U.S. Warns of Russian Cyberattacks Targeting Nuclear Scientists

RKS NEWS
RKS NEWS 5 Min Read
5 Min Read

New warnings indicate that Russian operatives have been targeting the emails of nuclear scientists, defense contractors, and government employees in the United States as part of a cyber espionage campaign.

A Russian hacking group spent the past year targeting nuclear researchers, defense industry contractors, and government personnel in a campaign aimed at gathering intelligence, according to private-sector cybersecurity researchers and warnings issued Thursday by intelligence agencies.

The targets suggest an interest in nuclear fusion technology and related intelligence that could potentially support the Kremlin’s strategic objectives amid its war against Ukraine.

The U.S. email security company Proofpoint, which investigated some of the activity, said the hackers targeted email servers used by “nuclear facilities and the defense industrial base” in the United States.

The hackers were “targeting entities and users with an interest in nuclear fusion,” Proofpoint researcher Greg Lesnewich told CNN.

The goal was likely “to see what advances Russia’s peers have made in this field,” he said.

A cybersecurity advisory issued by U.S. intelligence and security agencies, along with more than a dozen allied countries, warned of an ongoing Russian espionage campaign that tested hacking techniques in Ukraine before deploying them against NATO countries.

If additional victims are identified, the advisory could help the U.S. and its allies assess the extent of the intelligence collected by Russian operatives.

The hackers used a rare software vulnerability that required only that a target open an email on a vulnerable email system, without needing to click on any links.

The exploit could allow attackers to steal three months of a victim’s email communications, along with the organization’s broader email directory, according to the federal advisory.

The U.S. Department of Energy, which oversees multiple nuclear research laboratories, did not immediately respond to requests for comment regarding Proofpoint’s findings.

The FBI and the National Security Agency (NSA) said officials were not immediately available for interviews regarding the federal warning.

The Russian Embassy in Washington, D.C. did not respond to a request for comment.

U.S. officials and allies said that federal and local governments, law enforcement agencies, as well as the defense, education, and energy sectors, were targeted by the cyber activity, without providing specific details.

“The actor was most likely seeking strategic insight into Western military information, logistics, and political decision-making,” said Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks’ Unit 42 division, which is also tracking the activity.

The activity reflects an “increasing trend among Russian cyber threat groups to first target Ukrainian users — both as a priority objective and as a testing ground for malicious cyber techniques before broader global deployment,” the government advisory stated.

“Based on the success of this and previous campaigns, it is highly likely that the Russian group will continue targeting email systems used by Western organizations,” the advisory added.

“It is particularly concerning that these actors tested their methods against victims in Ukraine before targeting NATO members,” said UK Security Minister Dan Jarvis.

The detailed nature of the warning, which includes information not publicly released by cybersecurity firms, suggests that U.S. and allied intelligence agencies have gathered extensive information about the Russian espionage group.

Law enforcement agencies have also pursued members of the group. Thai authorities arrested a suspected member in November — a Russian man in his 30s — who was later extradited and appeared in court in Boston last month.

After an initial slowdown following Russia’s full-scale invasion of Ukraine in 2022, the United States has seen a significant increase in Russian cyber targeting, FBI cyber division official Brett Leatherman told CNN.