World
US intelligence and over a dozen allies warn of ongoing Russian cyber espionage targeting nuclear and defense sectors, following prior testing in Ukraine.

United States intelligence and security agencies, along with more than twelve allied countries, have issued a warning about an ongoing Russian espionage campaign. This campaign reportedly tested cyber intrusion techniques in Ukraine before deploying them against NATO member states.
The government alert highlighted a "growing trend among Russian cyber threat groups to initially target Ukrainian users—either as a priority target or as a testing ground for malicious cyber techniques before wider global deployment."
It further stated that "based on the success of this campaign and previous ones, it is highly likely that the Russian group will continue targeting email systems used by Western institutions."
Intelligence agencies are monitoring for new victims of these attacks, which will aid the United States and its allies in assessing the extent of damage and identifying the intelligence gathered by Russian operatives, according to CNN.
The detailed nature of the warning, including information not disclosed by cybersecurity firms, indicates that US and allied intelligence agencies have collected extensive intelligence on the Russian espionage group.
Law enforcement has pursued these hackers; Thai authorities arrested a Russian man in his thirties suspected of membership in the group last November. He was extradited to the United States and appeared in a Boston court for the first time last month.
Last year, a group of Russian hackers targeted nuclear scientists, defense contractors, and government employees in a cyber espionage campaign, according to private sector researchers and intelligence warnings issued on Thursday.
The targets of this group suggest an interest in nuclear fusion technology and intelligence that could support the Kremlin’s war effort in Ukraine.
Proofpoint, a US-based email security company that investigated aspects of this activity, reported that the hackers targeted email servers used by "nuclear facilities and defense industry bases" in the United States.
Greg Lysenewich, a researcher at Proofpoint, told the network that the hackers were "targeting entities and users with an interest in nuclear fusion," suggesting the likely aim was "to gain insight into developments achieved by Russian counterparts in this field."
The hackers exploited a rare software vulnerability that required the victim—who must have an email system susceptible to intrusion—only to open the email, without needing to click any links. This vulnerability enabled theft of the victim’s email correspondence spanning three months, along with the entire organization’s email contact list.
The United States and its allies stated that federal and local governments, law enforcement agencies, as well as defense, education, and energy sectors, were all targeted by this cyber activity, without providing specific details.
Sherrod DeGripo, Vice President of Threat Intelligence at Palo Alto Networks’ Unit 42 cybersecurity division, which is also tracking this activity, said, "The threat actor likely sought strategic insights related to Western military information, logistics, and political decisions."
British Security Minister Dan Jarvis commented in a statement that it was "particularly concerning that these aggressors tested their methods on victims in Ukraine before targeting NATO members."
Brett Litherland, Assistant Director of the FBI’s Cyber Crimes Division, told the network this month that following an initial lull after Russia’s 2022 invasion of Ukraine, "we have seen—perhaps over the past year or so—an escalation in Russian cyber targeting of the United States."
World
World
Football
World