Microsoft Says It Has Found Another Russian Operation Targeting Prominent Think Tanks

Advertisement
By Elizabeth Dwoskin, Craig Timberg, The Washington Post | Updated: 20 February 2019 17:55 IST

For the second time in six months, Microsoft has identified a Russian government-affiliated operation targeting prominent think tanks that have been critical of Russia, the company said in a blog post Tuesday evening.

The "spear-phishing" attacks - in which hackers send out phoney emails intended to trick people into visiting websites that look authentic but in fact enable them to infiltrate their victims' corporate computer systems - were tied to the APT28 hacking group, a unit of Russian military intelligence that meddled in the 2016 US election. The group targeted more than 100 European employees of the German Marshall Fund, the Aspen Institute Germany, and the German Council on Foreign Relations, influential groups that focus on transatlantic policy issues.

The attacks, which took place during the last three months of 2018, come ahead of European parliamentary elections in May. They highlight a continuously aggressive campaign by Russian operatives to undermine democratic institutions in countries it sees as adversaries.

Advertisement

The announcement is also the second time in the last six months that Microsoft has gone public with its efforts to thwart APT28, which is sometimes called Strontium or Fancy Bear.

Advertisement

Shortly before the US midterm elections, Microsoft disabled spear-phishing efforts aimed at prominent conservative organisations and the US Senate. APT28 created phony websites impersonating the groups, as well as people's colleagues and Microsoft's own properties.

"The attacks we've seen recently, coupled with others we discussed last year, suggest an ongoing effort to target democratic organisations," the company said in its blog post. "They validate the warnings from European leaders about the threat level we should expect to see in Europe this year."

Advertisement

In its earlier takedown, Microsoft said that it had been able to use a novel legal strategy to disable the phony domains. The company obtained a court order to transfer the domain names to its own servers by arguing that spoofing is a violation of the company's intellectual property rights, and then shut the sites down.

This time, however, Microsoft did not attempt to obtain a court order to block the attackers. The company declined to specify why it did not bring a case. It is only able to bring a case when it has the appropriate geographic jurisdiction or when it believes its intellectual property rights had been violated.

Advertisement

Microsoft did not provide other details about how it attempted to thwart the attacks. Beyond taking down fake domains, the company can alert customers and push out fixes to bugs in corporate software in order to stop attackers.

Andrew Kolb, communications director for the German Marshall Fund, said that he was not surprised that the group was a target of Russia.

"We've had a program for the last roughly two years that has focused specifically on authoritarian interference online - and a lot of that has meant looking at Russia," Kolb said. "We sort of assume we're going to be subject to these kinds of attacks at any time."

But Kolb said this was the first time he had been able to directly connect any attacks to a specific Russian group. "It's a reminder to be aware," he added.

The Aspen Institute Germany, which is the German affiliate of the Aspen Institute, and the German Council on Foreign Relations, a organisation that is distinct from the US Council on Foreign Relations, did not respond to requests for comment. Both organisations have hosted forums where speakers have criticised Russian policy in the US and Europe.

© The Washington Post 2018

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  2. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  3. Realme 16 Pro+ 5G Listed on Certification Website With These Specifications
  4. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  5. OnePlus 15, Nord CE 5 Prices Slashed During Community Sale: See Offers
  6. Dhurandhar OTT Release Date: What We Know So Far
  7. Google Pay Brings Its First Co-Branded UPI-Powered Digital Credit Card
  8. JWST observations may unlock new clues about dark matter
  9. iPhone Air 2 to Launch With Two Rear Cameras, Lower Price Tag: Report
  1. James Webb Space Telescope Could Help Reveal Dark Matter in a Way Scientists Did Not Anticipate
  2. Interstellar Comet 3I/ATLAS Nears Earth on Dec. 19, Offering Rare Insights Into Cosmic Visitors
  3. Europe’s Ariane 6 Rocket Lifts Off With First Galileo Satellites, Boosting Europe’s Navigation Network
  4. NASA’s Parker Solar Probe Observes Solar Wind Making ‘U-Turn’, Shedding Light on Space Weather
  5. ESA Reveals City-Size ‘Cosmic Butterfly’ Crater on Mars Containing Signs of Ancient Water
  6. The Holy Grail of Eris OTT Release: Know When and Where to Watch it Online
  7. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 12.1-Inch Display and 5G Connectivity: Price, Features
  8. OnePlus 15R Launched in India With 7,400mAh Battery, Snapdragon 8 Gen 5 SoC: Price, Specifications
  9. Flex By Google Pay: Google Partners With Axis Bank to Introduce UPI-Powered, Digital Credit Card
  10. Warner Bros. Plans to Reject Paramount Bid on Funding, Terms
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.