{"id":39462,"date":"2022-07-14T09:50:00","date_gmt":"2022-07-14T09:50:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/39462"},"modified":"2022-07-14T09:50:00","modified_gmt":"2022-07-14T09:50:00","slug":"how-hostile-government-apts-target-journalists-for-cyber-intrusions","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=39462","title":{"rendered":"How hostile government APTs target journalists for cyber intrusions"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/how-hostile-government-apts-target-journalists-for-cyber-intrusions.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The past 18 months have seen a series of sustained and ongoing cyber campaigns by <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/advanced-persistent-threat-APT\/\">state-aligned threat actors<\/a> targeting journalists and media organisations around the world, which show no sign of letting up, according to security firm <a href=\"https:\/\/www.proofpoint.com\/uk\">Proofpoint<\/a>.<\/p>\n<p>The firm\u2019s research team today (14 July) <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists\">published new analysis<\/a> revealing how advanced persistent threat (APT) groups with links to China, Iran, North Korea, Russia and Turkey have been both targeting and posing as journalists to advance their goals.<\/p>\n<p>While the media sector is vulnerable to exactly the same cyber threats as any other \u2013 ransomware attacks, and so on \u2013 APT groups target it for slightly different purposes, which could have far-reaching impacts on the lives of millions, making it extremely important for media organisations and journalists to protect themselves, their sources, and the integrity of the information they hold.<\/p>\n<p>The sector is particularly valued by state-backed APT actors for several reasons, chiefly because journalists, if compromised, can provide access and information that could prove highly valuable.<\/p>\n<p>Most commonly, said Proofpoint, cyber attacks on journalists are used for espionage or to gain insight into the inner workings of governments or organisations of interest to the attackers.<\/p>\n<p>A well-timed and successful attack on a journalist\u2019s email account could also provide data on political stories that might be damaging to the APT\u2019s paymasters, or enable them to identify and expose activists, political dissidents or whistleblowers.<\/p>\n<p>Compromised accounts can also be used to spread disinformation or propaganda on stories that are potentially damaging to the regime, such as <a href=\"https:\/\/www.computerweekly.com\/news\/252464902\/MP-brands-Huawei-exec-a-moral-vacuum-as-operators-demand-5G-clarity\">China\u2019s persecution of its Muslim minority in Xinjiang<\/a> or its abrogation of its commitments to democracy in Hong Kong.<\/p>\n<p>\u201cIn an era of digital dependency, the media, like the rest of us, is vulnerable to a variety of cyber threats,\u201d said Sherrod DeGrippo, Proofpoint\u2019s vice-president of threat research and detection.<\/p>\n<p>\u201cSome of the most potentially impactful are those stemming from APT actors. From reconnaissance activity prior to the 6 January 2021 riot to credential harvesting and delivering malware, Proofpoint is disclosing for the first time some specific APT activity targeting or posing as members of the media.\u201d<\/p>\n<p>Proofpoint\u2019s researchers focused on the activities of a handful of APT actors linked to the regimes in China, North Korea, Iran and Turkey.<\/p>\n<p>Its report reveals how China-backed <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252496730\/Chinese-APT-used-stolen-NSA-exploit-for-years\">TA412 (aka Zirconium)<\/a> APT targeted US-based journalists using malicious emails containing web beacons\/tracking pixels \u2013 hyperlinked non-visible objects in the body of an email which, when enabled, attempt to retrieve a benign image file from an actor-controlled server.<\/p>\n<p>This campaign was probably intended to validate that their targeted email accounts are active and to gather information about the recipients\u2019 network environments, such as externally visible IP addresses, user-agent strings and email addresses.<\/p>\n<p>The nature of this campaign shifted over its duration, with lures constantly changing to fit the current political environment in the US, while TA412 also switched up its list of targets depending on what the Chinese government was interested in at the time.<\/p>\n<p>Most notably, between January and February 2021, TA412 focused on journalists covering US politics and national security.<\/p>\n<p>A very abrupt shift in targeting took place immediately before <a href=\"https:\/\/www.techtarget.com\/searchunifiedcommunications\/news\/252494844\/Big-Techs-uneasy-balance-of-capitalism-censorship\">the 6 January 2021 insurrection<\/a> that saw a pro-Trump mob storm the Capitol in Washington DC in an attempt to halt the certification of Joe Biden and change the result of the 2020 election, when TA412 started to show a particular interest in Washington and White House correspondents specifically, using subject lines pulled from relevant news articles as lures.<\/p>\n<p>Meanwhile, the Proofpoint team observed multiple Iran-aligned APTs using journalists and newspapers as pretexts to surveil targets and attempt to steal their credentials. Probably the most active is <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252512805\/Iranian-hacking-groups-pick-up-the-pace-with-new-attacks\">TA453 (aka Charming Kitten)<\/a>, which is thought to be aligned with the intelligence operation of Iran\u2019s Islamic Revolutionary Guard Corps.<\/p>\n<p>TA453 was observed masquerading as journalists from all over the world to engage in ostensibly benign conversations with its targets, including academics and experts in Middle Eastern affairs. These journalist personas, and their targets, were well researched to increase the likelihood that their approaches, flattery and deception would be believed.<\/p>\n<p>During their conversation with the fake journalist, the target would typically receive a benign PDF file, usually delivered from a legitimate file-hosting service, that contained a link to a URL shortener and IP tracker, and redirected the target to a credential harvesting domain controlled by TA453.