Microsoft: Multiple Russian cyberattacks have been intercepted
Microsoft says it has blocked multiple hacking attempts from Russia. According to the company, the spies tried to break into Ukrainian and American targets. Some EU bodies are also said to have been targeted.
In a blog post, Microsoft writes that Strontium, a hacker group associated with Russian military intelligence GRU, has used seven Internet domains to spy on government bodies and think tanks in Europe and the United States. Some Ukrainian institutions, including media organizations, have been attacked through those domains, the company says.
Microsoft had received a court order on Wednesday to acquire the domains. He has redirected these domains to a sinkhole that the company manages. This allows Strontium to use the domains to a limited extent or not at all. After that, Microsoft notified the victims and targets, including the Ukrainian government.
“We believe that Strontium was trying to gain long-term access to its targets’ systems, providing tactical support for the physical invasion of Ukraine, and seeking sensitive information,” Microsoft wrote.
It is not known exactly which organizations and institutions were affected. Also, Microsoft does not say which domains were used in Strontium’s attacks. The American company has been researching Strontium since 2016. Microsoft says it has already taken over more than a hundred domains from the Russian hacker group.