The US Department of State has announced a $10 million bounty for information on three Russian Federal Security Service (FSB) officers accused of conducting malicious cyber activities against U.S. critical infrastructure organizations on behalf of the Russian government.

Background and Context

The three individuals, Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov, are part of the FSB's Center 16 or Military Unit 71330, which is tracked as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, and Koala Team.

In March 2022, the three FBS officers were also charged for their involvement in a campaign that took place between 2012 and 2017, targeting U.S. government agencies, including the Nuclear Regulatory Commission, as well as energy companies like Wolf Creek Nuclear Operating Corporation, which operates a nuclear power plant in Burlington, Kansas.

What Happened

The threat actors have been conducting phishing campaigns targeting commercial messaging applications (CMAs), posing as automated CMA support accounts to lure victims into clicking on a link or sharing verification codes to take over their accounts on messaging platforms such as Signal and WhatsApp.

In a fresh update, the US government warns that the attackers have renewed their tactics and are now asking victims for their Backup Recovery Keys to access historical conversations, including private and group messages. If a victim inadvertently shares their Backup Recovery Key, it remains valid even if they create a new account following the compromise using the same phone number.

Why It Matters

The US government's announcement of a $10 million bounty for information on Russian FSB hackers highlights the growing concern over state-sponsored cyber attacks targeting critical infrastructure organizations. The use of phishing campaigns and exploitation of vulnerabilities in commercial messaging applications is a concerning trend that requires attention from industry professionals.

For adult-industry platforms and operators, this news serves as a reminder of the importance of robust cybersecurity measures to protect against such threats. The use of secure communication channels, regular software updates, and employee education on phishing tactics can help mitigate the risk of successful attacks.

What Comes Next

The US government is seeking information on the threat actors' affiliation with RIS, entities that support them, their infrastructure and tooling, their funding sources, and financial networks, including banking accounts, cryptocurrency wallets, and transactions. The $10 million bounty is a significant incentive for individuals to come forward with information that can help disrupt these malicious activities.

Key Facts

  • The US Department of State has announced a $10 million bounty for information on three Russian FSB officers accused of conducting malicious cyber activities against U.S. critical infrastructure organizations.
  • The three individuals, Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov, are part of the FSB's Center 16 or Military Unit 71330.
  • The threat actors have been conducting phishing campaigns targeting commercial messaging applications (CMAs).
  • The attackers have renewed their tactics and are now asking victims for their Backup Recovery Keys to access historical conversations.
  • The US government is seeking information on the threat actors' affiliation with RIS, entities that support them, their infrastructure and tooling, their funding sources, and financial networks.