From Vietnam to Afghanistan: 30 Years of Service – We Are The Mighty
Six years ago, Dutch intelligence agents reportedly infiltrated a malicious group of hackers working out an office building not far from the Kremlin. Dutch agents hacked into a security camera that monitored people entering the Moscow building, according to the Dutch newspaper de Volkskrant; they also reportedly monitored in 2016 as the hackers broke into the servers of the U.S. Democratic Party.
The hackers came to be known as APT-29 or The Dukes, or more commonly, Cozy Bear, and have been linked to Russias security agencies. According to the report, the Dutch findings were passed onto U.S. officials, and may have been a key piece of evidence that led U.S. authorities to conclude the Kremlin was conducting offensive cyberoperations to hack U.S. political parties during the 2016 presidential campaign.
Fast forward to 2020: the Cozy Bear hackers are back though for those watching closely, they never really went anywhere.
British, American, and Canadian intelligence agencies on July 16 accused Cozy Bear hackers of using malware and so-called spear-phishing emails to deceive researchers at universities, private companies, and elsewhere.
The goal, the agencies said, was to steal research on the effort to create a vaccine for the disease caused by the new coronavirus, COVID-19.
APT-29 is likely to continue to target organizations involved in COVID-19 vaccine research and development, as they seek to answer additional intelligence questions relating to the pandemic, the British National Cyber Security Center said in a statement, released jointly with the Canadian and U.S. agencies.
Its totally unacceptable for Russian intelligence services to attack those who are fighting the coronavirus pandemic, British Foreign Secretary Dominic Raab said.
Kremlin spokesman Dmitry Peskov called the accusations unacceptable.
We can say only one thing: that Russia has nothing to do with these attempts, he told reporters.
The advisory did not name which companies or organizations had been targeted, nor did it say whether any specific data was actually stolen. The head of the British National Cyber Center said the penetrations were detected in February and that there was no sign any data had actually been stolen.
The advisory did say the hackers exploited a vulnerability within computer servers to gain initial footholds and that they had used custom malware not publicly associated with any campaigns previously attributed to the group.
Russias main intelligence agencies are believed to all have offensive cybercapabilities of one sort or another.
Cyber-researchers say Cozy Bear most likely is affiliated with Russias Foreign Intelligence Service, known as the SVR, possibly in coordination with the countrys main security agency, the Federal Security Service (FSB).
According to researchers, the groups origins date back to at least 2008 and it has targeted companies, universities, research institutes, and governments around the world.
The group is known for using sophisticated techniques of penetrating computer networks to gather intelligence to help guide Kremlin policymakers.
It is not, however, known for publicizing or leaking stolen information, something that sets it apart from a rival intelligence agency whose hacking and cyberoperations have been much more publicized in recent years the military intelligence agency known widely as the GRU.
GRU hackers, known as Fancy Bear, or APT-28, have been accused of not only hacking computer systems, but also stealing and publicizing information, with an eye toward discrediting a target. U.S. intelligence agencies have accused GRU hackers of stealing documents from U.S. Democratic Party officials in 2016, and also of leaking them to the public in the run-up to the November presidential election.
The GRU had multiple units, including Units 26165 and 74455, engaged in cyber operations that involved the staged releases of documents stolen through computer intrusions, Special Counsel Robert Mueller wrote in a July 2018 indictment that charged 12 GRU officers. These units conducted large-scale cyber operations to interfere with the 2016 U.S. presidential election.
Three months later, U.S. prosecutors in Pittsburg, Pennsylvania, issued a related Fancy Bear indictment accusing some of the same officers of conducting a four-year hacking campaign targeting international-sport anti-doping organizations, global soccers governing body, the Organization for the Prohibition of Chemical Weapons, and other groups.
A GRU officer named in the Mueller indictment has also been named by German intelligence as being behind the 2015 hack of the Bundestag.
But unlike the GRU and the Fancy Bear hackers, there has never been any public identification of specific Cozy Bear hackers or criminal indictments targeting them.
The U.S.-based cybersecurity company Crowdstrike, which was the first to publicly document the infiltration of the Democratic National Committee, said in its initial report that both the Cozy Bear and the Fancy Bear hackers had penetrated the committees network, apparently independently of each other.
Its not clear exactly what the motivation of the Cozy Bear hackers might be in targeting research organizations, though like many other nations, Russia is racing to develop a vaccine that would stop COVID-19, and stealing scientific data research might help give Russian researchers a leg up in the race.
Russia has reported more than 765,000 confirmed cases. Its official death toll, however, is unusually low, and a growing number of experts inside and outside the country say authorities are undercounting the fatalities.
In the past, Western intelligence and law enforcement have repeatedly warned of the pernicious capabilities of Russian state-sponsored hackers. In the United States, authorities have sought the arrest and extradition of dozens of Russians on various cybercharges around the world.
As in the Mueller indictments, U.S. authorities have used criminal charges to highlight the nexus between Russian government agencies and regular cybercriminals and also to signal to Russian authorities that U.S. spy agencies are watching.
For example, the Mueller indictment identified specific money transfers that the GRU allegedly made using the cryptocurrency bitcoin to buy server capacity and other tools as part of its hacking campaigns.
As of last year, those efforts had not had much effect in slowing down state-sponsored hacking, not just by Russia, but also by North Korea, Iran, China, and others.
[I]n spite of some impressive indictments against several named nation-state actors their activities show no signs of diminishing, Crowdstrike said in a 2019 threat report.
Gleb Pavlovsky, a Russian political consultant and former top Kremlin adviser, downplayed the Western allegations.
We are talking about the daily activities of all secret services, especially regarding hot topics like vaccine secrets, he told Current Time. Of course, they are all being stolen. Of course, stealing is not good, but secret services exist in order to steal.
In the U.S. Congress, some lawmakers signaled that the findings would add further momentum to new sanctions targeting Russia.
It should be clear by now that Russias hacking efforts didnt stop after the 2016 election, Mark Warner, the top Democrat on the U.S. Senate Intelligence Committee, said in a statement.
This article originally appeared on Radio Free Europe/Radio Liberty. Follow @RFERL on Twitter.
Read more:
From Vietnam to Afghanistan: 30 Years of Service - We Are The Mighty
- A future without women: Consequences of gender apartheid in Afghanistan - Global Voices - July 16th, 2025 [July 16th, 2025]
- Women This Week: Multilateral Organizations Increase Pressure on Taliban Over Oppression of Women and Girls in Afghanistan - Council on Foreign... - July 16th, 2025 [July 16th, 2025]
- Retreat from Afghanistan began as a farce, then it was a scandal, now it's a cover-up - news.sky.com - July 16th, 2025 [July 16th, 2025]
- The Islamic State in Afghanistan: A Jihadist Threat in Retreat? - International Crisis Group - July 16th, 2025 [July 16th, 2025]
- Afghan nationals: have you arrived in the UK under the Afghanistan Response Route? - The Guardian - July 16th, 2025 [July 16th, 2025]
- Teen From Afghanistan Reported Missing in Tehran Amid Surge in Migrant Hostility - KabulNow - July 16th, 2025 [July 16th, 2025]
- Afghanistan: Young woman driven to opium fields by Taliban restrictions - Amu TV - July 16th, 2025 [July 16th, 2025]
- Afghanistan: An Open Wound Still Alive, in Need of Becoming a Nation Again - 8am.media - July 16th, 2025 [July 16th, 2025]
- Remittance Disruption from Iran Deepens Economic Crisis for the People of Afghanistan - 8am.media - July 16th, 2025 [July 16th, 2025]
- Retreat from Afghanistan began as a farce, then it was a scandal, now it's a cover-up - Yahoo - July 16th, 2025 [July 16th, 2025]
- Over 178,000 People in Northern Afghanistan Benefit from Special Trust Fund Support - 8am.media - July 16th, 2025 [July 16th, 2025]
- Russia becomes the first country to recognize the Taliban regime in Afghanistan - MSN - July 14th, 2025 [July 14th, 2025]
- Afghanistan-Pakistan trade grows to nearly 1 bln USD in H1 - Xinhua - July 14th, 2025 [July 14th, 2025]
- Afghanistan 2024 Humanitarian Needs and Response Plan: End-year Response Gap Analysis of Financing, Achievements and Response Challenges (January -... - July 14th, 2025 [July 14th, 2025]
- Afghanistan Taxi Drivers Resort To DIY Car Coolers To Beat The Heat: Works Better Than AC - MSN - July 14th, 2025 [July 14th, 2025]
- Afghanistan: Taxi drivers use handmade air coolers to beat the heat - BBC - July 12th, 2025 [July 12th, 2025]
- 6-year-old girl sold into marriage with 45-year-old in Afghanistan; Taliban intervenes: Wait until shes - Times of India - July 12th, 2025 [July 12th, 2025]
- Barbie Battles Diabeetus, Angel Reese Is A Cover Athlete, And Afghanistan Is Open For Business - OutKick - July 12th, 2025 [July 12th, 2025]
- In Cinema Jazireh, a Woman Dresses up as a Man in Taliban Afghanistan in Search of Her Son, Hope - The Hollywood Reporter - July 12th, 2025 [July 12th, 2025]
- Russia Recognizes Talibans Apartheid Regime in Afghanistan - Foreign Policy in Focus - July 12th, 2025 [July 12th, 2025]
- Shafiqa Jalali says she has a hard time sleeping, eating or going out knowing her son is incarcerated in the U.S. and is scheduled to be deported to... - July 12th, 2025 [July 12th, 2025]
- Russia Just Legitimized the TalibanWhat Comes Next for Afghanistan and the World? - Security Clearance Jobs - July 12th, 2025 [July 12th, 2025]
- Afghanistan Taxi Drivers Resort To DIY Car Coolers To Beat The Heat: Works Better Than AC - Times Now - July 12th, 2025 [July 12th, 2025]
- 'Welcome to Afghanistan': Shocking tourism promo urging Americans to visit the country goes viral - Hindustan Times - Hindustan Times - July 10th, 2025 [July 10th, 2025]
- Trump dishes on Milley clash over leaving military equipment in Afghanistan: 'I knew he was an idiot' - Fox News - July 10th, 2025 [July 10th, 2025]
- Russia becomes the first country to recognize Taliban's rule in Afghanistan - NBC News - July 10th, 2025 [July 10th, 2025]
- Statement of the ICC Office of the Prosecutor on the issuance of arrest warrants in the Situation in Afghanistan - | International Criminal Court - July 10th, 2025 [July 10th, 2025]
- Following decades in Iran, 'there's nothing left' for millions of Afghan migrants in Afghanistan - France 24 - July 10th, 2025 [July 10th, 2025]
- 45-year-old man in Afghanistan married a 6-year-old child: the Taliban's reaction was swift - - July 10th, 2025 [July 10th, 2025]
- Welcome to Afghanistan': This could be the most bizarre tourism video ever - Stuff - July 10th, 2025 [July 10th, 2025]
- The Hairdressers Story: Exile, Loss, and a Forced Return to Afghanistan - 8am.media - July 10th, 2025 [July 10th, 2025]
- ICC expresses sadness at the passing of Afghanistan umpire Bismillah Jan Shinwari - ICC - July 8th, 2025 [July 8th, 2025]
- UN adopts resolution on Afghanistan's Taliban rule over US objections - ABC News - Breaking News, Latest News and Videos - July 8th, 2025 [July 8th, 2025]
- Will Pakistan Be Next to Recognise Taliban Rule in Afghanistan After Russia? - Times Now - July 8th, 2025 [July 8th, 2025]
- Russia becomes first nation to recognize Taliban government of Afghanistan since 2021 takeover - CNN - July 8th, 2025 [July 8th, 2025]
- India abstains from UNGA resolution on Afghanistan, calls for coordinated global efforts against terrorism - News On AIR - - July 8th, 2025 [July 8th, 2025]
- Experts: Russia Recognizing Taliban Rule in Afghanistan Largely a Symbolic Move - The Moscow Times - July 8th, 2025 [July 8th, 2025]
- Pakistan warns UN of escalating terror threat from Afghanistan - Dawn - July 8th, 2025 [July 8th, 2025]
- Tourists are trickling into Afghanistan. The Taliban are eager to welcome them - The Seattle Times - July 6th, 2025 [July 6th, 2025]
- Troops kill 30 militants trying to get into Pakistan from Afghanistan - Euronews - July 6th, 2025 [July 6th, 2025]
- Trump News | 'Afghanistan Maybe The Most Embarrassing Moment In The History Of US': Donald Trump - NDTV - July 6th, 2025 [July 6th, 2025]
- Tourists are trickling into Afghanistan and the Taliban government is eager to welcome them - Pittsburgh Post-Gazette - July 6th, 2025 [July 6th, 2025]
- Afghanistan Emerges as a New Frontier for Adventure Tourism: A Blend of Promise and Challenges - Travel And Tour World - July 6th, 2025 [July 6th, 2025]
- Afghanistan: A Hidden Gem That Deserves to Be Seen Up Close - Vocal - July 6th, 2025 [July 6th, 2025]
- Russia Becomes First Nation To Recognize Taliban-Led Afghanistan - The Media Line - July 6th, 2025 [July 6th, 2025]
- Russia is the first country to recognise the Taliban government in Afghanistan - Commonspace.eu - July 6th, 2025 [July 6th, 2025]
- Russia Becomes First State to Recognise Taliban Government of Afghanistan - UNITED24 Media - July 6th, 2025 [July 6th, 2025]
- Russia becomes first country to officially recognise Taliban in Afghanistan - bne IntelliNews - July 6th, 2025 [July 6th, 2025]
- The Unexpected Consequences of War Between Iran and Israel on Afghanistan - The Diplomat Asia-Pacific Current Affairs Magazine - July 6th, 2025 [July 6th, 2025]
- Russia is the first country in the world to recognize the Taliban government in Afghanistan - - July 6th, 2025 [July 6th, 2025]
- Sanctioned Businessman With Kremlin Ties Returns To Afghanistan - - July 6th, 2025 [July 6th, 2025]
- Pak security forces kill 30 terrorists trying to infiltrate from Afghanistan - Deccan Herald - July 4th, 2025 [July 4th, 2025]
- Russia Becomes First Country to Recognize Afghanistans Taliban Government - The New York Times - July 4th, 2025 [July 4th, 2025]
- Russia Is First Country to Recognize Taliban Rule in Afghanistan - The Daily Beast - July 4th, 2025 [July 4th, 2025]
- Troops kill 30 militants attempting to sneak into Pakistan from Afghanistan - AP News - July 4th, 2025 [July 4th, 2025]
- Taliban praise Russias brave decision to recognise their rule in Afghanistan - The Guardian - July 4th, 2025 [July 4th, 2025]
- Russia becomes first country to recognise Afghanistan's Taliban government - France 24 - July 4th, 2025 [July 4th, 2025]
- News - Pace Thanks Troops in Afghanistan, Notes Signs of Progress - DVIDS - July 4th, 2025 [July 4th, 2025]
- Russia becomes the first country to formally recognize Talibans latest rule in Afghanistan - AP News - July 4th, 2025 [July 4th, 2025]
- Troops kill 30 militants attempting to sneak into Pakistan from Afghanistan - WRAL.com - July 4th, 2025 [July 4th, 2025]
- News - Army Reservist to Receive Silver Star for Heroism in Afghanistan - DVIDS - July 4th, 2025 [July 4th, 2025]
- Russia becomes first nation to formally recognize Taliban-led government in Afghanistan - LiveNOW from FOX - July 4th, 2025 [July 4th, 2025]
- Hillsdale veteran Greg Whalen reflects on Afghanistan withdrawal through his music - Hillsdale Daily News - July 4th, 2025 [July 4th, 2025]
- Russia Becomes 1st Country To Recognise Taliban Government Of Afghanistan - NDTV - July 4th, 2025 [July 4th, 2025]
- China Hails Russias Decision To Recognize Taliban Rule In Afghanistan; Will Beijing Follow Suit? - EurAsian Times - July 4th, 2025 [July 4th, 2025]
- Russia Becomes First Nation to Recognise Taliban Rule in Afghanistan - The Wire India - July 4th, 2025 [July 4th, 2025]
- Russia becomes first country to recognize Taliban government in Afghanistan - Trkiye Today - July 4th, 2025 [July 4th, 2025]
- Russia the first to recognise Taliban government in Afghanistan - BBC - July 4th, 2025 [July 4th, 2025]
- Russia becomes first country to recognise Taliban government of Afghanistan - The Indian Express - July 4th, 2025 [July 4th, 2025]
- Russia officially recognises the Islamic Emirate of Afghanistan - 5Pillars - July 4th, 2025 [July 4th, 2025]
- Russia First to Officially Recognize Taliban Government in Afghanistan - - July 4th, 2025 [July 4th, 2025]
- Russia becomes first nation to formally recognize Taliban rule in Afghanistan - all details here - Mint - July 4th, 2025 [July 4th, 2025]
- Pakistan army kills 30 militants trying to cross from Afghanistan: Here's all we know - WION - July 4th, 2025 [July 4th, 2025]
- Kremlin's new stance: Russia first to officially recognise Afghanistan's Taliban government; will foster - Times of India - July 4th, 2025 [July 4th, 2025]
- Tourists Are Trickling into Afghanistan and the Taliban Government Is Eager to Welcome Them - Military.com - July 2nd, 2025 [July 2nd, 2025]
- Afghanistan: First-Hand Accounts Expose Torture by Taliban Intelligence Services - World Organisation Against Torture | OMCT - July 2nd, 2025 [July 2nd, 2025]
- Flight to freedom: A pilot's journey from the fall of Afghanistan to fighting fires in America - Fairfield Sun Times - July 2nd, 2025 [July 2nd, 2025]
- Building crutches, walkers, and stretchers from scratch in Afghanistan - Doctors Without Borders - July 2nd, 2025 [July 2nd, 2025]
- Russia to host seventh round of Moscow Format talks on Afghanistan this fall - Amu TV - July 2nd, 2025 [July 2nd, 2025]
- Earthquake of magnitude 3.9 strikes Afghanistan; third since June 28 - Business Standard - July 2nd, 2025 [July 2nd, 2025]