Security News > 2022 > February > Microsoft: Russian FSB hackers targeting Ukraine since October

Microsoft: Russian FSB hackers targeting Ukraine since October
2022-02-04 20:17

Microsoft said today that a Russian hacking group known as Gamaredon has been behind a streak of spear-phishing emails targeting Ukrainian entities and organizations related to Ukrainian affairs since October 2021.

Security and threat researchers with the Microsoft Threat Intelligence Center and the Microsoft Digital Security Unit said today that Gamaredon's cyber-espionage campaign is being coordinated out of Crimea, confirming SSU's assessment that the Gamaredon hackers are officers of the Crimean FSB who sided with Russia during the 2014 occupation.

"MSTIC has observed ACTINIUM targeting organizations in Ukraine spanning government, military, non-government organizations, judiciary, law enforcement, and non-profit, with the primary intent of exfiltrating sensitive information, maintaining access, and using acquired access to move laterally into related organizations," Microsoft added.

"Since October 2021, ACTINIUM has targeted or compromised accounts at organizations critical to emergency response and ensuring the security of Ukrainian territory, as well as organizations that would be involved in coordinating the distribution of international and humanitarian aid to Ukraine in a crisis."

Gamaredon is not linked to last month's cyberattacks that targeted multiple Ukraine government agencies and corporate entities with destructive data-wiping malware disguised as ransomware.

Palo Alto Networks' Unit 42 also issued a report regarding this group's recent activity targeting Ukraine and mentioned "An attempt to compromise a Western government entity in Ukraine on Jan. 19, 2022," via a spear-phishing attack pushing a malware downloader.


News URL

https://www.bleepingcomputer.com/news/microsoft/microsoft-russian-fsb-hackers-targeting-ukraine-since-october/