Russian Hackers Linked to New Attacks Exploiting Windows Vulnerability

By

Russia has repeatedly made headlines in the upcoming U.S. election, with government-sponsored hackers allegedly responsible for accessing Democratic Party emails and then publishing them through WikiLeaks and other sources. Now Microsoft has given the hacking sources additional validity, claiming a group previously linked to the Russian government and U.S. political hacks is responsible for recent attacks that exploited a newly discovered Windows security flaw.

Microsoft revealed on its website that “spear phishing” emails had been sent from the Strontium hacking group, also known as “Fancy Bear” and “APT 28.” Those emails were used to launch a small number of attacks by exploiting Windows vulnerabilities. Microsoft is releasing a patch on Election Day, November 8, to protect users against the threat.

The timing of Microsoft’s announcement, as well as the patch release on Election Day, adds yet another element of chaos into what has proven to be a historically unusual and turbulent election cycle. And much in the spirit of the impending election, rivals Microsoft and Google were at each other’s throats over the timing of the vulnerability announcement. According to Microsoft, the attacks exploit a vulnerability in Adobe’s Flash software as well as the Windows OS. Adobe released a patch for its vulnerability on Monday, and Google promptly went public with details of the attacks – well before Microsoft’s patch was prepared and available.

“Google’s decision to disclose these vulnerabilities before patches are broadly available and tested is disappointing, and puts customers at increased risk,” said Microsoft in a statement, while Google had no comment on the issue.

According to John Bambenek, threat systems manager at Fidelis Cybersecurity, a company specializing in threat detection and security, early disclosure was the right move in this scenario, and will protect more enterprises in the long run.

“There will always be a risk with acknowledging weakness,” said Bambenek. “Even releasing patches can give adversaries the very clues needed to weaponize and exploit. This was very much true with Microsoft patches years ago, which have been largely mitigated by automated patching and rebooting within 24 hours of release.”

“While we don’t have solid data to talk about how widely it is being used, we do know that this vulnerability is dangerous,” added Bambenek. “It's a local privilege escalation, which means that if a user can execute compromised code, that code could be used to run commands as the administrator and more deeply embed itself into a system. At this point, my preference is to release mitigation strategies so that enterprises can protect their users while awaiting a patch.”

The Fancy Bear hacking group has been primarily tied to GRU, Russia’s military intelligence agency. The group has been widely blamed for the recent hacks of Democratic Party databases and emails.




Edited by Alicia Young
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

TechZone360 Contributing Editor

SHARE THIS ARTICLE
Related Articles

ChatGPT Isn't Really AI: Here's Why

By: Contributing Writer    4/17/2024

ChatGPT is the biggest talking point in the world of AI, but is it actually artificial intelligence? Click here to find out the truth behind ChatGPT.

Read More

Revolutionizing Home Energy Management: The Partnership of Hub Controls and Four Square/TRE

By: Reece Loftus    4/16/2024

Through a recently announced partnership with manufacturer Four Square/TRE, Hub Controls is set to redefine the landscape of home energy management in…

Read More

4 Benefits of Time Tracking Software for Small Businesses

By: Contributing Writer    4/16/2024

Time tracking is invaluable for every business's success. It ensures teams and time are well managed. While you can do manual time tracking, it's time…

Read More

How the Terraform Registry Helps DevOps Teams Increase Efficiency

By: Contributing Writer    4/16/2024

A key component to HashiCorp's Terraform infrastructure-as-code (IaC) ecosystem, the Terraform Registry made it to the news in late 2023 when changes …

Read More

Nightmares, No More: New CanineAlert Device for Service Dogs Helps Reduce PTSD for Owners, Particularly Veterans

By: Alex Passett    4/11/2024

Canine Companions, a nonprofit organization that transforms the lives of veterans (and others) suffering PTSD with vigilant service dogs, has debuted …

Read More