Tag: russian

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics
News

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

Russian-origin threat actors have targeted Ukrainian organizations in an effort to steal confidential information and keep ongoing access to compromised networks. According to a recent assessment from the Symantec and Carbon Black Threat Hunter Team, the activity targeted a local government organization in the nation for a week and a large commercial services organization for two months. In order to minimize digital footprints and remain undiscovered for extended periods of time, the attackers mostly used dual-use tools and living-off-the-land (LotL) strategies, in conjunction with limited malware. The cybersecurity teams controlled by Broadcom said in a study published with The Hacker News that the attackers obtained access to the business services organization by installing web...
Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia
News

Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia

Potential ties between the cybercriminal group and Russian officials have been shown by the recently released cache of internal conversation logs between members of the Black Basta ransomware campaign. Over 200,000 communications from September 2023 to September 2024 were included in the leak, which was made public last month by @ExploitWhispers, a Telegram user. Cybersecurity firm Trellix analyzed the messages and found that Oleg Nefedov (also known as GG or AA), the accused commander of Black Basta, may have gotten assistance from Russian authorities after being arrested in Yerevan, Armenia, in June 2024, which allowed him to flee three days later. According to GG's claims in the chats, he made contact with senior officials read more about Leaked Black Basta Chats Suggest Russi...
SilentCryptoMiner Infects 2000 Russian Users via Fake VPN and DPI Bypass Tools
News

SilentCryptoMiner Infects 2000 Russian Users via Fake VPN and DPI Bypass Tools

A cryptocurrency miner called SilentCryptoMiner is infecting people as part of a new widespread malware operation that poses as a tool for getting around internet blocks and restrictions on online services. The action, according to Russian cybersecurity firm Kaspersky, is a part of a broader pattern in which hackers are using Windows Packet Divert (WPD) tools more frequently to disseminate malware masquerading as restriction-bypassing software. Researchers Leonid Bezvershenko, Dmitry Pikush, and Oleg Kupreev noted that such malware is frequently distributed as archives with text installation instructions. In these instructions, the developers advise turning off security solutions due to false positives. Attackers benefit from this since it gives them the opportunity to continue oper...
Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries
News

Microsoft Uncovers Sandworm Subgroup’s Global Cyber Attacks Spanning 15+ Countries

A multi-year initial access operation known as BadPilot that spanned the world has been linked to a subgroup within the notorious Russian state-sponsored hacking outfit Sandworm. In a new report shared with The Hacker News prior to publication, the Microsoft Threat Intelligence team stated that this subgroup has carried out a variety of worldwide compromises of Internet-facing infrastructure to allow Seashell Blizzard to continue targeting high-value targets and support customized network operations. All of North America, a number of European nations, and additional nations like Angola, Argentina, Australia, China, Egypt, India, Kazakhstan, Myanmar, Nigeria, Pakistan, Turkey, and Uzbekistan are among the targets of the initial access subgroup read more about Microsoft Uncovers Sandw...
Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware
News

Crazy Evil Gang Targets Crypto with StealC, AMOS, and Angel Drainer Malware

More than ten ongoing social media scams have been connected to the Russian-speaking cybercrime group Crazy Evil. These scams use a variety of specially designed lures to trick victims into installing malware, including StealC, Atomic macOS Stealer (also known as AMOS), and Angel Drainer. According to an investigation by Recorded Future's Insikt Group, Crazy Evil, which specializes in identity fraud, cryptocurrency theft, and information-stealing malware, uses a well-organized network of traffers, or social engineering specialists, who are entrusted with rerouting genuine traffic to dangerous phishing pages. One indication that the threat actor is targeting users of both Windows and macOS systems is the deployment of a varied malware arsenal by the cryptoscam gang, which puts the de...
FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine
News

FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine

The Federal Security Service (FSB) discreetly installed spyware on an Android tablet belonging to a Russian programmer who was arrested earlier this year on suspicion of giving money to Ukraine. The results are the result of a joint inquiry between the First Department and the Citizen Lab at the University of Toronto. According to the article, the spyware installed on his device gives the operator the ability to track the location of a target device, record keystrokes and phone conversations, and read messages from encrypted messaging apps, among other things. After being placed in administrative prison by Russian authorities for 15 days read more about FSB Uses Trojan App to Monitor Russian Programmer Accused of Supporting Ukraine. Get up to date on the latest cybersecurity n...
Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions
News

Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions

One of the few times Russian hackers have been found guilty of hacking and money laundering crimes is the sentencing of four members of the now-defunct REvil ransomware enterprise to several years in prison. A court in St. Petersburg found Artem Zaets, Alexei Malozemov, Daniil Puzyrevsky, and Ruslan Khansvyarov guilty of illegally circulating means of payment, according to the Russian news agency Kommersant. Additionally, Puzyrevsky and Khansvyarov were convicted of using and disseminating malware. Consequently, Zaets and Malozemov received prison terms of 4.5 and 5 years, respectively. Both Khansvyarov and Puzyrevsky were sentenced to 5.5 and 6 years in prison, respectively. The four members are among the 14 others who were first arrested in relation to the case read more about ...
US disrupts AI-powered bot farm pushing Russian propaganda on X
News

US disrupts AI-powered bot farm pushing Russian propaganda on X

A collaborative international law enforcement operation headed by the U.S. Justice Department took down 1,000 Twitter accounts that were part of a huge bot farm that was propagating Russian misinformation, as well as the domains that were used to register the bots. The Russian FSB officer and the deputy editor-in-chief of Russia Today (RT), who organized and oversaw the bots' usage of Meliorator, an AI-enabled program, to distribute misinformation to Twitter users worldwide, have been behind the disinformation campaign since 2022. RT affiliates created social media profiles with an authentic appearance using Meliorator, impersonating people from all around the world. This was done to spread misinformation and undermine Russian influence on Twitter. Widespread information dissemin...
ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor
News

ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor

A cybercrime group known as ExCobalt has been targeting Russian organizations with a backdoor known as GoRed that is built on Golang and was previously undiscovered. According to a technical analysis released this week by Positive Technologies experts Vladislav Lunin and Alexander Badayev, "ExCobalt focuses on cyber espionage and includes several members active since at least 2016 and presumably once part of the notorious Cobalt Gang." The report focused on cyber intrigue. To steal money, Cobalt assaulted banking institutions. Using the CobInt tool was one of Cobalt's distinguishing features; ExCobalt started using it in 2022. Over the past year, the threat actor has targeted attacks on a number of Russian industries read more about ExCobalt Cyber Gang Targets Russian Sectors wit...
Russian Power Companies, IT Firms, and Govt Agencies Hit by Decoy Dog Trojan
News

Russian Power Companies, IT Firms, and Govt Agencies Hit by Decoy Dog Trojan

Cyberattacks targeting Russian enterprises have been identified to distribute a Windows variant of a malware known as Decoy Dog. Under the moniker Operation Lahat, the cybersecurity firm Positive Technologies is monitoring the activity cluster and linking it to the HellHounds advanced persistent threat (APT) group. According to security analysts Stanislav Pyzhov and Aleksandr Grigorian, the Hellhounds group infiltrates the networks of the organizations they choose, becomes established there, and goes years without being discovered. The organization uses trusted relationships and vulnerable online services as their main compromise vectors read more Russian Power Companies IT Firms and Govt Agencies Hit by Decoy Dog Trojan. Get up to date on the latest cybersecurity news and enhanc...