HomeSecurityFancy Bear: Russian hackers infiltrated a US Federal Agency

Fancy Bear: Russian hackers infiltrated a US Federal Agency

That unknown hackers broke into a U.S. federal government agency and stole its data is alarming enough. But the attackers have apparently been identified and it seems likely they are part of a notorious hacking group working for the Russian military intelligence agency, the GRU.

Fancy Bear: Russian hackers infiltrated a US Federal Agency

Last week, CISA issued an advisory that hackers had infiltrated a U.S. federal agency. It did not identify the attackers or the agency, but it detailed the hackers’ methods and the use of a new and unique form of malware in an operation that successfully stole data . Evidence uncovered by a researcher at cybersecurity firm Dragos and an FBI alert obtained by WIRED in July suggest a possible answer to the mystery of who was behind the intrusion. It appears to be Fancy Bear, a group working for Russia’s GRU. Also known as APT28, the group is responsible for everything from hacking operations targeting the 2016 U.S. presidential election to a broad campaign of hacking attempts targeting political parties, consultants, and campaigns.

The evidence pointing to APT28 is based in part on a notice sent by the FBI to targets of a hacking campaign in May of this year, which was obtained by WIRED. The notice said that APT28 was targeting U.S. networks broadly ,including government agencies and educational institutions, and listed several IP addresses they were using in operations . Dragos researcher Joe Slowik noticed that an IP address identifying a server in Hungary used in this APT28 campaign matched an IP address listed in the CISA advisory. This suggests that APT28 used the same Hungarian server in the hack described by CISA — and that at least one of the attempted intrusions described by the FBI was successful.

hacker

In addition to this FBI alert, Slowik also found a second connection. A report last year from the Department of Energy warned that the APT28 group had targeted a US government from a server in Latvia, citing the IP address of that server. And that Latvian IP address also reappeared in the hack described in the CISA advisory. These matching IPs create a web of shared infrastructure that connects all of these operations.

But if APT28 is indeed the hacking group described in the CISA advisory, it’s a reminder that it’s capable of more sophisticated and targeted espionage operations, says John Hultquist, director of intelligence at security firm FireEye. “It’s a very sophisticated group and it’s still able to access sensitive services,” Hultquist says.

APT28 has a long history of espionage operations targeting U.S., NATO, and Eastern European. The CISA advisory, along with findings from the DOE and FBI monitoring related APT28 hacking campaigns, suggest that these espionage operations continue to this day.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS