Connect with us

World

Report says Russian hackers haven’t eased spying efforts

The elite Russian state hackers behind last year’s massive SolarWinds cyberespionage campaign hardly eased up this year, managing plenty of infiltrations of US and allied government agencies and foreign policy think tanks with consummate craft and stealth, a leading cybersecurity firm reported Monday.

On the anniversary of the public disclosure of the SolarWinds intrusions, Mandiant said the hackers associated with Russia’s SVR foreign intelligence agency continued to steal data “relevant to Russian interests” with great effect using novel, stealthy techniques that it detailed in a mostly technical report aimed at helping security professionals stay alert.

For the latest headlines, follow our Google News channel online or via the app.

It was Mandiant, not the US government, that disclosed SolarWinds.

While the number of government agencies and companies hacked by the SVR was smaller this year than last, when some 100 organizations were breached, assessing the damage is difficult, said Charles Carmakal, Mandiant’s chief technical officer. Overall, the impact is quite serious. “The companies that are getting hacked, they are also losing information.”

“Not everybody is disclosing the incident(s) because they don’t always have to disclose it legally,” he said, complicating damage-assessment.

The Russian cyber spying unfolded, as always, mostly in the shadows as the US government was consumed in 2021 by a separate, eminently “noisy” and headline-grabbling cyber threat — ransomware attacks launched not by nation-state hackers but rather criminal gangs. As it happens, those gangs are largely protected by the Kremlin.

The Mandiant findings follow an October report from Microsoft that the hackers, whose umbrella group it calls Nobelium, continue to infiltrate the government agencies, foreign policy think tanks and other organizations focused on Russian affairs through the cloud service companies and so-called managed services providers on which they increasingly rely. Mandiant tips its hat to Microsoft’s threat researchers in the report.

Mandiant researchers said the Russian hackers “continue to innovate and identify new techniques and tradecraft” that lets them linger in victim networks, hinder detection and confuse attempts to attribute hacks to them. In short, Russia’s most elite state-backed hackers are as crafty and adaptable as ever.

Mandiant did not identify individual victims or describe what specific information may have been stolen but did say unspecified “diplomatic entities” that received malicious phishing emails were among the targets.

Often, the researchers say, the hackers’ path of least resistance to their targets were cloud-computing services. From there, they used stolen credentials to infiltrate networks. The report describes how in one case they gained access to one victim’s Microsoft 365 system through a stolen session. And, the report says, the hackers routinely relied on advanced tradecraft to cover their tracks.

One clever technique discussed in the report illustrates the ongoing cat-and-mouse game that digital espionage entails. Hackers set up intrusion beachheads using IP addresses, a numeric designation that identifies its location on the internet, that were physically located near an account they are trying to breach — in the same address block, say, as the person’s local internet provider. That makes it highly difficult for security software to detect a hacker using stolen credentials posing as someone trying to access their work account remotely.

The SolarWinds hack exploited vulnerabilities in the software supply-chain system and went undetected for most of 2020 despite compromises at a broad swath of federal agencies — including the Justice Department — and dozens of companies, primarily telecommunications and information technology providers and including Mandiant and Microsoft.

The hacking campaign is named SolarWinds after the US software company whose product was exploited in the first-stage infection of that effort. The Biden administration imposed sanctions last April in response to the hack, including against six Russian companies that support the country’s cyber efforts.

Read more: Attorney for Hillary Clinton campaign indicted in US Trump-Russia probe

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

World

Almarai signs an MoU with the Authority of People with Disabilities to train and employ them.

Almarai Company signed a memorandum of understanding with the Authority of People with
Disabilities to train, qualify and employ persons with disabilities. This came on the sidelines of
the First International Labor Market Conference, organized by the Ministry of Human Resources
and Social Development on December 13 – 14, 2023, at the King Abdulaziz Convention Center
in Riyadh.

The memorandum was signed by the Chief Human Resources Officer of Almarai Company,
Fahad Mohammed Aldrees, and the CEO of the Authority of People with Disabilities, Dr.
Hisham bin Muhammad Al-Haidari.

“This agreement comes within the framework of the company’s social responsibility program, as
Almarai employs more than 500 people with disabilities, which is one of the most suitable work
environments for them.” Fahad Aldrees said. Pointing out that Almarai has the “Silent Line”,
which is one of its production lines that is designated for people with hearing disabilities.

It is worth mentioning that Almarai supports over 300 charity organizations annually across the
kingdom that operate in the field of community development.

Continue Reading

World

Central Phuket Shopping Center Prepared Surprises This Christmas & New Year 2024

Central Phuket Shopping Center, the luxury lifestyle landmark o Phuket, invites everyone to celebrate Christmas and New Year 2024 in The Great Celebration 2024 Campaign. Joining hands with global partner ‘The Pokémon Company’, Central Phuket bring over Pokémon, the super cute character popular around the world, for all locals and international fans. The special campaign launch presents a procession of cute ‘Pikachu’ alongside with the giant Christmas tree for the first time in Thailand.
This December, Central Phuket prepared many activities for shoppers when visiting Phuket! Experience the “Surprise of the Day” with free Cotton Candy for our little ones, a sweet and fluffy treat, a special gift from Central Phuket. Bring your kids to enjoy this sweet treat every Saturday and Sunday throughout the month of December. Don’t miss the Christmas Carol that
everyone loves, little Santas spread freshness by singing together in the Christmas Carol activity. Plus, Christmas Live Music, the festival of joy is back! Celebrate Christmas in a luxurious and classy atmosphere, enjoying the music that will bring us joy. Also, there will be Christmas Troop, Santa Claus is coming to town! The Santa troop will spread happiness throughout Central Phuket. Lastly, Cake Workshop, workshop activity with Chef Sebastien’s IRON CHEF Thailand teaching how to make Christmas Vanilla Cake. A special activity for the Christmas season. Moreover, Central Phuket provides special promotion exclusively for international tourists throughout December 23 – January 24 including:

1) Get Free! Tourist welcome discount package valued up to THB 10,000.
2) Receive THB 100 Gift voucher when spending up to THB 2,500 per receipt.
3) Get to buy ‘Happy Holiday Collections’ special price: Pokémon 2-in-1 pillow blanket, tumbler, travel bag set, and keychain. Visit redemption counter for the price.
4) Exclusive for Grab Users get discount code up to 25% off* when traveling to participating Central Shopping Centers.
5) Receive famous Elephant Pants when spending over THB 5,000 in shopping center.
6) Get Free! H&M THB 100 gift voucher when booking any accommodations in Phuket with Agoda. Terms and conditions apply.

Central Phuket is a home of global luxury brands such as Alexander McQueen, Balenciaga, Ermenegildo Zegna, Gucci, Hermès, Louis Vuitton, and Saint Laurent. Exclusive for this season, Louis Vuitton launches a pop-up store located at Central Phuket. The design is inspired by the story of Damier or Checkerboard, the brand’s signature pattern. This classic pattern was created by Louis
Vuitton and his son Georges Vuitton in 1888 and has always been part of the design of Maison’s iconic items and concepts. Find clothes, shoes, bags, and accessories for men at the Pop-up Store from Louis Vuitton at Central Phuket, 1st floor, from today until 31 March 2024. And with over 500 renowned fashion brands and lifestyle shops ranging from local to international
well-known brands covering all categories, international shoppers will be able to find what they are looking for in Central Phuket.
Central Phuket is located in the heart of one of the world’s most famous beach cities, Phuket and await to welcome both locals and international visitors this holiday. Also, don’t miss one of the most joyful New Year Count Down events in Phuket city at Central Phuket Shopping Center on December 31, 2023.

Continue Reading

World

Saudi Fund for Development Provides $100 Million Development Loan for the Rogun Hydropower Project

The Saudi Fund for Development (SFD) Chief Executive Officer, H.E. Sultan Al-Marshad, signed a new development loan agreement with the Minister of Finance of the Republic of Tajikistan, H.E. Kahhorzoda Fayziddin Sattor, through which SFD is contributing $100 million USD to fund the Rogun Hydropower Project, a landmark initiative that will enhance energy,
food, and water security, and foster sustainable development in the country. The signing was attended by the Ambassador of the Kingdom of Saudi Arabia to the Republic of Tajikistan, H.E. Waleed Al-Reshiadan, and the Ambassador of Tajikistan to Saudi Arabia, H.E. Akram Karimi, alongside other officials from both sides. SFD’s development loan will help contribute towards a more sustainable and equitable food and water future for Tajikistan, while driving the country’s energy transition and climate resilience. The project aims to contribute to the national energy security and will help advance sustainable
development in the Republic of Tajikistan, by providing the renewable electricity supply to meet local demand and expand electricity production domestically and regionally, producing 3600 MW of energy. The loan agreement will also finance the construction of a 335-meter-tall dam, which will enhance irrigation capabilities and bolster agricultural activities across the country. Additionally, the project will improve flood protection through the construction of four hydraulic
tunnels for diversion and drainage. It will also provide clean and drinkable water to people through desalination, and help advance socio-economic development, by creating both direct and indirect jobs.
Importantly, this project also supports the realization of the UN Sustainable Development Goals (SDGs); specifically, SDG 2, Zero Hunger, SDG 6, Clean Water and Sanitation, and SDG 7, Affordable and Clean Energy.
On this occasion, the CEO of SFD, H.E. Sultan Al-Marshad, said: “Today’s signing marks a major milestone in our shared journey towards a more sustainable future. With this landmark development loan, SFD is not just supporting Tajikistan’s energy future, but also its sustainable development and the well-being of its people. The Rogun Hydropower Project is a beacon of
hope for a bright future that is powered by clean, renewable energy. It will propel Tajikistan towards environmental stewardship and prosperity.”

Continue Reading

Trending