Russian Threat Actor Launches Spear Phishing Attacks Against French Diplomats

Stu Sjouwerman | Jun 27, 2024

Spear Phishing Bigger ProblemFrance’s cybersecurity agency ANSSI has issued an alert outlining a Russian spear phishing campaign targeting French diplomats, the Record reports.

The agency attributes the campaign to “Nobelium,” a threat actor tied to Russia’s Foreign Intelligence Service (the SVR).

“Most of Nobelium campaigns against diplomatic entities use compromised legitimate email accounts belonging to diplomatic staff and conduct phishing campaigns against diplomatic institutions, embassies, and consulates,” ANSSI’s advisory says.

“These activities are also publicly described as a campaign called “Diplomatic Orbiter”. The lure documents used in these attacks are typically forged to target diplomatic staff. The operators attempt to deliver their own private loaders, in order to execute public tools such as Cobalt Strike or Brute Ratel C4, to access the victim’s network, ensure persistence, and exfiltrate valuable intelligence. However, several IT companies have also reported that they have been targeted by Nobelium’s operators in late 2023 and 2024.”

ANSSI says Nobelium has been targeting French diplomatic entities and embassies for espionage purposes over the past several years. The threat actor uses convincingly crafted phishing documents tailored to deceive specific individuals.

“ANSSI and C4 members consider that the imputation of these activities against French diplomatic entities to Nobelium is consistent,” the agency says. “The tools and infrastructures employed by the attackers show similarities with other Nobelium-linked campaigns.

The victims of these activities aiming to exfiltrate strategic intelligence are consistent with the usual targeting associated with Nobelium by other observers. The capabilities implemented to compromise such a vast number of email accounts, the persistence of the attacks, the efforts put into the forgery of lure documents indicate that Nobelium is almost certainly operated on behalf of a state actor.”

New-school security awareness training can give your organization an essential layer of defense against these attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

The Record has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.