Posts

Showing posts with the label Belarus

Pro-Russia hackers claim responsibility for 'intense, ongoing' cyberattack against Lithuanian websites

By Sean Lyngaas, CNN An "intense, ongoing" cyberattack has hit the websites of government agencies and private firms in Lithuania, the Baltic country's defense ministry said Monday. A Russian-speaking hacking group, known as Killnet , claimed responsibility for at least some of the hacks, saying they were in retaliation for Lithuania blocking the shipment of some goods to the Russian enclave of Kaliningrad, which is wedged between Lithuania and Poland. Monday's cyberattacks were aimed in part at Lithuania's Secure Data Transfer Network, a communications network for government officials that is built to withstand war and other crises, according to the defense ministry. "Part of the Secure National Data Transfer Network users have been unable to access services, work is in progress to restore it to normal," Lithuania's National Cyber Security Centre (NKSC) said in a statement issued by the defense ministry. "It is highly probable that such, or eve...

What is ‘New Profile Pic’ app? Is it safe to use? Cybersecurity experts weigh in

Image
By Geoff Herbert, Penn Live If you’ve seen new Facebook profile pictures that look like a painting or cartoon, then you’ve probably noticed they all appear to come from a website and app called “New Profile Pic.” New Profile Pic, also sometimes written as one word “NewProfilePic,” allows users to submit photos of themselves for an “AI-driven” update that makes them look like works of art. The free app is currently No. 1 on the Apple Store and has exploded in popularity on social media this month. But some have also questioned its safety after some claimed the app “takes all your information and sends it to Moscow” as part of a Russian malware scam. The Daily Mail further suggested the app had Kremlin ties because it was developed by a tech company “overlooking the Moscow River three miles from Red Square,” but is that true? According to fact-checking website Snopes , New Profile Pic was created by a mobile development group called Informe Laboratories, Inc. , and copyrighted by Liner...

Google's TAG provides update on cybersecurity activity in Eastern Europe

Image
By  Dev Discourse Google's Threat Analysis Group (TAG) has observed a continuously growing number of threat actors using the Russia-Ukraine conflict as a lure in phishing and malware campaigns and targeting critical infrastructure entities including oil and gas, telecommunications and manufacturing. "Government-backed actors from China, Iran, North Korea and Russia, as well as various unattributed groups, have used various Ukraine war-related themes in an effort to get targets to open malicious emails or click malicious links. Financially motivated and criminal actors are also using current events as a means for targeting users," TAG wrote in a blog post . Below is the campaign activity observed by Google's TAG: APT28 or Fancy Bear, a threat actor attributed to Russia GRU, was seen targeting users in Ukraine with a new variant of malware which was distributed via email attachments inside of password-protected zip files (ua_report.zip). The malware is a .Net executable...

Pro-Ukraine hackers use Docker images to DDoS Russian sites

Image
By Bill Toulas,       Bleeping Computer Docker images with a download count of over 150,000 have been used to run distributed denial-of-service (DDoS) attacks against a dozen Russian and Belarusian websites managed by government, military, and news organizations. Behind the incidents are believed to be pro-Ukrainian actors such as hacktivists, likely backed by the country's IT Army. DDoS cyberattacks aim to cripple operations of by sending out more requests than the target can handle and becomes unavailable to legitimate clients. Targeting Docker APIs Among the 24 domains targeted include that of the Russian government, the Russian military, and Russian media like the TASS news agency. Two Docker images involved in the attacks were spotted by threat researchers at cybersecurity company CrowdStrike, who observed them being deployed between February and March 2022. Targeting exposed Docker APIs isn’t anything novel, as cryptocurrency mining gangs like Lemon_Duck and Te...

Hackers Claim to Target Russian Institutions in Barrage of Cyberattacks and Leaks

Image
By Kate Conger and David E. Sanger, New York Times Hackers claim to have broken into dozens of Russian institutions over the past two months, including the Kremlin's internet censor and one of its primary intelligence services, leaking e-mails and internal documents to the public in an apparent hack-and-leak campaign that is remarkable in its scope. The hacking operation comes as the Ukrainian government appears to have begun a parallel effort to punish Russia by publishing the names of purported Russian soldiers who operated in Bucha, Ukraine, the site of a massacre of civilians, and agents of the FSB, a major Russian intelligence agency, along with identifying information like dates of birth and passport numbers. It is unclear how the Ukrainian government obtained those names or whether they were part of the hacks. Much of the data released by the hackers and the Ukrainian government is by its nature impossible to verify. As an intelligence agency, the FSB would never confirm a l...