<\/p>\n<p>A second Iranian actor, TA456 (aka Tortoiseshell) was also observed masquerading as multiple news organisations including Fox News and the <em>Guardian<\/em>, to spread web beacons, similar to the Chinese group, probably to conduct reconnaissance before attempting to deliver malware, while a third operation, tracked as TA457, posed as an \u201ciNews Reporter\u201d to target internal public relations staffers at companies in Israel, Saudi Arabia and the US, using the subject line \u201cIran Cyber War\u201d as a lure. This particular campaign was spotted by Proofpoint when TA457 targeted a number of its customers.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Lazarus has entered the chat\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Lazarus has entered the chat<\/h3>\n<p>In the case of North Korea, it is perhaps little surprise to see TA404 \u2013 <a href=\"https:\/\/www.computerweekly.com\/news\/252496494\/North-Korean-Lazarus-Group-hackers-indicted-in-US\">more widely known as Lazarus<\/a> \u2013 involved in targeting the media sector.<\/p>\n<p>In one incident observed by Proofpoint\u2019s team, Lazarus trained its sights on a US media organisation that had published an article critical of North Korean dictator Kim Jong Un \u2013 an act that frequently causes North Korean APTs to take action. The campaign began with reconnaissance phishing, using URLs customised to its targets, masquerading as a job opportunity \u2013 <a href=\"https:\/\/www.computerweekly.com\/news\/252522378\/ESET-Lazarus-APT-hit-aero-defence-sector-with-fake-job-ads\">a favoured tactic of Lazarus<\/a>.<\/p>\n<p>If the target interacted with the URL, the server resolving the domain received confirmation that the email was delivered and interacted with, along with identifying information about the target\u2019s device.<\/p>\n<p>Proofpoint said it had not seen any follow-up emails in this campaign, but given Lazarus\u2019 well-documented fondness for malware, it is likely they would have tried to deliver some eventually.<\/p>\n<p>In the case of Turkey \u2013 which as a Nato country is not typically regarded as a hostile state, although it has been drifting towards authoritarianism \u2013 an APT tracked as TA482 has been regularly observed targeting journalists\u2019 social media accounts in a credential theft campaign.<\/p>\n<p>TA482 is not definitively linked to the Turkish government, but it uses services based in the country to host its domains and infrastructure, and Turkey has a history of exploiting social media to spread propaganda favourable to its hardline president, Recep Tayyip Erdogan, and the ruling party, so it is highly likely that it is aligned with the state.<\/p>\n<p>In one TA482 campaign observed this year, the group targeted the Twitter credentials of multiple journalists in both well-known and less prominent media outlets. Its lures were themed as Twitter security alerts concerning, ironically, a suspicious login to their account. Clicking the link in the email sends its target to a TA482-controlled landing page that impersonates Twitter\u2019s password reset function.<\/p>\n<p>Proofpoint said it could not necessarily verify the motivation behind this campaign, but based on what is known of Turkey\u2019s APT scene \u2013 not one of the world\u2019s most prominent \u2013 TA482 is likely trying to get access to journalists\u2019 contacts through their direct messages or hijack the accounts altogether to deface them and spread pro-Erdogan propaganda ahead of parliamentary and presidential elections to be held in 2023.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Soft targets\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Soft targets<\/h3>\n<p>Proofpoint\u2019s research team said it was certain that nation-state APTs will continue to target journalists and media organisations, regardless of their affiliation, because their usefulness in terms of opening doors to other targets is unparalleled.<\/p>\n<p>Also, many are perhaps less likely to have paid appropriate attention to cyber security than, for example, a government entity with hardened defences, so APTs targeting journalists are less likely to be discovered.<\/p>\n<p>In effect, attacks on journalists and media outlets are <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/supply-chain-attack\">somewhat akin to supply chain attacks<\/a>, such as those that wrought havoc among the customers of Kaseya and SolarWinds in the past two years.<\/p>\n<p>As the team\u2019s research demonstrates, because so many different approaches are used, it is vital that those operating in the media space remain vigilant.<\/p>\n<p>\u201cAssessing one\u2019s personal level of risk can give an individual a good sense of the odds they will end up as a target,\u201d the team wrote in their summing up.<\/p>\n<p>\u201cIf you report on China or North Korea or associated threat actors, you may become part of their collection requirements in the future.<\/p>\n<p>\u201cBeing aware of the broad attack surface \u2013 all the varied online platforms used for sharing information and news \u2013 that an APT actor can leverage is also key to preventing oneself from becoming a victim.<\/p>\n<p>\u201cAnd ultimately, practising caution and verifying the identity or source of an email can halt an APT attack in its nascent stage.\u201d<\/p>\n<p>Proofpoint\u2019s full write-up, which includes multiple screengrabs drawn from some of its observed campaigns, <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists\">can be found here<\/a>.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>The past 18 months have seen a series of sustained and ongoing cyber campaigns by state-aligned threat actors targeting journalists and media organisations around the world, which show no sign of letting up, according to security firm Proofpoint. The firm\u2019s research team today (14 July) published new analysis revealing how advanced persistent threat (APT) groups [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":39463,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-39462","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39462"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39462\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/39463"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}