State-backed Russian hackers are targeting pharmaceutical companies, healthcare, academic research centers and other organisations, in an attempt to get insights and steal data related to 'COVID-19' coronavirus vaccine development.
The advisory, which was put out by the UK's National Cyber Security Center (NCSC) with support from the U.S. National Security Agency (NSA) and the Department for Homeland Security (DHS), and the Canadian Communication Security Establishment (CSE), said that cyber attacks are from tje hacking group APT-29, or also known as 'Cozy Bear'.
While at this time there is no evidence to suggest that the hacking campaigns have been successful, but the NCSC said the attacks are still ongoing.
"We condemn these despicable attacks against those doing vital work to combat the coronavirus pandemic," said NCSC director of operations Paul Chichester.
APT-29 has been using a variety of tools and techniques, including spear-phishing and custom malware, like the WellMess and WellMail, which both can issue remote commands on infected machines. Its methods, according to NCSC, is "very adept" at exploiting vulnerabilities before patches can be applied.

“APT-29 is likely to continue to target organizations involved in COVID-19 vaccine research and development, as they seek to answer additional intelligence questions relating to the pandemic,” the NCSC statement said.
“While others pursue their selfish interests with reckless behavior, the UK and its allies are getting on with the hard work of finding a vaccine and protecting global health,” he said in a statement.
NCSC has high confidence about the group in working on behalf of the Russian government.
Canadian authorities said the attacks were hindering response efforts and that risks to health organizations were elevated. Canada's intelligence and cyber threat center advised institutions to take action to protect themselves.
In this instance, it appears that the targets have been protected from falling as victims. But it's thought that Russian hackers will continue to target healthcare as the world is seeking ways to cure this deadly disease.
The U.S. and the UK on the other hand, said that the networks of hackers were indeed targeting national and international organisations responding to the pandemic. But they said that such attacks have not previously been explicitly connected to the Russian state.
Besides searching for coronavirus vaccines developments, the hacker group is also continuing their existing campaigns in against targets including governments, diplomats, think-tanks and the energy sector in countries like the U.S., Japan, China, and Africa.
APT-29 is said to have links to the Russian intelligence services, and has identified as the culprit of a number of high profile international cyber attacks.
The group is also widely suspected of hacking the Democratic Party before the 2016 U.S. election.
I a separate announcement Britain also accused the hackers as "Russian actors" trying to interfere in its 2019 election by trying to spread leaked documents online.
The group is also known to scan for vulnerabilities in various networks, such as in Citrix, Pulse Secure and Fortigate products, which it can combine with known exploits to infiltrate systems and gain persistence to commit espionage and other malicious cyber activity.
Russian news agency RIA cited spokesman Dmitry Peskov as saying the Kremlin rejected London’s allegations, which he said were not backed by proper evidence.
"We can say only one thing: that Russia has nothing to do with these attempts," said Peskov to reporters.
Russia’s Foreign Ministry also said those accusations were "foggy and contradictory".























































































































































































































































































































































































