• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Four Russians Charged with Dragonfly Attacks on Critical Infrastructure

You are here: Home / General Cyber Security News / Four Russians Charged with Dragonfly Attacks on Critical Infrastructure
March 25, 2022

The US authorities have exposed indictments charging Russian state hackers with carrying out a string of attacks towards international electricity corporations around a six-calendar year period.

The initially indictment at first returned in June 2021 will involve Evgeny Viktorovich Gladkikh, a computer programmer with the Point out Research Centre of the Russian Federation FGUP Central Scientific Research Institute of Chemistry and Mechanics.

He reportedly hacked industrial handle programs (ICS) and operational technology (OT) between Could and September 2017. This bundled attacks on a Center East oil refinery utilizing the Triton malware, which compelled two unexpected emergency shutdowns.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Gladkikh then tried using to probe US refineries the following calendar year, together with co-conspirators, in accordance to the Department of Justice (DoJ).

The second indictment, returned in August 2021, includes a few FSB officers stated to be users of the infamous Dragonfly group (aka Energetic Bear, Crouching Yeti): Pavel Aleksandrovich Akulov, Mikhail Mikhailovich Gavrilov and Marat Valeryevich Tyukov.

Between 2021 and 2017, the indictment alleges that the 3 obtained covert accessibility to vitality sector networks, which includes SCADA and ICS devices in oil and gas companies, nuclear power vegetation and utility and electricity transmission firms.

The first phase of the attack, amongst 2012 and 2014, involved hiding Havex malware in respectable program updates for ICS/SCADA methods and spear-phishing and watering hole raids. This enabled them to install malware on much more than 17,000 exceptional units in the US and elsewhere, the DoJ reported.

The 2nd section, “Dragonfly 2.,” ran from 2014 to 2017 and included focusing on a lot more than 3300 people at over 500 US and international businesses, which includes US authorities agency the Nuclear Regulatory Fee and the Wolf Creek Nuclear Operating Corporation.

Following setting up a foothold in sufferer networks, the conspirators moved laterally to obtain other personal computers and networks, the DoJ said.

The news will be particularly about specified the challenges of new offensive Russian exercise in the US next its invasion of Ukraine.

“Russian condition-sponsored hackers pose a significant and persistent threat to critical infrastructure both equally in the United States and all over the globe,” stated deputy attorney Common Lisa Monaco.

“Although the criminal fees unsealed these days mirror past action, they make crystal clear the urgent ongoing have to have for American companies to harden their defenses and keep on being vigilant. Along with our associates listed here at dwelling and abroad, the Division of Justice is committed to exposing and keeping accountable condition-sponsored hackers who threaten our critical infrastructure with cyber-attacks.”


Some pieces of this post are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News UK Teen Arrested in Lapsus Crackdown
Next Post: London DJ Surrenders £214,000 of Music Kit in Money Laundering Case Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.