More Than 12,000 Windows Users Attacked by Government-backed Hackers – Google’s Threat Analysis Group Warned

Google’s Threat Analysis Group(TAG) has sent more than 12,000 warnings to users in 149 countries targeted by government-backed attackers. The warnings found to be sent between Jul-Sep 2019.

Phishing targets

TAG has analyzed more than 270 targeted or government-backed groups from 50 countries and their goals involving intelligence collection, stealing intellectual property, targeting dissidents and activists, destructive cyberattacks or spreading coordinated disinformation.

Cyber Attacks Targeted

TAG observed that more than 90% of users targeted via “credential phishing emails” and the emails are attempted to gain account credentials to hijack’s user accounts.

On such example is the fake email that is sent from “Goolge” asking users to secure the account, the phishing email aimed to gain account login credentials.

Phish Gmail users

Starting from December 2017 TAG observed a series of campaigns from Russia-nexus threat group called “Sandworm”. The sandworms activity particularly targeting Ukraine and their attacks targeting the 2018 Winter Olympics.

The first campaign targets South Korea, in the campaign Sandworm, was modifying legitimate Android applications with malware.

Starting from November 2018, the sandworm targeted software and mobile app developers in Ukraine via spear-phishing emails with malicious attachments. By compromising the app developers Sandworm built a backdoor with legitimate apps.

The good news is that the Google Play Protect team detected the malicious time at the time of upload and no users were infected.

TAG also plays part in tackling Disinformation, they observed a campaign that use inauthentic news outlets to disseminate messages promoting Russian interests in Africa.

TAG identified a campaign targeting the Indonesian provinces Papua and West Papua with messaging in opposition to the Free Papua Movement and the associated Youtube accounts terminated.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Also Read

Hackers Hosting Fake Military Veterans Website to Drop Malware

Orcus RAT Author Charged in International Malware Scheme For Infecting Thousands of Computers With RAT

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago