Here's 30 servers Russian intelligence uses to fling malware at the West, beams RiskIQ
- Reference: 1627662250
- News link: https://www.theregister.co.uk/2021/07/30/riskiq_reveals_30_svr_apt29_c2_servers/
- Source link:
Russia's Foreign Intelligence Service "is actively serving malware (WellMess, WellMail) previously used in espionage campaigns targeting COVID-19 research in the UK, US, and Canada," according to threat intel firm.
"Team Atlas assesses with high confidence that these IP addresses and certificates are in active use by APT29 at the time of this writeup," said RiskIQ in its [1]blog post . "We were unable to locate any malware which communicated with this infrastructure, but we suspect it is likely similar to previously identified samples."
[2]
Previously the SVR was [3]linked to the WellMess malware , seen being deployed against Western medical science institutions in early 2020 as nation states raced to develop effective vaccines against COVID-19.
[4]
[5]
In revealing these 30 servers' IP addresses and details of their SSL certificates, RiskIQ follows the lead of the US CISA infosec agency, which in April [6]told the world exactly what the SVR was deploying and from where , along with offering avoidance advice. The company also highlighted [7]Japan's CERT's uncovering of WellMess as a new malware strain targeting Windows and Linux back in 2018.
[8]Biden to Putin: Get your ransomware gangs under control and don’t you dare cyber-attack our infrastructure
[9]Somebody's Russian to meddle with UK coronavirus vaccine efforts, but GCHQ won't take it lying down
[10]Russian cyber-spies changed tactics after the UK and US outed their techniques – so here's a list of those changes
[11]Surprise surprise! Hostile states are hacking coronavirus vaccine research, warn UK and USA intelligence
Known to the infosec industry as APT29*, the SVR does not appear to have slowed down since [12]the well-publicised Biden-Putin summit of June, where the American president nicely asked his Russian counterpart to tone it down a bit.
SVR operations against the West have been fairly brazen, with responses varying from [13]quiet warnings through direct attribution to outright " [14]they won't sodding well stop so we're telling you exactly what the naughty buggers have moved onto now " from a fed-up National Cyber Security Centre in the UK. Just for good measure, the GCHQ offshoot also [15]briefed national newspapers in November that they were countering the SVR's continuing efforts to break into British research institutions, hinting they were deploying a form of encryption malware (think ransomware without the ransom) against the Russians. ®
Bootnote
*The SVR is also known as APT29, The Dukes, Cozy Bear, Yttrium, etc. etc. depending on which vendor's marketing team you're listening to that day. They're all the same crew.
Get our [16]Tech Resources
[1] https://www.riskiq.com/blog/external-threat-management/apt29-bear-tracks/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQR2ovr5uDxoUdGZJPbAPQAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2020/07/16/russia_coronavirus_hacking/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQR2ovr5uDxoUdGZJPbAPQAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQR2ovr5uDxoUdGZJPbAPQAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/04/27/apt29_russia_svr_tactics_cisa
[7] https://blogs.jpcert.or.jp/en/2018/07/malware-wellmes-9b78.html
[8] https://www.theregister.com/2021/06/17/biden_putin_summit_cybersecurity_discussion/
[9] https://www.theregister.com/2020/11/09/gchq_hacks_russia_vaccine_disinfo/
[10] https://www.theregister.com/2021/05/07/ncsc_russia_vulns_smart_cities_china_warning/
[11] https://www.theregister.com/2020/05/05/coronavirus_research_hacking/
[12] https://www.theregister.com/2021/06/17/biden_putin_summit_cybersecurity_discussion/
[13] https://www.theregister.com/2020/05/05/coronavirus_research_hacking/
[14] https://www.theregister.com/2021/05/07/ncsc_russia_vulns_smart_cities_china_warning/
[15] https://www.theregister.com/2020/11/09/gchq_hacks_russia_vaccine_disinfo/
[16] https://whitepapers.theregister.com/
Sadly, kremvax (and it's comrades, moskvax and kgbvax) have passed into the mists of lore and legend. The sagas claim they are still warm and blinkin', waiting for the day that they are needed again. You can still view their memorial at http://kremvax.demos.su/ ...
if you know the suspect addresses
Something is not being explained.
Can just 30 addresses really be a major problem? It should be real easy to block 30 addresses.
If not blocked by the local ISP, it can be blocked at the ISP outside Russia.
There are companies that sell real time reputation checking services - both as an ISP service and as a firewall feature.
It is easy to speak ill of Russia and China and forget the other players. There is no commitment from the USA, Israel, India and the EU to resist the temptation to hack their enemies.
Lead by example.
Re: if you know the suspect addresses
Those 30 addresses aren't directly causing the problem(s). Rather, they are being used to exploit tens of millions of compromised machines, which in turn cause the problem(s) being discussed.
These tens of millions of machines will remain a problem as long as the sheeple of the world are ineducable. Nobody will do anything to secure these compromised machines, as all sides use them.
Yes, you are correct. ALL countries engage in this kind of crap.
The only thing "leading by example" will do is remove a tool that the other side will happily continue to exploit. Not that I approve, far from it, but them's the facts.
Is it too much to hope that they are still using kremvax?