The Kremlin's cyberspies targeted German political parties in a phishing campaign that used emails disguised as dinner party invitations, according to Mandiant. Russia's Cozy Bear, also known as APT29 and Midnight Blizzard, engineered the messages to infect marks' Windows PCs with a backdoor first observed in January and dubbed WINELOADER. These were intended to provide long-term access to the political parties' networks and data, the Google-backed security biz asserted on Friday. This is the first time that the cyberespionage group, which has been linked to the Russian Foreign Intelligence Service (SVR), has targeted political parties, according to the report. "Western political parties and their associated bodies from across the political spectrum are likely also possible targets for future SVR-linked cyber espionage activity given Moscow's vital interest in understanding changing Western political dynamics related to Ukraine and other flashpoint foreign policy issues," Mandiant's Luke Jenkins and Dan Black wrote in an alert. This is the same crew that infamously backdoored SolarWinds' network monitoring software and then used that access to spy on customers such as the US Treasury, Justice, and Energy departments, and the Pentagon. Cozy Bear's latest phishing emails, sent out last month, were designed to give to the impression they were sent by Germany's Christian Democratic Union (CDU), and included the major political party's logo, inviting recipients to a March 1 dinner...
Russia's Cozy Bear caught phishing German politicos with phony dinner invites
The Register
·Jessica Lyons
·Published Mar 23, 2024
·Updated
Affected Software
2 affected components
Microsoft Windows
SolarWinds network monitoring software
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a phishing campaign conducted by Russia's Cozy Bear targeting German politicians using fake dinner invitations.
2
What security implications are discussed?
The article highlights the threat posed by state-sponsored hacking groups like Cozy Bear and their use of social engineering tactics in cyberattacks.
3
Who is Cozy Bear and what are they known for?
Cozy Bear, also known as APT29 or Midnight Blizzard, is a Russian cyber espionage group linked to the Kremlin.
4
What methods were used in the phishing campaign?
The campaign primarily utilized emails disguised as dinner party invitations to deceive recipients.
5
What products or software are affected by this phishing campaign?
The phishing campaign mentioned affects users of Microsoft Windows and SolarWinds network monitoring software.