A group of Russian hackers has, over the past year, been running a cyber-espionage campaign targeting nuclear scientists, defense industry contractors, and government employees.
This is according to CNN, UATV English reports.
American company Proofpoint, which specializes in email security and investigated part of this campaign, said the hackers attacked email servers used by “nuclear facilities and the defense industrial base” in the US. The choice of targets suggests the hackers’ interest in nuclear fusion technology, as well as intelligence that could help the Kremlin in the war against Ukraine.
A joint warning from US intelligence and security agencies and more than a dozen allied countries describes an “ongoing” Russian espionage campaign. As part of this operation, hackers tested their methods in Ukraine before applying them against NATO states.
If new attack victims emerge, this warning could help the US and its allies assess the scale of the damage done and determine exactly what intelligence Russian agents managed to obtain.
During the attacks, the hackers used a rare software exploit that required a victim only to open an email on a vulnerable email system — without clicking any links or taking additional action. According to the federal warning, this vulnerability allowed up to three months of a user’s email correspondence to be stolen, along with a complete list of the organization’s email addresses.
Targets of the campaign included US federal and local government bodies, law enforcement agencies, and institutions in defense, education, and energy. Authorities did not disclose details about specific organizations.
“The threat actor likely sought to obtain strategic information on military data, logistics, and the policymaking process in Western countries,” said Sherrod DeGrippo, Vice President of Threat Intelligence at Unit 42, the threat intelligence division of cybersecurity company Palo Alto Networks.
The government warning notes that this campaign is part of a “growing trend” among Russian cyber groups, which first attack Ukrainian organizations, using them both as priority targets and as a testing ground for new malicious methods before deploying them on a global scale.
“Given the success of this and previous campaigns, it’s highly likely that the [Russian] group will continue attacking the email systems used by Western organizations,” the document states.
“What’s particularly concerning is that these threat actors tested their methods on victims in Ukraine before moving on to attacks against NATO members,” said UK Security Minister Dan Jarvis.
Law enforcement is also trying to identify those involved in the attacks. In November, Thai law enforcement detained one suspected member of the group — a Russian man around 30 years old. He was extradited to the US, and last month appeared in court in Boston for the first time.
Following a relative lull that set in after the start of Russia’s full-scale invasion of Ukraine in 2022, American intelligence agencies are recording a new increase in the number of Russian cyberattacks against the US.
“We’re seeing, probably over the past year or so, an increase in the number of [Russian cyberattacks] directed against the United States,” said Brett Leatherman, deputy assistant director of the FBI’s cyber division.
As previously reported, the EU and its member states condemned Russia’s malicious cyber activity and its use of a cyber ecosystem encompassing both state and non-state actors, from intelligence services to cybercriminal groups, hacktivists, and private companies.
Read also: Zelenskyy: President Trump Has Understood Who Doesn’t Want to Stop the War














