HomeSecuritySuspected Russian group "Sandworm" targeted NATO in Ukraine

Suspected Russian group “Sandworm” targeted NATO in Ukraine

iSIGHT_Partners_sandworm_targets_13oct2014

A group of cyberspies has targeted NATO, Ukrainian and Polish government agencies and some sensitive European industries over the past year, in some cases using a previously unknown Windows vulnerability, according to a research report published Tuesday.

“Sandworm,” as it was dubbed by security consultancy iSight Partners, which discovered the zero-day attack, is believed to be of Russian origin based on technical details, the malware tools used, and the selection of targets, which included European government agencies and academics in the United States. If confirmed, the attack would shed light on the capabilities of Russian cyber-espionage.

The Sandworm Team also used a previously unknown software vulnerability to attack systems running versions of Windows Vista, Windows 7, Windows 8, and Windows RT.

“We can confirm that NATO was hit and we know from multiple sources that multiple organizations in Ukraine were targeted,” said John Hultquist, senior director of cyber-intelligence at iSight. “We have seen them use Ukrainian infrastructure as part of their attacks.”

The group first came to light in September, when some details of the attack were described by F-Secure and ESET. Those companies discovered that a relatively well-known spam, “Black Energy,” which was originally created seven years ago as a denial-of-service tool, was widely used in attacks by cybercriminals in Russia and Eastern Europe. There is also an upcoming banking trojan called “Dyre” that has already become popular.

The attackers exploited multiple vulnerabilities simultaneously to gain the necessary privileges and execute code, said iSight, which monitors at least five Russian cyber espionage groups.

The Sandworm Team targeted NATO in December 2013 as well as participants in the global security conference in May 2014. In June, they attacked a Polish energy company, a French telecommunications company, and other critical industries.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS