Saturday, June 3, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

Russian SolarWinds Culprits Launch Fresh Barrage of Espionage Cyberattacks

justmattg by justmattg
April 15, 2023
in Cyber Security
0
Crypto Drainers Are Ready to Ransack Investor Wallets
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter



As part of its ongoing invasion of Ukraine, Russian intelligence has once again enlisted the services of hacker group Nobelium/APT29, this time to spy on foreign ministries and diplomats from NATO-member states, as well as other targets in the European Union and Africa.

The timing also dovetails with a spate of attacks on Canadian infrastructure, also believed to be linked to Russia.

The Polish Military Counterintelligence Service and the CERT team in Poland issued an alert on April 13, along with indicators of compromise, warning potential targets of the espionage campaign about the threat. Nobelium, as the group is designated by Microsoft, also named APT29 by Mandiant, isn’t new to the nation-state espionage game, the group was behind the infamous SolarWinds supply chain attack nearly three years ago.

Now, APT29 is back with a whole new set of malware tools and reported marching orders to infiltrate the diplomatic corps of countries supportive of Ukraine, the Polish military and CERT alert explained.

APT29 Is Back With New Orders

In every instance, the advanced persistent threat (APT) begins its attack with a well-conceived spear-phishing email, according to the Polish alert.

“Emails impersonating embassies of European countries were sent to selected personnel at diplomatic posts,” authorities explained. “The correspondence contained an invitation to a meeting or to work together on documents.”

The message would then direct the recipient to click on a link or download a PDF to access the ambassador’s calendar, or get meeting details — both send the targets to a malicious site loaded with the threat group’s “signature script,” which the report identifies as “Envyscout.”

“It utilizes the HTML-smuggling technique — whereby a malicious file placed on the page is decoded using JavaScript when the page is opened and then downloaded on the victim’s device,” Polish authorities added. “This makes the malicious file more difficult to detect on the server side where it is stored.”

The malicious site also sends the targets a message reassuring them they downloaded the correct file, the alert said.

“Spear-phishing attacks are successful when the communications are well written, use personal information to demonstrate familiarity with the target, and appear to come from a legitimate source,” Patrick Harr, CEO of SlashNext, tells Dark Reading about the campaign. “This espionage campaign meets all of the criteria for success.”

One phishing email, for instance, impersonated the Polish embassy, and, interestingly, throughout the course of the observed campaign, the Envyscout tool was tweaked three times with obfuscation improvements, the Polish authorities noted.

Once compromised, the group uses modified versions of Snowyamber downloader, Halfrig, which runs Cobalt Strike as embedded code, and Quarterrig, which shares code with Halfrig, the Polish alert said.

“We are seeing an increase in these attacks where the bad actor uses multiple stages in a campaign to adjust and improve success,” Harr adds. “They employ automation and machine learning techniques to identify what is evading detection and modify subsequent attacks to improve success.”
Governments, diplomats, international organizations, and non-governmental organizations (NGOs) should be on high alert for this, and other, Russian espionage efforts, according to Polish cybersecurity authorities.

“The Military Counterintelligence Service and CERT.PL strongly recommend that all entities that may be in the actor’s area of interest implement configuration changes to disrupt the delivery mechanism that was used in the described campaign,” officials said.

Russian-Linked Attacks on Canada’s Infrastructure

Besides warnings from Polish cybersecurity officials, over the past week, Canada’s Prime Minister Justin Trudeau made public statements about a recent spate of Russian-linked cyberattacks aimed at Canadian infrastructure, including denial-of-service attacks on Hydro-Québec, electric utility, the website for Trudeau’s office, the Port of Québec, and Laurentian Bank. Trudeau said the cyberattacks are related to Canada’s support of Ukraine.

“A couple of denial-of-service attacks on government websites, bringing them down for a few hours, is not going to cause us to rethink our unequivocal stance of doing whatever it takes for as long as it takes to support Ukraine,” Trudeau said, according to reports.

The Canadian Centre for Cyber Security boss, Sami Khoury, said at a news conference last week that while there was no damage done to Canada’s infrastructure, “the threat is real.””If you run the critical systems that power our communities, offer Internet access to Canadians, provide health care, or generally operate any of the services Canadians can’t do without, you must protect your systems,” Khoury said. “Monitor your networks. Apply mitigations.”

Russia’s Cybercrime Efforts Rage On

As Russia’s invasion of Ukraine wages on into its second year, Mike Parkin with Vulcan Cyber says the recent campaigns should hardly be a surprise.

“The cybersecurity community has been watching the fallout and collateral damage from the conflict in Ukraine since it started, and we’ve known Russian and pro-Russian threat actors were active against Western targets,” Parkin says. “Considering the levels of cybercriminal activity we were already dealing with, [these are] just some new tools and new targets — and a reminder to make sure our defenses are up to date and properly configured.”



Source link

READ ALSO

The Importance of Managing Your Data Security Posture

‘PostalFurious’ SMS Attacks Target UAE Citizens for Data Theft

Related Posts

The Importance of Managing Your Data Security Posture
Cyber Security

The Importance of Managing Your Data Security Posture

June 3, 2023
Undetected Attacks Against Middle East Targets Conducted Since 2020
Cyber Security

‘PostalFurious’ SMS Attacks Target UAE Citizens for Data Theft

June 2, 2023
New Botnet Malware ‘Horabot’ Targets Spanish-Speaking Users in Latin America
Cyber Security

New Botnet Malware ‘Horabot’ Targets Spanish-Speaking Users in Latin America

June 2, 2023
Evasive QBot Malware Leverages Short-lived Residential IPs for Dynamic Attacks
Cyber Security

Evasive QBot Malware Leverages Short-lived Residential IPs for Dynamic Attacks

June 2, 2023
Malicious PyPI Packages Using Compiled Python Code to Bypass Detection
Cyber Security

Malicious PyPI Packages Using Compiled Python Code to Bypass Detection

June 1, 2023
Cybercriminals Targeting Apache NiFi Instances for Cryptocurrency Mining
Cyber Security

Cybercriminals Targeting Apache NiFi Instances for Cryptocurrency Mining

June 1, 2023
Next Post
Biometric Ticketing Comes to Osaka Station: Identity News Digest

Biometrics Vendors Gear Up for HIMSS: Identity News Digest

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

Zighra Gets Canada’s OK, Worldcoin Launches ‘World ID’: Identity News Digest

Zighra Gets Canada’s OK, Worldcoin Launches ‘World ID’: Identity News Digest

March 22, 2023
Researchers Uncover New BGP Flaws in Popular Internet Routing Protocol Software

Researchers Uncover New BGP Flaws in Popular Internet Routing Protocol Software

May 2, 2023
Dridex Malware Now Attacking macOS Systems with Novel Infection Method

Dridex Malware Now Attacking macOS Systems with Novel Infection Method

January 7, 2023
Leveraging Behavioral Analysis to Catch Living-Off-the-Land Attacks

Leveraging Behavioral Analysis to Catch Living-Off-the-Land Attacks

March 17, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • The Importance of Managing Your Data Security Posture
  • ‘PostalFurious’ SMS Attacks Target UAE Citizens for Data Theft
  • New Botnet Malware ‘Horabot’ Targets Spanish-Speaking Users in Latin America
  • Evasive QBot Malware Leverages Short-lived Residential IPs for Dynamic Attacks
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.