Russian cyberspies targeted punk rock band Pussy Riot

Pawn Storm, known for international spying, also targets Russians, Trend Micro said

A closely watched band of suspected Russian hackers have spied on domestic targets, including two members of the outspoken punk rock band Pussy Riot.

Trend Micro said the group, which it refers to as Pawn Storm, has also targeted a software developer in Russia, politicians, artists and journalists in the country.

“Pawn Storm’s targets have mostly been external political entities outside of Russia, but after our analysis we found that a great deal of targets can actually be found within the country’s borders,” wrote Feike Hacquebord, a Trend Micro threat researcher, in a blog post on Tuesday.

Trend came to its conclusion by studying phishing campaigns conducted by Pawn Storm. The group distributes its malware through emails which seek to trick users into clicking on malicious files or links.

It analyzed 12,000 phishing attacks, which sought to steal login credentials, from 2014 and this year. That made it possible “to derive reliable statistics on Pawn Storm targets worldwide,” Hacquebord wrote.

Other security companies, including FireEye, have kept an eye on Pawn Storm over the years. FireEye, which named it APT (advanced persistent threat) 28, said in October it suspected the group was in Russia.

FireEye said much of the group’s malware was set to a Russian language setting, and its working patterns adhered to business hours in Moscow.

Pawn Storm has been active for at least seven years and in the past has focused on geopolitical targets relating to the Caucasus region, Europe and its neighbor, Georgia.

Hacquebord wrote the latest analysis showed two members of the band Pussy Riot have been targeted, as well as a popular Russian rock star.

Russia imprisoned three members of Pussy Riot after they staged an impromptu performance in a Moscow church in early 2012. The group has been highly critical of the Russian government, and their sentences drew worldwide condemnation.

In one another instance, Pawn Storm targeted an active Russian military attache working in a NATO county, which “makes the spies’ motivations even more intriguing,” Hacquebord wrote.

The locations of the top three most targeted people were Ukraine, followed by the U.S. and U.K. In the U.S., Pawn Storm typically pursues the country’s military and affiliated defense companies although it is also interested in energy research, think tanks and academics, he wrote.

Last month, the group attacked high-profile people who use Yahoo’s free email system. The phishing emails were written as if they were notifications from Yahoo for an opt-in program that would improve the deliverability of their email, Hacquebord wrote.

But if users clicked on the link in the email, they unknowingly granted access to their accounts to the attackers using OAuth. OAuth is a protocol for logging into other services using account credentials from another.

“When Yahoo users would opt in, Pawn Storm would get unfettered access to the mailbox,” he wrote.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags punk rockcyberspiestrend microsecurityPawn StormPussy Riot

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Father’s Day Gift Guide

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?