Posts

Showing posts with the label Ukraine

Ukraine arrests hackers trying to sell 100 million stolen accounts

Image
By Bill Toulas,  Bleeping Computer The Ukrainian cyber police, in collaboration with investigators from the national police (ГУНП), have arrested three individuals who are accused of hijacking over 100 million emails and Instagram accounts worldwide. The three suspects, aged between 20 and 40, used specialized software to brute-force account passwords and then steal them. Brute force is the means of guessing account passwords through an automated trial-and-error process that has computers try many possible combinations until the correct one is found. This method's success relies on the available computational power in relation to the password length and complexity of the targeted account. The arrested cybercriminals monetized their illicit activities by selling access to compromised accounts to various fraud groups on the darknet. The buyers then used their access to these accounts to message the victims' contacts, requesting them to transfer money under false pretenses. The po...

Ukraine claims it hacked Russian Ministry of Defense servers

Image
By Bill Toulas,  Bleeping Computer The Main Intelligence Directorate (GUR) of Ukraine's Ministry of Defense claims that it breached the servers of the Russian Ministry of Defense (Minoborony) and stole sensitive documents. A press release published today on an official Ukrainian government domain describes the attack as a "special operation" carried out by GUR's cyber-specialists. As a result of the breach, the GUR claims to have obtained sensitive documents that contain secret service information, including: Software used by the Russian Ministry of Defense for protecting and encrypting data An array of secret service documents from the Russian Ministry of Defense, including orders, reports, directives, and various other documents, circulated among over 2000 structural units of the ministry. Information that allows establishing the complete structure of the system of the Minoborony and its links. Data that helped identify senior heads of structural units of the Minobo...

EU warns of Russian cyberattack spillover, escalation risks

By Sergiu Gatlan,  Bleeping Computer The Council of the European Union (EU) said today that Russian hackers and hacker groups increasingly attacking "essential" organizations worldwide could lead to spillover risks and potential escalation. "This increase in malicious cyber activities, in the context of the war against Ukraine, creates unacceptable risks of spillover effects, misinterpretation and possible escalation," the High Representative on behalf of the EU said Tuesday. "The latest distributed denial-of-service (DDoS) attacks against several EU Member States and partners claimed by pro-Russian hacker groups are yet another example of the heightened and tense cyber threat landscape that EU and its Member States have observed." In this context, the EU reminded Russia that all United Nations member states must adhere to the UN's Framework of responsible state behavior in cyberspace to ensure international security and peace. The EU urged all states ...

Microsoft Shows Its Power Against Russia

By Ellen Chang,  The Street Tech giant Microsoft  (MSFT) - Get Microsoft Corporation Report provided tech and monetary assistance to Ukraine as it fought against cyber attacks from Russia.  The company made both financial and technological commitments to Ukraine as it was invaded by Russia in February. Microsoft promised a total of $239 million in assistance, including $107 million to "literally move the government and much of the country of Ukraine from on-premises servers to the cloud," Microsoft President Brad Smith said in an interview with GeekWire last week at his office in Redmond, Washington. The Russian government has engaged in malicious cyber activities to suppress various political and social activity, according to the Cybersecurity and Infrastructure Security Agency (CISA). The Russian state-sponsored cyber actors have the ability to "compromise IT networks; develop mechanisms to maintain long-term, persistent access to IT networks; exfiltrate sensitive data...

Russian Hackers Continue Brutal Ukraine Cyber-Assault But Microsoft Is Fighting Back

By Nathan Wasson,  Hot Hardware Shortly after Russia invaded Ukraine near the beginning of this year, some prominent hacking groups announced that they would be joining the war within the digital realm. The hacking collective Anonymous declared cyberwar against the Russian government and has since been conducting cyberattacks on Russian and Belarusian government websites, news channels, and military operations systems. On the other side of the conflict is the Conti ransomware gang, which announced its full support of the Russian government and intention to strike back against Western cyber operations. The Russian-speaking ransomware group has since broken up and abandoned the Conti name, but other Russian-based hacking groups are still conducting cyberattacks on Ukraine and its Western allies. Microsoft is also participating in the conflict by joining the ongoing sanctions on Russia. Microsoft halted sales in Russia near the outset of the war, but, just last week, Microsoft began b...

Russia is well-prepared for cyber war

by Jurgita Lapienytė,  Cybernews For the first time ever, we are witnessing a real cyber war, Denys Tsvaig, the president of Ukraine’s national cybersecurity association, told Cybernews. The war in Ukraine caused turmoil in the cyber realm, with many pro-Ukrainian and pro-Russian citizens worldwide joining various efforts to fight. Hacktivism gained momentum soon after the invasion, causing collateral damage. Recently, the pro-Russian Killnet group made headlines after attacking Ukraine ally Lithuania’s websites in response to the Baltic country following EU sanctions. Hacktivism aside, Ukraine and Russia have used cyber weapons to support their kinetic operations. For example, Russia resorted to disinformation before many major military strikes. In its turn, Ukraine allegedly was able to cause some physical damage to Russian infrastructure using its IT resources, as unverified reports say. Some say Russia’s cyber weapons are just as weak as its artillery. The State Service of Spec...

Ukraine arrests cybercrime gang operating over 400 phishing sites

By Bill Toulas,  Bleeping Computer The Ukrainian cyberpolice force arrested nine members of a criminal group that operated over 400 phishing websites crafted to appear like legitimate EU portals offering financial assistance to Ukrainians. The threat actors used forms on the site to steal visitors' payment card data and online banking account credentials and perform fraudulent, unauthorized transactions like moving funds to accounts under their control. According to the police's estimates, the total damage caused by this cybercrime operation is 100 million hryvnias, or approximately $3,360,000, stolen from roughly 5,000 victimized citizens. Citizens who have entered personal details on any of the following domains should consider themselves compromised and report it to the cyberpolice and their bank to receive further instructions. The announcement does not mention how users ended up on the phishing sites, but it could be via spam email, SEO poisoning, direct messages, or scam ...

Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware

By Bill Toulas,  Bleeping Computer The Ukrainian Computer Emergency Response Team (CERT) is warning that Russian hacking groups are exploiting the Follina code execution vulnerability in new phishing campaigns to install the CredoMap malware and Cobalt Strike beacons. The APT28 hacking group is believed to be sending emails containing a malicious document name "Nuclear Terrorism A Very Real Threat.rtf.". The threat actors selected the topic of this email to entice recipients to open it, exploiting the fear that's spread among Ukrainians about a potential nuclear attack. Threat actors also used a similar tactic in May 2022, when CERT-UA identified the dissemination of malicious documents warning about a chemical attack. The RTF document used in the APT28 campaign attempts to exploit CVE-2022-30190, aka "Follina," to download and launch the CredoMap malware (docx.exe) on a target's device. This vulnerability is a flaw in the Microsoft Diagnostic Tool, exploite...

More cyber warfare with Russia lies on the horizon

By Loukia Papadopoulos,  Interesting Engineering What is on the horizon in Russia's war plans? According to Neal Higgins, deputy national cyber director for national cybersecurity, there could be more cyber warfare. The cybersecurity professional spoke to DefenseNews on June 14 at an event hosted by Defense One and had some pretty revealing comments.

Russian hackers start targeting Ukraine with Follina exploits

By Bill Toulas,  Bleeping Computer Ukraine's Computer Emergency Response Team (CERT) is warning that the Russian hacking group Sandworm may be exploiting Follina, a remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) currently tracked as CVE-2022-30190. The security issue can be triggered by either opening or selecting a specially crafted document and threat actors have been exploiting it in attacks since at least April 2022. It is worth noting that Ukraine's agency assesses with medium confidence that behind the malicious activity is the Sandworm hacker group.

Google terminates coordinated influence operations linked to Russia, China, and Costa Rica

by Anna Zhadan,  Cyber News The technology giant terminated hundreds of YouTube and Ads accounts for their involvement in coordinated influence operations designed to support Russia’s invasion of Ukraine, criticize Costa Rican politicians, and upload spam content. Google’s Threat Analysis Group (TAG) updated a bulletin for the second quarter of 2022 detailing all coordinated influence operation campaigns terminated on Google’s platforms over that period. This comes as a part of the platform's initiative to prevent the spread of misinformation and disinformation. As such, TAG terminated 138 YouTube channels and two Ads accounts for a campaign linked to a Russian consulting firm. The campaign praised Russia’s aggression in Ukraine and expressed critical views of Ukraine and the NATO alliance, disseminating content in Russian. Similarly, 44 YouTube channels and nine Ads accounts were removed for another campaign linked to the Internet Research Agency (IRA.) The channels were supporti...

Hacked Russian radio station broadcasts Ukrainian anthem

By Rachel Pannett and Brittany Shammas, Washington Post A Russian radio station’s news bulletin was interrupted Wednesday by the Ukrainian anthem and antiwar songs, in the latest example of Russian media outlets apparently being targeted by antiwar hackers. Kommersant FM’s online broadcast suddenly began playing the Ukrainian patriotic song “Oh, the Red Viburnum in the Meadow,” BBC Monitoring reporter Francis Scarr wrote on Twitter. The station’s editor in chief, Alexei Vorobyov, confirmed the incident to the Russian state-owned news agency Tass, saying it appeared the internet stream had been hacked. He said technicians were investigating the origin of the attack. While apparently under the control of hackers, the station also played the Ukrainian national anthem and the song “We Don’t Need War” by the Russian rock band Nogu Svelo. The station is owned by Uzbek-born billionaire Alisher Usmanov, who was sanctioned by the United States and the European Union following the invasion for h...

Wray: FBI blocked planned cyberattack on children’s hospital

By Eric Tucker & Alan Suderman, NBC The FBI thwarted a planned cyberattack on a children’s hospital in Boston that was to have been carried out by hackers sponsored by the Iranian government, FBI Director Christopher Wray said Wednesday. Wray told a Boston College cybersecurity conference that his agents learned of the planned digital attack from an unspecified intelligence partner and got Boston Children’s Hospital the information it needed last summer to block what would have been “one of the most despicable cyberattacks I’ve seen.” “And quick actions by everyone involved, especially at the hospital, protected both the network and the sick kids who depended on it,” Wray said. The FBI chief recounted that anecdote in a broader speech about cyber threats from Russia, China and Iran, and the need for partnerships between the U.S. government and the private sector. He said the bureau and Boston Children’s Hospital had worked closely after a hacktivist attacked the hospital’s computer...

A cyberwar is already happening in Ukraine, Microsoft analysts say

by Jenna McLaughlin, NPR Microsoft's global ubiquity gives its cybersecurity experts a unique window into the Russian cyberwar against Ukraine. The software giant is involved in both monitoring and combatting attacks.

NSA: Sanctions on Russia Having a Positive Effect on Ransomware Attacks, Attempts Down Due to Difficulty Collecting Ransom Payments

By Scott Ikeda, CPO Magazine National Security Agency (NSA) director of cybersecurity Rob Joyce told attendees of a recent UK security conference that ransomware attacks are down in roughly the last two months, and that trend can be traced directly to sanctions placed on Russia. Criminals that operate out of the country are struggling to find ways to cash out ransom payments and set up infrastructure, due in large part to sanctions attached to the invasion of Ukraine.

North Korean IT Workers Are Infiltrating Tech Companies

Plus: The Conti ransomware gang shuts down, Canada bans Huawei and ZTE, and more of the week’s top security news. By Matt Burgess, Wired As Russia's full-scale war in Ukraine heads towards its hundredth day, opposition from Ukrainian forces is as strong as ever. At the same time, hacktivists all around the world continue to breach Russian institutions and publish their files and emails. This week one hacktivist collective took a different—and slightly peculiar—approach: launching a service to prank-call Russian government officials. The new website uses leaked details to put two random Russian officials on a call with each other. It obviously won't make any difference to the outcome of the war, but the group that created it hopes the tool will cause some confusion and annoy those in Moscow. New research from Google’s Threat Analysis Group has delved into the surveillance-for-hire industry and found that spyware vendors are targeting Android devices with zero-day exploits. State...
By Lawrence Abrams, Bleeping Computer Ransomware attacks continue to slow down, likely due to the invasion of Ukraine, instability in the region, and subsequent worldwide sanctions against Russia. This does not mean, though, that there has been no ransomware activity. This week's biggest news is the Conti ransomware gang beginning to shut down their operation, with internal infrastructure taken offline and team leaders/members told that the brand is ending. While the 'Conti' brand may be shut down, cybersecurity firm Advanced Intel says that the cybercrime syndicate will continue to operate, with members joining other ransomware operations or the Conti leadership taking over smaller operations. By splintering into smaller 'cells,' it is believed that Conti will be able to evade law enforcement more easily and simply switch between different ransomware operation's encryptors. While this may mean less revenue for the syndicate, it creates greater mobility for the ...

Conti Ransomware Gang Strikes Major Component Supplier For Boeing And Lockheed Martin

Image
By Nathan Wasson, Hot Hardware The beginning of the year saw a flurry of stories about security breaches as the cybercriminal gang known as LAPSUS$ stole data from an alarming number of big name companies in a short period of time. However, while LAPSUS$ is no longer in operation, after the London police arrested all seven members of the group, other cybercriminal groups are still afoot and out to steal data. One of these groups is the Russian-based Conti ransomware group. When Russia’s war on Ukraine broke out in February, the Conti ransomware gang announced that it fully supported the Russian government and would carry out counterattacks against anyone who organized cyberattacks or other offensive measures against Russia. The group specifically called out “Western warmongers” and “American cyber aggression.” Earlier this month, the US Department of State announced its offering of up to $10 million for information that helps identify or locate key members of the Conti ransomware gang....

Italy prevents pro-Russian hacker attacks during Eurovision contest

By ,  Reuters MILAN, May 15 (Reuters) - Italian police thwarted hacker attacks by pro-Russian groups during the May 10 semi-final and Saturday final of the Eurovision Song Contest in Turin, authorities said on Sunday. Ukraine's Kalush Orchestra won the contest with their entry "Stefania", riding a wave of public support to claim an emotional victory that was welcomed by the country's president Volodymyr Zelenskiy. read more During voting and the performances, the police cybersecurity department blocked several cyber attacks on network infrastructure by the " Killnet " hacker group and its affiliate "Legion", police said. The police also gathered information from the pro-Russian group's Telegram channels to prevent other critical events and identified the attacks' geographic location. On May 11, "Killnet" claimed an attack on the websites of several Italian institutions, including the Senate, Italy's upper house of parliament, ...

Phishing Campaign by Russian Hackers Uses Trello, Dropbox to Target Diplomats

By Scott Ikeda, CPO Magazine A newly-uncovered phishing campaign is targeting diplomats by presenting malicious messages as official embassy communications, and basing out of legitimate cloud-based services such as DropBox and Trello to aid in evading detection and remediation. The scheme was uncovered by security firm Mandiant , who believe that state-backed Russian hackers are behind it. Embassies targeted by Russian hackers The phishing campaign is just one element of a rash of recent activity by advanced persistent threat group 29 (APT 29), probably better known to the general public as “Cozy Bear.” Believed to be backed by Russian intelligence, the group conducted a similar operation in 2021 that focused on compromising diplomats via legitimate-looking Constant Contact emails. Mandiant says that the current phishing campaign makes use of legitimate email addresses that have been previously compromised, and opens with what appears to be an administrative notice from an embassy. The...