HomeSecurityUSA: Domains used by APT29 in recent phishing campaign seized

US: Domains used by APT29 in recent phishing campaign seized

The (DoJ) U.S. have seized two domains used by the Russian hacking group “APT29” in phishing attacks targeting government agencies, think tanks, consultants and NGOs. The hackers behind the attacks impersonated the U.S. Agency for International Development (USAID) in order to distribute malware and gain access to internal networks.

The Russia-linked SVR group (also known as APT29, Cozy Bear, and The Dukes) , along with the hacking group “APT28 , ” participated in the hack of the Democratic National Committee and the wave of attacks targeting the 2016 US presidential election.

The two domains seized by US authorities are theyardservice[.]com and worldhomeoutlet[.]com.

Read also: US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

DoJ - FBI
US: Domains used by APT29 in recent phishing campaign seized

Specifically, the DoJ stated in its related announcement the following: “On May 28, pursuant to court orders issued in the Eastern District of Virginia, the United States seized two command-and-control (C2) and malware distribution domains used in a recent spear-phishing campaign that spoofed U.S. Agency for International Development (USAID) email communications. This malicious activity was the subject of a Microsoft security advisory on May 27, titled “New sophisticated email-based attack from Nobelium,”and a joint FBI and CISA on May 28.”

“These actions demonstrate our ability to respond rapidly to malicious cyber activity, leveraging our unique capabilities to disrupt our cyber adversaries,” said Steven M. D’Antuono, Assistant Director of the FBI Washington Field Office.

The domains were used as part of the command-and-control infrastructure used by the hackers.

See also: Hackers lure Android users with fake antivirus and infect them with malware

USA - domains 0 APT29 - phishing
US: Domains used by APT29 in recent phishing campaign seized

APT29, also said to be behind the SolarWinds, reportedly compromised an account on email marketing platform Constant Contact that belonged to the US agency USAID.

State hackers used the account to send 3,000 phishing emails to more than 150 organizations in 24 countries.

USA - domains - APT29 - phishing
US: Domains used by APT29 in recent phishing campaign seized

Once a recipient clicked on a link included in the messages, they were directed to download malware from a subdomain of theyardservice[.]com. After winning the initial step, the attackers would then download the Cobalt Strike to gain access to the target system and deploy additional tools or malicious payloads.

Suggestion: FBI: Links Conti ransomware to 16 attacks on major US organizations

Finally, Bryan Vorndran, Assistant Director of the FBI's Cyber ​​Division, stated the following: "The FBI remains committed to disrupting this type of malicious cyber activity that targets our federal agencies and American citizens."

"We will continue to use all the tools at our disposal and leverage our domestic and international partnerships, not only to disrupt this type of hacking activity, but also to impose risks and consequences on our adversaries to combat these threats."

Information source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS