Posts

Showing posts with the label Turla

Russian hackers perform reconnaissance against Austria, Estonia

By Bill Toulas, Bleeping Computer In a new reconnaissance campaign, the Russian state-sponsored hacking group Turla was observed targeting the Austrian Economic Chamber, a NATO platform, and the Baltic Defense College. This discovery comes from cybersecurity firm Sekoia, which built upon previous findings of Google’s TAG , which has been following Russian hackers closely this year. Google warned about coordinated Russian-based threat group activity in late March 2022, while in May, they spotted two Turla domains used in ongoing campaigns. Sekoia used this information to investigate further and found that Turla targeted the federal organization in Austria and the military college in the Baltic region.

Google's TAG provides update on cybersecurity activity in Eastern Europe

Image
By  Dev Discourse Google's Threat Analysis Group (TAG) has observed a continuously growing number of threat actors using the Russia-Ukraine conflict as a lure in phishing and malware campaigns and targeting critical infrastructure entities including oil and gas, telecommunications and manufacturing. "Government-backed actors from China, Iran, North Korea and Russia, as well as various unattributed groups, have used various Ukraine war-related themes in an effort to get targets to open malicious emails or click malicious links. Financially motivated and criminal actors are also using current events as a means for targeting users," TAG wrote in a blog post . Below is the campaign activity observed by Google's TAG: APT28 or Fancy Bear, a threat actor attributed to Russia GRU, was seen targeting users in Ukraine with a new variant of malware which was distributed via email attachments inside of password-protected zip files (ua_report.zip). The malware is a .Net executable...