Security News > 2022 > February > Microsoft: Russian FSB hackers hitting Ukraine since October
Microsoft said today that a Russian hacking group known as Gamaredon has been behind a streak of spear-phishing emails targeting Ukrainian entities and organizations related to Ukrainian affairs since October 2021.
Security and threat researchers with the Microsoft Threat Intelligence Center and the Microsoft Digital Security Unit said today that Gamaredon's cyber-espionage campaign is being coordinated out of Crimea, confirming SSU's assessment that the Gamaredon hackers are officers of the Crimean FSB who sided with Russia during the 2014 occupation.
"MSTIC has observed ACTINIUM targeting organizations in Ukraine spanning government, military, non-government organizations, judiciary, law enforcement, and non-profit, with the primary intent of exfiltrating sensitive information, maintaining access, and using acquired access to move laterally into related organizations," Microsoft added.
"Since October 2021, ACTINIUM has targeted or compromised accounts at organizations critical to emergency response and ensuring the security of Ukrainian territory, as well as organizations that would be involved in coordinating the distribution of international and humanitarian aid to Ukraine in a crisis."
Gamaredon is not linked to last month's cyberattacks that targeted multiple Ukraine government agencies and corporate entities with destructive data-wiping malware disguised as ransomware.
Palo Alto Networks' Unit 42 also issued a report regarding this group's recent activity targeting Ukraine and mentioned "An attempt to compromise a Western government entity in Ukraine on Jan. 19, 2022," via a spear-phishing attack pushing a malware downloader.
News URL
Related news
- FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine (source)
- Russian Turla hackers hit Starlink-connected devices in Ukraine (source)
- Russian cyber spies hide behind other hackers to target Ukraine (source)
- Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested (source)
- North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks (source)
- Russian hackers hijack Pakistani hackers' servers for their own attacks (source)
- Russian hackers hijack Pakistani hackers' servers for their own attacks (source)
- New Android spyware found on phone seized by Russian FSB (source)
- Badass Russian techie outsmarts FSB, flees Putinland all while being tracked with spyware (source)
- Microsoft dangles $10K for hackers to hijack LLM email service (source)