FYI Russia is totally hacking the West's labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies
- Reference: 1594925764
- News link: https://www.theregister.co.uk/2020/07/16/russia_coronavirus_hacking/
- Source link:
The Kremlin-backed APT29 crew, also known by a variety of other names such as Cozy Bear, Iron Hemlock, or The Dukes, depending on which threat intel company you’re talking to that week, is believed by most reputable analysts to be a wholly owned subsidiary of the FSB, modern-day successor to the infamous Soviet KGB.
NCSC ops director Paul Chichester said in a [1]statement : “We condemn these despicable attacks against those doing vital work to combat the coronavirus pandemic."
Foreign Secretary Dominic Raab [2]added : "It is completely unacceptable that the Russian Intelligence Services are targeting those working to combat the coronavirus pandemic. While others pursue their selfish interests with reckless behaviour, the UK and its allies are getting on with the hard work of finding a vaccine and protecting global health."
NCSC and its international chums say they are 95 per cent confident that the attacks they investigated came from Russia. By abusing publicly known vulnerabilities, including those in Citrix and popular VPN products, the Russians were able to gain access to targeted networks. Once inside they deploy a custom malware named WellMess or WellMail, it's claimed.
“WellMess is a lightweight malware designed to execute arbitrary shell commands, upload and download files. The malware supports HTTP, TLS and DNS communications methods,” said NCSC in its [3]advisory [PDF complete with IOCs and detection rules].
WellMail uses SMTP port 25 to communicate, runs commands or scripts, and uploads its findings to a hard-coded command and control server using TLS encryption. Both pieces of malware are written in Go, the open source language devised by Google. The report neatly summarizes the situation:
Throughout 2020, APT29 has targeted various organisations involved in COVID-19 vaccine development in Canada, the United States and the United Kingdom, highly likely with the intention of stealing information and intellectual property relating to the development and testing of COVID-19 vaccines.
We're Putin our foot down! DHS, FBI blame Russia for ongoing infrastructure hacks [4]READ MORE
Intriguingly, NCSC – along with the US CISA and Canada’s Communications Security Establishment – also said APT29 was deploying a custom malware it named SoreFang against products from Chinese enterprise networking biz Sangfor. However, it cautioned that Sangfor was already a target for other malicious folk before APT29 got wind of it and so not all attacks against Sangfor kit were necessarily proof of state-level espionage.
Today’s attribution follows on from warnings back in May that nameless-but-nefarious bods were [5]targeting those same coronavirus research institutions. In light of today's news, it could be argued that that public shot across the FSB's bows didn't do much to stop the digital attacks.
“This also demonstrates that Iron Hemlock (aka APT29, Cozy Bear) is a very capable threat actor that conducts low visibility operations over an extended period, since at least 2018 in this case, while attracting minimal publicity," Rafe Pilling, a researcher at infosec biz Secureworks, told The Register .
"Every time we see this group emerge in public they are using novel malware and tradecraft. A strong focus on operational security prompts constant change, a stark contrast to some of their comrades in other parts of government and the military.”
He added that it’s not just Russia doing the hacking, although Vladimir Putin’s nation is at the forefront of today’s report: "The NCSC report emphasises that the global interest in COVID-19 is driving an intelligence collection agenda for Russia, as well as nations like Iran, that has previously been identified targeting COVID-19 related research," he opined.
"The organizations developing vaccines and treatments for the virus are being heavily targeted by Russian, Iranian, and Chinese actors seeking a leg up on their own research."
Meanwhile, Mandiant Threat Intelligence’s John Hultquist said in a statement that APT29 tended to stay below the radar and steal data, making today’s attribution all the more eye-catching for espionage watchers.
"Despite involvement in several high-profile incidents, APT29 rarely receives the same attention as other Russian actors because they tend to quietly focus on intelligence collection," he explained. "Whereas GRU actors have brazenly leaked documents and carried out destructive attacks, APT29 digs in for the long term, siphoning intelligence away from its target."
Back in 2015 Fireeye observed APT29 [6]deploying a Twitter-dependent malware strain it called Hammertoss, while last year Eset spotted the same hackers [7]quietly targeting EU nations’ foreign offices and embassies. It seems the state-backed threat is never all that far away. ®
Get our [8]Tech Resources
[1] https://www.ncsc.gov.uk/news/uk-and-allies-expose-russian-attacks-on-coronavirus-vaccine-development
[2] https://uk.reuters.com/article/uk-health-coronavirus-security-raab/raab-says-unacceptable-for-russian-intelligence-services-to-target-covid-19-work-idUKKCN24H24O
[3] https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development.pdf
[4] https://www.theregister.com/2018/03/15/dhs_fbi_blame_russian_government_for_dragonfly_attack_on_infrastructure/
[5] https://www.theregister.com/2020/05/05/coronavirus_research_hacking/
[6] https://www.theregister.com/2015/07/29/russian_apt_menace_hammertoss/
[7] https://www.theregister.com/2019/10/17/apt29_still_active_eset_dukes_cozy_bear/
[8] https://whitepapers.theregister.com/
"What? are we at war with eurasia again? Did I miss a memo?"
So you think Russia isn't trying to hack Covid research? Why would it not?
Why?
Why should I or anyone else care if the Russians, Chinese, or Lower Elbownians read US Coronavirus research? We ought to give them logins. Maybe that'd somehow help humanity come up with a badly needed vaccine.
Get a grip folks.
This sort of thing is what happens when you let people who think government can't work try to run a government.
Re: Why?
Yeah, despite the downvotes you got, and I'll probably get, it seems hypocritical to claim you're all about saving lives, but then not just sharing what you know that might help.
Does everything have to be about war and hate?
Those things do help people in power justify their continued power, but it doesn't seem like they help us as much as simple, and traditional, scientific sharing of knowledge we can all build on - the shoulders of giants - does.
Why is it bad for someone else to possibly learn how to cure or prevent this nasty? In truth, even clutching a solution to your chest only buys you a little time before it gets reverse engineered anyway.
So short sighted and petty. Disgusting.
Mandiant? I knew them, Horatio.
Back in those heady days before I retired, my company laptop was just about usable until one day it had Mandiant software pushed to it.
Re: Mandiant?[**] I knew them, Horatio.
** Other adverts for cybersecurity products also available
This is just a diversion. They (USSR/FSB/KGB) get their real feeds from BJ and DJT
They spent their money and effort well. Now for the rewards.
I'm guessing the western intelligence organizations have been pretty well castrated also.
Why would we not just give it to them?
Because whoever develops a cure or vaccine will make an obscene amount of money.
Vaccines are not money makers, historically. Try again.
Exactly. Who cares if it saves lives? The world is a mess, they should all be sharing their research freely and once they have a vaccine it should be free. However some people want money and lots of it, the more the better. What they don't realise is that one day that will bite them in the arse.
If America develops a vaccine, they will use it for themselves first and sell any left over at a premium price. And certain countries will have to pay more than others.
If Britain developes a vaccine, they will meekly hand it to the America for free, who will do as previously described.
If anyone else develops a vaccine, America will outbid everyone else and buy up the entire stock and all future production for their own use.
Whatever happens, countries like Russia aren't getting any vaccine unless they can steal it or develop it themselves.
There is no altruism in global economics.
The scary thing with the scenario you outlined is that it is entirely plausible and not outlandish.
Sometimes I really think humans as a species - does not deserve to exist and the sooner we are all made extinct the better.
Then I see a beautiful woman and I want to make babies.
Why?
Are they trying to disrupt research or steal it?
Seems an obvious question to ask.
Both disruption and stealing is of course an option because if you can nab the research and build on it whilst hindering those you've nicked it from there is money to be made in being first to market with the vaccine.
A bit of detail on this area would be nice (well not really nice) to know.
Re: Why?
"there is money to be made in being first to market with the vaccine."
To a point. No country is likely to let stand some tiny Russian company that suddenly patents a Covid vaccine a few days before a well-known research team patents the same one.
Re: Why?
'To a point. No country is likely to let stand some tiny Russian company that suddenly patents a Covid vaccine a few days before a well-known research team patents the same one.'
Fair point DavCrav.
Re: Why?
TBH no country is going to let a patent stand in the way of them copying any successful vaccine
Re: Why?
AIUI the main Russian vaccine group has already said that if they succeed the recipe will be made available to the world FoC. Why wouldn't they? If they tried to sell it the US would sanction it, they cannot do so if it is FOSVV and Russia gains huge brownie points.
Re: Why?
I'm pretty sure a variation of this has occurred with the F35
Two points can be made here.
First, Governments have always spied on each other for both political and economic reasons. The only thing that has changed is the methodology, there is nothing new here.
Second, granted that in the present econoomic set-up whoever produces a working vaccine first is going to make a substantial amount of money but it can be argued on humanitarian grounds that this research should be open sourced. That would, of course, obviate the need for spying.
A beer because it is again possibble to go for one.
Chris Cosgrove
In a better world, the various countries would be working together to find something to eradicate this virus. After all, it IS affecting the whole planet.
But money drives way to much "progress". If you can't make a 300% to 1000% profit, it too often doesn't happen.
I 4 1
Я, например, приветствую наших новых повелителей
You for example welcome our new overlords? Google doesn't always translate properly.
As I understand what is really behind this, some naughty person leaked some embarrassing information about the government's plans to cave in to the US on the NHS and food, but leaked it obscurely on Reddit.
Some nasty Russians found the leaked information and made sure it got out more publicly. A bit like investigative journalists used to do back when Presidents had to resign over Watergates rather than pardon people and lie about things on Twitter.
Dom thought they weren't supposed to do that and threw a fit. He forgot that while he and Johnson had been acquired by one group of Russians, there were others that didn't agree with the first lot.
In summary
Every govermeny is hacking and spying on every other goverment.
If it wasn't for goverments and religion (the original oppresive form of goverment) most of of the population of the world would actually get on with each other.
Once more the idiots in charge want to use that oh so secure for proprietary data storage. Haven't they learned yet that a net is just a bunch of holes held together by string?
What? are we at war with eurasia again? Did I miss a memo?