(The Canadian Press)

Russian hackers seeking to steal COVID-19 vaccine data: intel agencies

It is believed APT29, also known as ‘the Dukes’ or ‘Cozy Bear’ was responsible

Canadian, British and U.S. security services say hackers they believe are working for Russian intelligence have been trying to steal research on COVID-19 vaccines from organizations in all three countries and around the world.

Canada’s Communications Security Establishment says the malicious cyberactivities were very likely undertaken to pilfer information and intellectual property relating to the development and testing of vaccines for the novel coronavirus.

The cyberspy agency says the clandestine activity is hindering response efforts at a time when health-care experts and medical researchers need every available resource to help fight the pandemic.

The CSE’s Centre for Cyber Security assesses that APT29, also known as ”the Dukes” or “Cozy Bear,” was responsible, and almost certainly operates as part of Russian intelligence services.

“The group uses a variety of tools and techniques to predominantly target governmental, diplomatic, think-tank, health-care and energy targets for intelligence gain,” says a joint advisory from the CSE and its allies.

“APT29 is likely to continue to target organizations involved in COVID-19 vaccine research and development, as they seek to answer additional intelligence questions relating to the pandemic.”

This assessment is supported by partners at Britain’s Government Communications Headquarters’ National Cyber Security Centre, the U.S. National Security Agency, and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency.

The CSE is urging Canadian health organizations to review a technical advisory on the threat and to take any necessary actions to protect themselves. “We encourage them as well to contact the Cyber Centre if they suspect they have been targeted by cyberactors.”

The joint advisory says APT29 targeted COVID-19 vaccine research and development by scanning specific computer IP addresses of interest for vulnerabilities, a tactic that can help the group obtain login credentials to systems.

“This broad targeting potentially gives the group access to a large number of systems globally, many of which are unlikely to be of immediate intelligence value,” the advisory says.

“The group may maintain a store of stolen credentials in order to access these systems in the event that they become more relevant to their requirements in the future.”

By Jim Bronskill , The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

EDITORIAL: Managing wildfires

Wildfires have the potential to cause significant damage within our province

Opening night lineup for online Roots & Blues festival released

The first night of the festival on Aug. 14 will be stacked with favourites from previous years

Revelstoke’s forestry museum launches podcasts and new website

One of their summer students is working remotely

Glimpses of Revelstoke’s past for Aug. 6

Chautauqua, CPR strike and destructive fire

Morning Start: The human body contains trace amounts of gold

Your morning start for Friday, August 7, 2020

53 new COVID-19 cases, no new deaths cap off week of high infection rates in B.C.

Roughly 1,500 people are self-isolating because they either have COVID-19 or have been exposed to it

Moving on: Tanev scores 11 seconds into OT as Canucks oust Wild

Vancouver beats Minnesota 5-4 to move into first round of NHL playoffs

Number of Kelowna-linked COVID-19 cases grows to 159

Interior Health reported four new cases region-wide on Friday, 18 remain active

Gene editing debate takes root with organic broccoli, new UBC research shows

Broccoli is one of the best-known vegetables with origins in this scientific haze

VIDEO: U.S. Air Force pilot does fly-by for B.C. son amid COVID border separation

Sky-high father-son visit plays out over White Rock Pier

3 Vancouver police officers test positive for COVID after responding to large party

Union president says other officers are self-isolating due to possible exposure

New mothers with COVID-19 should still breastfeed: Canada’s top doctor

Dr. Theresa Tam made the recommendation during World Breastfeeding Awareness Week

Collapse of Nunavut ice shelf ‘like losing a good friend:’ glaciologist

The ice shelf on the northwestern edge of Ellesmere Island has shrunk 43 per cent

Police watchdog deems Kelowna RCMP not responsible for man’s death

The man spoke to police after a car crash before leaving on foot; he was found dead six hours later

Most Read