Russian hackers target British Ministry of Defense

The British Ministry of Defense revealed that it was a complex, cyber attack target, which made Russian-connected hackers form the pose of journalists.
According to the Ministry of Defense, the foiled attack is one of more than 90,000 cyberattacks related to hostile countries defending the UK over the past two years.
The Spear phishing campaign aims at employees to plant malware on MOD systems, known as the “Big Peacock”.
MOD investigators at the Global Operations Security Control Center in Cotham, Wiltshire explained that the attack was in honor of the famous feathered residents of the Market Town.
The initial attacks included two emails, with hackers pretending to make an emergency request on behalf of a news agency, according to a report released by the Department of Defense and the National Cybersecurity Center.
Later attacks used financial topics to try to trick recipients into clicking a link to a file sharing site.
Anyone who clicks a link in a phishing email can be tricked into downloading a malicious executable file masquerading as a PDF, and running the file will display the bait document when malware is retrieved from an external website.
The malware is digitally signed using a certificate issued to the Russian company Futurico LLC in an attempt to give a clock of legitimacy.
According to the researchers, specific malware against MOD has never been seen before, but it appears to be linked to Romcom’s malware family, which had previously been connected to Russia’s Storm-0978 hacker hacking group, engaged in attacks by the Ukrainian government and military groups, as well as other agencies in the U.S. states and Europe.
Last November, it was revealed that Russian hackers stole the login details needed for Mod’s defense gateway portal – an online platform for all British military personnel – but it is not clear whether this is related to the “Dam Peacock” attack.
As Sky News British military is reportedly strengthening its capabilities to be able to launch cyber attacks against hostile countries such as Russia.