
A ransomware gang from Russia, which came under fire from the U.S. Department of Justice in December, has begun attacking the government, major corporations and a news organization in America. Russian hackers are trying to break into their networks, targeting employees working from home.
The recent attacks were detected by Symantec Corp., a unit of Broadcom. In an urgent alert posted Thursday night, the company said Russian hackers were taking advantage of the sudden change in American work habits to introduce malicious code into corporate networks.
These Russian hackers usually attack with ransomware and demand huge sums of money from victims.
Ransomware is a major problem in the United States. Many local governments (Atlanta, Baltimore, Texas, Florida, etc.) have been the victims of ransomware attacks. However, these attacks are taking on new dimensions this time, as elections. The Department of Homeland Security is trying to secure systems , because there are concerns that foreign criminals will try to attack the systems to cause chaos in the elections on3 .
Recent ransomware attacks have been aimed at financial gain. But they could also be used to delete data and disrupt the systems of both companies and government agencies. An FBIon May 1 said ransomware attacks on U.S. government networks would likely threaten the availability of data on interconnected servers , even if that wasn’t the criminals’ intention. It’s something that has happened before.
Symantec did not name the companies or organizations that fell victim to the Russian hackers, but said it had already identified 31 victims, including major American brands and Fortune 500 companies.
According to the warning, these Russian hackers have at least 10 years of experience and don't waste time with small companies. They only go after the largest American companies.
The hacking group is called “Evil Corp.” In December, the Justice Department said the Russian hackers were involved in countless crimes, developing malware to steal tens of millions of dollars from online banking systems. The Treasury Department imposed sanctions and the government offered a $5 million reward for information leading to the arrest or conviction of the group’s leader.
According to Symantec, recent attacks targeted employees working from home (mainly due to COVID-19).

Malware has been deployed on websites. But it doesn't infect every user who's shopping online or reading the news of the day. Instead, the malware code looks for a sign that the computer is part of a large corporate or government network. For example, many companies tell employees to use a VPN, a protected channel that allows workers to connect to corporate systems as if they were in the office.
“These attacks don’t try to break into the VPN,” the researchers said. “They just use it to determine who the user works for.” The systems then wait for the employee to visit a public or commercial website to infect their computer. Once the machine reconnects to the corporate network, the code is deployed in the hopes of gaining access to corporate systems.
In the last month, other ransomware attacks by this group have been observed.
