Russia-linked cyber attacks targeted 104 accounts of European think tanks

Russia-linked cyber attacks targeted 104 accounts of European think tanks

 

Hybrid War

On 20 February 2019, Microsoft announced that it had discovered cyber attacks against several democratic institutions, think tanks, and non-profit organizations in Europe, totaling 104 breach attempts. The hacks took place between September and December 2018, affecting institutions including the German Council on Foreign Relations and European offices of The Aspen Institute and The German Marshall Fund.

In total, 104 employee accounts in Belgium, France, Germany, Poland, Romania, and Serbia were targeted via spear phishing campaigns designed to gain access to employee credentials and deliver malware. Spear phishing attacks are a more sophisticated form of phishing, in which hackers include malicious URLs in spoofed email addresses that look legitimate to the recipient.

While the sources of the cyber attacks are still being investigated by Microsoft’s Threat Intelligence Center, the company has stated with confidence that the majority originated from a group called Strontium – also known as APT 28 or Fancy Bear – which is believed to be associated with Russia’s military intelligence agency, the GRU. Fancy Bear is one of the groups responsible for the 2016 hacking of the US Democratic National Committee and has also been linked to intrusions into the German Bundestag and France’s TV5 Monde. In 2018, Fancy Bear leaked emails stolen from the International Olympic Committee and anti-doping agencies following Russia’s ban from the 2018 Winter Olympics.

A Microsoft company blog post highlights the ongoing cyber threat facing Europe and emphasizes that such “attacks are not limited to campaigns themselves but often extend to think tanks and non-profit organizations working on topics related to democracy, electoral integrity, and public policy and those are often in contact with government officials.”

In light of these latest attacks and persistent security concerns about the upcoming European elections, Microsoft has confirmed the rollout of its free cybersecurity service AccountGuard to twelve new EU nations in order to help them close their security gaps. The company did not mince words about the severity of the threat: “The attacks we’ve seen recently, coupled with others we discussed last year, suggest an ongoing effort to target democratic organizations. They validate the warnings from European leaders about the threat level we should expect to see in Europe this year.”

Editor’s Note

Meanwhile, Ukraine remains a testing ground for the Russian cyber attacks for years. For example, the latest attack on the servers of the Central Election Commission just a month before the presidential election had been recorded on 24-25 February, according to President Petro Poroshenko, and the Security Service o Ukraine has reportedly repelled it.


Further reading:

 

Edited by: Yuri Zoria

Source: EU vs Disinfo

Dear readers! We need your help. COVID-19 has hit independent media outlets hard, but even more so in Ukraine, where most outlets are controlled by oligarchs. To make matters worse, several English-language media sources from Ukraine have closed recently. And even worse, this comes at a time of troubling government tendencies and amid a pro-Russian resurgence in Ukraine.  Help keep us online and reporting on the most important of Ukrainian issues for you in these troubling times, bringing the voices of civic society to the forefront of the information war. Our articles are free for everyone to use but we depend on our readers to keep going.  We are a small independent journalist team on a shoestring budget and have no political or state affiliation. If you like what you see, please support us with a donation

Tags: , , , , , , , ,