The (DoJ) U.S. have seized two domains used by the Russian hacking group “APT29” in phishing attacks targeting government agencies, think tanks, consultants and NGOs. The hackers behind the attacks impersonated the U.S. Agency for International Development (USAID) in order to distribute malware and gain access to internal networks.
The Russia-linked SVR group (also known as APT29, Cozy Bear, and The Dukes) , along with the hacking group “APT28 , ” participated in the hack of the Democratic National Committee and the wave of attacks targeting the 2016 US presidential election.
The two domains seized by US authorities are theyardservice[.]com and worldhomeoutlet[.]com.
Read also: US: Officially Blames SVR for SolarWinds Hack – Sanctions and Expulsion of Russian Diplomats

Specifically, the DoJ stated in its related announcement the following: “On May 28, pursuant to court orders issued in the Eastern District of Virginia, the United States seized two command-and-control (C2) and malware distribution domains used in a recent spear-phishing campaign that spoofed U.S. Agency for International Development (USAID) email communications. This malicious activity was the subject of a Microsoft security advisory on May 27, titled “New sophisticated email-based attack from Nobelium,”and a joint FBI and CISA on May 28.”
“These actions demonstrate our ability to respond rapidly to malicious cyber activity, leveraging our unique capabilities to disrupt our cyber adversaries,” said Steven M. D’Antuono, Assistant Director of the FBI Washington Field Office.
The domains were used as part of the command-and-control infrastructure used by the hackers.
See also: Hackers lure Android users with fake antivirus and infect them with malware

APT29, also said to be behind the SolarWinds, reportedly compromised an account on email marketing platform Constant Contact that belonged to the US agency USAID.
State hackers used the account to send 3,000 phishing emails to more than 150 organizations in 24 countries.

Once a recipient clicked on a link included in the messages, they were directed to download malware from a subdomain of theyardservice[.]com. After winning the initial step, the attackers would then download the Cobalt Strike to gain access to the target system and deploy additional tools or malicious payloads.
Suggestion: FBI: Links Conti ransomware to 16 attacks on major US organizations
Finally, Bryan Vorndran, Assistant Director of the FBI's Cyber Division, stated the following: "The FBI remains committed to disrupting this type of malicious cyber activity that targets our federal agencies and American citizens."
"We will continue to use all the tools at our disposal and leverage our domestic and international partnerships, not only to disrupt this type of hacking activity, but also to impose risks and consequences on our adversaries to combat these threats."
Information source: securityaffairs.co
