{"id":30878,"date":"2023-08-10T09:30:27","date_gmt":"2023-08-10T09:30:27","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/08\/10\/belarus-hackers-target-foreign-diplomats-with-help-of-local-isps-researchers-say-techcrunch\/"},"modified":"2023-08-10T09:30:27","modified_gmt":"2023-08-10T09:30:27","slug":"belarus-hackers-target-foreign-diplomats-with-help-of-local-isps-researchers-say-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/08\/10\/belarus-hackers-target-foreign-diplomats-with-help-of-local-isps-researchers-say-techcrunch\/","title":{"rendered":"Belarus hackers target foreign diplomats with help of local ISPs, researchers say | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\">Hackers with apparent links to the Belarusian government have been targeting foreign diplomats in the country for nearly 10 years, according to security researchers.<\/p>\n<p>On Thursday, antivirus firm ESET <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus\/\" target=\"_blank\" rel=\"noopener\">published a report<\/a> that details the activities of a newly discovered government hacking group that the company has dubbed MoustachedBouncer. The group has likely been hacking or at least targeting diplomats by intercepting their connections at the internet service provider (ISP) level, suggesting close collaboration with Belarus\u2019 government, according to ESET.<\/p>\n<p>Since 2014, MoustachedBouncer has targeted at least four foreign embassies in Belarus: two European nations, one from South Asia, and another from Africa.<\/p>\n<p>\u201cThe operators were trained to find some confidential documents, but we\u2019re not sure exactly what they were looking for,\u201d ESET researcher Matthieu Faou told TechCrunch in an interview ahead of his talk at the <a href=\"https:\/\/techcrunch.com\/tag\/black-hat-2023\/\" target=\"_blank\" rel=\"noopener\">Black Hat cybersecurity conference<\/a> in Las Vegas. \u201cThey are operating only inside Belarus against foreign diplomats. So we have never seen any attack by MustachedBouncer outside of Belarus.\u201d<\/p>\n<p>ESET said it first detected MoustachedBouncer in February 2022, days after Russia invaded Ukraine, with a cyberattack against specific diplomats in the embassy of a European country \u201csomehow involved in the war,\u201d Faou said, declining to name the country.<\/p>\n<p>By tampering with network traffic, the hacking group is able to trick the target\u2019s Windows operating system into believing it\u2019s connected to a network with a captive portal. The target is then redirected to a fake and malicious site masquerading as Windows Update, which warns the target that there are \u201ccritical system security updates that must be installed,\u201d according to the report.<\/p>\n<p>It\u2019s not clear how MoustachedBouncer can intercept and modify traffic \u2014 a technique known as an adversary-in-the-middle, or <a href=\"https:\/\/attack.mitre.org\/techniques\/T1557\/\" target=\"_blank\" rel=\"noopener\">AitM<\/a> \u2014 but ESET researchers believe it\u2019s because Belarusian ISPs are collaborating with the attacks, allowing the hackers to use a lawful intercept system similar to the one Russia deploys, known as <a href=\"https:\/\/techcrunch.com\/2019\/09\/18\/russia-sorm-nokia-surveillance\/\" target=\"_blank\" rel=\"noopener\">SORM<\/a>.<\/p>\n<p>The existence of this surveillance system has been known for years. In Belarus, all telecom providers \u201cmust make their hardware compatible with the SORM system,\u201d <a href=\"https:\/\/www.amnesty.at\/media\/1119\/amnesty-surveillance-in-belarus.pdf\" target=\"_blank\" rel=\"noopener\">according to a 2016 Amnesty International report<\/a>.<\/p>\n<p>Once ESET researchers found the attack last February and analyzed the malware used, they were able to discover other attacks \u2014 the oldest dating back to 2014\u00a0\u2014 although there is no trace of them between 2014 and 2018, according to Faou.<\/p>\n<p>\u201cThey stayed under the radar for a long time. And so it means that they\u2019re quite successful if they were able to compromise high profile targets such as diplomats, while no one really spoke about them, and there have been very few malware samples available for analysis,\u201d he said. \u201cIt shows that they\u2019re quite careful when doing the operations.\u201d<\/p>\n<hr\/>\n<p><em>Do you have information about this hacking group? Or other advanced persistent threats (APTs)? We\u2019d love to hear from you. From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com. You also can contact TechCrunch via <a href=\"https:\/\/techcrunch.com\/tips\" target=\"_blank\" rel=\"noopener\">SecureDrop<\/a>.<\/em><\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2023\/08\/10\/belarus-hackers-target-foreign-diplomats\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers with apparent links to the Belarusian government have been targeting foreign diplomats in the country for nearly 10 years, according to security researchers. On Thursday, antivirus firm ESET published a report that details the activities of a newly discovered government hacking group that the company has dubbed MoustachedBouncer. The group has likely been hacking [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":30879,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-30878","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/30878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=30878"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/30878\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/30879"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=30878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=30878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=30878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}