A Russian cyber espionage group has spent the past year targeting American nuclear scientists, defence contractors and government officials in a sophisticated intelligence-gathering campaign that reportedly leveraged a rare “no-click” email exploit, cybersecurity researchers and more than a dozen allies say.
The campaign seems to have been geared towards gathering information on nuclear fusion research, military technology and strategic policy development. The intelligence might support Moscow's broader strategic goals, according to investigators in the Ukraine war.
Unlike other phishing campaigns, the hacking campaign didn’t require the victim to click on suspicious links or download malware or viruses. Instead the hackers exploited vulnerable email systems and could hack systems just by opening a vulnerable email.
The cyber security company Proofpoint, which carried out part of the operation, said the hackers targeted email servers at US nuclear facilities and organisations connected to the country’s defence industrial base.
Greg Lesnewich, a threat researcher at Proofpoint, said the campaign seemed to target people and institutions involved in nuclear fusion research. The targeting indicated that the attackers may have been looking for intelligence on scientific and technological developments in which Russia has a strategic interest.
Rare Exploit Enabled Silent Access
At the time, we were aware the operation was conducted using an unusual software vulnerability that could be exploited to gain access to email systems without requiring users to interact with a malicious link or attachment, the multinational cybersecurity advisory said.
When that vulnerability was exploited, the attackers could extract up to three months of email correspondence and gain access to an organisation's entire email directory. This kind of access could provide rich information on research projects, institutional relationships, internal communications and senior officials.
The ability to access an entire email directory could also help hackers map networks of researchers, government officials and defence personnel, possibly helping them identify additional targets for future operations.
To the security experts, the technique represented a significant evolution in cyber espionage tactics. Traditional phishing attacks usually rely on human error, e.g., clicking on a fake link and also opening an infected file. A vulnerability-based attack on email infrastructure can reduce the likelihood of victims finding suspicious activity.
Ukraine Allegedly Used as Testing Ground
The joint advisory allegedly found that Russian operators had tested several of their cyber techniques against Ukrainian targets before expanding their operations against NATO members and other Western institutions.
Ukraine is understood to have served as a testing ground for Russian cyber operations since the full-scale invasion started. Researchers said techniques learned in the Ukrainian attacks were also employed for government agencies, defence institutions and critical infrastructure in other countries.
Sherrod DeGrippo, Vice President of Threat Intelligence at Palo Alto Networks' Unit 42, said the attackers were likely seeking information about Western military planning, logistics and policy decisions.
UK Security Minister Dan Jarvis also expressed concern over the apparent progression of the campaign. He said that the use of techniques first tested against Ukrainian victims before being deployed against NATO members suggested a deliberate expansion of Russian cyber espionage capabilities.
We believe email security is increasingly important in the context of sensitive scientific research, national defence and government policy. Cybersecurity experts have been warning that hackers are now using software vulnerabilities so well to bypass traditional security measures as opposed to relying solely on social engineering.
The latest operation also demonstrates how cyber espionage can target scientific research and defence technology and traditional government networks. Nuclear fusion research in particular has become a strategic focus because of its potential for energy and advanced technology in the future.
Hence, officials are advising organisations affected by this to enhance email security, fix insecure systems and monitor networks for signs of unauthorised access, officials say.
In doing so, the campaign underscores how cyber conflict is increasingly a global phenomenon with the techniques learned during an attack in a single theatre being used for spying on governments, research institutes and defence organisations worldwide.