Kazakhstan's Diplomatic Documents Reportedly Targeted in Cyber Campaign
Photo: Elements.envato.com, ill. purposes
A cyber espionage campaign, allegedly connected to the Kremlin, has reportedly targeted Central Asian countries, including Kazakhstan, according to digital security firm Sekoia.
Infosecurity Magazine reports:
According to recent findings by cybersecurity firm Sekoia, the campaign involved weaponized Microsoft Word documents designed to deliver HatVibe and CherrySpy malware, collecting strategic intelligence on Kazakhstan’s diplomatic and economic relations.
The investigation began in October when Sekoia discovered a document in the VirusTotal database.
The attackers used a macro to activate malware on recipients' devices, first deploying the HatVibe backdoor, followed by the more sophisticated CherrySpy malware – a technique previously used against Ukrainian scientific institutions.
The compromised documents included diplomatic correspondence and administrative files from Kazakhstan's Foreign Ministry dating from 2021 to 2024.
The attack bears hallmarks of APT28, a group allegedly connected to Russia's GRU and funded by the Kremlin.
APT28 has a history of targeting diplomatic, defense and scientific sectors across Europe and Asia, often using spear phishing with malicious macros and scheduled task persistence, notes Infosecurity Magazine.
According to Sekoia's analysis:
The most recent documents are two diplomatic letters, one from the Embassy of Kazakhstan in Afghanistan, the second from the Embassy of Kazakhstan in Belgium, both intended for the central Ministry of Foreign Affairs regarding diplomatic cooperation and economic issues. The both are dated early September 2024.
The documents supposedly included materials related to President Toqayev's state visit to Mongolia and his meeting with American companies in New York.
The hackers also accessed a Kyrgyz Defense Ministry letter discussing military cooperation in Central Asia, which contained information about a "special operation by the PRC against Taiwan."
The UAC-0063 utility used in this campaign has previously targeted Ukraine, Israel, India, Kyrgyzstan, and Tajikistan.
Another major data breach in early 2024 included personal information about Kazakhstani security officials, though Kazakhstan's authorities never officially confirmed this. Chinese hackers had been stealing data from Kazakhstani information networks for two years.
Orda.kz has sent official inquiries to Kazakhstan's Foreign Ministry, the Ministry of Digital Development, Innovation and Aerospace Industry, and the Center for Analysis and Investigation of Cyberattacks.
Original Author: Nikita Drobny
Latest news
- Part of Shymkent’s 3-Billion-Tenge Dam Destroyed One Month After Completion
- Putin to Visit Kazakhstan in Late May at Tokayev’s Invitation
- Clean Air for Almaty: Coal Power to Be Moved to Pavlodar Region
- Burger King Employee With Autism Allegedly Pressured to Resign After Management Change
- Bagdat Musin Explains Why KazLLM Is Not «Kazakhstan’s ChatGPT»
- Military Convoys in Three Kazakh Cities — What the Defense Ministry Says
- Kazakhstan Takes Two Golds at Artistic Swimming World Cup Stage in Medellín
- 2,500 Participants from 22 Countries: Almaty Opens the Running Season
- Snow and Frost: Weather Forecast for February 15
- Tokayev congratulates Serbia’s President Vucic on Statehood Day
- Mikhail Shaidorov Wins Kazakhstan’s First Winter Olympic Gold Since 1994
- Indian Crested Porcupines Spotted by Camera Trap in Ile-Alatau National Park
- Kazakhstan’s Air Pollution Isn’t Driven by Factories — Ministry of Ecology
- How the US Views Kazakhstan’s Constitutional Reform and Free Speech
- US Ambassador to Kazakhstan: Visa Restrictions for Kazakhstanis Are a Temporary Measure
- China-to-Russia Shipments Are Increasingly Bypassing Kazakhstan
- Shokan Ualikhanov Private School Reclassified as Large Business After Staff Tops 250
- Former Priest Yakov Vorontsov Reportedly Detained in Kazakhstan
- Kazakhstan Proposes Differentiated Toll Rates for Transit Foreign Drivers
- World Bank Ready to Provide Kazakhstan Up to $1 Billion a Year for Six Years