Google TAG: APT31 Targeting US govt Affiliates in Phishing Campaign

Google's Threat Analysis Group (TAG) warned Gmail users about Chinese APT31 (Judgement Panda/Zirconium) observed phishing activity targeting high-profile accounts affiliated with the US government. Shane Huntley of Google TAG shared on Twitter information about this campaign including assurance that Google blocked 100% of these emails and classified them as spam.


The campaign was first detected in February 2022 and, so far, shows no indication that it is related to the current Ukraine/Russia conflict.

Google continues to monitor and react specifically to government-backed threat alerts. Back in October, some 50,000 alerts regarding state-sponsored activity and/or phishing were sent to customers throughout the 2021 year. Over 15,000 of these alerts were confidently linked to Russian GRU's APT28 (Fancy Bear).



APT31 has been linked in the past with the theft of the EpMe NSA exploit some years before the Shadow Brokers leaked it in 2017. Microsoft analysts have also observed APT31 targeting high-profile persons linked to the Joe Biden presidential campaign.

The group is clearly motivated by international espionage with the US being a primary target. Google's redesign of the APT alert system in 2017 has helped add critical context and information to observed activity for the customers.

Shane Huntley's Twitter post

Mandiant APT groups resource

Comments

Popular posts from this blog

Russian GRU Unit 29155 recent operations