Microsoft Shuts Down Domains Associated with Attacks on Ukraine

ukraine digital computer

Microsoft published a recent blog post, informing of the actions the company has taken to disrupt the activity of a "Russian nation-state actor" that was targeting entities in Ukraine.

The blog post specifically pegs the threat actor in question as the entity that Microsoft calls "Strontium". The same threat actor is known by a number of other names, used by different infosec experts and organizations.

Strontium and its many faces

Whether they are called Strontium, Fancy Bear, or Sofacy, and perhaps best known as APT28, the active persistent threat actor in question had some of its infrastructure taken down following Microsoft's efforts.

The tech giant was able to do this by first obtaining a court order, allowing Microsoft to take complete control over seven different domains. According to the blog post, the threat actors at Strontium were using those domains to launch cyberattacks on Ukrainian entities.

In addition to the attacks on Ukrainian targets, Microsoft stated Strontium was also using the domains for attacks on "government institutions and think tanks" both in the US and in the European Union. According to Microsoft, the purpose of the threat actor was to gain a low-profile, persistent foothold inside those entities and perform long-term espionage, in order to support the Russian military campaign inside Ukraine.

Microsoft fighting Strontium since 2016

This is the latest wave in a long line of similar activities undertaken by Microsoft. According to the post, the campaign to counter Strontium's activity started as early as 2016 and this latest takedown that affected seven domains was the fifteenth time something like this was taking place.

The domains taken over in this latest push by Microsoft were redirected to a sinkhole controlled and operated by Microsoft, allowing them to neutralize any malicious activity the domains were used for.

The war in Ukraine was accompanied by several waves of cyberattacks targeting various institutions and systems located in Ukraine with different strains of destructive malware.

April 14, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.