• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Positive Technologies detects a series of cyberattacks against government organisations in Russia and the CIS

by CXO Staff
April 4, 2024
in Government, Industries, News

Positive Technologies Expert Security Center (PT ESC) discovered a new cybergroup called Lazy Koala

Positive Technologies detects a series of cyberattacks against government organisations in Russia and the CIS

Positive Technologies Expert Security Center (PT ESC) discovered a new cybergroup called Lazy Koala. Experts confirm that the criminals use simple but effective attack techniques. Victims of the group include organizations from Russia and six CIS countries, with approximately 867 employee accounts compromised to date.

As part of the threat research, PT ESC specialists discovered a series of attacks aimed at organizations in Russia, Belarus, Kazakhstan, Uzbekistan, Kyrgyzstan, Tajikistan, and Armenia. Government and financial organizations, as well as medical and educational institutions, were the main targets. Positive Technologies specialists notified affected organizations that they were compromised.

Research shows that the attackers’ main goal was to steal accounts to various services from government organization employee computers. The next step was likely use this information in further attacks on the internal structures of the organizations. Stolen data can also be sold on the dark web cyber services market.

Behind the attacks is a previously unknown group that experts have dubbed Lazy Koala because of its basic techniques and the username. Koala of the person managing the Telegram bots with stolen data. Researchers were unable to establish connections with already known groups using the same techniques.

“The calling card of the new group is this: ‘harder doesn’t mean better.’ Lazy Koala doesn’t bother with complex tools, tactics, and techniques, but they still get the job done. Their main weapon is a primitive password stealer malware that we assume is distributed using basic phishing. The scammers convince victims to open an attachment and launch the file in the browser. For each country, the attachment is even in the local language. After establishing itself on the infected device, the malware exfiltrates the stolen data using Telegram, a favorite tool among attackers,” shares Denis Kuvshinov, Head of Threat Analysis, Positive Technologies Expert Security Center. “We notified the victims and believe that the fate of the stolen data is resale and use in subsequent attacks on the internal structures of organizations.”

Phishing remains one of the main ways for attackers to penetrate infrastructure. Users are advised not to open suspicious messages or follow unknown links. Don’t download software from suspicious sites and torrents; instead, use licensed versions from trusted sources. Employees should be kept informed of all the latest phishing techniques and scams.

These attacks can be detected using specialized security tools, while attack analysis and prevention should involve cyber incident investigation professionals.

MaxPatrol SIEM can detect the key event of data theft with the Credential_Access_to_Passwords_Storage rule, and the previous stages (phishing and data transfer) using the Run_Masquerading_Executable_File and Suspicious_Connection rules. The PT NAD network traffic behavioral analysis system helps detect calls to the Telegram API using the “tls.server_name == “api.telegram.org”” filter and set convenient notifications about them. If a new host starts accessing the Telegram API, PT NAD will send a notification to the SOC operator. PT Sandbox detects the actions of this APT group using a rule written specifically for them: a behavioral analysis verdict of Trojan-PSW.Win32.LazyStealer.n. Similar attacks can also be detected using endpoint protection systems such as MaxPatrol EDR.

Tags: Positive Technologies
ShareTweet

Related Posts

NVIDIA RTX 5090 and 5080 out now and NVIDIA app updates released
Future

DLSS 4 with multi frame generation is multiplying performance in Dragonkin

This week, DLSS 4 with Multi Frame Generation is multiplying performance in Dragonkin: The Banished, Marvel's Spider-Man 2, Mecha BREAK,...

June 11, 2025
IBM sets path to scalable Quantum Computing
Future

IBM sets path to scalable Quantum Computing

IBM unveiled its path to build the world’s first large-scale, fault-tolerant quantum computer, setting the stage for practical and scalable...

June 11, 2025

Discussion about this post

Latest Issue

Dell Technologies’ Mohammed Amin on ‘unleashing AI’ and powering human progress

Dell Technologies’ Mohammed Amin on ‘unleashing AI’ and powering human progress

June 11, 2025
NVIDIA RTX 5090 and 5080 out now and NVIDIA app updates released

DLSS 4 with multi frame generation is multiplying performance in Dragonkin

June 11, 2025
Axis introduces next-gen AI-powered dome cameras

Axis introduces next-gen AI-powered dome cameras

June 11, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2024 - CXO Insight Middle East. All Rights Reserved.