HomeSecurityMicrosoft: Prevented attacks against Ukraine by removing domains of Russian APT28

Microsoft: Prevented attacks against Ukraine by removing domains of Russian APT28

Microsoft has managed to disrupt attacks by the Russian hacking group APT28 against Ukrainian organizations, taking down seven domains that were used as part of the attack infrastructure.

APT28, also known as Fancy Bear and Strontium, is linked to the Russian military intelligence agency GRU and appears to have used these domains to target multiple Ukrainian entities, including media organizations.

See also: Facebook accounts of Ukrainian soldiers targeted by hackers

APT28 Microsoft

According to Microsoft, these domains were also used in attacks against US and EU government institutions related to foreign policy.

Microsoft did not identify any of the targets by name.

On Wednesday, April 6, we received a court order authorizing us to take control of seven internet domains that Strontium was using to conduct these attacks,” said Tom Burt, Corporate Vice President of Customer Security & Trust at Microsoft. “We have since redirected these domains to a Microsoft-controlled sinkhole so that we can restrict Strontium’s ongoing use of these domains.”

Microsoft believes that the Russian hacking group APT28 was attempting to gain persistent access to the targets' systems, provide support for a physical intrusion, and steal sensitive information.

Useful information: What are the best antivirus software for 2022?

The company informed the Ukrainian government about APT28's malicious activities against the country. It also informed the country about the removal of the domains and the cessation of APT28's attempts to compromise Ukrainian networks.

APT28 Russia

The Russian group has targeted many governments in the past

In August 2018, Microsoft again targeted APT28, and proceeded to seize 91 malicious domains.

“ This disruption is part of an ongoing campaign, begun in 2016, to take legal and technical steps to seize the infrastructure used by Strontium. We have established a legal process that enables us to make swift court decisions on this project ,” Burt added

The Russian group was closely monitored even before the Russian invasion of Ukraine. Both the US and the UK had issued a joint warning about APT28 attacks.

In July, the US National Security Agency, the Department of Homeland Security's Cybersecurity and Infrastructure Agency, the Federal Bureau of Investigation and the UK's National Cybersecurity Center warned that the hacking group was conducting brute-force attacks to gain access to networks with the aim of stealing personal data.

Useful information: Identity Theft scams: What is it and how to protect yourself?

The attacks targeted government services as well as the private sector worldwide.

Ukraine attacks

A few words about the Russian hacking group APT28

The group has been active since at least 2004 and works for the Russian government. It is behind well-known cyberespionage that have targeted governments around the world. In 2015, it attacked the German Federal Parliament and later targeted the Democratic National Committee (DNC) and the Democratic Congressional Campaign Committee (DCCC).

The US has accused some members of the group of hacking into the DNC and DCCC in 2018 as well as targeting and breaching individual members of the Clinton Campaign.

Two years later, the Council of the European Union announced sanctions against several members of APT28 for their involvement in the hacking of the German federal parliament (Deutscher Bundestag) in 2015.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS