Advertisement

Russian hackers are impersonating as US State Department employees: Report

Russia is keen to resume an aggressive campaign of attacks on U.S. targets

Advertisement
|Nov 17, 2018, 16:03:06 IST
Hackers linked to the Russian government are impersonating US State Department employees in an operation aimed at infecting computers of US government agencies, think tanks and businesses, two cybersecurity firms told Reuters.[caption id="attachment_4836531" align="alignnone" width="1280"]Representational image. PTI

Representational image. PTI[/caption]The operation, which began on Wednesday, suggests Russia is keen to resume an aggressive campaign of attacks on U.S. targets after a lull going into the November 6 US midterm election, in which Republicans lost control of the House of Representatives, according to CrowdStrike and FireEye Inc.US intelligence agencies have charged that Russia was behind a string of hacks in the 2016 presidential campaign in a bid to boost support for Donald Trump. The U.S. government and private cyber security firms have said Russia was not behind hacking campaigns in this year’s congressional elections.In the newly discovered operation, hackers linked to the Russian government sent emails purporting to come from State Department public affairs specialist Susan Stevenson, according to a sample phishing email reviewed by Reuters.It encouraged recipients to download malicious documents that claimed to be from Heather Nauert, a State Department official who Trump has said he is considering naming ambassador to the United Nations.That file would install malicious software that would grant hackers wide access to their systems, according to FireEye.More than 20 FireEye customers were targeted, including military agencies, law enforcement, defense contractors, media companies and pharmaceutical companies, according to the cybersecurity firm.CrowdStrike and FireEye did not say how many organizations had been compromised in the campaign or identify specific targets.The hackers are part of a group known as APT29, according to FireEye. Dutch intelligence has said that APT29 works for the SVR Russian Foreign Intelligence Service.Moscow-based cybersecurity firm Kaspersky Lab confirmed that the campaign was the work of APT29, and said the group had not been active since last year.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Nov 17, 2018, 15:20:52 IST
Advertisement
Advertisement
Trending Stories

China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost

Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
Advertisement
Advertisement
Up Next