Russian Cyber-Attackers Used 2 Previously Unknown Flaws: FireEye

Advertisement
By Reuters | Updated: 20 April 2015 15:05 IST
Russian Cyber-Attackers Used 2 Previously Unknown Flaws: FireEye

Widely reported Russian cyber-spying campaign against diplomatic targets in the United States and elsewhere has been using two previously unknown flaws in software to penetrate target machines, a security company investigating the matter said on Saturday.

FireEye, a prominent US security company, said the espionage effort took advantage of holes in Adobe's Flash software for viewing active content and Microsoft's ubiquitous Windows operating system.

The campaign has been tied by other firms to a serious breach at US State Department computers. The same hackers are also believed to have broken into White House machines containing unclassified but sensitive information such as the president's travel schedule.

FireEye has been assisting the agencies probing those attacks, but it said it could not comment on whether the spies are the same ones who penetrated the White House because that would be classified as secret.

Advertisement

FireEye said that Adobe had issued a fix for the security weakness on Tuesday, so that users with the most current versions should be protected. The Microsoft problem by itself is less dangerous, since it involves enhanced powers on a computer from those of an ordinary user.

A Microsoft spokesman said the company was working on a patch.

Advertisement

In October, FireEye said the group it calls APT28 had been at work since 2007 and had targeted US defence attaches and military contractors, NATO alliance offices, and government officials in Georgia and other countries of special interest to the Kremlin.

Days before that report, security firm Trend Micro Inc described a campaign it called "Pawn Storm" against computers in the State Department, Russian dissidents, NATO and other Eastern European nations. Because Pawn Storm and APT28 used some of the same tools and hit the same targets, other information security professionals concluded they were the same hackers.

Advertisement

On Thursday, Trend Micro said that the Pawn Storm hackers had increased their activity recently and had targeted bloggers who had interviewed President Barack Obama. It also said the group had "probably" stolen online credentials of a military correspondent at an unnamed major US newspaper.

Though the security flaws APT28 used are new, it had been well established that the group was highly skilled. Saturday's report is one in a flurry generated by rival firms ahead of the RSA Conference next week in San Francisco, the largest annual technology security gathering in the country.

© Thomson Reuters 2015

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Adobe, FireEye, Internet, Microsoft, Windows
Advertisement

Related Stories

Popular Mobile Brands
  1. Itel Super Guru 4G Max Launched in India With Built-In AI Voice Assistant
  2. OnePlus Pad Lite Launched in India With 11-Inch Display, 9,340mAh Battery
  3. Moto G86 Power India Launch Date Confirmed: Check Features, Colour Options
  4. Realme 15 5G Series Launching Today: All You Need to Know
  5. Samsung Galaxy S26 Edge Tipped to Come With Two Major Upgrades
  6. Upcoming Redmi Smartphone in India With Battery Could Be the Redmi 15 5G
  7. Meta Is Improving Safety for Teen Accounts on Instagram With New Features
  8. Google Pixel 10 Lineup Accidentally Leaked via Play Store Banner
  9. Pioneer VREC-H320SC Dashcam Review
  10. AppleCare One Announced; Lets You Add Up to 3 Devices Under a Single Plan
  1. Qi2 25W Wireless Charging Specification Announced; WPC Says 'Major Android Smartphones' to Join Ecosystem
  2. Google Pixel 10 Pro Fold Leaked Design Renders Showcase New Colour Options
  3. Samsung Galaxy S26 Edge Tipped to Be Thinner Than Its Predecessor, Could Pack a Larger Battery
  4. Google Pixel 10 Series Reportedly Leaked via Play Store Banner; Official Dimensions Surface
  5. AppleCare One Subscription Announced; Lets You Add Up to 3 Devices Under One Plan
  6. Realme 15 5G Series Launching Today: Know Price in India, Features and Specifications
  7. SpaceX Launches Two O3b mPOWER Satellites, Successfully Lands Falcon 9 Booster at Sea
  8. Astronomers Solve Betelgeuse’s 6-Year Dimming Mystery by Spotting Secret Companion Star
  9. Google I/O Connect India 2025: Eight Indian Startups Showcased Applications Built With Google's AI Models
  10. Microsoft Knew of SharePoint Security Flaw but Failed to Effectively Patch It, Timeline Shows
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.