Tuesday, June 24, 2025
  • Login
Whats Current In
Advertisement
  • Cyber Security
No Result
View All Result
  • Cyber Security
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

French Diplomatic Entities Targeted in Russian-Linked Cyber Attacks

wcisrvadm by wcisrvadm
June 20, 2024
in Cyber Security
0
French Diplomatic Entities Targeted in Russian-Linked Cyber Attacks
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

This post was originally published on this site

Jun 20, 2024NewsroomCyber Espionage / Hacking News

Russian-Linked Cyber Attacks

State-sponsored actors with ties to Russia have been linked to targeted cyber attacks aimed at French diplomatic entities, the country’s information security agency ANSSI said in an advisory.

The attacks have been attributed to a cluster tracked by Microsoft under the name Midnight Blizzard (formerly Nobelium), which overlaps with activity tracked as APT29, BlueBravo, Cloaked Ursa, Cozy Bear, and The Dukes.

While the monikers APT29 and Midnight Blizzard have been interchangeably used to refer to intrusion sets associated with the Russian Foreign Intelligence Service (SVR), ANSSI said it prefers to treat them as disparate threat clusters alongside a third one dubbed Dark Halo, which has been held responsible for the 2020 supply chain attack via SolarWinds software.

Cybersecurity

“Nobelium is characterized by the use of specific codes, tactics, techniques, and procedures. Most of Nobelium campaigns against diplomatic entities use compromised legitimate email accounts belonging to diplomatic staff, and conduct phishing campaigns against diplomatic institutions, embassies, and consulates,” the agency said.

It’s worth noting that the targeting of diplomatic entities is also monitored under the name Diplomatic Orbiter.

The attacks entail sending phishing emails to French public organizations from foreign institutions and individuals previously compromised by the threat actor to initiate a series of malicious actions.

“In May 2023, several European embassies in Kyiv were targeted by a phishing campaign conducted by Nobelium’s operators,” it said. “The French embassy in Kyiv was one of the targets of this campaign, which was conducted through an email that was themed about a ‘Diplomatic car for sale.'”

Another attack observed in the same month targeting the French Embassy in Romania was ultimately unsuccessful, ANSSI noted.

Other intrusions mounted by the threat actor have leveraged security flaws in JetBrains TeamCity servers as part of an opportunistic campaign. In recent months, it has also been linked to breaches of Microsoft and Hewlett Packard Enterprise (HPE).

Cybersecurity

“The targeting of IT and cybersecurity entities for espionage purposes by Nobelium operators potentially strengthens their offensive capabilities and the threat they represent,” the agency said. “The intelligence gathered during recent attacks against IT sector entities could also facilitate Nobelium’s future operations.”

The disclosure comes as Poland revealed that Russian hackers could be behind the DDoS attack on Telewizja Polska (TVP) that led to the disruption of an online broadcast of the Euro 2024 soccer tournament on June 16, 2024.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.
Previous Post

CHERI Alliance Aims to Secure Hardware Memory

Next Post

Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

wcisrvadm

wcisrvadm

Next Post
Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

Recent Posts

  • New FileFix attack weaponizes Windows File Explorer for stealthy commands
  • Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue
  • How Today’s Pentest Models Compare and Why Continuous Wins
  • How the US Military Is Redefining Zero Trust
  • US House bans WhatsApp on staff devices over security concerns

Recent Comments

No comments to show.

Archives

  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024

Categories

  • Cyber Security

Browse by Category

  • Cyber Security
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cyber Security

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.