Security News > 2022 > February > US says Russian state hackers breached cleared defense contractors
Russian-backed hackers have been targeting and compromising U.S. cleared defense contractors since at least January 2020 to gain access to and steal sensitive info that gives insight into U.S. defense and intelligence programs and capabilities.
Since January 2020, Russian hacking groups have breached multiple CDC networks and, in some cases, have maintained persistence for at least six months, regularly exfiltrating hundreds of documents, emails, and other data.
"Compromised entities have included CDCs supporting the U.S. Army, U.S. Air Force, U.S. Navy, U.S. Space Force, and DoD and Intelligence programs," the FBI, NSA, and CISA revealed in a joint advisory published today.
Last month, the three agencies also warned that Russian-backed hacking groups are targeting organizations from U.S. critical infrastructure sectors.
In July 2021, the U.S. government also announced a reward of up to $10 million through its Rewards for Justice program for information on malicious cyber activities coordinated by state hackers targeting critical infrastructure sectors.
"NSA encourages all U.S. cleared defense contractors - with or without evidence of compromise - to apply the mitigations in the advisory to reduce the risk of compromise by Russian state-sponsored cyber actors," the NSA added today.
News URL
Related news
- Faraway Russian hackers breached US organization via Wi-Fi (source)
- Russian suspected Phobos ransomware admin extradited to US over $16M extortion (source)
- Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and Asia (source)
- Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack' (source)
- Hackers abuse Avast anti-rootkit driver to disable defenses (source)
- Firefox and Windows zero-days exploited by Russian RomCom hackers (source)
- Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested (source)
- North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks (source)
- US shares tips to block hackers behind recent telecom breaches (source)
- Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email Defenses (source)