Showing posts with label Fancy Bear. Show all posts
Showing posts with label Fancy Bear. Show all posts

Saturday, 13 January 2018

Russian hackers targeting US Senate email accounts since June 2017: Report

Photo: Reuters

A hacking group allegedly associated with the Russian government is actively targeting the US Senate's internal email system since June 2017, a cybersecurity firm claimed on Saturday.

According to Japanese cybersecurity firm Trend Micro, this is the same group that hacked into the Democratic National Committee (DNC) in 2016.

The hackers' activities began in June 2017 when they attempted to compromise a lawmaker's credentials through a phishing site designed to look like the Senate's internal email system.

"Beginning in June 2017, phishing sites were set up mimicking the ADFS (Active Directory Federation Services) of the US Senate. By looking at the digital fingerprints of these phishing sites and comparing them with a large data set that spans almost five years, we can uniquely relate them to a couple of 'Pawn Storm' incidents in 2016 and 2017," the security company said in a blog post.

"The real ADFS server of the U. S.

Senate is not reachable on the open internet, however phishing of users' credentials on an ADFS server that is behind a firewall still makes sense. In case an actor already has a foothold in an organization after compromising one user account, credential phishing could help him get closer to high profile users of interest," it added.

Trend Micro's report focuses on the efforts of a hacking group called "Pawn Storm" -- "an extremely active espionage actor group" more commonly known as "Fancy Bear".

Cybersecurity firm CrowdStrike has deemed the group a "Russian-based threat actor" with likely ties to Russian military intelligence, Tech Crunch reported.
READ MORE

Saturday, 6 January 2018

Hackers already targeting 2018 Pyeongchang Olympics: McAfee report

Photo: Reuters

Hackers have already begun targeting the Pyeongchang Olympic Games with malware-infected emails which may be aimed at stealing passwords or financial information, researchers have said.

The security firm McAfee said in a report that several organisations associated with the Olympics had received the malicious email with the primary target being groups affiliated with ice hockey.

"The majority of these organizations (targeted) had some association with the Olympics, either in providing infrastructure or in a supporting role," the McAfee report said.

"The attackers appear to be casting a wide net with this campaign."

In the attacks, which began as early as December 22, emails were "spoofed" to make them appear to come from South Korea's National Counter-Terrorism Center, which was in the process of conducting antiterror drills in the region in preparation for the Games.

McAfee said the emails came in fact from an address in Singapore, and instructed the readers to open a text document in Korean.

The document was titled "Organized by Ministry of Agriculture and Forestry and Pyeongchang Winter Olympics," according to the report.
READ MORE