Microsoft und DOJ stören die Angriffsinfrastruktur der russischen FSB-Hacker

Teilen:

Microsoft and the Justice Department have seized over 100 domains used by the Russian ColdRiver hacking group to target United States government employees and nonprofit organizations from Russia and worldwide in spear-phishing attacks.

In December, the United Kingdom and its Five Eyes allies linked this threat group to Russia’s Federal Security Service (FSB), the country’s internal security and counterintelligence service.

According to a partially unsealed affidavit, they attacked a wide range of targets, including United States-based companies and former and current employees of the United States Intelligence Community, Department of Defense, and Department of State, as well as staff at the Department of Energy and U.S. military defense contractors.

“Between January 2023 and August 2024, Microsoft observed Star Blizzard target over 30 civil society organizations – journalists, think tanks, and non-governmental organizations (NGOs) core to ensuring democracy can thrive – by deploying spear-phishing campaigns to exfiltrate sensitive information and interfere in their activities,” said Steven Masada, Assistant General Counsel at Microsoft’s Digital Crimes Unit.

Together, Microsoft and the DOJ seized 107 domains—66 by Microsoft and 41 by the DOJ—dismantling the attack infrastructure used by ColdRiver hackers in ongoing attacks.

“The Russian government ran this scheme to steal Americans’ sensitive information, using seemingly legitimate email accounts to trick victims into revealing account credentials,” stated Deputy Attorney General Lisa Monaco.

“This seizure is part of a coordinated response with our private sector partners to dismantle the infrastructure that cyber espionage actors use to attack U.S. and international targets,” U.S. Attorney Ismail J. Ramsey added.

Active since at least 2017

Also tracked as Callisto Group, Seaborgium, and Star Blizzard, the ColdRiver threat group has used open-source intelligence (OSINT) and social engineering skills to research and lure targets since at least 2017.

Five Eyes cyber agencies warned in December 2023 of ColdRiver’s spear-phishing attacks against academia, defense, governmental organizations, NGOs, think tanks, and politicians. In 2022, after Russia invaded Ukraine, these attacks expanded to defense-industrial targets and U.S. Department of Energy facilities.

Microsoft previously thwarted ColdRiver attacks against several European NATO nations by disabling the Microsoft accounts they used to harvest emails and monitor their victims’ activity.

In December, the U.S. State Department sanctioned two ColdRiver operators (one of them an FSB officer) who the DOJ also indicted for their involvement in a global hacking campaign coordinated by the Russian government.

The State Department now offers up to $10 million in rewards for information that could help locate or identify other ColdRiver members.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:34 am, Juli 4, 2025
Wetter-Symbol 15°C
L: 12° | H: 16°
broken clouds
Luftfeuchtigkeit: 66 %
Druck: 1028 mb
Wind: 1 mph W
Windböe: 2 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 77%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 16°°C 0 mm 0% 13 mph 66 % 1028 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 18°°C 1 mm 100% 11 mph 92 % 1021 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
15° | 20°°C 0.23 mm 23% 10 mph 92 % 1010 mb 0 mm/h
Mo. Juli 07 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 12 mph 74 % 1015 mb 0 mm/h
Di. Juli 08 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 9 mph 77 % 1021 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 15°°C 0 mm 0% 5 mph 66 % 1028 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
15° | 16°°C 0 mm 0% 5 mph 63 % 1028 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 21°°C 0 mm 0% 6 mph 49 % 1028 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 9 mph 30 % 1026 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 12 mph 25 % 1024 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 13 mph 26 % 1023 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 10 mph 41 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 49 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,947.02
0.60%
Ethereum(ETH)
€2,199.39
0.76%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.91
0.55%
Solana(SOL)
€129.26
-0.32%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.146023
1.71%
Shiba Inu(SHIB)
€0.000010
-0.01%
Pepe(PEPE)
€0.000008
-0.75%
Nach oben scrollen