Phishing Campaign by Russian Hackers Uses Trello, Dropbox to Target Diplomats
By Scott Ikeda, CPO Magazine A newly-uncovered phishing campaign is targeting diplomats by presenting malicious messages as official embassy communications, and basing out of legitimate cloud-based services such as DropBox and Trello to aid in evading detection and remediation. The scheme was uncovered by security firm Mandiant , who believe that state-backed Russian hackers are behind it. Embassies targeted by Russian hackers The phishing campaign is just one element of a rash of recent activity by advanced persistent threat group 29 (APT 29), probably better known to the general public as “Cozy Bear.” Believed to be backed by Russian intelligence, the group conducted a similar operation in 2021 that focused on compromising diplomats via legitimate-looking Constant Contact emails. Mandiant says that the current phishing campaign makes use of legitimate email addresses that have been previously compromised, and opens with what appears to be an administrative notice from an embassy. The...