
It seems that Microsoftwas fighting a secret battle with Iranian government hackers.
The company sued and won the lawsuit against a group of Iranian hackers, known in cybersecurity circles as APT35, Phosphorus, Charming Kitten and Ajax Security team, taking control of 99 web domains, which they had previously operated.
The domains were used to spread phishing campaigns, targeting users in the U.S. and around the world.
The hackers had registered these domains and incorporated the names of well-known brands, such as Microsoft, Yahoo, and others. They were then used to collect login credentials from the users the group had tricked. This tactic is quite old, but it is still extremely successful even today in tricking users into revealing their username and password.
Companies often use court orders to take over domains that infringe on their trademarks and copyrights, but over the past year, Microsoft has also used this legal trick to combat hacking groups.
The company used a court order to take over domains previously controlled by government cyber espionage groups.
During the summer of 2018, Microsoft also took control of domains operated by APT28, a Russian espionage group also known as Strontium and Fancy Bear. Microsoft’s Corporate Vice President of Customer Security & Trust, Tom Burt, said it used this trick 15 times to take control of 91 domains operated by APT28, some of which were used for campaigns targeting the 2018 US election.
