ZeroHour
CyberScooppublished ()ingested @snlyngaas

Before targeting Belarus, Eastern Europe

criticalExploit / PoC exploited in the wildimportance 60
Full article821 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Despite the explosion of security firms that track state-linked hackers, a significant amount of that activity goes unnoticed.

ESET, RSA 2019
Researchers at Slovakian anti-virus company ESET made the discovery. (Scoop News Group photo)

A mysterious cyber-espionage group, active for nearly a decade but documented in detail by private researchers for the first time Friday, has been hacking into government organizations in Eastern Europe in search of secrets.

The hacking group has targeted military organizations, foreign ministries and private firms in Russia, Ukraine, Belarus and the Balkans with pinpoint espionage. Researchers from the anti-virus firm ESET, which claimed the discovery and christened the group “XDSpy,” said the attackers have been scouring a few dozen computers in search of sensitive PDF and Microsoft Word documents.

One of the few other public indicators that XDSpy was on the prowl came from a February advisory from the Belarusian government’s National Computer Emergency Response Team. That statement listed four Belarusian government email accounts that had been compromised by the attackers, but warned that various government officials had been targeted.

The broader region has long been subject to cyber-espionage activity, as hackers from Russia and elsewhere aim to track policymakers from former Soviet states such as Ukraine and Georgia, according to a large body of cybersecurity research. Belarus, in particular, has been the subject of international headlines after autocrat Alexander Lukashenko used technology to crack down on protesters following a disputed election.

The identity of the group behind the XDSpy attacks remains unclear.

“I believe [XDSpy] attracted attention in 2020 because they increase their attack tempo,” ESET researcher Mathieu Faou told CyberScoop. “Their operation became noisier and several people started to look at their activities.”

ESET researchers say it appears to be state-sponsored, but they declined to speculate on which government might be behind it. They did say that the operatives appeared to be based in the same time zones as many of their targets.

The research is a peak behind the curtain of typical espionage activity. The attackers appeared to have tracked their targets’ locations by monitoring wireless access points, and in some cases attempted to exfiltrate data from compromised computers.

Faou said the group’s rather “basic” malware has been effective over the years. But the XDSpy hackers may have also turned to a murky software exploit market where spies and private code-slingers increasingly rub shoulders.

In June, the spies exploited a vulnerability in Internet Explorer. There was little public data on the exploit at the time, ESET said, suggesting that XDSpy either developed it on their own or bought it from an unnamed broker. The code from the exploit bears similarities to one used by DarkHotel, a different espionage group suspected of operating out of South Korea.

More Scoops

Belarus' President Alexander Lukashenko meets with foreign media at his residence, the Independence Palace, in the capital Minsk on July 6, 2023. (Photo by ALEXANDER NEMENOV/AFP via Getty Images)
Belarus’ President Alexander Lukashenko meets with foreign media at his residence, the Independence Palace, in the capital Minsk on July 6, 2023. (Photo by ALEXANDER NEMENOV/AFP via Getty Images)

Hackers with links to Pro-Russian groups compromised foreign embassies in Belarus, researchers say

The work has been carried out by a newly identified group dubbed "MustachedBouncer," according to researchers with ESET.

Ukraine refugees program
Ukrainian citizens board a train toward Wroclaw, Poland, as part of the temporary program for refugees arriving from Ukraine on March 2, 2022 in Przemysl, Poland (Photo by Omar Marques/Getty Images)

NATO countries’ refugee management may have been targeted by Belarus-linked hackers

Ukraine
An observer from the Organization for Security and Co-operation in Europe (OSCE) is seen at a demonstration in Odessa, Ukraine, on May 2. An OSCE employee is among the recent possible hacking targets of suspected Russian spies. (Photo by Pierre Crom/Getty Images)

Ex-US ambassador, anti-corruption activists in Ukraine were targets of suspected Russian phishing

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/eset-xdspy-eastern-europe-espionage/