ZeroHour
CyberScooppublished ()ingested @AJVicens

NATO countries' refugee management may have been targeted by Belarus

criticalExploit / PoC exploited in the wildimportance 60
Full article809 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

A phishing campaign aimed at countries taking refugees is potentially linked to a group known to researchers as TA445, UNC1151 or Ghostwriter.

Ukraine refugees program
Ukrainian citizens board a train toward Wroclaw, Poland, as part of the temporary program for refugees arriving from Ukraine on March 2, 2022 in Przemysl, Poland (Photo by Omar Marques/Getty Images)

A hacking group with a history of phishing attacks and disinformation against NATO nations may be using compromised Ukrainian armed service member emails to target European officials tasked with managing logistics around refugees fleeing Ukraine, according to findings published Monday.

Researchers with cybersecurity firm Proofpoint report they detected an email Feb. 24 that carried a subject referencing the Feb. 24 emergency meeting of NATO on the day the Russian government began its military attack on Ukraine. The email included an attached Microsoft Excel spreadsheet titled “list of persons.xlsx” that the researchers later determined included malware that, if installed, sought to gather information and intelligence from target computers.

The social engineering lure used in this campaign was timely, the researchers said, given the NATO meeting and “a news story about a Russian government ‘kill list’ targeting Ukrainians that began circulating in Western media outlets” Feb. 21.

Proofpoint did not definitively attribute the campaign, but “several temporal and anecdotal indicators exist” suggesting activity associated with a group tracked variously as TA445, UNC1151 or Ghostwriter. The group — with a documented history of disinformation efforts aimed at manipulating sentiment about refugees in NATO countries — is believed to be operating out of Minsk in furtherance of Belarusian and Russian government objectives.

On Feb. 25, the day after the phishing emails were sent, the Ukrainian government Computer Emergency Response Team posted a warning about “mass phishing emails” targeting the accounts of Ukrainian military personnel and related individuals, and attributed the effort to UNC1151 and the Ministry of Defense of the Republic of Belarus.

Proofpoint’s researches note that the data observed allowed for only “limited conclusions” about the targets of the campaign, but noted they were “European governmental entities” with a range of professional responsibilities but were mostly tide to transportation, financial and budget allocation, administration, and population movement within Europe.

“This campaign may represent an attempt to gain intelligence regarding the logistics surrounding the movement of funds, supplies, and people within NATO member countries,” the researchers wrote.

“While the utilized techniques in this campaign are not groundbreaking individually, if deployed collectively, and during a high tempo conflict, they possess the capability to be quite effective,” the researchers wrote. “As the conflict continues, researchers assess similar attacks against governmental entities in NATO countries are likely.”

More Scoops

The Russian flag flies at the embassy’s compound in Washington, DC, on April 15, 2021. (Photo by MANDEL NGAN/AFP via Getty Images)

Multi-national warning issued over Russia’s targeting of logistics, tech firms

The campaign traces back at least to early 2022, coinciding with the start of Russia’s full-scale invasion of Ukraine.

A woman looks at a smartphone in front of part of a graffiti on a wall depicting an anti-tank missile, reading “The only target”, in Kyiv, on Jan. 25. (Photo by SERGEI SUPINSKY/AFP via Getty Images)

Hacks, leaks and wipers: Google analyzes a year of Russian cyberattacks on Ukraine

An Oil Refining and Petrochemical facility. (Getty Images)

Russian hackers attempted to breach petroleum refining company in NATO country, researchers say

Hackers linked to the Chinese government increasingly target Russia, analysis suggests

Hacktivist personas back latest GhostWriter disinfo op targeting Poland, Ukraine

Multiple government hacking groups stay busy targeting Ukraine and the region, Google researchers say

Russian, Chinese, Belarusian hackers increasingly using Ukraine-themed lures in attacks, Google observes

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ghostwriter-phishing-refugees-nato-russia-ukraine/