. Military Space News .
CYBER WARS
Russian hackers of SolarWinds back on the attack
By Rob Lever
Washington (AFP) May 28, 2021

The state-backed Russian group behind a massive hacking campaign revealed last year has re-emerged with a series of attacks on government agencies, think tanks, consultants and other organizations, according to officials and researchers.

A security update from Microsoft late Thursday said the group known as Nobelium has stepped up attacks, notably targeting government agencies involved in foreign policy as part of intelligence gathering efforts.

The US government's Cybersecurity and Infrastructure Security Agency posted a link to the Microsoft update and urged computer network administrators to "apply the necessary mitigations."

Microsoft said it detected a "sophisticated" and large-scale campaign that delivered phishing emails delivering malicious software and enabling the hackers to get protected data from victims.

"This wave of attacks targeted approximately 3,000 email accounts at more than 150 different organizations," Microsoft vice president Tom Burt said in a blog post.

The news comes a month after Washington imposed sanctions and expelled Russian diplomats in response to Moscow's involvement in the massive attacks last year on SolarWinds, a security software firm, as well as for election interference and other hostile activity.

"When coupled with the attack on SolarWinds, it's clear that part of Nobelium's playbook is to gain access to trusted technology providers and infect their customers," wrote Burt.

"By piggybacking on software updates and now mass email providers, Nobelium increases the chances of collateral damage in espionage operations and undermines trust in the technology ecosystem."

The new attacks enabled the hackers were able to gain access to email servers operated by the firm Constant Contact to be able spoof to the US Agency for International Development and send out mass emails with disinformation, according to the update.

In one example, emails appearing to be from USAID showed a "special alert" stating that "Donald Trump has published new documents on election fraud."

Users who clicked on the link were directed to a site delivering malicious software and enabling the hackers to exfiltrate data, according to Microsoft.

- Attack is ongoing -

"This attack is still active, so these indicators should not be considered exhaustive for this observed activity," Microsoft said in its update.

The security firm Volexity, which also published research on the hacking, said it appears "the attacker is likely having some success in breaching targets."

The security firm said in a blog post: "While Volexity cannot say with certainty who is behind these attacks, it does believe it has the earmarks of a known threat actor it has dealt with on several previous occasions," citing a Russian-based hacker group.

John Dickson of the security firm Denim Group said the latest attacks suggest the sanctions imposed by Washington are insufficient.

"I think the sanctions were a starting point and we need to ratchet them up," Dickson told AFP.

Dickson said the various hacking operations from Russia "are all different iterations of the same information operations" with Kremlin approval and that "they're doing it without fear of retribution."

SolarWinds last year disclosed that as many as 18,000 customers and more than 100 US companies were affected by the hack. Its roster of clients includes government agencies and companies among the top 500 in the United States.

Hackers used Orion to gain entry into networks, allowing them to swipe data and install malicious codes that served as "backdoors" that could be used to sneak into systems as desired.

Washington has accused Russia of orchestrating the online assault, explicitly citing its Foreign Intelligence Service (SVR).

The hacking revelation comes as US President Joe Biden and Russian leader Vladimir Putin prepare for their first summit next month in Geneva.

The June 16 meeting will include discussions on "the full range of pressing issues, as we seek to restore predictability and stability to the US-Russia relationship," White House Press Secretary Jen Psaki said earlier this week.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


CYBER WARS
EU wants more from Big Tech against disinformation
Brussels (AFP) May 26, 2021
The EU on Wednesday tasked tech giants such as Facebook, YouTube and TikTok to do more against disinformation and provide much better access to their algorithms as well as beef up fact-checking. The proposal is the EU's effort to strengthen its existing code of conduct against disinformation, which was launched in 2018 after revelations that platforms had facilitated and amplified false information in the ramp up to the Brexit vote and elections in the US in 2016. It was signed by Google, Facebo ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
First modernized SBIRS Missile Warning Satellite under Space Force control

ULA postpones launch of missile detection satellite

SBIRS GEO-5 encapsulated ahead of upcoming launch

GAO report: Missile Defense Agency missed 2020 delivery, testing goals

CYBER WARS
French frigate downs supersonic missile in NATO exercise

Marines' 24th MEU deploys with HIMARS rocket system

BAE Systems Australia to build joint strike missile components

US Navy Orders Additional Sea Skimming Target Vehicles from Northrop Grumman

CYBER WARS
AFRL completes Golden Horde Collaborative Small Diameter Bomb flight demonstrations

Northrop Grumman Maritime Autonomous system surpasses 40,000 flight hours

Europe's Future unmanned Combat Air System

Poland becomes first NATO country to buy Turkish drones

CYBER WARS
Bad connections: US-China defense relations mired in call dispute

SES Government Solutions provides medium earth orbit satellite services for combatant command

STPSat-6 safely arrives in Florida

Hughes and OneWeb to demonstrate LEO services for Arctic Region on behalf of US Air Force

CYBER WARS
Marine Corps ends involvement in tank warfare

N.C. National Guard unit first to use new Army M109A7 Paladin howitzer

Air Force demonstrates value of rapid prototyping at Emerald Warrior

BATMAN support of SIBR PROJECT increases combat survival potential

CYBER WARS
Austin, Milley say $715B defense budget is ample for DoD's needs

GAO report: Lack of data causing delays in military spare parts contracts

US Senate leader pushes bill to boost industry against China

Grassley, Sanders introduce bill requiring Pentagon to pass audits

CYBER WARS
Russia looms large as NATO trains in neighbouring Estonia

NATO HQ limits access to Belarus diplomats s access to Belarus diplomats

Crime boss's wild claims shake Turkish government

China jails blogger who 'slandered' dead in India border clash

CYBER WARS
Nano-Bio Materials Consortium introduces new AFRL-Industry Co-Development Program

Nanostructured device stops light in its tracks

Scientists use DNA technology to build tough 3D nanomaterials









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.