Security News
![GitHub suspends accounts of Russian devs at sanctioned companies](/static/build/img/news/github-suspends-accounts-of-russian-devs-at-sanctioned-companies-small.jpg)
Russian software developers are reporting that their GitHub accounts are being suspended without warning if they work for or previously worked for companies under US sanctions. The GitHub accounts of Sberbank Technology, Sberbank AI Lab, and the Alfa Bank Laboratory had their code repositories initially disabled and are now removed from the platform.
![OldGremlin ransomware deploys new malware on Russian mining org](/static/build/img/news/oldgremlin-ransomware-deploys-new-malware-on-russian-mining-org-small.jpg)
Despite being less active, which may suggest that the ransomware business is closer to moonlighting, OldGremlin has demanded ransoms as high as $3 million from one of its victims. Security researchers at Singapore-based cybersecurity company Group-IB say that this time OldGremlin impersonated a senior accountant at a Russian financial organization warning that the recent sanctions imposed on Russia would suspend the operations of the Visa and Mastercard payment processing systems.
![Russian Cyberattack against Ukrainian Power Grid Prevented](/static/build/img/news/alt/ransomware-stats-small.jpg)
A Russian cyberweapon, similar to the one used in 2016, was detected and removed before it could be used. ESET researchers collaborated with CERT-UA to analyze the attack against the Ukrainian energy company The destructive actions were scheduled for 2022-04-08 but artifacts suggest that the attack had been planned for at least two weeks The attack used ICS-capable malware and regular disk wipers for Windows, Linux and Solaris operating systems We assess with high confidence that the attackers used a new version of the Industroyer malware, which was used in 2016 to cut power in Ukraine We assess with high confidence that the APT group Sandworm is responsible for this new attack Posted on April 13, 2022 at 6:32 AM 0 Comments.
![Huawei reportedly furloughs Russian staff and stops taking orders](/static/build/img/news/huawei-reportedly-furloughs-russian-staff-and-stops-taking-orders-small.jpg)
Chinese telecom giant Huawei has issued a mandatory month-long furlough to some of its Russia-based staff and suspended new orders, according to Russian media. The business mag also reported that Chinese nationals working for Huawei Russia are still going to the office.
![CISA warns orgs of WatchGuard bug exploited by Russian state hackers](/static/build/img/news/cisa-warns-orgs-of-watchguard-bug-exploited-by-russian-state-hackers-small.jpg)
The Cybersecurity and Infrastructure Security Agency has ordered federal civilian agencies and urged all US organizations on Monday to patch an actively exploited bug impacting WatchGuard Firebox and XTM firewall appliances. Sandworm, a Russian-sponsored hacking group, believed to be part of the GRU Russian military intelligence agency, also exploited this high severity privilege escalation flaw to build a new botnet dubbed Cyclops Blink out of compromised WatchGuard Small Office/Home Office network devices.
![Hackers use Conti's leaked ransomware to attack Russian companies](/static/build/img/news/hackers-use-conti-s-leaked-ransomware-to-attack-russian-companies-small.jpg)
A hacking group used the Conti's leaked ransomware source code to create their own ransomware to use in cyberattacks against Russian organizations. While it is common to hear of ransomware attacks targeting companies and encrypting data, we rarely hear about Russian organizations getting attacked similarly.
![US Disrupts Russian Botnet](/static/build/img/news/alt/Geopolitical-Cybersecurity-Predictions-small.jpg)
The Justice Department today announced a court-authorized operation, conducted in March 2022, to disrupt a two-tiered global botnet of thousands of infected network hardware devices under the control of a threat actor known to security researchers as Sandworm, which the U.S. government has previously attributed to the Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation. The operation copied and removed malware from vulnerable internet-connected firewall devices that Sandworm used for command and control of the underlying botnet.
![US disrupts Russian Cyclops Blink botnet before being used in attacks](/static/build/img/news/us-disrupts-russian-cyclops-blink-botnet-before-being-used-in-attacks-small.jpg)
US government officials announced today the disruption of the Cyclops Blink botnet linked to the Russian-backed Sandworm hacking group before it was used in attacks. The malware, used by Sandworm to create this botnet since at least June 2019, is targeting WatchGuard Firebox firewall appliances and multiple ASUS router models.
![Germany Shuts Down Russian Hydra Darknet Market; Seizes $25 Million in Bitcoin](/static/build/img/news/germany-shuts-down-russian-hydra-darknet-market-seizes-25-million-in-bitcoin-small.jpg)
Germany's Federal Criminal Police Office, the Bundeskriminalamt, on Tuesday announced the official takedown of Hydra, the world's largest illegal dark web marketplace. " Bitcoins amounting to currently the equivalent of approximately €23 million were seized, which are attributed to the marketplace," the BKA said in a press release.
![Ukraine spots Russian-linked 'Armageddon' phishing attacks](/static/build/img/news/ukraine-spots-russian-linked-armageddon-phishing-attacks-small.jpg)
The Computer Emergency Response Team of Ukraine has spotted new phishing attempts attributed to the Russian threat group tracked as Armageddon. Armageddon is a Russian state-sponsored threat actor who has been targeting Ukraine since at least 2014 and is considered part of the FSB. According to a detailed technical report published by the Ukrainian secret service in November 2021, Armageddon has launched at least 5,000 cyber-attacks against 1,500 critical entities in the country.