Yandex, Russia's Google, Said to Have Been Hacked by Western Intelligence

The malware, called Regin, is known to be used by the "Five Eyes" intelligence-sharing alliance.

Advertisement
By Reuters | Updated: 28 June 2019 17:47 IST

Hackers working for Western intelligence agencies broke into Russian internet search company Yandex in late 2018 deploying a rare type of malware in an attempt to spy on user accounts, four people with knowledge of the matter told Reuters.

The malware, called Regin, is known to be used by the "Five Eyes" intelligence-sharing alliance of the United States, Britain, Australia, New Zealand and Canada, the sources said. Intelligence agencies in those countries declined to comment.

Advertisement

Western cyber-attacks against Russia are seldom acknowledged or spoken about in public. It could not be determined which of the five countries was behind the attack on Yandex, said sources in Russia and elsewhere, three of whom had direct knowledge of the hack. The breach took place between October and November 2018.

Yandex spokesman Ilya Grabovsky acknowledged the incident in a statement to Reuters, but declined to provide further details. "This particular attack was detected at a very early stage by the Yandex security team. It was fully neutralized before any damage was done," he said.

Advertisement

The company also said that "the Yandex security team's response ensured that no user data was compromised by the attack."

The company, widely known as "Russia's Google" for its array of online services from internet search to email and taxi reservations, says it has more than 108 million monthly users in Russia. It also operates in Belarus, Kazakhstan and Turkey.

Advertisement

The sources who described the attack to Reuters said the hackers appeared to be searching for technical information that could explain how Yandex authenticates user accounts. Such information could help a spy agency impersonate a Yandex user and access their private messages.

The hack of Yandex's research and development unit was intended for espionage purposes rather than to disrupt or steal intellectual property, the sources said. The hackers covertly maintained access to Yandex for at least several weeks without being detected, they said.

Advertisement

The Regin malware was identified as a Five Eyes tool in 2014 following revelations by former US National Security Agency (NSA) contractor Edward Snowden.

Reports by The Intercept, in partnership with a Dutch and Belgian newspaper, tied an earlier version of Regin to a hack at Belgian telecom firm Belgacom in 2013 and said British spy agency Government Communications Headquarters (GCHQ) and the NSA were responsible. At the time GCHQ declined to comment and the NSA denied involvement.

'Crown jewel'
Security experts say attributing cyber-attacks can be difficult because of obfuscation methods used by hackers.

But some of the Regin code found on Yandex's systems had not been deployed in any known previous cyber-attacks, the sources said, reducing the risk that attackers were deliberately using known Western hacking tools to cover their tracks.

Yandex called in Russian cyber-security company Kaspersky, which established the attackers were targeting a group of developers inside Yandex, three sources said. A private assessment by Kaspersky, described to Reuters, concluded hackers likely tied to Western intelligence breached Yandex using Regin.

A Kaspersky spokeswoman declined to comment.

The US Office of the Director of National Intelligence declined to comment. The White House National Security Council did not respond to a request for comment.

The Kremlin did not immediately respond to a Reuters request for comment.

Moscow-based Yandex, listed on the NASDAQ in the United States and the Moscow Exchange, has come under tighter regulatory control by the Russian government after the passage of new internet laws. Former Russian economics and trade minister Herman Gref became a Yandex board member in 2014.

US cybersecurity firm Symantec said it had also recently discovered a new version of Regin. Symantec declined to discuss where this sample was discovered, citing client confidentiality.

"Regin is the crown jewel of attack frameworks used for espionage. Its architecture, complexity and capability sits in a ballpark of its own," Vikram Thakur, technical director at Symantec Security Response, told Reuters. "We have seen different components of Regin in the past few months."

"Based on the victimology coupled with the investment required to create, maintain, and operate Regin, we believe there are at best a handful of countries that could be behind its existence," said Thakur. "Regin came back on the radar in 2019."

© Thomson Reuters 2019

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Yandex, Hacking
Advertisement

Related Stories

Popular Mobile Brands
  1. These Vivo Smartphones Will Cost More in India Due to the Latest Price Hike
  2. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  3. Redmi A7 Pro 4G and Redmi A7 4G Launched in India With These Features
  4. Redmi Pad 2 SE 4G Debuts With 9.7-Inch Display, 7,600mAh Battery: See Price
  5. Oppo Find X9 Ultra Battery, Chipset Details Revealed Ahead of Global Launch
  6. Greenland 2 Migration OTT Release Date Confirmed: When and Where to Watch it Online?
  7. iPhone 18 May Not Arrive With Hardware Upgrades as Apple Cuts Costs: Report
  8. Dyson Launches Supersonic Travel as Smaller, Lighter Hair Dryer
  9. Redmi Buds 8 Launched With Up to 50dB ANC, Up to 44 Hours Total Battery Life
  10. Samsung Galaxy S27 Ultra Might Arrive With This Battery Upgrade
  1. Vivo Y600 Pro Listings on Geekbench, Regulatory Databases Reveal Key Specifications, Features
  2. Redmi Buds 8 Launched With Up to 50dB ANC, Up to 44 Hours Total Battery Life: Price, Features
  3. Redmi Pad 2 SE 4G Launched With Snapdragon 6s 4G Gen 2 SoC, 7,600mAh Battery: Price, Specifications
  4. Motorola Razr 2026 Launch Date Teased Alongside Design and Colour Options
  5. Redmi A7 Pro 4G Launched in India With Unisoc T7250 Chip Alongside Redmi A7 4G: Price, Specifications
  6. Google DeepMind Has Reportedly Assembled an A-Team to Take on Anthropic’s AI Coding Prowess
  7. Samsung Galaxy S27 Ultra Could Launch With Silicon-Carbon Battery Upgrade: Report
  8. Bitcoin Steadies Around $75,800 as Institutional Buying Supports Recovery
  9. iOS 27 Leak Suggests Four Models Might Not Receive Apple's Next iPhone OS Upgrade
  10. Poco M8s 5G Launched With 7,000mAh Battery, 50-Megapixel Camera: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.