Nov 16, 2018

Cozy Bear hackers may be impersonating State Department

Photo: Mandel Ngan/AFP/Getty Images

Cozy Bear, hackers who the U.S. and other governments believe to be Russian intelligence, appears to be impersonating the State Department in a new hacking campaign that's been observed attacking several sectors. FireEye, a cybersecurity company, first made the announcement on Twitter.

The big picture: It's nothing new for Cozy Bear to impersonate government officials, or anyone else who could lure people into downloading a file. That doesn't make it less aggressive — or less dangerous — for them to use the State Department to accomplish their goal.

FireEye is not making a firm attribution to Cozy Bear at this time. It's just saying the attacks show similarities to Cozy Bear's toolkit and techniques.

The targets spanned different sectors: defense, law enforcement, local government, media, pharmaceuticals, think tanks, transportation and the public sector. They appear to be the same or similar targets to a 2016 campaign associated with Cozy Bear.

What they're saying: "FireEye is continuing to investigate the true intention of the campaign," said Nick Carr, senior manager of adversary methods at FireEye.

Editor's note: The headline and story have been corrected to show that the Russian hacking group in question is Cozy Bear (not Fancy Bear).

Go deeper

Updated 11 mins ago - Health

World coronavirus updates

Data: The Center for Systems Science and Engineering at Johns Hopkins; Map: Axios Visuals

Over 500 schools in South Korea have either closed or postponed reopening, according to the Korea Times, which cites data from the Ministry of Education.

Why it matters: South Korea has been a model for how to handle the novel coronavirus, and the closures reportedly followed concerns from parents and teachers over child safety. The country's confirmed death toll has plateaued at 269 over the past few days, with few increases, per Johns Hopkins data.

Updated 12 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 4 p.m. ET: 5,877,503— Total deaths: 362,731 — Total recoveries — 2,464,595Map.
  2. U.S.: Total confirmed cases as of 4 p.m. ET: 1,735,971 — Total deaths: 102,286 — Total recoveries: 399,991 — Total tested: 15,646,041Map.
  3. Public health: Hydroxychloroquine prescription fills exploded in March —How the U.S. might distribute a vaccine.
  4. 2020: North Carolina asks RNC if convention will honor Trump's wish for no masks or social distancing.
  5. Supreme Court: Senators Grassley, Leahy urge Supreme Court to continue live streams post-pandemic.
  6. Business: Fed chair Powell says coronavirus is "great increaser" of income inequality.
  7. 🚀 Space: How to virtually watch SpaceX's first crewed launch Saturday.

Trump to end Hong Kong’s special trade status

President Trump. Photo: Win McNamee/Getty Images

President Trump announced on Friday that the U.S. would be fundamentally changing longstanding policies toward Hong Kong as a result of Chinese encroachment on the city's autonomy.

Why it matters: Trump said he would be effectively ending the special trade status that has allowed Hong Kong to flourish as a gateway to the Chinese market. That leaves an uncertain future for businesses that operate in Hong Kong, not to mention the city's 7 million residents, and could be met with reprisals from Beijing.