Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Tech

Tech Bytes: Microsoft aids FBI in seizing 100+ websites involved in alleged Russian espionage

The US Federal Bureau of Investigation (FBI) has taken control of more than 100 web domains said to be part of a Russian espionage effort, with the help of tech giant Microsoft.

The FBI alleges the websites were used to plan cyber espionage attacks, targeting everyone from US Department of Energy personnel and military defence contractors to Russian not-for-profits and anti-Kremlin media publications.

In the warrant application, the FBI says the domains were used predominantly for money laundering and spear phishing campaigns by the “Callisto” hacking group.

Phishing campaigns use information from compromised email accounts to create convincing emails, seemingly from trusted sources, that include compromising links or pdfs that then steal credentials, gaining access to the next layer of targets.

Often, the stolen credentials can then be used to access other personal or corporate accounts, or even government portals, where the victim has used the same log-in details.

Microsoft takes control of 66 domains

The justice department seized 41 web domains directly and granted a further 66 to Microsoft as part of the same operation.

The FBI’s affidavit says the Russian actors targeted sensitive information related to the “identity of United States employees, defense foreign affairs, and security policies”.

The “criminal conspiracy” also targeted “nuclear energy related technology, research, and development, all of which is particularly valuable to the Russian government’s efforts to engage in malign foreign influence operations within the United States”.

The FBI directly accuses the FSB, Russia’s state security service and successor to the KGB, of being behind the conspiracy and directly names several operatives identified during the course of the investigation.

Hacking group a persistent threat

In its own release on the takedown, Microsoft says its Digital Crimes Unit (DCU) is actively engaged in disrupting the technical infrastructure used by this particular hacking group.

Callisto, also known as Star Blizzard, has been on Microsoft’s radar since 2017 – the company has been directly impacted by the group’s attacks, leading the mega cap to invest significant resources in countering their espionage efforts.

“While we expect Star Blizzard to always be establishing new infrastructure, today’s action impacts their operations at a critical point in time when foreign interference in US democratic processes is of utmost concern,” DCU assistant general counsel Steven Masada wrote.

“It will also enable us to quickly disrupt any new infrastructure we identify through an existing court proceeding.

“Furthermore, through this civil action and discovery, Microsoft’s DCU and Microsoft Threat Intelligence will gather additional valuable intelligence about this actor and the scope of its activities, which we can use to improve the security of our products, share with cross-sector partners to aid them in their own investigations and identify and assist victims with remediation efforts.”

Masada warns that the group is both intelligent and persistent, meticulously studying their targets before posing as trusted contacts to steal information.

“Since January 2023, Microsoft has identified 82 customers targeted by this group, at a rate of approximately one attack per week,” he said.

“This frequency underscores the group’s diligence in identifying high-value targets, crafting personalised phishing emails, and developing the necessary infrastructure for credential theft.”

Microsoft applauded the FBI’s efforts against the group and encouraged all civil society groups to improve their cybersecurity protections and use strong multi-factor authentication like passkeys on both personal and professional accounts.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK