pwshub.com

Russian state-sponsored phishing campaign targets Western NGOs and diplomats

A Russian state-sponsored spear phishing campaign has been found to be targeting Western and Russian civil society targets, including nongovernmental organizations, independent media and at least one former U.S. ambassador.

The campaign, detailed Wednesday by Citizen Lab and dubbed “River of Phish,” engaged targets with personalized and highly plausible social engineering in an attempt to gain access to their online accounts. The campaign is believed to be run by the Coldriver group, which Western governments believe is linked to the Russian Federal Security Service.

The targets have included Russian opposition figures in exile to staff at nongovernmental organizations in the U.S. and Europe, funders and media organizations. Among the targets was Polina Machold, the publisher of a media out that conducts high-profile investigative reporting into official corruption and abuses of power in Russia.

Citizen Lab also observed the group targeting former officials and academics in U.S. think tanks and policy organizations. Among them was former U.S. Ambassador to Ukraine Steven Pifer, who was targeted with a highly credible approach impersonating someone known to him — a fellow former U.S. ambassador.

Though certain targeted groups and individuals have been identified, Citizen Labs notes that they suspect the total pool of targets is likely much larger than the civil society groups it has analyzed. Notably, the Russian group was also found to be impersonating U.S. government personnel as part of its campaign, meaning that there could be further compromises within the U.S. government.

“Cybercriminals target anyone with an email address, but targeting high-profile people in government is a win for them,” James McQuiggan, security awareness advocate at KnowBe4 Inc., told SiliconANGLE. “Gaining access to a system that is within the government can be the stepping stone to a much larger payoff” as the attackers “can leverage the victim’s system to access other systems with the government infrastructure to then be able to collect data or maintain persistence for future access, which could lead to an attack or possible ransomware outcome.”

“Email should be treated with skepticism,” McQuiggan added, “If it’s not expected or the sender is unknown, like answering the front door of your home and seeing a package that wasn’t ordered, it should be met with skepticism and verify the sender or the contents of the email.”

Source: siliconangle.com

Related stories
1 month ago - Regulators are circling ever closer to big tech companies — the latest being Google, which the Federal Trade Commission more than hinted this week should be broken up. It’s not at all certain that will happen, since it’s up to the judge...
1 month ago - Google LLC’s Threat Analysis Group today shared details on multiple observed in-the-wild exploit campaigns that used watering-hole attacks on Mongolian government websites between November 2023 and July this year. A watering-hole attack...
1 month ago - The U.S. Department of Justice, State and Treasury announced today sanctions and criminal charges in relation to claimed Russian government-sponsored attempts to manipulate public opinion ahead of the Presidential election currently...
2 weeks ago - The landscape of today’s cyber threats means that the lines between nation-state espionage, cyber warfare and private-sector attacks are increasingly blurred. How can companies navigate those intricate lines to overcome threats, such as...
1 month ago - U.S. intelligence agencies, led by the Federal Bureau of Investigation, said in the statement today that they believe that Iran is behind attempts to hack both the Trump and Harris presidential campaigns. The statement follows previous...
Other stories
47 minutes ago - The Dow and the S&P 500 closed at a record high. Markets are waiting for September inflation data, a key data point ahead of the Fed's next move.
47 minutes ago - The most oversold stocks in the health care sector present an opportunity to buy into undervalued companies. The RSI is a momentum indicator, which compares a stock’s strength on days when prices go up to its strength on days when prices...
1 hour ago - Asian stocks got a lift on Thursday from Chinese stocks as China's central bank kicked off its 500 billion yuan facility to spur capital markets, while the dollar lingered near a two-month high ahead of U.S. inflation data later in the...
2 hours ago - Palantir Technologies, Inc. (NYSE:PLTR) shares have been on a tear ever since the company was added to the S&P 500 Index. The stock inflection has followed an inflection in the company’s fundamentals, and on Tuesday the data analytics...
2 hours ago - Cathie Wood, the founder and CEO of ARK Investment Management, is again making waves with her investment decisions regarding Amazon.com, Inc. (NASDAQ:AMZN). What Happened: Known for her high-risk, high-reward strategy, Wood’s latest moves...