Before targeting Belarus, Eastern Europe
Full article821 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Despite the explosion of security firms that track state-linked hackers, a significant amount of that activity goes unnoticed.
A mysterious cyber-espionage group, active for nearly a decade but documented in detail by private researchers for the first time Friday, has been hacking into government organizations in Eastern Europe in search of secrets.
The hacking group has targeted military organizations, foreign ministries and private firms in Russia, Ukraine, Belarus and the Balkans with pinpoint espionage. Researchers from the anti-virus firm ESET, which claimed the discovery and christened the group “XDSpy,” said the attackers have been scouring a few dozen computers in search of sensitive PDF and Microsoft Word documents.
One of the few other public indicators that XDSpy was on the prowl came from a February advisory from the Belarusian government’s National Computer Emergency Response Team. That statement listed four Belarusian government email accounts that had been compromised by the attackers, but warned that various government officials had been targeted.
The broader region has long been subject to cyber-espionage activity, as hackers from Russia and elsewhere aim to track policymakers from former Soviet states such as Ukraine and Georgia, according to a large body of cybersecurity research. Belarus, in particular, has been the subject of international headlines after autocrat Alexander Lukashenko used technology to crack down on protesters following a disputed election.
The identity of the group behind the XDSpy attacks remains unclear.
“I believe [XDSpy] attracted attention in 2020 because they increase their attack tempo,” ESET researcher Mathieu Faou told CyberScoop. “Their operation became noisier and several people started to look at their activities.”
ESET researchers say it appears to be state-sponsored, but they declined to speculate on which government might be behind it. They did say that the operatives appeared to be based in the same time zones as many of their targets.
The research is a peak behind the curtain of typical espionage activity. The attackers appeared to have tracked their targets’ locations by monitoring wireless access points, and in some cases attempted to exfiltrate data from compromised computers.
Faou said the group’s rather “basic” malware has been effective over the years. But the XDSpy hackers may have also turned to a murky software exploit market where spies and private code-slingers increasingly rub shoulders.
In June, the spies exploited a vulnerability in Internet Explorer. There was little public data on the exploit at the time, ESET said, suggesting that XDSpy either developed it on their own or bought it from an unnamed broker. The code from the exploit bears similarities to one used by DarkHotel, a different espionage group suspected of operating out of South Korea.
More Scoops
Hackers with links to Pro-Russian groups compromised foreign embassies in Belarus, researchers say
The work has been carried out by a newly identified group dubbed "MustachedBouncer," according to researchers with ESET.
NATO countries’ refugee management may have been targeted by Belarus-linked hackers
Ex-US ambassador, anti-corruption activists in Ukraine were targets of suspected Russian phishing
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/eset-xdspy-eastern-europe-espionage/