Showing posts sorted by relevance for query russia. Sort by date Show all posts
Showing posts sorted by relevance for query russia. Sort by date Show all posts

16 February 2022

Follow the money: Russian Cybercriminals Drive Significant Ransomware and Cryptocurrency-based Money Laundering Activity

Russia has long been home to some of the most skilled hackers in the world. According to cybersecurity investigators like Brian Krebs, this is largely due to the country’s excellence in computer science education, combined with low economic prospects even for those who are skilled in the field. Given this background, it may not be surprising that Russia leads the way in ransomware. But the degree to which Russia-based ransomware strains dominate is quite shocking. 

Before we dive into the data, a quick explainer - we generally tie specific ransomware strains to Russian cybercriminals based on one of three criteria:

1) Evil Corp is a Russia-based cybercriminal organization that has been prolific in ransomware, and whose leadership is believed to have ties to the Russian government. 

2) The Commonwealth of Independent States (CIS) is an intergovernmental organization of Russian-speaking, former Soviet countries. Many ransomware strains contain code that prevents the encryption of files if it detects the victim’s operating system is located in a CIS country. In other cases, ransomware operators have even given over decryptors to return file access after learning they inadvertently targeted a Russian organization. We can attribute CIS-avoiding strains to Russian cybercriminals, though with a lesser degree of confidence, as some of them may be based in other CIS countries.

3) There are several other ransomware characteristics that can indicate a strain is likely based in Russia. Examples include ransomware strains that share documents and announcements in the Russian language, or whose affiliates are believed to be located in Russia with a high degree of confidence. 

Overall, roughly 74% of ransomware revenue in 2021 - over $400 million worth of cryptocurrency - went to strains we can say are highly likely to be affiliated with Russia in some way. 

Blockchain analysis combined with web traffic data also tells us that after ransomware attacks take place, most of the extorted funds are laundered through services primarily catering to Russian users.

www.chainalysis.com


25 February 2022

Pray for Ukraine

The Archbishop of York spoke in the debate in the House of Lords today regarding the situation in Ukraine. This is his speech in full:

My Lords you may have seen that the Archbishop of Canterbury and I have already spoken about the unprovoked attack on Ukraine as an act of great evil. This is a dark hour for Europe. We have called on Anglican churches to make this coming Sunday a day of prayer for peace  and on Tuesday encourage parishes to join with the Anglican diocese in Europe in prayer at 6 pm, especially for those who minister and witness for peace in Ukraine itself where we have chaplaincies and minister alongside other denominations and faith communities. We are all invited to join with Pope Francis in making Ash Wednesday a day of fasting and prayer for peace.

Perhaps in the west, we have taken peace for granted. The horrors being visited on Ukraine must be a wake-up call for us that peace is something you need to work at. What is happening in Ukraine is truly shocking, but, sadly it is not surprising. We have seen it coming. Ukraine now stands alone, unprotected by the treaties that protect us and allow us to believe that peace is a normal state of affairs. 

But it isn’t. 

Peace is a choice. It is a decision that we need to make each day about the way we live and about our responsibilities to and with our neighbour, be that in our family, in our local community, or between the nations of the world. And we need the policies, the wisdom, the tenacity and the international resolve that will deliver it.

Previous generations knew this. They knew it, because they had experienced the horrors of war that most of us haven’t. 

In the post-war period we invested in international bodies and associations that would bind us to each other. In 1950, for instance, Robert Schuman, the French Foreign Minister, said when announcing a plan to pool coal and steel production, that the plan was motivated so that solidarity in production would make war between France and Germany “not only unthinkable, but materially impossible.”

But Ukraine is not defended by NATO. What we have seen from Vladimir Putin in the last few days is a terrible, flagrant disregard of the Ukrainian people’s legitimate right to self-determination. As the noble Lady Baroness Goldie has put it, he has chosen war.

Right now, as well as generous, humanitarian aid and support for refugees, about which I hope the minister will say more in his summing up – we need to know what is happening - we must use all our diplomatic muscle and energy, stringent economic sanctions, and focused political will to force Russia to step back from this aggression, withdraw its troops and silence the guns, not least because effective sanctions will mean many innocent Russians suffer as well. Our actions must be swift and cohesive if they are to be decisive. 

Jesus urged his followers to be peacemakers, not simply peacelovers. This is an important distinction, because it is a call to action.   

First, in  support of Ukraine, and especially the many innocent children and families, potential refugees living with this conflict and its consequences, and support for those who are bravely protesting on the streets of Russia. But peace, lasting peace, requires more. It requires a new commitment to international instruments of law and order, accountability and investment so that we make peace and choose peace, not just hope to keep it. The suffering of Ukraine, the imperialist ambition of Russia, our own acceptance that ‘immoral flood of corrupt money that flows (from Russia) through London’ has to stop.

And as followers of Jesus, we pray because we believe God’s grace has the final word, not the horrors of sin, not death. 

But we also pray because that prayer will shape our will and will shape our resolve The prayers of Christian people and of all people of faith and goodwill are with our government, and with all the leaders of the free world, as we both implore Russia to change course, but also determine to play our part in the active pursuit of peace in our world today.

www.archbishopofyork.org


20 February 2024

Navalny: The disciple who 'laid down his life' to fight Putin


A Christian historian and analyst of Russia told Premier that the death and courageous example of Putin-opponent Alexei Navalny are impacting even those "who are sympathetic to the Putin narrative" in Russia.

Navalny, who was 47 and a professing Christian convert from staunch atheism, was announced dead on Friday, having died in a penal colony in the Arctic Circle.

His mother and lawyer have been stopped from seeing his body, while his widow Yulia claims he was poisoned with Novichok by the Kremlin.

Navalny survived an FSB Novichok attack in 2020, becoming unwell after getting on a plane in the Siberian city of Tomsk for a flight back to Moscow.

Five months after falling victim, he decided to return to Russia and was arrested on arrival.

Speaking on Premier's Inspirational Breakfast, historian Martyn Whittock said Navalny's legacy would be one that enables other Christians to stand up to Putinism in Russia, despite the Orthodox church's official support for the leader.

www.premierchristian.news


11 March 2022

Russia mulls legalizing software piracy as it’s cut off from Western tech

 

Following the Russian war against Ukraine, and with sanctions against Russia starting to bite, the Kremlin is mulling ways to keep businesses and the government running. The latest is a creative twist on state asset seizures, only instead of the government taking over an oil refinery, for example, Russia is considering legalizing software piracy.

Russian law already allows for the government to authorize - “without consent of the patent holder”—the use of any intellectual property “in case of emergency related to ensuring the defense and security of the state.” The government hasn’t taken that step yet, but it may soon, according to a report from Russian business newspaper Kommersant, spotted and translated by Kyle Mitchell, an attorney who specializes in technology law. It's yet another sign of a Cyber Curtain that's increasingly separating Russia from the West.

www.arstechnica.com


15 December 2017

Internet traffic to major tech firms (briefly) rerouted to Russia.


Internet traffic for some of the world’s largest tech firms was briefly rerouted to Russia earlier this week in what appeared to be a Border Gateway Protocol (BGP) attack.

OpenDNS-owned Internet monitoring service BGPmon reported the incident on Tuesday. BGPmon noticed that 80 IP prefixes for organizations such as Google, Microsoft, Apple, Facebook, NTT Communications, Twitch and Riot Games had been announced by a Russian Autonomous System (AS).

It happened twice on Tuesday and each time it only lasted for roughly three minutes. The first event took place between 04:43 and 04:46 UTC, and the second between 07:07 and 07:10 UTC.

Despite being short-lived, BGPmon said the incidents were significant, including due to the fact that the announcements were picked up by several peers and some large ISPs, such as Hurricane Electric and Zayo in the U.S., Telstra in Australia, and NORDUnet, which is a joint project of several Nordic countries.


Meanwhile, in other news...

Russia a 'risk' to undersea cables, defence chief warns. The UK's most senior military officer has warned of a new threat posed by Russia to communications and internet cables that run under the sea.

Air Chief Marshal Sir Stuart Peach, the chief of the defence staff, said Britain and Nato needed to prioritise protecting the lines of communication. He said it would be an "immediately and potentially catastrophic" hit to the economy if they were cut or disrupted.

The cables criss-cross the seabed, connecting up countries and continents.


14 January 2022

REvil ransomware gang arrested in Russia

Authorities in Russia say they have dismantled the ransomware crime group REvil and charged several of its members.

The United States had offered a reward of up to $10m (£7.3m) for information leading to the gang members, following ransomware attacks.

Russia's intelligence bureau FSB said the group had "ceased to exist". However, it does not appear that any Russian members of the gang will be extradited to the United States.

The agency said it had acted after being provided with information about the REvil gang by the US. According to the Russian state news service Tass, REvil "developed malicious software" and "organised the theft of money from the bank accounts of foreign citizens".

The FSB said it had seized more than 426 million rubles (£4m), including about £440,000 worth of crypto-currency. It also seized more than 20 "premium cars" which had been purchased with the proceeds of crime.

www.bbc.co.uk


13 January 2023

Royal Mail hit by Russia-linked ransomware attack

 

Severe disruption to Royal Mail's overseas deliveries has been caused by ransomware linked to Russian criminals, the BBC has been told.

The cyber-attack has affected the computer systems Royal Mail uses to despatch deliveries abroad. Royal Mail has been warning customers since Wednesday of disruption due to a "cyber-incident". Its latest advice is for people not to try to send international letters and parcels until the issue is resolved.

Ransomware is malicious computer software that encrypts data and locks up systems. The ransomware used in the attack is "Lockbit", according to a source close to the investigation. Computer security firms say the software has been developed and used by criminal gangs with links to Russia.

www.bbc.co.uk


15 March 2022

Use Kaspersky software? Time for a rethink - read this...

The German Federal Office for Information Security (BSI) warned organizations against using Kaspersky antivirus software over fears it could be exploited for cyber-espionage or launching cyberattacks amid Russia’s ongoing war in Ukraine.

While the office is not explicitly banning the use of Kaspersky software, the security agency is urging German organizations to replace products made by the Moscow-headquartered firm with alternative software from non-Russian vendors, warning that Russia’s military and intelligence activities in Ukraine, along with its threats against Europe, NATO, and Germany, means there is “a considerable risk of a successful IT attack.”

“A Russian IT manufacturer can carry out offensive operations itself, be forced to attack target systems against its will, or be spied on without its knowledge as a victim of a cyber operation, or be misused as a tool for attacks against its own customers,” the BSI said in a statement, explaining that antivirus software such as Kaspersky’s have deep system access and must maintain a permanent, encrypted and non-verifiable connection to the manufacturer’s servers. “Companies and authorities with special security interests and operators of critical infrastructures are particularly at risk,” the statement adds.

www.techcrunch.com


14 July 2026

The US government warns that Russia state hackers are coming after your router

The US federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.

Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.

When was the last time you checked your router settings, or to see if it's running up to date firmware? Need a hand: contact Donline.

www.arstechnica.com


13 November 2025

Watch: Russia's AI robot falls seconds after being unveiled

 

BBC News: Footage shows the moment Russia's first anthropomorphic robot, AIdol, fell just seconds after its debut at a technology event in Moscow.

The robot was being led on stage to the soundtrack from the film 'Rocky', before it suddenly lost its balance and fell. Assistants could then be seen scrambling to cover it with a cloth - which ended up tangling in the process.

Meanwhile at Boston Dynamics - here's a video of what their robots can do now. Four years ago their robot Atlas was doing parkour, and Spot was dancing to The Rolling Stones & Start Me Up!

Personally, I'm not too keen on all this stuff. I hope & pray that the future of robotics is more like the first clip (rubbish) and not like this one :0(

www.bbc.co.uk

 

08 August 2019

Microsoft finds Russia-backed attacks that exploit IoT devices


The STRONTIUM hacking group, which has been strongly linked by security researchers to Russia’s GRU military intelligence agency, was responsible for an IoT-based attack on unnamed Microsoft customers, according to the company - a blog post from the company’s security response center issued Monday.

Microsoft said in a blog that the attack, which it discovered in April, targeted three specific IoT devices - a VoIP phone, a video decoder and a printer (the company declined to specify the brands) - and used them to gain access to unspecified corporate networks. Two of the devices were compromised because nobody had changed the manufacturer’s default password, and the other one hadn’t had the latest security patch applied.

Devices compromised in this way acted as back doors to secured networks, allowing the attackers to freely scan those networks for further vulnerabilities, access additional systems, and gain more and more information. The attackers were also seen investigating administrative groups on compromised networks, in an attempt to gain still more access, as well as analyzing local subnet traffic for additional data.


01 March 2022

Ukraine: The Salvation Army is already there and helping

The Salvation Army has programmes and personnel in Ukraine, Russia, Poland, Romania, Moldova and other European countries who were able to offer practical assistance as soon as the violence escalated.

Some rushed to the border of Ukraine to hand out urgent provisions, while others made arrangements to offer support to Ukraine’s people seeking shelter in their country.

In particular, The Salvation’s Army’s response includes:

  • Romania has formed an emergency team, filled the car with essential items and travelled to the border to offer support.
  • Moldova will provide free assistance to Ukraine’s displaced people, including temporary accommodation, hot meals and drinks, access to Wi-Fi and other necessary items.
  • Poland is preparing relief parcels for Ukrainian people coming into the country.
  • Slovakia is preparing to offer accommodation, food and drink, and emotional support.
  • The Czech Republic is already home to some 200,000 Ukrainians and anticipates many more of them will seek help from family and friends already in the country. The Salvation Army in Czech Republic has available capacity in residential centres, so they stand ready to provide support.

The Salvation Army in Ukraine reports that officers are sleeping in shelters alongside the communities they serve, but doing their best to offer hope and support.

If you would like to make a donation towards The Salvation’s Army’s work in Ukraine, it would be gratefully received.

www.salvationarmy.org.uk


01 May 2020

The true cost of cheap phones: Xiaomi harvesting user data - transmitting it to remote servers!


Security researcher Gabi Cirlig has discovered that his Redmi Note 8 usage habits were being tracked and sent to servers hosted by Alibaba in Singapore and Russia that have been rented by Xiaomi. This included the folders he opened on his phone, the screens he swiped to including the status bar and the settings menu. As if that was not enough, Xiaomi was even tracking what music Cirlig was listening to using the default music player on his Redmi phone.

The security researcher also found that whenever he browsed the web using Xiaomi's default browser app, it kept a record of all the websites he visited, search engine queries, and the items viewed on the browser's newsfeed. More worryingly, the behavior continued even when using the incognito mode in the browser. The security researcher found the same tracking code in other Xiaomi phones as well including premium models like the Redmi K20, Mi 10, and Mi Mix 3.


26 September 2022

Good Floyd vs Bad (ex) Floyd

Planned concerts in Poland by Pink Floyd co-founder Roger Waters have been cancelled amid outrage over the musician's stance on the Ukraine warThe concert's promoter, Live Nation Poland, confirmed the cancellation but gave no reason for it.

The controversy was triggered by an open letter Waters wrote to Ukraine's first lady, Olena ZelenskaIn it, he said, "extreme nationalists" in Ukraine "have set your country on the path to this disastrous war".

He accused her husband, Ukrainian President Volodymyr Zelensky, of failing to fulfil his election campaign promises to bring peace to the Donbas region and and made no mention of Russia's responsibility for the war.

Contrast the above shabby behaviour with the honourable stance of his ex-colleagues here. It's not hard to imagine why Mr Waters & the rest of Pink Floyd didn't see eye to eye...

www.bbc.co.uk


26 May 2018

FBI tells router users to reboot now to kill malware infecting 500k devices


The FBI is advising users of consumer-grade routers and network-attached storage devices to reboot them as soon as possible to counter Russian-engineered malware that has infected hundreds of thousands devices.

Researchers from Cisco’s Talos security team first disclosed the existence of the malware on Wednesday. The detailed report said the malware infected more than 500,000 devices made by Linksys, Mikrotik, Netgear, QNAP, and TP-Link. Known as VPNFilter, the malware allowed attackers to collect communications, launch attacks on others, and permanently destroy the devices with a single command. The report said the malware was developed by hackers working for an advanced nation, possibly Russia, and advised users of affected router models to perform a factory reset, or at a minimum to reboot.


24 January 2018

Major UK cyber attack is "when, not if", says security chief



A major cyber attack on the UK is a case of "when, not if", says the head of the National Cyber Security Centre.

Speaking to the Guardian, Ciaran Martin said the country had been lucky to avoid a "category one" attack - targeting infrastructure like energy companies and financial services. But Mr Martin said the UK was increasing its defence capabilities.

His comments came after Gen Sir Nick Carter called for more defence spending to tackle the threat. The head of the British Army said the UK needed to protect itself from "cyber-warfare" from Russia.


01 March 2022

Tech news related to Putin's invasion of Ukraine

 

SecurityWeek: Twitter will put warnings on tweets sharing links to Russian state-affiliated media, the platform said Monday, as Kremlin-tied outlets are accused of spreading misinformation on Moscow's invasion of Ukraine.

Pressure is on social media giants to squelch misleading or false information about the attack, which has drawn fierce international condemnation.

Kremlin-run media outlets RT and Sputnik have both faced accusations of using false narratives in an effort to argue in favour of war.

=============

Microsoft: Several hours before the launch of missiles or movement of tanks on February 24, Microsoft’s Threat Intelligence Center (MSTIC) detected a new round of offensive and destructive cyberattacks directed against Ukraine’s digital infrastructure. We immediately advised the Ukrainian government about the situation, including our identification of the use of a new malware package (which we denominated FoxBlade), and provided technical advice on steps to prevent the malware’s success. (Within three hours of this discovery, signatures to detect this new exploit had been written and added to our Defender anti-malware service, helping to defend against this new threat.) In recent days, we have provided threat intelligence and defensive suggestions to Ukrainian officials regarding attacks on a range of targets, including Ukrainian military institutions and manufacturers and several other Ukrainian government agencies. This work is ongoing.

=============

Reuters: Germany's Enercon on Monday said a "massive disruption" of satellite connections in Europe was affecting the operations of 5,800 wind turbines in central Europe.

It said the satellite connections stopped working on Thursday, knocking out remote monitoring and control of the wind turbines, which have a total capacity of 11 gigawatt (GW).

"The exact cause of the disruption is not yet known. The communication services failed almost simultaneously with the start of the Russian invasion of Ukraine," Enercon said in a statement.

In other news, BBC reports: European gas prices have risen after the approval of the Nord Stream 2 pipeline to Germany was halted because of Russia's actions in Ukraine.


16 January 2018

'Very high level of confidence' Russia used Kaspersky software for devastating NSA leaks


Three months after U.S. officials asserted that Russian intelligence used popular antivirus company Kaspersky to steal U.S. classified information, there are indications that the alleged espionage is related to a public campaign of highly damaging NSA leaks by a mysterious group called the Shadow Brokers.

U.S. investigators “now believe that those manuals [leaked by Shadow Brokers] may have been obtained using Kaspersky to scan computers on which they were stored.”


28 October 2022

Didn't see this coming: Europe now has so much natural gas that prices just dipped below zero

Europe has more natural gas than it knows what to do with. So much, in fact, that spot prices briefly went negative earlier this week.

For months, officials have warned of an energy crisis this winter as Russia — once the region’s biggest supplier of natural gas — slashed supplies in retaliation for sanctions Europe imposed over its invasion of Ukraine.

Now, EU gas storage facilities are close to full, tankers carrying liquefied natural gas (LNG) are lining up at ports, unable to unload their cargoes, and prices are tumbling.

The price of benchmark European natural gas futures has dropped 20% since last Thursday, and by more than 70% since hitting a record high in late August. On Monday, Dutch gas spot prices for delivery within an hour — which reflect real time European market conditions — dipped below €0, according to data from the Intercontinental Exchange.

Prices turned negative because of an “oversupplied grid,” Tomas Marzec-Manser, head of gas analytics at the Independent Commodity Intelligence Services (ICIS), told CNN Business.

It is a hugely surprising turn of events for Europe, where households and businesses have been clobbered by eye-watering rises in the price of one of its most important energy sources over the past year.

edition.cnn.com


19 July 2022

Iran: where having a pet could soon land you in jail

The Iranian parliament could soon approve the Protection of the Public's Rights Against Animals bill, which would restrict pet ownership across the board.

Police there recently announced that walking dogs in parks was a crime. The ban was justified as a measure to "protect the safety of the public".

According to the proposed legislation, pet ownership would be subject to a permit issued by a special committee. There would also be a minimum fine of around $800 (790 euros; £670) for the "import, purchase and sale, transportation and keeping" of a range of animals, including common pets such as dogs, cats, turtles and rabbits.

"Debates around this bill started more than a decade ago, when a group of Iranian MPs tried to promote a law to confiscate all dogs and give them to zoos or leave them in deserts," Dr Payam Mohebi, the president of the Iran Veterinary Association and an opponent of the bill, told the BBC.

I'm struggling to get my head around some countries: Pakistan, Iran, Russia, China, and others. Do they not look at themselves in the mirror & realise: we're the baddies?

www.bbc.co.uk