• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Positive Technologies detects a series of cyberattacks against government organisations in Russia and the CIS

by CXO Staff
April 4, 2024
in Government, Industries, News

Positive Technologies Expert Security Center (PT ESC) discovered a new cybergroup called Lazy Koala

Positive Technologies detects a series of cyberattacks against government organisations in Russia and the CIS

Positive Technologies Expert Security Center (PT ESC) discovered a new cybergroup called Lazy Koala. Experts confirm that the criminals use simple but effective attack techniques. Victims of the group include organizations from Russia and six CIS countries, with approximately 867 employee accounts compromised to date.

As part of the threat research, PT ESC specialists discovered a series of attacks aimed at organizations in Russia, Belarus, Kazakhstan, Uzbekistan, Kyrgyzstan, Tajikistan, and Armenia. Government and financial organizations, as well as medical and educational institutions, were the main targets. Positive Technologies specialists notified affected organizations that they were compromised.

Research shows that the attackers’ main goal was to steal accounts to various services from government organization employee computers. The next step was likely use this information in further attacks on the internal structures of the organizations. Stolen data can also be sold on the dark web cyber services market.

Behind the attacks is a previously unknown group that experts have dubbed Lazy Koala because of its basic techniques and the username. Koala of the person managing the Telegram bots with stolen data. Researchers were unable to establish connections with already known groups using the same techniques.

“The calling card of the new group is this: ‘harder doesn’t mean better.’ Lazy Koala doesn’t bother with complex tools, tactics, and techniques, but they still get the job done. Their main weapon is a primitive password stealer malware that we assume is distributed using basic phishing. The scammers convince victims to open an attachment and launch the file in the browser. For each country, the attachment is even in the local language. After establishing itself on the infected device, the malware exfiltrates the stolen data using Telegram, a favorite tool among attackers,” shares Denis Kuvshinov, Head of Threat Analysis, Positive Technologies Expert Security Center. “We notified the victims and believe that the fate of the stolen data is resale and use in subsequent attacks on the internal structures of organizations.”

Phishing remains one of the main ways for attackers to penetrate infrastructure. Users are advised not to open suspicious messages or follow unknown links. Don’t download software from suspicious sites and torrents; instead, use licensed versions from trusted sources. Employees should be kept informed of all the latest phishing techniques and scams.

These attacks can be detected using specialized security tools, while attack analysis and prevention should involve cyber incident investigation professionals.

MaxPatrol SIEM can detect the key event of data theft with the Credential_Access_to_Passwords_Storage rule, and the previous stages (phishing and data transfer) using the Run_Masquerading_Executable_File and Suspicious_Connection rules. The PT NAD network traffic behavioral analysis system helps detect calls to the Telegram API using the “tls.server_name == “api.telegram.org”” filter and set convenient notifications about them. If a new host starts accessing the Telegram API, PT NAD will send a notification to the SOC operator. PT Sandbox detects the actions of this APT group using a rule written specifically for them: a behavioral analysis verdict of Trojan-PSW.Win32.LazyStealer.n. Similar attacks can also be detected using endpoint protection systems such as MaxPatrol EDR.

Tags: Positive Technologies
ShareTweet

Related Posts

GEMS Education partners with UAE fintech Leap
Business

GEMS Education partners with UAE fintech Leap

February 19, 2026

GEMS Education has partnered with UAE fintech platform Leap to introduce a co-branded financial literacy experience designed exclusively for GEMS...

Alpha Data highlights the strategic role of cybersecurity as a business enabler
Business

Alpha Data highlights the strategic role of cybersecurity as a business enabler

February 19, 2026

In an industry dialogue hosted by emt, a QBS Technology Group company, Alpha Data shared insights on how cybersecurity in...

Discussion about this post

Latest Issue

Oracle NetSuite on the next phase for AI in ERP

Oracle NetSuite on the next phase for AI in ERP

February 20, 2026
ServiceNow’s Cathy Mauzaize: Why AI governance is a leadership imperative

ServiceNow’s Cathy Mauzaize: Why AI governance is a leadership imperative

February 20, 2026
AI risk in GCC companies: What enterprises can’t see can hurt them

AI risk in GCC companies: What enterprises can’t see can hurt them

February 20, 2026

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX x AI Everything
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.