Site navigation

NCSC Warns Fancy Bear Malware Hijacking Email Accounts

Tom Quinn

,

Russia malware attack
“The Kremlin should be in no doubt: we see what they are trying to do in the shadows and we won’t tolerate it,” said the foreign secretary, David Lammy.

The UK’s National Cyber Security Centre (NCSC) has revealed that hacking groups linked to Russian military intelligence are behind the use of sophisticated malware that steals victims’ login details and tokens to allow attackers long-term access to email accounts. 

The previously unknown malicious software, dubbed AUTHENTIC ANTICS, has been attributed to the cyber threat group APT 28, otherwise known by Fancy Bear, Forest Blizard and Blue Delta, with UK intelligence placing the group as part of Russia’s GRU 85th Main Special Service Centre, Military Unit 26165.

NCSC analysis of AUTHENTIC ANTICS shows it has been specifically designed to allow persistent endpoint access to Microsoft cloud accounts by blending in with legitimate activity. 

It first displays a login window prompting the user to share their credentials which are then intercepted by the malware, along with OAuth authentication tokens allowing access to Microsoft services.

The NCSC said that the malware can exfiltrate data by sending emails from the victim’s account to an actor-controlled email address, but without the emails showing in the ‘sent’ folder.  

“The use of AUTHENTIC ANTICS malware demonstrates the persistence and sophistication of the cyber threat posed by Russia’s GRU,” said Paul Chichester, NCSC director of operations.

“NCSC investigations of GRU activities over many years show that network defenders should not take this threat for granted and that monitoring and protective action is essential for defending systems.”

The warning marks the second time this year that the NCSC have exposed a malicious cyber offensive by Russian intelligence.

In May, the UK and its allies revealed that Fancy Bear had been discovered carrying out a malicious campaign targeting Western organisations, particularly those supporting Ukraine, which included activity like credential guessing, spear-phishing and exploiting Microsoft Exchange mailbox permissions.

The NCSC said that Russia’s GRU has been targeting both public and private organisations with these tactics since at least 2022, with AUTHENTIC ANTICS in particular first discovered in the aftermath of an incident investigated by Microsoft and NCC Group in 2023.

The attribution of AUTHENTIC ANTICS comes alongside fresh UK Government sanctions against three other GRU Units, 26165, 29155 and 74455, as well as eighteen GRU officers and agents for their part in cyber operations across the globe.


Recommended reading


The UK has exposed Unit 29155 for carrying out digital sabotage attacks, while Unit 74455, also known as Sandworm, has been found using the Cyclops Blink malware and attempted an attack on the Organisation for the Prohibition of Chemical Weapons in 2018.

“The Kremlin should be in no doubt: we see what they are trying to do in the shadows and we won’t tolerate it,” said the foreign secretary, David Lammy.

“That’s why we’re taking decisive action with sanctions against Russian spies. Putin’s hybrid threats and aggression will never break our resolve. The UK and our allies’ support for Ukraine and Europe’s security is ironclad.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data