SolarWinds hackers set up phony media outlets to trick targets
Full article528 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
New infrastructure, old tricks.
The Russian hacking group behind the SolarWinds hack, Nobelium, is setting up new infrastructure to launch attacks using old tricks, researchers at Recorded Future found. The findings, published Tuesday and shared first with CyberScoop, demonstrate how the group has evolved in recent months in an effort to avoid researcher detection.
Researchers identified more than four dozen domains the group used in phishing attacks, some of which attempted to emulate real brands. The tactic, in which hackers register potentially misspelled versions of real brand domains to trick targets, is known as “typosquatting.”
By posing as legitimate-looking entities, hackers can more easily trick victims into clicking on links that may be used in credential theft and other crimes. Typosquatting is a common tool associated with Nobelium and has been used by the group in other campaigns, including recent attacks against Ukrainian targets.
The set of domains that Recorded Future identified emulated brands across industries but particularly focused on posing as news and media organizations. Researchers emphasized that the industries emulated did not necessarily equate to industries the group targeted.
Nobelium, also known as APT29 or CozyBear, is believed to have ties with the Russian Foreign Intelligence Service. Since making a splash with an extensive hacking campaign that exploited SolarWinds software, the group has kept busy trying to phish diplomats and international aid groups. Last May, the group launched a spearphishing attack posing as the U.S. Agency for International Development, leading to a Justice Department seizure of domains used in the campaign.
Most recently, Microsoft researchers spotted Nobelium attempting to phish diplomats from Ukraine and NATO members.
Recorded Future researchers were unable to clearly identify victims tied to the newly identified domains, but found ties to the same malware used in previous campaigns. Researchers expressed high confidence in their findings given overlaps with previously identified Nobelium infrastructure, including the consistent use of specifically customized security certificates.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/solarwinds-recorded-future-nobelium-apt29/