3.000 US government email accounts under attack

Fireeye News

Share post

A Russian hacker group behind the SolarWinds spy campaign has launched a new wave of global cyberattacks and hijacked an email system. According to Microsoft, 3.000 US government email accounts in 150 agencies were affected by the attack. The "active attack" covers at least 24 countries.

Commenting on the latest findings on the attacks, John Hultquist, Vice President of Analysis, Mandiant Threat Intelligence at FireEye, the market leader in intelligence-based security solutions. “FireEye has tracked several waves of similar spear phishing emails sent since March 2021. In addition to the USAID content, a variety of lures, such as diplomatic communications and embassy invitations, were used. All of these actions focused on governments, think tanks and similar organizations that have traditionally been targets of SVR actions.

Successor to the SolarWinds attack

John Hultquist, Vice President of Analysis, Client Threat Intelligence

John Hultquist, Vice President of Analysis, Mandiant Threat Intelligence at FireEye. (Source: FireEye)

Although the SolarWinds attack was significant due to its malice and careful execution, conspicuous and widespread spear phishing attacks have long been the flagship of the SVR, which often carried out suspicious phishing campaigns. These actions were often effective, including access to key government agencies. Although the spear phishing emails were quickly identified, we believe that the attacks by these actors are very sophisticated and covert once they have been compromised.

Recent activity appears to have picked up just as supply chain-based compromises decreased. Given the audacity of this incident, the SVR appears unwilling to curb its cyber espionage activities, let alone go to great lengths to hide new activities. Rather, this incident reminds us that cyber espionage will continue in the future. "

More at FireEye.com

 


About Trellix

Trellix is ​​a global company redefining the future of cybersecurity. The company's open and native Extended Detection and Response (XDR) platform helps organizations facing today's most advanced threats gain confidence that their operations are protected and resilient. Trellix security experts, along with an extensive partner ecosystem, accelerate technology innovation through machine learning and automation to support over 40.000 business and government customers.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more