HomeSecurityUSA: Officially Blames SVR for SolarWinds Hack - Sanctions and...

US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

The US government has officially blamed the Russian Foreign Intelligence Service (SVR) for the SolarWinds hack, in which hackers gained access to the networks of several private US technology agencies and companies. In a brief announcement of sanctions against Russia for actions against US interests, the White House says that the APT group “Cozy Bear” is behind this act of cyberespionage that exploits the SolarWinds Orion. The US government has also announced the expulsion of diplomats, as well as a series of other measures against Russia, in response to the devastating cyberattack as well as its other malicious activities.

The statement issued by the White House confirms previous media reports citing unofficial sources that SVR was behind the SolarWinds hack.

Read also: DHS: SolarWinds hackers breached officials' email accounts

USA Biden
US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

In early January, the Cyber ​​Unified Coordination Group (UCG) attributed the cyberattack to a Russian-backed hacking group, without giving a specific name.

On April 15, the White House formally charged the SVR with conducting a “wide-ranging cyberespionage campaign” through Cozy Bear (also known as The Dukes or APT29).

See also: SolarWinds fixes critical vulnerabilities in Orion platform

"The U.S. Intelligence Community has high confidence in its assessment of the attribution of the attack to the SVR," the White House report notes.

SolarWinds hack
US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

With the SolarWinds hack, SVR gained access to over 16,000 computers worldwide. However, this malicious campaign has specific targets, such as cybersecurity companies (FireEye, Malwarebytes, Mimecast)as well as US government and federal agencies.

In a joint security advisory issued by the NSA, CISA, and FBI, they warn of the top five vulnerabilities that the SVR exploits in attacks against American interests. Organizations should heed the warning and take the necessary steps to detect and defend against malicious activity carried out by the SVR.

Sanctions and expulsion of Russian diplomats
US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

U.S. President Joe Biden issued an executive order on April 15 to block assets related to malign activities by the government of the Russian Federation. Under this order, the U.S. Treasury Department has imposed sanctions on the following Russian technology companies for assisting the SVR, the Russian Federal Security Service (FSB), and the Russian Central Intelligence Agency (GRU) in conducting malicious cyber activities against the United States.

Suggestion: Microsoft reveals 3 more malware strains used by SolarWinds hackers

  • ERA Technopolis: A research center and technology park funded and operated by the Russian Ministry of Defense. ERA Technopolis houses and supports units of Russia's Main Intelligence Directorate (GRU) responsible for offensive cyber operations.
  • Pasit: Russia-based IT company that conducted research and development in support of the SVR's malicious cyber-operational services.
  • SVA: A Russian state research institute specializing in advanced IT systems located in Russia. SVA conducted research and development in support of the SVR's malicious cyber operations.
  • Neobit: St. Petersburg-based IT company whose clients include the Russian Ministry of Defense, the SVR, and the Federal Security Service of Russia (FSB). Neobit conducted research and development in support of cyber operations conducted by the FSB, GRU, and SVR.
  • AST: Russian IT company, whose clients include the Russian Ministry of Defense, the SVR and the FSB. AST provided technical support to cyber operations conducted by the FSB, GRU and SVR.
  • Positive Technologies: Russian IT company that supports Russian government clients, including the FSB. Positive Technologies provides computer network security solutions to Russian businesses, foreign governments, and international corporations, and hosts large-scale contracts used as recruiting events for the FSB and GRU.
USA- SVR -SolarWinds hack - Sanctions and expulsion of Russian diplomats
US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

companies and financial institutions US can no longer do business with the aforementioned companies without first applying for and receiving permission from the Office of Foreign Assets Control (OFAC).

At the same time, the US Treasury Department announced that it had imposed sanctions on 32 individuals and entities for their alleged involvement in the elections and "Russian government-sponsored attempts to influence the 2020 elections through disinformation and interference."

The White House also announced the expulsion of ten Russians from the diplomatic mission in Washington, who were operating as intelligence officers under the cover of their diplomatic status.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS