Site icon Secplicity – Security Simplified

UK, Canada and US All Warn of New Attacks on Covid-19 Research

The UK Cyber Security Center (NCSC) and Canada’s Communications Security Establishment (CSE) with the help of the NSA released an advisory today on attacks from APT29 (also known as ‘the Dukes’ or ‘Cozy Bear’), a group with ties to the Russian intelligence services.

“APT29 is using custom malware known as ‘WellMess’ and ‘WellMail’ to target a

number of organisations globally. This includes those organisations involved with

COVID-19 vaccine development. “

The report gives a few examples of what vulnerabilities APT29 uses to compromise targets.

Known since 2018, WellMess targets Windows and Linux to run shell commands and download files. WellMail malware, a new malware targeting Linux servers, run commands on the victim’s computer and sends the results to its command and control server. For further details on the malware see the full report.

Targeted attacks on COVID-19 research continues and we have written about these attacks previously. Hospitals and research facilities mush take care to protect these servers and networks.

Exit mobile version