PanaTimes

Friday, Jun 09, 2023

Russian hacking team ‘Cold River’ targeted US nuclear scientists

Russian hacking team ‘Cold River’ targeted US nuclear scientists

A Russian hacking team known as “Cold River” targeted three nuclear research laboratories in the United States this past summer, according to internet records reviewed by Reuters and five cybersecurity experts.

Between August and September, as President Vladimir Putin indicated Russia would be willing to use nuclear weapons to defend its territory, Cold River targeted the Brookhaven (BNL), Argonne (ANL) and Lawrence Livermore National Laboratories (LLNL), according to internet records that showed the hackers creating fake login pages for each institution and emailing nuclear scientists in a bid to make them reveal their passwords.

Reuters was unable to determine why the labs were targeted or if any attempted intrusion was successful. A BNL spokesperson declined to comment. LLNL did not respond to a request for comment. An ANL spokesperson referred questions to the US Department of Energy, which declined to comment.

Cold River has escalated its hacking campaign against Kyiv’s allies since the invasion of Ukraine, according to cybersecurity researchers and western government officials. The digital blitz against the US labs occurred as UN experts entered Russian-controlled Ukrainian territory to inspect Europe’s biggest atomic power plant and assess the risk of what both sides said could be a devastating radiation disaster amid heavy shelling nearby.

Cold River, which first appeared on the radar of intelligence professionals after targeting Britain’s foreign office in 2016, has been involved in dozens of other high-profile hacking incidents in recent years, according to interviews with nine cybersecurity firms.

Reuters traced email accounts used in its hacking operations between 2015 and 2020 to an IT worker in the Russian city of Syktyvkar.

“This is one of the most important hacking groups you’ve never heard of,” said Adam Meyer, senior vice president of intelligence at US cybersecurity firm CrowdStrike. “They are involved in directly supporting Kremlin information operations.”

Russia’s Federal Security Service (FSB), the domestic security agency that also conducts espionage campaigns for Moscow, and Russia’s embassy in Washington did not respond to emailed requests for comment.

Western officials say the Russian government is a global leader in hacking and uses cyber-espionage to spy on foreign governments and industries to seek a competitive advantage. However, Moscow has consistently denied that it carries out hacking operations.

Reuters showed its findings to five industry experts who confirmed the involvement of Cold River in the attempted nuclear labs hacks, based on shared digital fingerprints that researchers have historically tied to the group.

The US National Security Agency (NSA) declined to comment on Cold River’s activities. Britain’s Global Communications Headquarters (GCHQ), its NSA equivalent, did not comment. The foreign office declined to comment.


‘Intelligence collection’


In May, Cold River broke into and leaked emails belonging to the former head of Britain’s MI6 spy service. That was just one of several ‘hack and leak’ operations last year by Russia-linked hackers in which confidential communications were made public in Britain, Poland and Latvia, according to cybersecurity experts and Eastern European security officials.

In another recent espionage operation targeting critics of Moscow, Cold River registered domain names designed to imitate at least three European NGOs investigating war crimes, according to French cybersecurity firm SEKOIA.IO.

The NGO-related hacking attempts occurred just before and after the October 18 launch of a report by a UN independent commission of enquiry that found Russian forces were responsible for the “vast majority” of human rights violations in the early weeks of the Ukraine war, which Russia has called a “special military operation.”

In a blog post, SEKOIA.IO said that, based on its targeting of the NGOs, Cold River was seeking to contribute to “Russian intelligence collection about identified war crime-related evidence and/or international justice procedures.” Reuters was unable independently to confirm why Cold River targeted the NGOs.

The Commission for International Justice and Accountability (CIJA), a nonprofit founded by a veteran war crimes investigator, said it had been repeatedly targeted by Russian-backed hackers in the past eight years without success. The other two NGOs, the International Center of Nonviolent Conflict and the Center for Humanitarian Dialogue, did not respond to requests for comment.

Russia’s embassy in Washington did not return a request seeking comment about the attempted hack against CIJA.

Cold River has employed tactics such as tricking people into entering their usernames and passwords on fake websites to gain access to their computer systems, security researchers told Reuters. To do this, Cold River has used a variety of email accounts to register domain names such as “goo-link online” and “online365-office com” which at a glance look similar to legitimate services operated by firms like Google and Microsoft, the security researchers said.


Deep ties to Russia


Cold River made several missteps in recent years that allowed cybersecurity analysts to pinpoint the exact location and identity of one of its members, providing the clearest indication yet of the group’s Russian origin, according to experts from Internet giant Google, British defense contractor BAE, and US intelligence firm Nisos.

Multiple personal email addresses used to set up Cold River missions belong to Andrey Korinets, a 35-year-old IT worker and bodybuilder in Syktyvkar, about 1,600 kilometers (1,000 miles) northeast of Moscow. Usage of these accounts left a trail of digital evidence from different hacks back to Korinets’ online life, including social media accounts and personal websites.

Billy Leonard, a Security Engineer on Google’s Threat Analysis Group who investigates nation state hacking, said Korinets was involved. “Google has tied this individual to the Russian hacking group Cold River and their early operations,” he said.

Vincas Ciziunas, a security researcher at Nisos who also connected Korinets’ email addresses to Cold River activity, said the IT worker appeared to be a “central figure” in the Syktyvkar hacking community, historically. Ciziunas discovered a series of Russian language internet forums, including an eZine, where Korinets had discussed hacking, and shared those posts with Reuters.

Korinets confirmed that he owned the relevant email accounts in an interview with Reuters but he denied any knowledge of Cold River. He said his only experience with hacking came years ago when he was fined by a Russian court over a computer crime committed during a business dispute with a former customer.

Reuters was able separately to confirm Korinets’ links to Cold River by using data compiled through cybersecurity research platforms Constella Intelligence and DomainTools, which help identify the owners of websites: the data showed that Korinets’ email addresses registered numerous websites used in Cold River hacking campaigns between 2015 and 2020.

It is unclear whether Korinets has been involved in hacking operations since 2020. He offered no explanation of why these email addresses were used and did not respond to further phone calls and emailed questions.

AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Comments

Brad 153 days ago
Al Qaeda 100% Pentagon Run: Michael Springman US Government Gives Terrorists Passport's
The US federal government is now, and has been, using Al Qaeda inside Syria in its years-long effort to overthrow the Syrian government.  So if Al Qaeda does, in fact, carry out another attack here inside the United States, we can thank our own federal government for making it possible.
The US government used the CIA to overthrow Ukraine in 2014 installed (Petro Poroshenko)

Then installed Zelensky a known actor/comedian on record.

The CIA is running this operation against the BRICS system but also to put NATO military bases along Thr Russian border.

For centuries, it has been at the center of a tug-of-war between powers seeking to control its rich lands and access to the Black Sea.
 Western

media will claim it's a people’s revolution, it was in fact a coup d’état scripted and staged by NGO (George Soros ) the U.S. State Department.

They’re linked to the CIA…CIA interests are not America’s interests, they never have been. The CIA has been morally corrupt since the beginning.”

Days after Russia invaded Ukraine in February, Stone condemned the “hysteria of the Western media” and called for a sober analysis of the geopolitical situation from all sides.

Watch: Oliver Stone’s Bombshell Ukraine On Fire 🔥
Brad 153 days ago
A 70-Year War on ‘Propaganda’ Built by the CIA
Udo Ulfkotte says all media controlled by the CIA: A 70-Year War on ‘Propaganda’ Built by the CIA

Western Journalists for Hire: How the CIA Buys News

CIA Buys News” Ulfkotte goes over how the CIA along with German Intelligence (BND) were guilty of bribing journalists to write articles that either spun the truth or were completely fictitious in order to promote a pro-western, pro-NATO bent, and that he was one of those bought journalists.

Ulfkotte finally built up the nerve to publish the book, in response to the erupting crisis in Ukraine stating

Ulfkotte has publicly stated:

I am deeply worried about the Ukrainian crisis and the possible devastating consequences for all of Europe and all of us…I am not at all pro-Russia, but it is clear that many journalists blindly follow and publish whatever the NATO press office provides. And this type of information and reports are completely one-sided”.

“I am ashamed of it. The people I worked for knew from the get-go everything I did. And the truth must come out. It’s not just about FAZ, this is the whole system that’s corrupt all the way.”

Udo Ulfkotte has since passed away. He died January 2017, found dead in his home, it is said by a heart attack. His body was quickly after cremated and thus prevented any possibility of an autopsy occurring.

In another interview Ulfkotte stated:

The articles appeared under my name several times, but they were not my intellectual product. I was once approached by someone from German Intelligence and the CIA, who told me that I should write about Gaddafi and report how he was trying to secretly build a chemical weapons factory in Libya. I had no information on any of this, but they showed me various documents, I just had to put my name on the article. Do you think this can be called journalism? I don’t think so.”

Newsletter

Related Articles

PanaTimes
Close
0:00
0:00
US and European Intelligence Agencies Uncover Evidence of Ukrainian Role in Terror Attack on Nord Stream Pipeline
Nvidia Joins Tech Giants as First Chipmaker to Reach $1 Trillion Valuation
Drone Attack on Moscow's Wealthiest Neighborhoods Suspected to be Launched by Ukraine
UK Prime Minister Rishi Sunak to Hold Power Talks with President Biden in Washington
AI ‘extinction’ should be same priority as nuclear war – experts
Prominent Hacker Forum RaidForums Suffers Substantial Data Breach
Nvidia CEO Huang says firms, individuals without AI expertise will be left behind
WPP Revolutionizes Advertising with NVIDIA's AI Powerhouse
Two US Employees Fired For Chasing Robbers Out Of Store As They Broke ''Company Policy''
If you donated to BLM, you got played
Pfizer, the EU, and disappearing ink - Smoke, Mirrors, and the Billion-Dose Pfizer Vaccine Deal: EU's 'Open Secret
Actor Tom Hanks told Harvard University graduates to be superheroes in their defense of truth and American ideals, and to resist those who twist the truth for their own gain
The Sussexes' Royal Rebound: Could Harry and Meghan Markle Return to the UK?
A provocative study suggests: Left-Wing Extremism and its Unsettling Connection to Psychopathy and Narcissism
France Arrests 10 on Suspicion of Failing to Respond in Time to Migrant Drowning
Neuralink Receives FDA Approval for First-in-Human Clinical Study
Saudi Arabia and Canada Restore Diplomatic Relations
Bernard Arnault Loses $11.2 Billion in One Day as Investors Fear Slowdown in US Growth Will Reduce Demand for Luxury Products
Russian’s Wagner Group leader: “I am not a chef, I am a butcher. Russia is in danger of a revolution like in 1917.”
TikTok Sues Montana Over Law Banning the App
Ron DeSantis Jumps Into 2024 Presidential Race, Setting Up Showdown With Trump
Last Walmart in North Portland Closing Down
Florida's DeSantis seeks to disqualify judge in Disney case
Talks between US House Republicans and President Biden's Democratic administration on raising the federal government's $31.4tn debt ceiling have paused
Disney has canceled plans to build a new campus in Florida worth almost $1 billion
Biden Administration Eyeing High-Profile Visits to China: The Biden Administration is heating things up by looking into setting up a series of top-level visits to Beijing by top officials in the coming months
New evidence in special counsel probe may undercut Trump’s claim documents he took were automatically declassified
A French court of appeals confirmed former President Nicolas Sarkozy's three-year jail term for corruption and influence peddling
Debt Ceiling Crises Have Unleashed Political Chaos
Weibao Wang, a former software engineer at Apple, was charged with stealing trade secrets related to autonomous systems, including self-driving cars
Mobile phone giant Vodafone to cut 11,000 jobs globally over three years as new boss says its performance not good enough
Elon Musk compares George Soros to Magneto, the supervillain from the Marvel Comics series.
Warren Buffett Sells TSMC Shares Over Concerns About Taiwan's Stability
New Study Finds That Secondary Bacterial Pneumonia Is a Major Cause of Death in COVID-19 Patients Who Require Ventilator Assistance
King Charles III being crowned.
'Godfather Of AI' Geoffrey Hinton Quits Google To Warn Of The Tech's Dangers
A Real woman
Vermont Man Charged with Stalking After Secretly Tracking Woman with Apple AirTag
Elon Musk Statements About Tesla Autopilot Could Be 'Deepfakes,' Lawyers Claim. Judge Evette Pennypacker Does Not Understand How Far and Advanced This Technology Became
Ukraine More Prepared for Counterattack as Reinforcements Arrive
UK Prime Minister Rishi Sunak and Italian Prime Minister Giorgia Meloni Discuss Migration, Defence, and Ukraine
Tucker Carlson is back, soon!
AT&T's Successful Test of Satellite-Based Phone Call Raises Possibility of Widespread Coverage
CNN: "Joe Biden is asking for four more years — when 74% of Americans think the country is heading the wrong way“
Turkish President Recep Tayyip Erdogan Cuts Short Live TV Interview Due to Health Issue
US Congresswoman threaten Twitter Files journalist with arrest
Pulitzer Prize-winning journalist Seymour Hersh slams New York Times' pro-government stance and treatment of sources
Enough is enough: it's time to end the war in Ukraine. While Russia may be to blame for starting it, Russia is not the one refusing to stop it
Fox News Settles their case with Dominion Voting Systems for a staggering $787.5 MILLION
The land of the free violence
×