Microsoft seizes internet domains linked to GRU cyberattacks against Ukraine
Full article674 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Strontium — a group linked to Russian military intelligence — was using the domains to target Ukrainian institutions, Microsoft said.
Microsoft says it has shut down internet infrastructure that Russian state-backed hackers used to attack the networks of organizations in Ukraine as well as government agencies and think tanks in the U.S. and European Union.
The company said Thursday that it seized seven domains it linked to the GRU military intelligence agency and re-directed the related traffic “to a sinkhole controlled by Microsoft.” The blog post about the maneuver attributed the hacking to a GRU group known to cybersecurity researchers as Strontium, Fancy Bear or Sofacy.
“We believe Strontium was attempting to establish long-term access to the systems of its targets, provide tactical support for the physical invasion and exfiltrate sensitive information,” Microsoft said. “We have notified Ukraine’s government about the activity we detected and the action we’ve taken.”
Ukrainian media organizations were among the targets, the company said.
The takedown is the latest in a series of Western moves to disrupt the Kremlin’s cyber-operations as its war on Ukraine continues. On Wednesday, the U.S. government said it had disrupted a botnet built by another GRU-linked advanced persistent threat (APT) group, Sandworm. Researchers have reported some overlap between GRU hacking teams, but in some cases the activity is attributable to distinct units within the spy agency.
Microsoft said it got a court order on April 6 for the Strontium-linked seizure. It’s not the first time the tech giant has taken over internet domains to stop Russia-linked hacking. The company has made similar moves to thwart campaigns linked to North Korea and China, too.
“We have established a legal process that enables us to obtain rapid court decisions for this work,” the blog post said. “Prior to this week, we had taken action through this process 15 times to seize control of more than 100 Strontium controlled domains.”
The company did not specify the internet domains that were involved, nor did it describe the exact nature of the cyberattacks.
Thursday’s announcement is just a small part of Microsoft’s efforts to help the Ukrainian government, Microsoft said.
Since Russia’s invasion began, “we have observed nearly all of Russia’s nation-state actors engaged in the ongoing full-scale offensive against Ukraine’s government and critical infrastructure, and we continue to work closely with government and organizations of all kinds in Ukraine to help them defend against this onslaught,” the company said.
Microsoft itself is also the subject of relentless pressure from foreign hackers. The cybercrime group Lapsus$ claimed in March that it had breached part of the company’s networks. Microsoft investigated and said “a single account had been compromised, granting limited access.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/strontium-microsoft-seizes-7-internet-domains/