Nobelium Hacks EU Agencies
2023-03-158 turns8,589 charstext-davinci-002-render-sha
Summary
Nobelium hackers targeted EU agencies using fake schedules, bogus websites, and Notion app impersonation.
Messages
A Russian state-backed hacker group known as Nobelium is behind recent attempted cyberattacks on diplomatic entities and government agencies in the European Union, cybersecurity researchers say.
Nobelium is a Russian state-sponsored hacking group that has been active since at least 2011. The group is known for using a variety of advanced techniques to gain access to sensitive information and government systems.
In June 2021, cybersecurity researchers reported that Nobelium was behind a wave of attacks targeting government agencies, think tanks, and non-governmental organizations in the United States. The group used a variety of tactics, including phishing emails and exploiting vulnerabilities in Microsoft Exchange servers.
Now, in March 2023, cybersecurity researchers are reporting that Nobelium is behind recent attempted cyberattacks on diplomatic entities and government agencies in the European Union. The group used similar tactics as in the US attacks, including spear-phishing emails and exploiting vulnerabilities in Microsoft Exchange servers.
It's important to note that Nobelium is not the only state-sponsored hacking group active in the world. Many countries have their own state-sponsored hacking groups that are tasked with conducting cyber espionage and other types of cyber operations. As such, it's important for organizations and individuals to take steps to protect themselves from cyber threats, such as using strong passwords, keeping software up to date, and being cautious when opening email attachments or clicking on links.
text-davinci-002-render-sha
A Russian state-backed hacker group known as Nobelium is behind recent attempted cyberattacks on diplomatic entities and government agencies in the European Union, cybersecurity researchers say.
In a campaign identified in early March, the hackers sent phishing emails with content related to diplomatic relations between Poland and the U.S., according to a report by cybersecurity firm BlackBerry. The emphasis was on targeting entities that are “aiding Ukrainian citizens fleeing the country, and providing help to the government of Ukraine,” the researchers said.
In particular, Nobelium — also commonly known as APT29 or Cozy Bear — sent phishing emails with the alleged 2023 schedule for the Polish ambassador to the U.S. The emails carried EnvyScout malware, which allows attackers to drop malicious files on a computer, BlackBerry said.
"The threat actors carefully follow geopolitical events and use them to increase their possibility of a successful infection," the researchers said.
Nobelium is a well-funded group controlled by the Russian Foreign Intelligence Service (SVR), which collects intelligence outside Russia, including electronic surveillance. The hackers have been linked to several high-profile incidents, including the SolarWinds supply chain attack in 2020, which affected thousands of organizations globally and led to a series of data breaches.
During the war in Ukraine, Nobelium has carried out cyberattacks against the Ukrainian military and its political parties, as well as international governments, think tanks and nonprofit organizations, according to Ukraine’s state security service.
Stealthy and patient
Apart from using the fake schedule of the ambassador to deceive victims, the hackers also developed bogus websites for LegisWrite and eTrustEx, which European Union nations use for secure data transfer and information exchange.
Nobelium may not have advanced phishing tactics, according to the researchers, but the hackers are agile and efficient once they gain access to a network. The main goal is to exfiltrate data, BlackBerry said.
The group’s operators are also known “to be stealthy, extremely patient, and skilled in utilizing innovative intrusion techniques that abuse Microsoft technologies and services,” the researchers said.
In previous campaigns, Nobelium hackers used compromised command-and-control communication servers hosted in the Microsoft Azure cloud infrastructure to make their malicious activity look legitimate.
This time, Russian hackers used the note-taking app Notion’s application programming interface (API) to communicate with a compromised system, according to BlackBerry. The group also used Notion during a campaign in November.
Yes, that is correct. A Russian state-sponsored hacking group known as Nobelium, also known as APT29 or Cozy Bear, is believed to be behind a recent attempted cyberattack campaign on diplomatic entities and government agencies in the European Union. The group reportedly used phishing emails and malware to target entities that were allegedly aiding Ukrainian citizens fleeing the country and providing help to the government of Ukraine.
Nobelium is known for using innovative intrusion techniques that abuse Microsoft technologies and services. The group has previously been linked to high-profile cyberattacks, including the SolarWinds supply chain attack in 2020, which affected thousands of organizations globally. The group is believed to be controlled by the Russian Foreign Intelligence Service (SVR), which collects intelligence outside of Russia.
During this recent campaign, the group sent phishing emails containing malware disguised as the 2023 schedule for the Polish ambassador to the U.S. The emails carried EnvyScout malware, which allowed the hackers to drop malicious files on a computer. The group also developed fake websites for LegisWrite and eTrustEx, which are used by European Union nations for secure data transfer and information exchange.
The researchers noted that while the group's phishing tactics may not be advanced, Nobelium is agile and efficient once it gains access to a network. The group is known to be stealthy, extremely patient, and skilled in utilizing innovative intrusion techniques. During previous campaigns, the group used compromised command-and-control communication servers hosted in the Microsoft Azure cloud infrastructure to make their malicious activity look legitimate. However, this time, the group used the note-taking app Notion's API to communicate with a compromised system.
text-davinci-002-render-sha
Apart from using the fake schedule of the ambassador to deceive victims, the hackers also developed bogus websites for LegisWrite and eTrustEx, which European Union nations use for secure data transfer and information exchange.
Yes, that's correct. In addition to using the fake schedule of the Polish ambassador to the U.S. to deceive victims, Nobelium hackers also developed bogus websites for LegisWrite and eTrustEx, which are used by European Union nations for secure data transfer and information exchange. These fake websites were likely used to collect sensitive information or credentials from unsuspecting victims.
It's not uncommon for hackers to use tactics like phishing emails and fake websites to gain access to sensitive information or systems. That's why it's important for individuals and organizations to be vigilant and cautious when it comes to opening emails, clicking on links, or providing personal or sensitive information online. It's also important to keep software and systems up to date with the latest security patches and to use strong passwords and two-factor authentication whenever possible.
text-davinci-002-render-sha
In previous campaigns, Nobelium hackers used compromised command-and-control communication servers hosted in the Microsoft Azure cloud infrastructure to make their malicious activity look legitimate.
This time, Russian hackers used the note-taking app Notion’s application programming interface (API) to communicate with a compromised system, according to BlackBerry. The group also used Notion during a campaign in November.
That's correct. In previous campaigns, Nobelium hackers have used compromised command-and-control communication servers hosted in the Microsoft Azure cloud infrastructure to make their malicious activity look legitimate.
However, during this recent campaign, the group used the note-taking app Notion's application programming interface (API) to communicate with a compromised system. This allowed the hackers to avoid detection and appear as legitimate users of the app. The group also reportedly used Notion during a campaign in November.
Using legitimate software or services to communicate with compromised systems or to hide malicious activity is a common tactic used by cybercriminals and state-sponsored hacking groups. It's important for organizations to monitor their networks and systems for any suspicious activity and to implement strong security measures to protect against potential cyber threats.
text-davinci-002-render-sha