farrell's address came by subpoena on the institute — and that obtaining it that way was not a Fourth Amendment search.
A charity, a ticket exchange and a bank
On 21 July Brian Krebs wrote that banks tracing fraudulent card charges had converged on Goodwill Industries stores across the United States, and the charity confirmed it was working with federal investigators. What had happened took six more weeks to establish: in early September Goodwill said the compromise lay with a third party it would not name, identified a fortnight later as C&K Systems of Murrells Inlet, South Carolina, which ran point-of-sale environments for 20 of its 165 independent member organisations. About 868,000 cards were exposed across roughly 330 stores, the malware present intermittently from 10 February 2013 to 14 August 2014. On 23 July the Manhattan District Attorney's office and the Secret Service announced charges over a ring said to have taken more than $10 million in electronic tickets from StubHub, with about twenty suspects raided in the United States, Canada and Britain and the alleged organiser, Vadim Polyakov of St Petersburg, detained on holiday in Spain. Investigators said the accounts had been entered with passwords stolen elsewhere; the exchange itself had not been breached. On 24 July the European Central Bank said a database serving its public website — event registrations, kept apart from internal systems — had been raided. Most of the data were encrypted, it said; email addresses, some street addresses and telephone numbers were not. Around 20,000 addresses were reported taken, though the bank's own statement carried no number. The theft had surfaced when an anonymous message arrived asking for money.
A friendly country, a first budget
India's July began with a document from someone else's archive. At the end of June the Washington Post, working from material supplied by Edward Snowden, reported that a 2010 certification approved by the United States Foreign Intelligence Surveillance Court had authorised the National Security Agency to collect on 193 foreign governments and on a list of organisations that included six political parties — among them Pakistan's PPP, Egypt's Muslim Brotherhood and India's Bharatiya Janata Party. The BJP had been in opposition in 2010. By July 2014 it was the government. On 2 July the Ministry of External Affairs summoned a senior American diplomat; its spokesman, Syed Akbaruddin, said India had asked whether such collection had been authorised and had taken place, and that if it had, it was "highly objectionable". Delhi had raised NSA collection twice during 2013 and was still waiting for answers.
Eight days later, on 10 July, Arun Jaitley presented the new government's first budget. Paragraph 62 proposed a pan-India Digital India programme — village-level broadband, services delivered over IT platforms, a National Rural Internet and Technology Mission, an e-Kranti scheme for government service delivery — and put ₹500 crore behind it; ₹7,060 crore went to a hundred smart cities. Little was said about defending it. The Department of Electronics and Information Technology's cyber-security allocation for 2014-15 was ₹116 crore, and the National Cyber Coordination Centre, costed at about ₹1,000 crore, was still waiting for Cabinet clearance; the Economic Times reported the following January that specialists thought the sum badly short. Digital India was formally launched a year later, on 1 July 2015. The obligations came later still — CERT-In's six-hour reporting direction in 2022, the DPDP Act in 2023.
Show dogs and a three-billion-dollar bet
On 14 July 2014 Harry Shum opened the fifteenth Microsoft Research Faculty Summit in Redmond with three show dogs on stage; a phone pointed at one of them, running a research system called Project Adam behind Cortana, named its breed. Microsoft said Adam had learned from 14 million images in more than 22,000 categories, into a network of over two billion connections trained on thirty times fewer machines than comparable systems, and claimed twice the accuracy at fifty times the speed. Four days earlier IBM had committed $3 billion over five years to chip research, split between silicon at seven nanometres and below and whatever might replace it: carbon nanotubes, neuromorphic and cognitive computing, quantum. On 29 July Twitter bought Madbits, a deep-learning image startup founded by Clément Farabet and Louis-Alexandre Etezad-Heydari that had never launched publicly, for an undisclosed sum; it became the seed of Twitter Cortex, and Farabet is now vice-president of research at Google DeepMind.
Project Zero, and what went undetected
On 15 July 2014 Google announced Project Zero, a team paid to hunt zero-day flaws in any widely used software rather than only its own. Bugs would go to the vendor alone, then into a public database once patched, each vendor's time to fix on view. Chris Evans of Chrome security led it; Tavis Ormandy, Ben Hawkes and Ian Beer were named at launch and George Hotz joined as an intern, their time given wholly, Google said, to "improving security across the Internet". The ninety-day deadline attached to it is argued over still, first and loudest with Microsoft in January 2015. On 30 July Offensive Security disclosed three privilege-escalation flaws in Symantec Endpoint Protection, found during a client's penetration test, where the software bought to protect the client was the way in; Symantec said the fault sat in one component, was not reachable remotely, and affected only clients running it. The next day US-CERT and the Secret Service warned of Backoff, point-of-sale malware circulating since at least October 2013 and, they said, largely undetected by anti-virus vendors.
⏳ Time capsule — July 2014
- On 8 July Germany beat Brazil 7–1 in the World Cup semi-final at Belo Horizonte, the largest winning margin in the history of the fixture.
- On 13 July Germany beat Argentina 1–0 in the final at the Maracanã in Rio de Janeiro, Mario Götze scoring in extra time.
- On 17 July Malaysia Airlines Flight 17, flying from Amsterdam to Kuala Lumpur, was shot down over Donetsk Oblast in eastern Ukraine; all 298 people aboard, 283 passengers and 15 crew, were killed.
- On 23 July the Commonwealth Games opened at Celtic Park in Glasgow, running to 3 August with 4,947 athletes from 71 teams.
The shortest way in
July 2014 is where this archive's supply-chain line begins in earnest. The method — put the payload inside something the target has already decided to trust, then let the target's own change-management carry it in — returns at Kiev in June 2017, when a Ukrainian accounting package's update mechanism delivered NotPetya, and at Austin in December 2020, when a build system produced signed releases with a backdoor inside them. In each case the perimeter held and the door was opened from the inside by an administrator doing the job correctly. What has changed by 2026 is the paperwork: bills of materials, signing requirements and vendor attestations are procurement conditions now rather than aspirations. What has not changed is that a small supplier remains the shortest way into a large one.
The Tor episode left two residues. One is legal — the February 2016 holding that an address learned through relays the government did not run was not protected, a ruling that shaped years of argument about investigative techniques. The other is ethical: experimenting on a live anonymity network without consent or review is now the case study, not the paper, and the relay-early signalling trick itself was closed within days by the Tor releases that followed the advisory. The month's smaller stories aged into constants: Goodwill's loss came through a payment vendor, StubHub's through passwords its customers had used elsewhere, the European Central Bank's with a demand for money. And the canvas fingerprinting ProPublica described on 21 July 2014, found on about five per cent of the top hundred thousand sites, outlived the third-party cookie.