Microsoft ties January Ukraine attack to notorious Sandworm group
Full article814 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Expect to see more attacks, Microsoft says.
Microsoft on Wednesday tied a January data-wiping malware attack in Ukraine to notorious Russian hacking group Sandworm.
The new link fleshes out the operations of the group, also dubbed Iridium by Microsoft, during a heated war between Russia and Ukraine. Ukraine has already blamed the Sandworm group, which is affiliated with Russia’s GRU military agency for staging a malware attack on Ukraine’s power grid earlier this month — the third time in the group’s history.
Microsoft reports observing close to 40 destructive attacks targeting hundreds of systems since the conflict started. Roughly 32% of the attacks went after Ukrainian governmental organizations while more than 40% of destructive attacks were aimed at organizations in critical infrastructure sectors. Microsoft’s timeline of Russia’s cyber operations indicated that it began pre-positioning for conflict as early as March 2021, working to gain a foothold in Ukrainian systems and gain access to supply chain vendors critical to Ukraine.
The report found that Russia’s use of cyberattacks appears to be sometimes timed with its physical warfare. For instance, around the same time Russian forces invaded Mariupol, Russian operatives began sending emails posing as a Mariupol resident claiming the Ukrainian government had abandoned its people.
Microsoft also noted some limited espionage-related attacks against other NATO member states and some disinformation.
Victor Zhora, the deputy chief of Ukraine’s State Service of Special Communication and Information Protection, suggested to reporters on Wednesday that Russia’s cyberattacks had plateaued in severity.
“If they wanted to arrange anything very destructive they had two months to do that,” Zhora said.
Microsoft estimates that Russia has deployed at least eight destructive malware families on Ukrainian networks, including the industrial control system-specific malware used in the electric grid attack, Industroyer2. Zhora says that the Ukrainian government has not observed signs of Industroyer2 being used against any other energy companies but doesn’t rule out the possibility.
Microsoft was more negative in its few of Russia’s potential for scaling up operations.
“If threat actors can maintain the current pace of development and deployment, we anticipate more destructive malware will be discovered as the conflict continues,” Microsoft vice president Tom Burt warned in a blog post.
AJ Vicens contributed to this story.
More Scoops
What keeps CISOs up at night? Mandiant leaders share top cyber concerns
A trio of top brass for Mandiant shared the emerging advanced tactics, techniques and procedures that they see troubling cyber professionals.
Russian hackers disrupted Ukrainian electrical grid last year
Russian hacking operations target Ukrainian law enforcement
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-ties-january-ukraine-attack-to-notorious-sandworm-group/