SnowyAmber Malware Leveraged by Russian Cyberspies To Attack NATO & EU Organizations

ruransom target russian users

In recent cybersecurity news sources, it was reported that Russian cyberspies had launched a new malware toolset, which they used to target NATO and European Union (EU) organizations. The malware toolset has been found to be a highly sophisticated and stealthy malware, capable of evading detection by traditional antivirus software.

According to the report, the MontysThree malware toolset may be the culprit and has been in use since at least 2018, with the primary targets being NATO and EU organizations. The attackers are said to have used a variety of tactics, including spear-phishing emails and watering hole attacks, to gain access to their target networks. Additionally, the payload was found to be the SNOWYAMBER malware threat, which was reported and found in October 2022.

What Does SNOWYAMBER Do?

Once inside the target network, the SNOWYAMBER malware can perform a wide range of malicious activities, including stealing sensitive data, monitoring network traffic, and even executing additional malware payloads. The malware has been found to be highly adaptable, with the attackers using different techniques and payloads depending on the specific target.

The report also notes that the attackers behind the MontysThree malware toolset are likely to be state-sponsored, given the level of sophistication and resources required to develop and maintain such a toolset. While the exact motives of the attackers are not clear, it is believed that the primary goal is to gather intelligence and steal sensitive data utilizing tools like SNOWYAMBER.

Overall, the discovery of the SNOWYAMBER malware threat highlights the ongoing targeting posed by state-sponsored cyber-espionage. As the attackers continue to develop increasingly sophisticated and stealthy malware toolsets, it is essential for organizations to remain vigilant and take proactive steps to protect their networks and sensitive data.

Computer users must also beware of the SNOWYAMBER malware threat as it could be leveraged in a way to hit a system and have its malicious instructions downloaded from a command-and-control server. There is also some relation to the APT29 group that was known to be rooted out of Russia and has associations with the groups going by the names of Cozy Bear, Cozy Duke, Dukes, and Office Monkeys.

April 14, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.