Russian State Hackers Target Critical Networks in France and Europe with Webmail Exploits

TL;DR Summary
The Russian APT28 hacking group, also known as Strontium or Fancy Bear, has been targeting critical networks in France since the second half of 2021. The group, believed to be part of Russia's military intelligence service GRU, has been using various techniques, including exploiting vulnerabilities in WinRAR and Microsoft Outlook, compromising peripheral devices, and utilizing legitimate cloud services for command and control infrastructure. The French National Agency for the Security of Information Systems (ANSSI) has published a report detailing the group's activities and recommends a comprehensive approach to security, with a focus on email security.
- France says Russian state hackers breached numerous critical networks BleepingComputer
- Pro-Russia Hackers Target European Government With Roundcube Webmail Bug Gizmodo
- France accuses Russian state hackers of targeting government systems, universities, think tanks The Record from Recorded Future News
- Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacks Security Affairs
- Pro-Russia hackers target inboxes with 0-day in webmail app used by millions Ars Technica
Reading Insights
Total Reads
0
Unique Readers
1
Time Saved
2 min
vs 3 min read
Condensed
83%
554 → 95 words
Want the full story? Read the original article
Read on BleepingComputer