Philippine Daily Inquirer

Vaccine data theft: Russia hand seen

UK, US, Canada say hackers from Moscow’s intelligen­ce services using phishing, malware to steal research on COVID-19

- LONDON—THE —STORY BY REUTERS

United Kingdom, United States and Canada said hackers backed by Russia are trying to steal COVID-19 vaccine and treatment research from academic and pharmaceut­ical institutio­ns around the world. Using phishing tools and malware, hackers identified as APT29 reportedly gained access to secure computers containing research on the pandemic. Moscow re- jected the allegation­s.

backed by the Russian state are trying to steal COVID-19 vaccine and treatment research from academic and pharmaceut­ical institutio­ns around the world, Britain’s National Cyber Security Center (NCSC) said on Thursday.

A coordinate­d statement from Britain, the United States and Canada attributed the attacks to group APT29, also known as Cozy Bear, which they said was almost certainly operating as part of Russian intelligen­ce services.

“We condemn these despicable attacks against those doing vital work to combat the coronaviru­s pandemic,” said NCSC director of operations

Paul Chichester.

Cybersecur­ity researcher­s said an APT29 hacking tool was used against clients located in the United States, Japan, China and Africa over the last year.

Russian news agency RIA cited spokespers­on Dmitry Peskov as saying the Kremlin rejected London’s allegation­s, which he said were not backed by proper evidence.

‘Russian actors’

In a separate announceme­nt Britain also accused “Russian actors” of trying to interfere in its 2019 election by trying to spread leaked documents online. Russia’s foreign ministry said those accusation­s were “foggy and contradict­ory.”

Britain is expected to publish a long-delayed report into Russian influence in British politics next week.

British foreign minister

Dominic Raab said it was “completely unacceptab­le” for Russian intelligen­ce services to target work on the pandemic.

“While others pursue their selfish interests with reckless behavior, the UK and its allies are getting on with the hard work of finding a vaccine and protecting global health,” he said in a statement. He said Britain would work with allies to hold perpetrato­rs to account.

The NCSC said the group’s attacks were continuing and used a variety of tools and techniques, including spear-phishing and custom malware.

Still a threat

“APT29 is likely to continue to target organizati­ons involved in COVID-19 vaccine research and developmen­t, as they seek to answer additional intelligen­ce questions relating to the pandemic,” the NCSC statement said.

The US Department of Homeland Security and US Cyber Command also released technical informatio­n on Thursday about three hacking tools being deployed by the Russian hackers, codenamed Wellmail, Sorefang and Wellmess.

Private sector cybersecur­ity researcher­s who had spotted the Wellmess malware over the last year were unaware of its Russian origins until Thursday.

Remote access

In several cases, Wellmess was found within US pharmaceut­ical companies, said three investigat­ors familiar with the matter, who spoke on condition of anonymity to discuss confidenti­al informatio­n. The tool allowed the hackers to stealthily gain remote access to secure computers. They declined to name the victims.

Britain and the United States said in May that networks of hackers were targeting national and internatio­nal organizati­ons responding to the pandemic. But such attacks have not previously been explicitly connected to the Russian state.

 ??  ??
 ?? —REUTERS ?? GOING IN A researcher working prepares to inject an experiment­al vaccine into a volunteer at a university clinic in Tuebingen, Germany, on June 22.
—REUTERS GOING IN A researcher working prepares to inject an experiment­al vaccine into a volunteer at a university clinic in Tuebingen, Germany, on June 22.
 ??  ?? LONDON/OTTAWA—HACKERS
LONDON/OTTAWA—HACKERS

Newspapers in English

Newspapers from Philippines