Top Russian military hackers target NATO using Microsoft Outlook exploits

A stressed out hacker looking at a laptop screen
(Image credit: Yuri A/Shutterstock)

Between April and December 2022, the NATO Rapid Deployable Corps, a NATO force that can quickly be deployed to command NATO forces, was targeted by Russian state-sponsored hackers. 

This is according to cybersecurity researchers Unit 42, a security arm of Palo Alto Networks, who noted that the hackers were after sensitive data and other valuable intelligence.

A few weeks after the invasion of Ukraine, a threat actor known as APT28 (AKA Fancy Bear, Fighting Ursa) started abusing a zero-day vulnerability in Microsoft Outlook to target the State Migration Service of Ukraine with malware. A month later, Unit 42 says, it used the same vulnerability - tracked as CVE-2023-23397, in more campaigns. In total, networks of roughly 15 government, military, energy, and transportation organizations around Europe were targeted. The Russians were after emails with military intelligence, which might aid the country’s war effort.

NATO members under attack

When Microsoft patched the flaw a year later, APT28 was already deep enough, obtained enough credentials, and established enough persistence to keep going. It expanded its campaign in May this year, when it started abusing a separate flaw, tracked as CVE-2023-29324.

Now, Unit 42 claims all of the affected countries are NATO members, and in one instance, even the NATO Rapid Deployable Corps was a target. 

"Using a zero-day exploit against a target indicates it is of significant value. It also suggests that existing access and intelligence for that target were insufficient at the time," Unit 42 said. "In the second and third campaigns, Fighting Ursa continued to use a publicly known exploit that was already attributed to them, without changing their techniques. This suggests that the access and intelligence generated by these operations outweighed the ramifications of public outing and discovery.”

"For these reasons, the organizations targeted in all three campaigns were most likely a higher than normal priority for Russian intelligence."

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Russia
Major Russian hacking group shifts focus to US and UK targets
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Russian criminal gang Star Blizzard found hitting WhatsApp accounts
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
Russian flag on a laptop
Major Russian IT service provider hit with cyberattack
Russian flag on a laptop
Hackers are using Russian domains to launch complex document-based phishing attacks
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Latest in News
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired