A joint report published by Rostelecom-Solar and the FSB's National Coordination Center for Computer Incidents (NKTsKI) revealed that foreign hackers have stolen information from Russian federal agencies.
The attacks were discovered in 2020 – hackers conducted spear-phishing attacks, exploited vulnerabilities in web applications, and hacked into contractors' infrastructure to infiltrate the infrastructure of Russian federal executive authorities.
Experts believe that the hackers behind the intrusions were hired by a foreign state.
Read also: Alaska DHSS: Hackers "hit" the Ministry of Health website!

In particular, the report states the following: “The level of the attackers (the technologies and mechanisms used, the speed and quality of the work they have done) makes it possible to identify them as hackers serving the interests of a foreign state. Such attackers could remain inside the infrastructure for a long time. The main goal of the hackers was to completely undermine the IT infrastructure and steal confidential information, including documents from closed departments and emails of key federal executive authorities.”
Once they breached the networks of the targeted organizations, the hackers gathered sensitive information from internal systems. The attackers gained access to mail servers, electronic document management servers, file servers, and workstations of various levels, to steal the information they were interested in.
See also: FBI: Hackers impersonate Truist Bank in spear-phishing campaign!
The attackers used two previously undetected malware strains – dubbed “Mail-O” and “Webdav-O” .
“Mail-O is a downloader that accesses the Mail.ru Cloud associated with an account that has been “stitched” to the sample. All communication is carried out using the Mail.ru Cloud API. Webdav-O is another malware that has never been described before. Like Mail-O, it interacts with the management server via the Yandex.Disk cloud. The malware supports two authentication methods: basic (with login and password) and oauth (using a token),” the report notes.
Additionally, according to the report, hackers have specifically targeted systems at federal agencies and have designed their malware to bypass the most popular Russian antivirus from Kaspersky that is typically installed by federal agencies.

Suggestion: Microsoft: Hackers target airline organizations with new malware!
"The malware developed by the hackers used the cloud storages of Russian companies Yandex and Mail.ru Group to download the collected data. The hackers presented their network activity in such a way that it resembled the legitimate Yandex Disk and Disk-O utilities. Such malware has never been encountered anywhere before," the report notes.
The FSB concludes that these are unprecedented attacks, taking into account the following factors:
- Threat level, the attacks hit federal agencies.
- 5th threat level according to the model used by Solar JSOC.
- Complete infrastructure breach and theft of confidential government data.
- Development of malware that has not been encountered before.
- Using multiple attack vectors.
- Use of cloud providers “Yandex” and “Mail.ru Group” of Russia.
- Zero detection rate of the involved artifacts.
It is worth mentioning, however, that the FSB has not so far attributed the attack to any specific foreign country.
Information source: securityaffairs.co
