Security News > 2020 > September > China, Russia and Iran all attacking US elections and using some nasty new tactics, says Microsoft
Microsoft believes there have been extensive "Cyberattacks targeting people and organizations involved in the upcoming presidential election," and that foreign government hackers responsible for attacks ahead of the 2016 vote are back with new and nastier tactics.
The Windows giant's corporate veep for Customer Security & Trust Tom Burt said both sides of US politics are being attacked, that China, Russia and Iran are all active, and that the spies are also actively targeting UK political parties and other international institutions.
Strontium has largely abandoned phishing and is now using brute-force attacks and password spray, Microsoft suggests.
Microsoft has code-named China's attackers Zirconium, and Burt wrote that the team has conducted "Thousands of attacks. between March 2020 and September 2020 resulting in nearly 150 compromises."
"While the political organizations targeted in attacks from these actors are not those that maintain or operate voting systems, this increased activity related to the US electoral process is concerning for the whole ecosystem. We continue to encourage state and local election authorities in the US to harden their operations and prepare for potential attacks. But as election security experts have noted, additional funding is still needed, especially as resources are stretched to accommodate the shift in COVID-19-related voting."
News URL
Related news
- China’s Spamouflage cranks up trolling of US Senator Rubio as election day looms (source)
- AI and the 2024 US Elections (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Russia arrests US-sanctioned Cryptex founder, 95 other linked suspects (source)
- US Government, Microsoft Aim to Disrupt Russian threat actor ‘Star Blizzard’ (source)
- China Possibly Hacking US “Lawful Access” Backdoor (source)
- US and UK govts warn: Russia scanning for your unpatched vulnerabilities (source)
- China again claims Volt Typhoon cyber-attack crew was invented by the US to discredit it (source)
- Phishing scams and malicious domains take center stage as the US election approaches (source)
- US warns of last-minute Iranian and Russian election influence ops (source)