Report: APT28 breached German foreign and defense ministries
Full article520 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Russian group infamous for hacking the DNC successfully breached German government agencies, German media report.
Hackers believed to be tied to the Russian government successfully compromised the networks of the German defense and foreign ministries in at attack that may have lasted for a year, German news agency Deutsche Presse-Agentur reported Wednesday.
Citing unnamed officials, the news agency reported that APT28 used malware to steal data from the government agencies, but the extent of the impact is unclear.
Another German outlet, Deutsche Welle, reports that the hackers infiltrated a specially designed network used by the government to keep communications secure and separate.
German press claim that that the BSI and BfV intelligence agencies are investigating the breach.
APT28, commonly known as FancyBear, has been blamed by both private cybersecurity companies and U.S. intelligence agencies for carrying out attacks that target governments and political entities. Most notably, the group is known for obtaining and then leaking private information from Democratic National Commission in the 2016 U.S. election. More recently, the group leaked information from the International Luge Federation. Ukrainian intelligence agencies have blamed APT28 for other incidents, including the BadRabbit and NotPetya ransomware attacks of last year.
Also on Wednesday, U.S. cybersecurity firm Palo Alto Networks published a report detailing a campaign by APT28 to target foreign affairs ministries around the world. Ryan Olson, senior threat intelligence director at Palo Alto Netoworks’ Unit 42 research team, told CyberScoop that it’s not clear if the new research and German data breach are in any way connected.
However, he indicated, the fact that both reports involve APT28 and foreign ministries is noteworthy.
“Given how [APT28] works, it is reasonable to see both of these as related,” Olson said.
This is far from the first time APT28 has attacked German government institutions. The hacking group has also reportedly targeted the German parliament and country’s elections in recent years.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apt28-fancy-bear-germany-foreign-defense/