AIRLINK 177.92 Increased By ▲ 0.92 (0.52%)
BOP 12.88 Increased By ▲ 0.07 (0.55%)
CNERGY 7.58 Increased By ▲ 0.09 (1.2%)
FCCL 45.99 Increased By ▲ 3.97 (9.45%)
FFL 15.16 Increased By ▲ 0.32 (2.16%)
FLYNG 27.34 Decreased By ▼ -0.36 (-1.3%)
HUBC 132.04 Decreased By ▼ -2.47 (-1.84%)
HUMNL 13.29 Increased By ▲ 0.33 (2.55%)
KEL 4.46 Increased By ▲ 0.02 (0.45%)
KOSM 6.06 No Change ▼ 0.00 (0%)
MLCF 56.63 Increased By ▲ 2.12 (3.89%)
OGDC 223.84 Increased By ▲ 1.26 (0.57%)
PACE 5.99 Decreased By ▼ -0.04 (-0.66%)
PAEL 41.51 Increased By ▲ 0.21 (0.51%)
PIAHCLA 16.01 Increased By ▲ 0.39 (2.5%)
PIBTL 9.88 Decreased By ▼ -0.18 (-1.79%)
POWER 11.16 Decreased By ▼ -0.01 (-0.09%)
PPL 186.63 Increased By ▲ 2.64 (1.43%)
PRL 34.90 Increased By ▲ 0.59 (1.72%)
PTC 23.53 Increased By ▲ 0.19 (0.81%)
SEARL 94.96 Increased By ▲ 3.89 (4.27%)
SILK 1.14 Increased By ▲ 0.03 (2.7%)
SSGC 35.50 Increased By ▲ 1.52 (4.47%)
SYM 15.64 Decreased By ▼ -0.32 (-2.01%)
TELE 7.87 Increased By ▲ 0.01 (0.13%)
TPLP 10.93 Decreased By ▼ -0.08 (-0.73%)
TRG 59.20 Increased By ▲ 0.48 (0.82%)
WAVESAPP 10.78 Decreased By ▼ -0.01 (-0.09%)
WTL 1.35 Decreased By ▼ -0.01 (-0.74%)
YOUW 3.80 Decreased By ▼ -0.01 (-0.26%)
AIRLINK 177.92 Increased By ▲ 0.92 (0.52%)
BOP 12.88 Increased By ▲ 0.07 (0.55%)
CNERGY 7.58 Increased By ▲ 0.09 (1.2%)
FCCL 45.99 Increased By ▲ 3.97 (9.45%)
FFL 15.16 Increased By ▲ 0.32 (2.16%)
FLYNG 27.34 Decreased By ▼ -0.36 (-1.3%)
HUBC 132.04 Decreased By ▼ -2.47 (-1.84%)
HUMNL 13.29 Increased By ▲ 0.33 (2.55%)
KEL 4.46 Increased By ▲ 0.02 (0.45%)
KOSM 6.06 No Change ▼ 0.00 (0%)
MLCF 56.63 Increased By ▲ 2.12 (3.89%)
OGDC 223.84 Increased By ▲ 1.26 (0.57%)
PACE 5.99 Decreased By ▼ -0.04 (-0.66%)
PAEL 41.51 Increased By ▲ 0.21 (0.51%)
PIAHCLA 16.01 Increased By ▲ 0.39 (2.5%)
PIBTL 9.88 Decreased By ▼ -0.18 (-1.79%)
POWER 11.16 Decreased By ▼ -0.01 (-0.09%)
PPL 186.63 Increased By ▲ 2.64 (1.43%)
PRL 34.90 Increased By ▲ 0.59 (1.72%)
PTC 23.53 Increased By ▲ 0.19 (0.81%)
SEARL 94.96 Increased By ▲ 3.89 (4.27%)
SILK 1.14 Increased By ▲ 0.03 (2.7%)
SSGC 35.50 Increased By ▲ 1.52 (4.47%)
SYM 15.64 Decreased By ▼ -0.32 (-2.01%)
TELE 7.87 Increased By ▲ 0.01 (0.13%)
TPLP 10.93 Decreased By ▼ -0.08 (-0.73%)
TRG 59.20 Increased By ▲ 0.48 (0.82%)
WAVESAPP 10.78 Decreased By ▼ -0.01 (-0.09%)
WTL 1.35 Decreased By ▼ -0.01 (-0.74%)
YOUW 3.80 Decreased By ▼ -0.01 (-0.26%)
BR100 12,130 Increased By 107.3 (0.89%)
BR30 37,246 Increased By 640.2 (1.75%)
KSE100 114,399 Increased By 685.5 (0.6%)
KSE30 35,458 Increased By 156.2 (0.44%)

WASHINGTON: The state-backed Russian group behind a massive hacking campaign revealed last year has re-emerged with a series of attacks on government agencies, think tanks, consultants and other organizations, Microsoft security researchers said.

A security update from Microsoft late Thursday said the group known as Nobelium has stepped up attacks, notably targeting government agencies involved in foreign policy as part of intelligence gathering efforts.

Microsoft said it detected a “sophisticated” and large-scale campaign that delivered phishing emails delivering malicious software and enabling the hackers to get protected data from victims.

“This wave of attacks targeted approximately 3,000 email accounts at more than 150 different organizations,” Microsoft vice president Tom Burt said in a blog post.

The news comes a month after Washington imposed sanctions and expelled Russian diplomats in response to Moscow’s involvement in the massive attacks last year on SolarWinds, a security software firm, election interference and other hostile activity.

“When coupled with the attack on SolarWinds, it’s clear that part of Nobelium’s playbook is to gain access to trusted technology providers and infect their customers,” wrote Burt. “By piggybacking on software updates and now mass email providers, Nobelium increases the chances of collateral damage in espionage operations and undermines trust in the technology ecosystem.”

The new attacks enabled the hackers were able to gain access to email servers to be able spoof the US Agency for International Development and send out mass emails with disinformation, according to the update.

In one example, emails appearing to be from USAID showed a “special alert” stating that “Donald Trump has published new documents on election fraud.”

Users who clicked on the link were directed to a site delivering malicious software and enabling the hackers to exfiltrate data, according to Microsoft.

“This attack is still active, so these indicators should not be considered exhaustive for this observed activity,” Microsoft said in its update.

SolarWinds last year disclosed that as many as 18,000 customers and more than 100 US companies were affected by the hack. Its roster of clients includes government agencies and companies among the top 500 in the United States.

Washington has accused Russia of orchestrating the online assault, explicitly citing its Foreign Intelligence Service (SVR).

Comments

Comments are closed.