HomeSecurity$10 million reward for information on the hacking gang "Cadet...

$10 million reward for information on the “Cadet Blizzard” hacking gang

The US government, with international partners, attributed responsibility for attacks related to the 161st Specialist Training Center to a Russian hacking group, “Cadet Blizzard”.

Cadet Blizzard

“Such hacking gangs have been responsible for attacks on global organizations for espionage, sabotage and reputational damage since 2020,” the authorities said. “Since the beginning of 2022, the goal of the “Cadet Blizzard” gang has been to hinder humanitarian aid efforts in Ukraine.”.

See also: Singapore's Ministry of Education removes Mobile Guardian app from students' devices after hacking attack

The attacks focus on critical infrastructure and essential resources, including government agencies, financial institutions, transportation systems, energy sectors, and healthcare services. The targets of these attacks include NATO, the European Union, as well as Central American and Asian states.

The briefing, released last week as part of a coordinated exercise called Operation Toy Soldier, comes from cybersecurity and intelligence authorities from the US, the Netherlands, the Czech Republic, Germany, Estonia, Latvia, Ukraine, Canada, Australia and the UK.

The Cadet Blizzard group, also known as Ember Bear, FROZENVISTA, Nodaria, Ruinous Ursa, UAC-0056, and UNC2589, gained attention in January 2022 due to the deployment of the destructive WhisperGate malware (also known as PAYWIPE) against various organizations affected by the Russian military invasion of Ukraine.

In June 2024, a 22-year-old Russian citizen, Amin Timovich Stigal, was indicted in the US for his alleged role in orchestrating devastating cyberattacks against Ukraine using wiper malware. However, the use of WhisperGate is not limited to this group.

The US Department of Justice (DoJ) has charged five officers of Unit 29155 with conspiracy to commit computer intrusions and computer fraud against targets in Ukraine, the US and 25 other NATO countries.

The names of the five officers are listed below –

  • Yuriy Denisov (Юрий Денисов), Russian Army Colonel and Commander of Cyberspace Operations for Unit 29155
  • Vladislav Borovkov (Владислав Боровков), Denis Denisenko (Денис Денисенко), Dmitriy Goloshubov (Дима Голошубов) and Nikolay Korchagin (Николай Корчагин), Russian army lieutenants assigned to Unit 29155 working on cyber operations.

“The defendants sought to cause concern among Ukrainian citizens about the security of government systems and their personal data,” the Justice Department said. “Their targets included Ukrainian government systems and data not related to military or defense activities. Further targets included computer systems in various countries that provided support to Ukraine.”

Concurrently with the announcement of the charges, the U.S. State Department's Rewards for Justice program has offered a reward of up to $10 million for information regarding the defendants' locations or their malicious cyber activity.

Read also: Toyota – Data Breach: Data Leaked on Hacking Forum

Evidence suggests that Unit 29155 is responsible for coup attempts, sabotage, influence operations and assassination attempts across Europe, with the adversary expanding its activities to include offensive actions in cyberspace since at least 2020.

The ultimate goal of these cyberattacks is to collect sensitive information for espionage purposes, cause reputational damage through data leaks, and carry out destructive operations aimed at sabotaging systems containing valuable information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Unit 29155, according to the information, includes junior, active-duty GRU officers who work with known cybercriminals and other political actors, such as Stigall, to facilitate their missions.

These activities include website defacement, infrastructure scanning, data filtering, and information leaks that may include rendering data on public platforms or selling it to third parties.

The attack chains begin with scanning activities that exploit known security flaws in platforms such as Atlassian Confluence Server and Data Center, Dahua Security, and Sophos firewall, with the aim of compromising victims’ environments. This process is followed by the use of Impacket for post-exploitation and lateral movement, ultimately resulting in data extraction to a dedicated infrastructure.

Cadet Blizzard

See more: Vulnerabilities expose solar systems to hacking

“The hackers may have used the malware as an access broker,” authorities said. They targeted victims’ Microsoft Outlook Web Access (OWA) infrastructure, using password spraying to obtain valid usernames and passwords.

Organizations are advised to prioritize regular system updates and patch known exploitable vulnerabilities. Additionally, they should segment their networks to prevent the spread of malicious activity and enforce phishing-resistant multi-factor authentication (MFA) for all external account services.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS