Categories: News

The Russian Nobelium group comes back with phishing

The Russian hackers in the Nobelium group, who were behind the SolarWinds attack are back with a phishing attack. They struck again, according to Tom Burt, Microsoft vice president.

Nobelium sent phishing emails

In his post, Burt mentioned that hackers managed to gain access to the “Constant Contact” email marketing service. The United StatesAgency for International Development (USAID) operates this service.

Once they gained access, the group sent phishing emails infused with malware. Thus, hackers installed the NativeZone backdoor. This managed to exfiltrate data and spread the malware across the networks.

Although the attack is global, most of its victims were in the US. The attack affected more than 3,000 accounts from 150 organizations.

Microsoft mentioned that they observed the attack of the hackers behind the attack against SolarWinds in January 2021, with “significant experimentation,” but still little impact. Still, this changed a few days ago, when hackers started using Constant Contact. Simultaneously, they unleashed the phishing attack.

Initially, the hackers made the victims that clicked legit Constant Contact the link bump to an infrastructure they controlled. Then, they started a malicious .iso file, which gave hackers access to the machine.

Dangerous messages went through the filters

According to Microsoft, automated filters managed to catch most of the phishing messages. Still, some made it through and became very dangerous. So, the company advised blocking theyardservice[dot]com, which hackers used for redirection. Also, users should adopt multi-factor authentication.

Security experts mentioned that the new Nobelium attack came just after Joe Biden announced a meeting with Vladimir Putin, next month. The US president accused Russia for exploits such as the Colonial Pipeline ransomware attack. Still, Russia denied its involvement.

Because of the incident, the US Department of Treasury decided sanctions on Russian cyber companies. Moreover, it expelled diplomats from US embassies.

The number of cyber attacks that experts link to Russia increased significantly, during the last few months.

Laurentiu Titei

Recent Posts

How to Set Your Preferred Default Printer Windows 10/11

Tired of Windows managing your printer choices? Then, you are not alone; it happens with…

2 days ago

Top 17 Best Free Driver Updater Tools for Windows 10 and 11 in 2026

Are you on the lookout for the best free driver updater software? Look no further!…

2 days ago

Best Game Booster and Optimizer Tools for Windows

In this guide, we will have a look at some of the best game booster…

2 days ago

Best Live Wallpaper Apps for Windows PC

Tired of staring at the same static desktop every day? Bring your PC to life…

3 days ago

Epson L3150 Resetter Free Download | Epson L3150 Adjustment Program

Epson L3150 is a highly efficient all-in-one solution for wireless printing. This wireless EcoTank printer…

3 days ago

Best Microsoft PowerToys with Download and Installation Guide

Microsoft PowerToys are named “PowerToys” for an interesting reason. These tools help power users, such…

4 days ago