Microsoft using lawyers to tackle top Russian hacking group

Microsoft has used the lawsuit to wrest control of 70 different command-and-control points

Microsoft
Photo: Shutterstock
IANS San Francisco
Last Updated : Jul 25 2017 | 2:52 AM IST

US Tech giant Microsoft is going after a Russian hacking group believed to be connected to the country's intelligence agency GRU and behind several high-profile cyber attacks including on the NATO and the Hillary Clinton campaign.

According to a report in The Daily Beast late on Friday, Microsoft was using lawyers to take on the hacker group known as Fancy Bear -- accusing it of computer intrusion, cybersquatting and infringing on Microsoft's trademarks.

"The action, though, is not about dragging the hackers into court. The lawsuit is a tool for Microsoft to target what it calls 'the most vulnerable point' in Fancy Bear's espionage operations: the command-and-control servers the hackers use to covertly direct malware on victim computers," the report added.

So far, Microsoft has used the lawsuit to wrest control of 70 different command-and-control points from Fancy Bear.

Microsoft has "identified over 120 new targets of the Kremlin's cyber spying and control-alt-deleting segments of Russian President Vladimir Putin's hacking apparatus, the report added.

Microsoft's approach is indirect, but effective, it said.

"Rather than getting physical custody of the servers, which Fancy Bear rents from data centres around the world, Microsoft has been taking over the Internet domain names that route to them," the report noted.

These are addresses like "livemicrosoft[.]net" or "rsshotmail[.]com" that Fancy Bear registers for about $10 each.

"Once under Microsoft's control, the domains get redirected from Russia's servers to the company's, cutting off the hackers from their victims, and giving Microsoft a omniscient view of that servers' network of automated spies, the report said.

A judge in Alexandria, Virginia is scheduled to rule whether to grant Microsoft a permanent injunction against Fancy Bear.

Fancy Bear, also known as 'APT28', 'Sofacy', 'Pawn Storm' and 'Strontium' has been conducting cyber attacks since 2007.

According to the US intelligence findings, Fancy Bear targeted the Democratic National Committee (DNC) and the Clinton campaign as part of Moscow's efforts to help Donald Trump win the 2016 election.

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jul 25 2017 | 2:51 AM IST

Next Story