2024-09-05
US DOJ Indicts Russian Hackers Behind WhisperGate Campaign
The US Department of Justice has unsealed an indictment against six hackers belonging to a Russian military intelligence unit (GRU 29155) for the 2022 'WhisperGate' malware attacks on Ukrainian and Central European systems. Security services in nine countries have joined with the FBI, CISA, and NSA to issue a security advisory aimed at mitigating risk from similar attacks. Charges include the destruction of both defensive and civilian systems in Ukraine, the exfiltration and sale of Ukrainian civilians' personal information, wire fraud, and 'computer network operations' targeting systems in North America, Latin America, Central Asia, and Europe.
Editor's Note
The bulletin is up-front with mitigations for this type of attack. Keep systems updated, remediate known vulnerabilities, implement (phishing-resistant) MFA for anything internet facing, particularly critical systems, email and VPN. Segment your networks. To which I would add monitoring and alerting. Make sure you can track anomalous behavior, verify the breach notification agreement with your cloud and outsource service providers. Make sure you're really on the same page, not just what they are paying lip service to, and address any discrepancies.
Lee Neely
Read more in
Justice: Five Russian GRU Officers and One Civilian Charged for Conspiring to Hack Ukrainian Government
CISA: Russian Military Cyber Actors Target US and Global Critical Infrastructure
The Register: Uncle Sam charges Russian GRU cyber-spies behind 'WhisperGate intrusions'
The Record: US posts indictments, rewards in Russia's WhisperGate hacks against Ukraine
Security Week: Russian GRU Unit Tied to Assassinations Linked to Global Cyber Sabotage and Espionage
Wired: Russia's Most Notorious Special Forces Unit Now Has Its Own Cyber Warfare Team
Cyberscoop: U.S. charges five Russian military members for destructive cyber ops, hack-and-leak campaigns