Amazon Seizes Domains Used by Russian Hackers Targeting Windows Users

1 month ago 10
YOUR AD HERE
Amazon Seizes Domains Used by Russian Hackers Targeting Windows UsersThe reason Amazon stepped-in is that the attacks were done while impersonating the company’s cloud arm, known as Amazon Web Services (AWS); recipients of the phishing emails noted they were written in Ukrainian, reports say.

SEATTLE, WA – Online shopping retail giant Amazon this week seized multiple internet domains that have been utilized by Russian hackers to launch phishing attacks that targeted users of Microsoft’s Windows operating system.

Chief Information Security Officer at Amazon, CJ Moses, announced in a blog post that Midnight Blizzard, otherwise known as APT29 – a threat actor directly sponsored by the Russian government – had been targeting government agencies, empires, and military organizations with large scale phishing attacks.

The reason Amazon stepped-in is that the attacks launched by Midnight Blizzard were done while impersonating the company’s cloud arm, known as Amazon Web Services (AWS); recipients of the phishing emails noted they were written in Ukrainian, reports say.

However, it was revealed that the goal of the Midnight Blizzard campaign was to steal Windows credentials to use through Windows Remote Desktop, as opposed to targeting AWS or stealing AWS credentials from the service’s users.

Moses noted that, in addition to Amazon taking action, CERT-UA – the Computer Emergency Response Team of Ukraine, part of the country’s State Center for Cyber Defense – released a comprehensive update on their usual procedures to help victims tell legitimate communications from cyberattacks carried out by third-parties.

Upon learning of this activity, we immediately initiated the process of seizing the domains APT29 was abusing which impersonated AWS in order to interrupt the operation,” Moses said. “CERT-UA has issued an advisory with additional details on their work.”

Midnight Blizzard previously gained a measure of infamy following their attack upon Microsoft earlier in 2024 – with the threat actor gaining access to both corporate email accounts in the company’s cybersecurity and legal departments, as well as those of outside organizations – leading to the tech giant implementing completely new and stringent security policies going forward.

Filed Under: Domain Names, Security Issues Tagged With: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Read Entire Article