France’s cybersecurity agency ANSSI has issued an alert outlining a Russian spear phishing campaign targeting French diplomats, the Record reports.
The agency attributes the campaign to “Nobelium,” a threat actor tied to Russia’s Foreign Intelligence Service (the SVR).
“Most of Nobelium campaigns against diplomatic entities use compromised legitimate email accounts belonging to diplomatic staff and conduct phishing campaigns against diplomatic institutions, embassies, and consulates,” ANSSI’s advisory says.
“These activities are also publicly described as a campaign called “Diplomatic Orbiter”. The lure documents used in these attacks are typically forged to target diplomatic staff. The operators attempt to deliver their own private loaders, in order to execute public tools such as Cobalt Strike or Brute Ratel C4, to access the victim’s network, ensure persistence, and exfiltrate valuable intelligence. However, several IT companies have also reported that they have been targeted by Nobelium’s operators in late 2023 and 2024.”
ANSSI says Nobelium has been targeting French diplomatic entities and embassies for espionage purposes over the past several years. The threat actor uses convincingly crafted phishing documents tailored to deceive specific individuals.
“ANSSI and C4 members consider that the imputation of these activities against French diplomatic entities to Nobelium is consistent,” the agency says. “The tools and infrastructures employed by the attackers show similarities with other Nobelium-linked campaigns.
The victims of these activities aiming to exfiltrate strategic intelligence are consistent with the usual targeting associated with Nobelium by other observers. The capabilities implemented to compromise such a vast number of email accounts, the persistence of the attacks, the efforts put into the forgery of lure documents indicate that Nobelium is almost certainly operated on behalf of a state actor.”
New-school security awareness training can give your organization an essential layer of defense against these attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
The Record has the story.