None
EN
Laundry Bear’s webmail hackers had more in store after February, report says
[]
The Record from Recorded Future News
Researchers say the Russian state-linked hacking group tracked as Laundry Bear has been more active in recent months than originally thought.
Laundry Bear targeted “US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors,” the researchers said.
Laundry Bear compromised accounts with “half-click” exploits, meaning that simply opening an email was enough to begin the infection chain, Proofpoint said.
Laundry Bear, also tracked as TA488 and Void Blizzard, started laying the groundwork for the OWAReaper campaign in March, Proofpoint said.
Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year.