pwshub.com

Justice Department and Microsoft target Russian phishing campaigns with domain seizures

The U.S. Department of Justice and Microsoft Corp. have seized 107 websites allegedly used by Russian intelligence agents and their proxies in the U.S. as part of a crackdown on computer fraud and abuse.

The Justice Department seized 41 domains named via warrant, while Microsoft managed to seize 66 domains through civil action. Collectively, the domains are claimed to have been used by a Russian nation-state actor Microsoft Threat Intelligence tracks as Star Blizzard, a group also known by the names of SEABORGIUM and Callisto Group.

According to Microsoft today, the domains were used by Star Blizzard to target over 30 civil society organizations, including journalists, think tanks and non-government organizations between January 2023 and August 2024. The domains were utilized as part of spear-phishing campaigns that attempted to exfiltrate sensitive information and interfere in the activities of the targeted victims.

Star Blizzard itself is believed to have been active since 2017, with the group upping its hacking game in 2022 with improved detection evasion capabilities while remaining focused on email credential threats. Recent targets of the group have included NGOs and think tanks that support government employees and military and intelligence officials, especially those supporting Ukraine.

The group is more than a standard phishing operation, however, with Microsoft noting that they meticulously study their targets and pose as trusted contacts to achieve their goals. The group identifies high-value targets and then crafts personalized phishing emails and develops the necessary infrastructure for credential theft. The victims, often unaware of the malicious intent, then unknowingly engage with these messages, leading to the compromise of their credentials.

Targets of Star Blizzard include former employees of the US intelligence community, personnel at U.S. defense contractors and officials at the Departments of Defense, State and Energy.

While the takedown is being celebrated by the Department of Justice, complete with a media release full of self-congratulatory quotes, in reality, seizing some domain names is nothing more than a minor speed bump in alleged Russian hacking activities.

“This takedown is likely only scratching the surface when it comes to FSB or other groups who have purchased domains to seed malignant websites,” Sean M. McNee, head of Threat Research at DomainTools LLC, told SIliconANGLE via email. “We have found that some domain hosting services sell domain registrations indiscriminately and are not always responsive when notified about malicious content or coordinated misinformation.”

Source: siliconangle.com

Related stories
1 month ago - Regulators are circling ever closer to big tech companies — the latest being Google, which the Federal Trade Commission more than hinted this week should be broken up. It’s not at all certain that will happen, since it’s up to the judge...
6 days ago - This week brought yet another big shakeup at OpenAI, as Chief Technology Officer Mira Murati and others quit. But CEO Sam Altman seems to be cementing his control. And Chief Financial Officer Sarah Friar said in a memo that OpenAI’s...
3 weeks ago - It’s no surprise that entrepreneurs with a pedigree like Ilya Sutskever’s can raise a billion dollars, as the OpenAI co-founder did this week for his startup, SSI. And he wasn’t alone, as Nvidia and others also invested in two other...
1 month ago - Volkswagen is considering closing factories in Germany for the first time in its 87-year history as the carmaker battles to cut costs and survive the transition to electric cars.
4 days ago - A long-standing feud between Google and Microsoft is spilling into public view once again.
Other stories
52 minutes ago - With the rise of visual data in inbound telemetry, computer vision has the potential to transform analytics. It automates the extraction of insights from videos and images. By offering real-time visual data analysis and insights, computer...
53 minutes ago - Google LLC is making a new version of its popular Gemini 1.5 Flash artificial intelligence model available that’s smaller and faster than the original. It’s called Gemini 1.5 Flash-8B, and it’s much more affordable, at half the...
53 minutes ago - OpenAI is updating ChatGPT with a new interface section, called canvas, that promises to make the chatbot more useful for writing and coding tasks. The company debuted the feature today. It marks OpenAI’s first product update since the...
59 minutes ago - "Blackwell is in full production, Blackwell is as planned," Jensen Huang said. "Everybody wants to have the most and everybody wants to be first."
2 hours ago - Indexes edged lower Thursday as investors took in an uptick in jobless claims and simmering tensions in the Middle East. A key jobs report is due Friday.