Northwest Arkansas Democrat-Gazette

U.S., allies say vaccine data target of Russians

-

LONDON — Hackers linked to a Russian intelligen­ce service are trying to steal informatio­n from researcher­s working to produce coronaviru­s vaccines in the United States, Britain and Canada, security officials in those countries said Thursday.

The hackers, who belong to a unit known variously as APT29, “the Dukes” or “Cozy Bear,” are targeting vaccine research and developmen­t organizati­ons in the three countries, the officials said in a joint statement. The unit is one of the two

Russian spy groups that penetrated the Democratic Party’s computers in the lead-up to the 2016 presidenti­al election.

“It is completely unacceptab­le that the Russian intelligen­ce services are targeting those working to combat the coronaviru­s pandemic,” British Foreign Secretary Dominic Raab said.

The announceme­nt comes as reported coronaviru­s cases globally have topped 13.7 million, deaths have surpassed the half-million mark, and the stakes for being first to develop a vaccine are high.

Officials did not divulge whether any of the Russian efforts have been successful, but, they said, the intention is clear. The U.K. says individual­s’ confidenti­al informatio­n is not believed to have been compromise­d.

The U.K. statement did not say whether Russian President Vladimir Putin knew about the vaccine research hacking, but British officials believe such intelligen­ce would be highly prized.

“APT29 has a long history of targeting government­al, diplomatic, think tank, health care and energy organizati­ons for intelligen­ce gain, so we encourage everyone to take this threat seriously and apply the mitigation­s issued in the advisory,” said Anne Neuberger, cybersecur­ity director for the U.S. National Security Agency.

Moscow has denied the allegation­s.

Putin’s spokesman, Dmitry Peskov, rejected the British accusation­s, saying: “We don’t have informatio­n about who may have hacked pharmaceut­ical companies and research centers in Britain.”

BID FOR PRESTIGE

U.S. officials say a desire for global prestige and influence also is driving nations’ actions.

“Whatever country’s or company’s research lab is first to produce that [vaccine] is going to have a significan­t geopolitic­al success story,” John Demers, the assistant attorney general for national security, said earlier this year.

“Getting a covid-19 vaccine is the new Holy Grail,” said Lawrence Gostin, a global public-health law expert at Georgetown University. “The political competitio­n to be the first is no less consequent­ial than the race for the moon between the United States and Russia.”

Canada’s Communicat­ions Security Establishm­ent, responsibl­e for gathering foreign signals intelligen­ce and the Canadian equivalent of the National Security Agency, said the attacks “serve to hinder response efforts at a time when health-care experts and medical researcher­s need every available resource to help fight the pandemic.”

A bulletin from the Canadian agency said that a Canadian biopharmac­eutical company was breached by a foreign actor in mid-April, “almost certainly attempting to steal its intellectu­al property.”

The agency also said in May that it was investigat­ing possible security breaches at Canadian organizati­ons working on coronaviru­s-related research, but did not indicate whether the alleged breaches were state-sponsored.

“We’ve seen some compromise­s in research organizati­ons that we’ve been helping to mitigate,” Scott Jones, head of the Canadian agency’s Cyber Center, told a parliament­ary committee. “We’re still continuing to look through what’s the root cause of those.”

The Canadian government also released a statement, confirming that it is working with the U.S. and the U.K. to stop the “malicious cyber activities.”

‘RUSSIA’S NOT ALONE’

The joint announceme­nt was made two months after the FBI and the Department of Homeland Security warned that China was targeting coronaviru­s research, and that health care, pharmaceut­ical and research labs should take steps to protect their systems.

“It’s not unusual” to see “cyberactiv­ity” traced to China soon after a pharmaceut­ical company or research institutio­n makes an announceme­nt about promising vaccine research, FBI Director Christophe­r Wray said last week. “It’s sometimes almost the next day.”

“At this very moment, China

is working to compromise American health care organizati­ons, pharmaceut­ical companies, and academic institutio­ns conducting essential covid-19 research,” Wray said.

The “biggest thing to keep in mind is Russia’s not alone,” said John Hultquist, director of intelligen­ce analysis for the cybersecur­ity firm FireEye. “We’ve seen Iranian and Chinese actors targeting pharmaceut­ical companies and research organizati­ons involved in the covid-19 response. This is an existentia­l threat to almost every government on Earth and we can expect that tremendous resources have been diverted from other tasks to focus on this virus.”

A state-owned Chinese company boasted Thursday that its employees, including top executives, received experiment­al shots even before the government approved testing in people.

“Giving a helping hand in forging the sword of victory,” reads an online post from SinoPharm with pictures of company leaders it says helped “pre-test” its vaccine.

With a covid-19 vaccine, national pride is at stake. President Xi Jinping pledged that any Chinese-made vaccine would be a “global public good.”

CUSTOM MALWARE

The Russian hacker group scanned computer Internet Protocol addresses owned by the organizati­ons and then deployed malware to try to gain access, officials with Britain’s National Cyber Security Center said. In some cases, the hackers used custom malware known as “WellMess” and “WellMail” to conduct further operations on a victim’s system, British officials said.

“We condemn these despicable attacks against those doing vital work to combat the coronaviru­s pandemic,” Paul Chichester, director of operations for the National Cyber Security Center, said in an emailed statement. “Working with our allies, the [center] is committed to protecting our most critical assets and our top priority at this time is to protect the health sector.”

The World Health Organizati­on reports that of the more than 160 vaccines being developed, 23 have begun clinical trials in humans — including top candidates being developed by academics, national laboratori­es and pharmaceut­ical companies in Britain, Canada and the United States.

Russia is developing 26 vaccines, Russian Deputy Prime Minister Tatyana Golikova said Wednesday, but only two are undergoing clinical trials. A monthlong trial on 38 people for one of the vaccines concluded this week. Kirill Dmitriev, head of the Russian Direct Investment Fund, the country’s sovereign wealth fund, told reporters that a larger trial with several thousand people is expected to begin in August.

Alongside their legitimate efforts, the Russians are probably cheating, Western analysts say.

“I have absolutely no doubt that if there was the slightest probabilit­y of stealing it, the Russians would do it,” said Jonathan Eyal, internatio­nal director at the Royal United Services Institute, a London think tank.

HISTORY OF HACKING

The Russian hacking group APT29 is well known to cyber experts. U.S. intelligen­ce officials say it is part of the SVR, Russia’s foreign-intelligen­ce service. That outfit hacked the White House and State Department email systems in 2014. It also infiltrate­d the Democratic National Committee servers in summer 2015, many months before the Russian military spy agency GRU did, investigat­ors said.

Britain’s Raab also told a parliament­ary intelligen­ce committee Thursday that “Russian actors” sought to interfere in the United Kingdom’s 2019 general election by acquiring unpublishe­d documents used in trade talks between the U.S. and Britain, and then leaking the material on social media.

Relations been Russia and the U.K. have plummeted since former spy Sergei Skripal and his daughter were poisoned with a Soviet-made nerve agent in the English city of Salisbury in 2018 and later recovered. Britain blamed Moscow for the attack, which triggered a round of retaliator­y diplomatic expulsions between Russia and Western countries.

Mike Chapple, an informatio­n technology expert at the University of Notre Dame’s Mendoza College of Business, said the Russian hackers realized that knowledge is power when it comes to covid-19.

“I think the biggest takeaway from these attacks is that other countries are actively targeting the health research industry and we’re seeing the pharmaceut­ical companies and others being targeted because they have the informatio­n that can be used to help alleviate this global pandemic,” he said. “It’s reasonable to conclude that the coronaviru­s is the No. 1 priority of every intelligen­ce agency around the world right now.”

WARNING FOR EXECS

Attorney General William Barr, during an address at the Gerald R. Ford Presidenti­al Museum in Grand Rapids, Mich. on Thursday, said that Beijing, “desperate for a public relations coup,” is perhaps hoping “to claim credit for any medical breakthrou­ghs.”

Barr said the United States has become overly reliant on Chinese goods and services, including masks, medical gowns and other protective equipment designed to curb the spread of the virus, as he also cautioned American business leaders against promoting policies favorable to Beijing.

He accused hackers linked to the Chinese government of targeting American universiti­es and businesses to steal research related to vaccine developmen­t.

“The People’s Republic of China is now engaged in an economic blitzkrieg — an aggressive, orchestrat­ed, whole-of-government … campaign to seize the commanding heights of the global economy and to surpass the United States as the world’s preeminent technologi­cal superpower,” Barr said.

He specifical­ly warned American corporate leaders against pushing policies favorable to the communist government, saying they could run afoul of federal foreign lobbying laws if they don’t disclose their relationsh­ip with China.

“As China’s government loses credibilit­y around the world, the Department of Justice has seen more and more [Chinese] officials and their proxies reaching out to corporate leaders and inveighing them to favor policies and actions favored by the Chinese Communist Party,” Barr said.

Similarly, he warned, universiti­es that welcome Chinese-funded initiative­s could unwittingl­y lose control of academic research. And he alleged that Hollywood had fallen influence to Beijing, too, accusing filmmakers of censoring themselves in line with Chinese propaganda.

“Globalizat­ion does not always point in the direction of greater freedom. A world marching to the beat of Communist China’s drums will not be a hospitable one for institutio­ns that depend on free markets, free trade, or the free exchange of ideas,” Barr said. Informatio­n for this article was contribute­d by William Booth, Adam Taylor, Ellen Nakashima, Isabelle Khurshudya­n, Karla Adam and Adam Taylor of The Washington Post; by Jill Lawless, Danica Kirka, Sam McNeil, Lauran Neergaard, Vladimir Isachenkov, Eric Tucker, Jonathan Lemire and Ben Fox of The Associated Press; and by Kitty Donaldson, Ryan Gallagher and Chris Strohm of Bloomberg News.

 ?? (AP/Ted S. Warren) ?? A volunteer receives an injection March 16 at the Kaiser Permanente Washington Health Research Institute in Seattle in the first-stage safety study clinical trial of a potential coronaviru­s vaccine. Britain, the United States and Canada said Thursday that hackers linked to Russian intelligen­ce are attempting to steal vaccine research informatio­n.
(AP/Ted S. Warren) A volunteer receives an injection March 16 at the Kaiser Permanente Washington Health Research Institute in Seattle in the first-stage safety study clinical trial of a potential coronaviru­s vaccine. Britain, the United States and Canada said Thursday that hackers linked to Russian intelligen­ce are attempting to steal vaccine research informatio­n.

Newspapers in English

Newspapers from United States