Security News > 2022 > February > Microsoft: Russian FSB hackers hitting Ukraine since October
Microsoft said today that a Russian hacking group known as Gamaredon has been behind a streak of spear-phishing emails targeting Ukrainian entities and organizations related to Ukrainian affairs since October 2021.
Security and threat researchers with the Microsoft Threat Intelligence Center and the Microsoft Digital Security Unit said today that Gamaredon's cyber-espionage campaign is being coordinated out of Crimea, confirming SSU's assessment that the Gamaredon hackers are officers of the Crimean FSB who sided with Russia during the 2014 occupation.
"MSTIC has observed ACTINIUM targeting organizations in Ukraine spanning government, military, non-government organizations, judiciary, law enforcement, and non-profit, with the primary intent of exfiltrating sensitive information, maintaining access, and using acquired access to move laterally into related organizations," Microsoft added.
"Since October 2021, ACTINIUM has targeted or compromised accounts at organizations critical to emergency response and ensuring the security of Ukrainian territory, as well as organizations that would be involved in coordinating the distribution of international and humanitarian aid to Ukraine in a crisis."
Gamaredon is not linked to last month's cyberattacks that targeted multiple Ukraine government agencies and corporate entities with destructive data-wiping malware disguised as ransomware.
Palo Alto Networks' Unit 42 also issued a report regarding this group's recent activity targeting Ukraine and mentioned "An attempt to compromise a Western government entity in Ukraine on Jan. 19, 2022," via a spear-phishing attack pushing a malware downloader.
News URL
Related news
- Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure (source)
- Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware (source)
- A Hacker's Era: Why Microsoft 365 Protection Reigns Supreme (source)
- 100+ domains seized to stymie Russian Star Blizzard hackers (source)
- U.S. and Microsoft Seize 107 Russian Domains in Major Cyber Fraud Crackdown (source)
- US Government, Microsoft Aim to Disrupt Russian threat actor ‘Star Blizzard’ (source)
- Pro-Ukrainian Hackers Strike Russian State TV on Putin's Birthday (source)
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers (source)
- Russian hackers deliver malicious RDP configuration files to thousands (source)
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials (source)