NewsRussian hackers target diplomats with fake car sale emails

Russian hackers target diplomats with fake car sale emails

A fake email announcing the sale of a car contained malicious code, targeting information on diplomats' computers. The "inspiration" for the group linked to Russian military intelligence was a real email sent by a Polish diplomat.

The Unit 42 division at Palo Alto Networks, a cybersecurity company, tracked down the hackers.
The Unit 42 division at Palo Alto Networks, a cybersecurity company, tracked down the hackers.
Images source: © Getty Images | PeopleImages.com - #2690425

4:31 PM EDT, August 13, 2024

It all started with a real email from a Polish diplomat who sent an offer to sell a BMW 5 Series car in Kyiv to his contacts.

The hackers, who likely broke into the account of one of the recipients, used a similar method. However, in this case, they attached a virus to the attachment. The announcement was sent to many diplomatic posts in Kyiv. It was titled: "Diplomatic car for sale."

When a potential buyer wanted to check exactly what the car looked like from different angles, malicious software known as a backdoor was activated on their computer. This program gave criminals remote access to the buyer's device.

The Unit 42 division at Palo Alto Networks, a cybersecurity company, traced the hackers. Experts claim that the attack was aimed at diplomats from Eastern European countries, but Poland was not among them.

The attack was believed to have been carried out by the group APT28, also known as Fighting Ursa. The hackers are linked to Russian military intelligence and had previously attacked the German parliament and the US Democratic Party.

"Analyzing the attacks carried out by Fighting Ursa provides insight into the military priorities of Russian services. We predict that, apart from Ukraine, all European countries that are NATO members could be targets of similar attacks," Wojciech Gołębiowski, Managing Director of Palo Alto Networks in Eastern Europe.

Related content
© essanews.com
·

Downloading, reproduction, storage, or any other use of content available on this website—regardless of its nature and form of expression (in particular, but not limited to verbal, verbal-musical, musical, audiovisual, audio, textual, graphic, and the data and information contained therein, databases and the data contained therein) and its form (e.g., literary, journalistic, scientific, cartographic, computer programs, visual arts, photographic)—requires prior and explicit consent from Wirtualna Polska Media Spółka Akcyjna, headquartered in Warsaw, the owner of this website, regardless of the method of exploration and the technique used (manual or automated, including the use of machine learning or artificial intelligence programs). The above restriction does not apply solely to facilitate their search by internet search engines and uses within contractual relations or permitted use as specified by applicable law.Detailed information regarding this notice can be found  here.