Microsoft says Russia-linked hackers target sports organisations

The company has in the past taken legal steps to prevent Strontium from using fake Microsoft internet domains


Reuters October 29, 2019
The Microsoft sign is shown on top of the Microsoft Theatre in Los Angeles, California, US, October 19,2018. PHOTO: REUTERS

Microsoft Corp said it has tracked “significant” cyberattacks coming from a group it calls “Strontium” or “Fancy Bear”, targeting anti-doping authorities and global sporting organisations.

The group, also called APT28, has been linked to the Russian government, Microsoft said in a blog post.

At least 16 national and international sporting and anti-doping organisations across three continents were targeted in the attacks which began on September 16, according to the company.

The company said some of these attacks had been successful, but the majority had not. Microsoft has notified all customers targeted in these attacks.

Google accused of ripping off digital ad technology

Strontium, one of the world’s oldest cyberespionage groups, has also been called Sofancy and Pawn Storm by a range of security firms and government officials. Security firm CrowdStrike has said the group may be associated with the Russian military intelligence agency GRU.

Microsoft said Strontium reportedly released medical records and emails taken from sporting organisations and anti-doping officials in 2016 and 2018, resulting in an indictment in a federal court in the United States in 2018.

The software giant added that the methods used in the most recent attacks were similar to those used by Strontium to target governments, militaries, think-tanks, law firms, human rights organisations, financial firms and universities around the world.

Strontium’s methods include spear-phishing, password spray, exploiting internet-connected devices and the use of both open-source and custom malware, it added.

Microsoft says new augmented reality headset to go on sale in September

Microsoft has in the past taken legal steps to prevent Strontium from using fake Microsoft internet domains to execute its attacks.

By August last year, Microsoft had shut down 84 fake websites in 12 court-approved actions over the past two years.

Microsoft said at the time that hackers linked to Russia’s government sought to launch cyber-attacks on US political groups.

COMMENTS

Replying to X

Comments are moderated and generally will be posted if they are on-topic and not abusive.

For more information, please see our Comments FAQ