Daily Management Review

Security Firm Claims Hotel Guests Across Europe Were Targeted By Russia-Linked Hackers


08/13/2017




Security Firm Claims Hotel Guests Across Europe Were Targeted By Russia-Linked Hackers
Researchers at security firm FireEye said that probably behind a campaign targeting hotel guests in eight mostly European countries last month, was a cyber-spying group with suspected links to Russian military intelligence.
 
FireEye said in a report that in order then to infect their organizational networks back home, using hotel wi-fi networks, the espionage group, dubbed APT 28, sought to steal password credentials from Western government and business travelers.
 
It said that staying in several hotel chains in at least seven countries in Europe and one in the Middle East, the wave of attacks during the first week of July targeted travelers.
 
Including Hillary Clinton's unsuccessful White House bid last year, the allegations that Russia is engaged in far-flung hacking activity aimed at governments, businesses and election campaigns were given body by these preliminary findings.
 
APT 28 has been linked to the GRU, Russia's military intelligence directorate by several governments and security research firms. While stopping short of linking APT 28 to the Russian state, other researchers have tracked the same pattern of attacks.
 
Moscow vehemently denies the accusations.
 
Clearly pointing to APT 28, whose vast scope of activities his firm has detailed since 2014, are the technical exploits and remote chain of command used to mount the attacks, said Benjamin Read, manager of cyber espionage analysis for U.S.-based FireEye.
 
"We are moderately confident in our assessment," Read told Reuters, saying this was because the technical inquiry was still in its early days. "We just don't have the smoking gun yet."
 
The latest attempts were identified and thwarted in the initial infiltration stage. But the computer of a U.S. government employee was breached in the autumn of 2016 at hotels in Europe by the use of similar methods.
 
As infected hotel reservation document was installed GAMEFISH malware run remotely from internet sites known to be controlled by APT 28 after hotel employees were tricked to download spear-phishing emails in the July attacks, FireEye found.
 
Cyber spies could sniff unencrypted data being transmitted to shared network drives in the up-market, business-class hotels of major cities and grab passwords of targeted victims by this foothold which gave the cyber spies control over guest wi-fi networks.
 
"We did not observe any guest credentials being stolen. However there were multiple hotel chains targeted and we don't know the full extent of the operation," Read said.
 
Hackers were given a highly sophisticated way to move silently inside organizations' networks once they infect even a single machine in the July attacks as the hackers took advantage of a recently leaked piece of malicious software known as EternalBlue, believed to have been stolen from the U.S. National Security Agency.
 
The NotPetya attack against Ukraine in June, which fanned out globally to hit dozens of major firms and the worldwide spread of WannaCry ransomware in May were fueled by EternalBlue.
 
(Source:www.reutrs.com) 






Science & Technology

Designing Of Cars Being Done With Hologram Goggles At Ford

The Already Surging Cyber Attacks Are Set To Rise Even Further, Says A Study

Chinese to equip smartphones with OLED displays

Based On One Photo, Research Shows A.I. Can Detect The Sexual Orientation Of A Person

Cyber Crime Risks Are Substantial, Systemic, Says SEC Chief

Tech Titans, Amazon & Microsoft, Partner To Integrate Their Respective A.I. ‘Voice Assistants’

SpaceX Selects Technical University Team’s Hyperloop As The Winner Of The ‘Fast Pod’

Market of autonomous cars will accelerate by 2025

AHA Customers In Iceland Enjoy The First ‘Drone Delivery Service’ In The World

Wal-Mart to unite with Google's voice platform

World Politics

World & Politics

Strong 3.4 magnitude earthquake detected coming from North Korea’s nuclear test site

Even As Kim And Trump Trade Threats, South Korea Approves $8 Million Aid For The North

From October 1 Uber is banned in London

Concerns about the far-right party are growing in Germany

Fight for clean air: 7 countries against internal combustion engines

Japan, India Agree To Deepen Defence With China In Mind

Myanmar's Rohingya Crisis May Be Taken Advantage Of By Terror Groups

The French people voted for Labour Reforms, there is no turning back: French Prime Minister Edouard Philippe