Remove tag fancy-bear
article thumbnail

Google: Russian Hackers Target Ukrainians, European Allies via Phishing Attacks

The Hacker News

A broad range of threat actors, including Fancy Bear, Ghostwriter, and Mustang Panda, have launched phishing campaigns against Ukraine, Poland, and other European entities amid Russia's invasion of Ukraine.

Phishing 101
article thumbnail

Google alerts over 50k users about State funded Cyber Attacks

CyberSecurity Insiders

Ajax Bash, the Security Engineer of Google Threat Analysis Group (TAG) endorsed the statement and attributed a large global campaign to a group of threat actors belonging to Kremlin based Fancy Bear (APT28).

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Google sent over 50,000 warnings of state-sponsored attacks, +33% from same period in 2020

Security Affairs

The data were provided by Google’s Threat Analysis Group (TAG), which tracks government-backed hacking campaign, which warns of a significant increase in the number of the alert compared to the previous year. This spike is largely due to blocking an unusually large campaign from a Russian actor known as APT28 or Fancy Bear.”

article thumbnail

China-linked APT Curious Gorge targeted Russian govt agencies

Security Affairs

China-linked Curious Gorge APT is targeting Russian government agencies, Google Threat Analysis Group (TAG) warns. Google Threat Analysis Group (TAG) reported that an APT group linked to China’s People’s Liberation Army Strategic Support Force (PLA SSF), tracked as Curious Gorge , is targeting Russian government agencies.

article thumbnail

Google warns of APT28 attack attempts against 14,000 Gmail users

Security Affairs

Shane Huntley, the head of the Threat Analysis Group (TAG), wrote on Twitter that his group had sent an above-average batch of government-backed security warnings. . TAG sent a above average batch of government-backed security warnings yesterday.

article thumbnail

APT28 and Upcoming Elections: evidence of possible interference

Security Affairs

Figure 4: Payload stored in “Company” tag of document metadata. APT28 (aka Fancy Bear , Pawn Storm , SofacyGroup , Sednit , and STRONTIUM ) launched several attacks on democratic institutions in Europe between September and December 2018.

Malware 89
article thumbnail

Advanced threat predictions for 2024

SecureList

Mail servers become priority targets In June, Recorded Future warned that BlueDelta (aka Sofacy, APT28, Fancy Bear and Sednit) exploited vulnerabilities in Roundcube Webmail to hack multiple organizations including government institutions and military entities involved in aviation infrastructure.

Hacking 101