An ongoing cyber espionage campaign targeting Kazakhstan as part of the Kremlin’s aim to obtain political and economic intelligence in Central Asia has been traced to threat actors with ties to Russia.
According to assessments, the effort was carried out by an intrusion set known as UAC-0063, which most likely shares similarities with APT28, a nation-state organization connected to Russia’s General Staff Main Intelligence Directorate (GRU). Other names for it include Iron Twilight, Forest Blizzard, FROZENLAKE, Pawn Storm, Blue Athena, BlueDelta, Fancy Bear, Fighting Ursa, ITG05, Sednit, Sofacy, and TA422.
The Computer Emergency Response Team of Ukraine (CERT-UA) initially reported UAC-0063 in early 2023, describing its use of malware families known as HATVIBE, CHERRYSPY, and STILLARCH (also known as DownEx) to attack government organizations read more about Russian-Linked Hackers Target Kazakhstan in Espionage Campaign with HATVIBE Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
