Mandiant Insight on Russia & Ukraine
Mandiant’s review of the conflict between Russia and Ukraine warns of retaliation by Russia against organizations that condemn Russia and/or support Ukraine.
Mandiant’s review of the conflict between Russia and Ukraine warns of retaliation by Russia against organizations that condemn Russia and/or support Ukraine.
Anonymous Hacking Group Takes Aim at Russia Industry: N/A | Level: Strategic | Source: Joe.co.ukRussian aggression has provoked hacking group Anonymous who have declared “cyber war” against Russia. From the group’s Twitter handle @YourAnonOne, the group posted the following tweet “The Anonymous collective is officially in cyber war against the Russian government.” The hacking group is making an impact quickly as they have already taken down Russian news websites, “The #Anonymous collective has taken down the website of the #Russian propaganda station RT News.” |
APT29/Nobelium Targets Embassies
Research from FortiGuard has identified threat actor group, APT29/Nobelium/Cozy Bear to be targeting embassies as an observed email impersonating the “Embassy of the Republic of Turkey.” Analysis of the email’s malicious HTML attachment uncovers a malicious JavaScript, which creates an ISO file requiring the user to execute the ISO file. A shortcut pointing to a malicious DLL file is executed for Cobalt Strike. This tactic is likely conducted to monitor activity in embassies to assist in Russian operations.
Symantec reports findings of Trojan.Killdisk, a disk-wiping malware discovered on February 24, 2022 prior to the Russian invasion of Ukraine.
Consolidating available advisory information from the Cybersecurity and Infrastructure Security Agency (CISA), regarding the Ukraine and Russia crisis, provided technical guidance on threat TTPs, associated with Russian threat actors, continuing to urge organizations to have increased awareness of cybersecurity.
With rising tensions between Russia and Ukraine, US regulators have warned banks to brace for potential cyber-attacks.