HomeSecurityCozyDuke hackers are likely of Russian origin

CozyDuke hackers are likely of Russian origin

CozyDuke hackers are likely of Russian origin

The group of attackers responsible for the cyber intrusions into the White House and the Department of State had used malware with very strong similarities to cyberespionage tools allegedly of Russian origin.

 

Russian-Hackers-min

 

Security researchers from Kaspersky Lab have identified the cyber espionage group called CozyDuke, and report that:

"This group has been conspicuously targeting high-profile victims since the second half of last year. Its toolset includes malware droppers, information-stealing programs, and backdoors that have antivirus evasion capabilities and use cryptography.".

Most importantly, technical evidence suggests that some elements of the CozyDuke malware have many similarities to "functional and structural parts" of the MiniDuke, CosmicDuke and OnionDuke cyberespionage tools, Kaspersky researchers said.

 

These three threats (MiniDuke, CosmicDuke, and OnionDuke) have been used by hackers to attack NATO members and European governments over the past two years and are believed to be related.

 

white-house-hacked-by-russian-hackers.1280x600-min

While Kaspersky researchers did not discuss the possible origins of CozyDuke in their statement, researchers from other companies who have analyzed MiniDuke, CosmicDuke, and OnionDuke in the past believe it is the work of the Russian government.

In a blog post in January, researchers from F-Secure noted that none of the high-profile targets of CosmicDuke or OnionDuke were from Russia. The only victims detected in Russia had connections to illegal elements, and they speculate that these spyware tools were used in support of law enforcement investigations in the country.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS