Belarus likely funding cyberattacks to stop refugees fleeing UkraineVish Gainon March 2, 2022 at 12:00 Silicon RepublicSilicon Republic
Cybersecurity researchers in the US have identified a new state-sponsored phishing campaign based in Belarus that is targeting European governments in their effort to manage refugees fleeing from Ukraine, which is on its seventh day of an invasion by Russia.
Using a malware known as SunSeed, the state actors are using the compromised email accounts of Ukrainian armed forces members to disrupt the logistics involved in the movement of Ukrainian refugees to neighbouring countries such as Poland, Hungary and Slovakia.
The discovery was made by California-based cybersecurity company Proofpoint, which released details of the phishing campaign on its website yesterday (1 March), calling it a “weaponisation of migrants and refugees of war through a hybrid information warfare and targeted cyber-attack model”.
“This campaign represents an effort to target NATO entities with compromised Ukrainian military accounts during an active period of armed conflict between Russia, its proxies, and Ukraine,” Proofpoint researchers said in a statement emailed to SiliconRepublic.com.
Ukraine has been subject to a spate of cyberattacks in recent days, starting just ahead of Russia’s invasion of the country last Thursday.
Proofpoint researchers have tentatively attributed the SunSeed malware-based phishing campaign to a group called Ghostwriter, which it tracks as TA445, and thinks is likely based in the eastern European country of Belarus – a key Russian ally.
TA445 is known to have engaged in “a significant volume of disinformation operations” in the past that aimed at manipulating European sentiment around the movement of refugees within NATO countries.
Its latest SunSeed phishing attack involved emails that targeted EU individuals responsible for transportation, finance and budget allocation, and administration of refugee movement from Ukraine into the rest of Europe, with the objective to gather data on funds, supplies and people in NATO countries.
While Proofpoint researchers think that techniques used in the campaign are “not ground-breaking individually”, they can be quite effective if deployed collectively during a “high-tempo conflict”.
They also think that similar attacks against government entities in NATO countries are likely to happen again as the invasion of Ukraine rages on.
“The possibility of exploiting intelligence around refugee movements in Europe for disinformation purposes is a proven part of Russian and Belarussian-state techniques. Being aware of this threat and disclosing it publicly are paramount for cultivating awareness among targeted entities,” the company wrote in the statement.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
The post Belarus likely funding cyberattacks to stop refugees fleeing Ukraine appeared first on Silicon Republic.