World

Russia’s critics targeted with global hacking campaign, rights group says

2024.08.14 08:34

By Zeba Siddiqui

(Reuters) – Hackers linked to Russian intelligence are targeting the Kremlin’s critics around the globe with phishing emails, according to new research published on Wednesday by digital rights groups Citizen Lab and Access Now.

The phishing campaign is part of a sweeping internet espionage operation, the researchers say, and comes as U.S. officials are closely monitoring computer networks to thwart any cyberattacks against the 2024 presidential election.

The email hacks began around 2022 and have targeted prominent Russian opposition figures-in-exile, former U.S. think tank and policy officials and academics, U.S. and EU nonprofit staff, as well as media organizations, the report said.

Some of those targeted were still in Russia, “placing them at considerable risk”, the researchers said, adding that the victims may have been selected to try to gain access to their extensive networks of contacts.

While phishing is a common hacking technique, a hallmark of this operation was that the malicious emails often impersonated people known to the victims, making them seem more authentic.

Citizen Lab attributed the hacking to two groups: the prominent Russian hacking outfit Cold River, which Western intelligence and security officials have linked to Russia’s Federal Security Service (FSB), and a new group dubbed Coldwastrel, which appeared to support Russian intelligence.

The Russian embassy in Washington did not respond to a request for comment. Russia has consistently denied allegations of hacking during past incidents linked to Cold River.

One of the victims of the hacking operation was a former U.S. ambassador to Ukraine, who was targeted with a “credible effort” impersonating a fellow former ambassador known to him, according to the report, which didn’t name the person.

The booby-trap emails usually had an attached PDF that solicited a click to decrypt. That click took the target to a website resembling the Gmail or ProtonMail login pages, where if they entered their credentials, the hackers would be able to access their accounts and mailing lists.

Some of those targeted by the campaign fell for it, said Dmitry Zair-Bek, who heads the Russian rights group First Department, which was also involved in the research.

“This attack is not really complicated, but it’s no less effective, because you do not expect a phishing email from your colleague,” Zair-Bek told Reuters.

The total number of people targeted was in the double digits, and most were hit this year, he added, without elaborating.

Citizen Lab said the targets had extensive networks of contacts within sensitive communities, including high-risk individuals within Russia.

“For some, successful compromise could result in extremely serious consequences, such as imprisonment,” it said.

© Reuters. FILE PHOTO: The Russian flag flies on the dome of the Kremlin Senate building behind Spasskaya Tower, in central Moscow, Russia, May 4, 2023. REUTERS/Stringer/File Photo

Cold River has emerged as one of the most prolific Russian hacking groups since it first appeared on the radar of intelligence officials in 2016.

It has escalated its hacking campaign against Kyiv’s allies following Russia’s invasion of Ukraine, and some of its members were sanctioned by U.S. and British officials in December.



Source link

Related Articles

Back to top button
bitcoin
Bitcoin (BTC) $ 105,247.20 2.93%
ethereum
Ethereum (ETH) $ 3,272.01 5.51%
xrp
XRP (XRP) $ 3.11 2.99%
tether
Tether (USDT) $ 1.00 0.03%
solana
Solana (SOL) $ 240.84 5.58%
bnb
BNB (BNB) $ 680.89 2.52%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.334534 3.53%
cardano
Cardano (ADA) $ 0.97069 5.74%
staked-ether
Lido Staked Ether (STETH) $ 3,271.34 5.50%
tron
TRON (TRX) $ 0.251775 5.55%
chainlink
Chainlink (LINK) $ 24.85 8.97%
avalanche-2
Avalanche (AVAX) $ 34.37 5.54%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 104,942.12 2.84%
stellar
Stellar (XLM) $ 0.436891 12.48%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,886.08 5.13%
sui
Sui (SUI) $ 4.13 11.78%
hedera-hashgraph
Hedera (HBAR) $ 0.317539 5.90%
the-open-network
Toncoin (TON) $ 4.82 0.10%
shiba-inu
Shiba Inu (SHIB) $ 0.000019 3.64%
weth
WETH (WETH) $ 3,271.88 5.53%
litecoin
Litecoin (LTC) $ 129.07 15.32%
polkadot
Polkadot (DOT) $ 6.17 9.29%
leo-token
LEO Token (LEO) $ 9.74 0.12%
hyperliquid
Hyperliquid (HYPE) $ 26.82 16.23%
bitcoin-cash
Bitcoin Cash (BCH) $ 438.08 6.83%
bitget-token
Bitget Token (BGB) $ 6.95 3.25%
uniswap
Uniswap (UNI) $ 12.13 4.66%
usds
USDS (USDS) $ 0.999817 0.05%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,463.21 5.45%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.12%
pepe
Pepe (PEPE) $ 0.000013 6.59%
near
NEAR Protocol (NEAR) $ 4.64 5.91%
official-trump
Official Trump (TRUMP) $ 27.12 0.31%
mantra-dao
MANTRA (OM) $ 5.60 24.01%
ondo-finance
Ondo (ONDO) $ 1.59 11.60%
aave
Aave (AAVE) $ 316.04 9.22%
aptos
Aptos (APT) $ 7.97 9.37%
internet-computer
Internet Computer (ICP) $ 9.23 8.47%
monero
Monero (XMR) $ 225.74 2.83%
whitebit
WhiteBIT Coin (WBT) $ 28.47 0.21%
ethereum-classic
Ethereum Classic (ETC) $ 26.51 5.18%
mantle
Mantle (MNT) $ 1.17 9.49%
vechain
VeChain (VET) $ 0.047443 12.54%
bittensor
Bittensor (TAO) $ 466.20 1.86%
crypto-com-chain
Cronos (CRO) $ 0.131935 2.18%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.417353 6.63%
dai
Dai (DAI) $ 0.999935 0.06%
kaspa
Kaspa (KAS) $ 0.133295 10.76%
okb
OKB (OKB) $ 56.21 4.22%