Russian Intel group “APT29,” “CozyBear” or “The Dukes” target COVID-19 research and vaccine development in the United States,

In response to Russian Intelligence Services targeting COVID-19 research and vaccine development in the United States, United Kingdom and Canada, the National Security AgencyNational Cyber Security Center,  Communications Security Establishment  and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency released a joint cybersecurity advisory to expose the malicious activity by the group publicly known as “APT29,” “CozyBear” or “The Dukes.” APT29 uses a variety of tools and techniques to predominantly target governmental, diplomatic, think-tank, healthcare and energy targets for intelligence gain.

The advisory details how the Russian Intelligence Service group targeted organizations involved in COVID-19 vaccine development in the United States, Canada and the United Kingdom, likely to steal information and intellectual property relating to the development and testing of COVID-19 vaccines. The report shares APT29’s tactics, techniques and procedures (TTPs) with network defenders as well as indicators of compromise (IOCs). The advisory also highlights malware commonly used by APT29 that has not previously been linked to the group. 

System owners and administrators are encouraged to follow the mitigation steps in the advisory to reduce risk of being compromised by this actor.

The United Kingdom’s National Cyber Security Centre (NCSC) and Canada’s Communications Security Establishment (CSE) assess that APT29 (also known as ‘the Dukes’ or ‘Cozy Bear’) is a cyber espionage group, almost certainly part of the Russian intelligence services. The United States’ National Security Agency (NSA) agrees with this attribution and the details provided in this report.
The United States’ Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (DHS CISA) endorses the technical detail and mitigation advice provided in this advisory.
The group uses a variety of tools and techniques to predominantly target governmental, diplomatic, think-tank, healthcare and energy targets for intelligence gain.
Throughout 2020, APT29 has targeted various organisations involved in COVID-19 vaccine development in Canada, the United States and the United Kingdom, highly likely with the intention of stealing information and intellectual property relating to the development and testing of COVID-19 vaccines.
APT29 is using custom malware known as ‘WellMess’ and ‘WellMail’ to target a number of organisations globally. This includes those organisations involved with COVID-19 vaccine development. WellMess and WellMail have not previously been publicly associated to APT29.
Details of techniques Initial infection vectors
The group frequently uses publicly available exploits to conduct widespread scanning and exploitation against vulnerable systems, likely in an effort to obtain authentication credentials to allow further access. This broad targeting potentially gives the group access to a large number of systems globally, many of which are unlikely to be of immediate intelligence value. The group may maintain a store of stolen credentials in order to access these systems in the event that they become more relevant to their requirements in the future.
In recent attacks targeting COVID-19 vaccine research and development, the group conducted basic vulnerability scanning against specific external IP addresses owned by the organisations. The group then deployed public exploits against the vulnerable services identified.

Читайте на сайте