ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign

Land
|

The Australian Signals Directorate and Australia’s National Cyber Security Coordinator Lieutenant General Michelle McGuinness have warned of an ongoing phishing campaign being undertaken by Russian state-sponsored actors.

The Australian Signals Directorate and Australia’s National Cyber Security Coordinator Lieutenant General Michelle McGuinness have warned of an ongoing phishing campaign being undertaken by Russian state-sponsored actors.

The joint advisory with international partners relates to cyber activity linked to the Russian state-sponsored group LAUNDRY BEAR.

It’s alleged that Russian state-sponsored cyber actors are conducting phishing campaigns targeting users of Zimbra Collaboration Suite since July last year with the intention to steal credentials and gain unauthorised access to email accounts and organisational networks.

 
 

The Russian state-supported advanced persistent threat group’s activity is tracked in the cybersecurity community under several names, primarily as ‘LAUNDRY BEAR,’ a name initially coined by the Netherlands General Intelligence and Security Service and Defence Intelligence and Security Service

“The advisory explains how the group exploited a previously unknown vulnerability in Zimbra Collaboration Suite to access organisations’ email systems,” according to the Australian Signals Directorate.

“Unlike most phishing attacks, this technique can begin when a user simply views a malicious email in a vulnerable version of the webmail service.

“The group uses this technique to steal emails, contact lists and other sensitive information, and may attempt to maintain access to compromised networks for further malicious activity.

“Organisations using ZCS, particularly across government, law enforcement, technology, education, energy, media, NGOs, and the Defence Industrial Base, should review the advisory and assess whether they may be affected.

“We strongly encourage organisations and network defenders to apply security updates, patch vulnerable systems and monitor email services for signs of compromise. The advisory also includes guidance on identifying and responding to affected systems.”

Organisations are advised to enable multi-factor authentication for all Zimbra accounts where possible, educate users to identify and report phishing emails and suspicious login requests, apply the latest security updates and patches for Zimbra Collaboration Suite; and monitor accounts and network activity for signs of unauthorised access or credential theft.

“Australia has joined Five Eyes and European partners to release a technical advisory warning of an ongoing phishing campaign being undertaken by Russian state-sponsored actors,” according to the National Cyber Security Coordinator.

“The latest campaign highlighted by the Australian Signals Directorate has targeted organisations using the Zimbra Collaboration Suite online platform – likely for espionage purposes.

“Organisations using Zimbra Collaboration Suite should ensure they have implemented the recommended mitigations outlined in the advisory.

“Strong cyber hygiene matters. No country can be complacent about cyber threats and Australia calls on all states and cyber actors to act responsibly in cyberspace.

“Australian entities can report cyber security incidents at cyber.gov.au or by calling the 24/7 Australian Cyber Security Hotline on 1300 CYBER1.”

Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service.

Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means.

LAUNDRY BEAR has primarily relied on ProtonMail for distribution of malicious email. However, more recent efforts likely have shifted to distributing the payload through previous victims.

Robert Dougherty

Robert is a senior journalist who has previously worked for Seven West Media in Western Australia, as well as Fairfax Media and Australian Community Media in New South Wales. He has produced national headlines, photography and videography of emergency services, business, community, defence and government news across Australia. Robert graduated with a Bachelor of Arts, Majoring in Public Relations and Journalism at Curtin University, attended student exchange program with Fudan University and holds Tier 1 General Advice certification for Kaplan Professional. Reach out via email at This email address is being protected from spambots. You need JavaScript enabled to view it. or via LinkedIn.

Want to see more stories from trusted news sources?
Make Defence Connect a preferred news source on Google.
Click here to add Defence Connect as a preferred news source.

Tags: