(The Canadian Press)

(The Canadian Press)

Russian hackers seeking to steal COVID-19 vaccine data: intel agencies

It is believed APT29, also known as ‘the Dukes’ or ‘Cozy Bear’ was responsible

Canadian, British and U.S. security services say hackers they believe are working for Russian intelligence have been trying to steal research on COVID-19 vaccines from organizations in all three countries and around the world.

Canada’s Communications Security Establishment says the malicious cyberactivities were very likely undertaken to pilfer information and intellectual property relating to the development and testing of vaccines for the novel coronavirus.

The cyberspy agency says the clandestine activity is hindering response efforts at a time when health-care experts and medical researchers need every available resource to help fight the pandemic.

The CSE’s Centre for Cyber Security assesses that APT29, also known as ”the Dukes” or “Cozy Bear,” was responsible, and almost certainly operates as part of Russian intelligence services.

“The group uses a variety of tools and techniques to predominantly target governmental, diplomatic, think-tank, health-care and energy targets for intelligence gain,” says a joint advisory from the CSE and its allies.

“APT29 is likely to continue to target organizations involved in COVID-19 vaccine research and development, as they seek to answer additional intelligence questions relating to the pandemic.”

This assessment is supported by partners at Britain’s Government Communications Headquarters’ National Cyber Security Centre, the U.S. National Security Agency, and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency.

The CSE is urging Canadian health organizations to review a technical advisory on the threat and to take any necessary actions to protect themselves. “We encourage them as well to contact the Cyber Centre if they suspect they have been targeted by cyberactors.”

The joint advisory says APT29 targeted COVID-19 vaccine research and development by scanning specific computer IP addresses of interest for vulnerabilities, a tactic that can help the group obtain login credentials to systems.

“This broad targeting potentially gives the group access to a large number of systems globally, many of which are unlikely to be of immediate intelligence value,” the advisory says.

“The group may maintain a store of stolen credentials in order to access these systems in the event that they become more relevant to their requirements in the future.”

By Jim Bronskill , The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

(Black Press file photo)
Highway 3 cleared, open after vehicle incident

The road was closed for about three hours earlier on Jan. 18

/ Kevin Mills Photo
Hundreds participate in solidarity parade for transgender student who was bullied

Cars, horses and even planes passed by the Mission waterfront to show support

Kent Search and Rescue sent down three rescuers
UPDATE: Two people involved in ATV rollover 100 feet down ravine in Harrison, at least one injured

Incident happened shortly before 5 p.m. on Harrison East Forest Service Road

An amethyst rock was stolen from Swinstones Granite Shop’s showroom in Chilliwack on Yale Rd. West, and they are hoping it will be spotted and returned. They discovered their window smashed and the purple rock stolen on the morning of Jan. 17, 2020. Here a portion of it is pictured to the right. (Submitted image)
Amethyst stolen from Chilliwack stone shop’s showroom

Window smashed at business where purple rock has been on display for nearly 16 years

sdf
Another Mission student arrested for assault, in 2nd case of in-school violence this week

RCMP notified of local Instagram page with videos (now deleted) showing student assaults, bullying

A scene from “Canada and the Gulf War: In their own words,” a video by The Memory Project, a program of Historica Canada, is shown in this undated illustration. THE CANADIAN PRESS/HO - Historica Canada
New video marks Canada’s contributions to first Gulf War on 30th anniversary

Veterans Affairs Canada says around 4,500 Canadian military personnel served during the war

BC Emergency Health Services has deployed the Major Incident Response Team (MIRRT) as COVID-19 positive cases rise in the Williams Lake region. (Monica Lamb-Yorski photo - Williams Lake Tribune)
B.C.’s rapid response paramedics deployed to Williams Lake as COVID-19 cases climb

BC Emergency Health Services has sent a Major Incident Rapid Response Team to the lakecity

RCMP were called to the 5600 block of 201A Street just after midnight on Monday were they found a 27-year-old man in an underground parking garage who had sustained multiple shot wounds. (Lisa Farquharson/Langley Advance Times)
27-year-old taken to hospital after overnight targeted shooting in Langley

RCMP have not confirmed the incident is link to the Lower Mainland gang conflict

U.S. military units march in front of the Capitol, Monday, Jan. 18, 2021 in Washington, as they rehearse for President-elect Joe Biden’s inauguration ceremony, which will be held at the Capitol on Wednesday. (AP Photo/J. Scott Applewhite)
Biden aims for unifying speech at daunting moment for U.S.

President Donald Trump won’t be there to hear it

Williams Lake physician Dr. Ivan Scrooby and medical graduate student Vionarica Gusti hold up the COSMIC Bubble Helmet. Both are part of the non-profit organization COSMIC Medical which has come together to develop devices for treating patients with COVID-19. (Monica Lamb-Yorski photo - Williams Lake Tribune)
Group of B.C. doctors, engineers developing ‘bubble helmet’ for COVID-19 patients

The helmet could support several patients at once, says the group

A 17-year-old snowmobiler used his backcountry survival sense in preparation to spend the night on the mountain near 100 Mile House Saturday, Jan. 16, 2021 after getting lost. (South Cariboo Search and Rescue Facebook photo)
Teen praised for backcountry survival skills after getting lost in B.C.’s Cariboo mountains

“This young man did everything right after things went wrong.”

Conservative Leader Erin O’Toole holds a press conference on Parliament Hill, in Ottawa on December 10, 2020. THE CANADIAN PRESS/Sean Kilpatrick
No place for ‘far right’ in Conservative Party, Erin O’Toole says

O’Toole condemned the Capitol attack as ‘horrifying’ and sought to distance himself and the Tories from Trumpism

A passer by walks in High Park, in Toronto, Thursday, Jan. 14, 2021. This workweek will kick off with what’s fabled to be the most depressing day of the year, during one of the darkest eras in recent history. THE CANADIAN PRESS/Chris Young
‘Blue Monday’ getting you down? Exercise may be the cure, say experts

Many jurisdictions are tightening restrictions to curb soaring COVID-19 case counts

Pindie Dhaliwal, one of the organizers for the Surrey Challo protest for Indian farmers. She says organizers were told by Surrey RCMP that the event was not allowed due to COVID-19. Organizers ended up moving the protest to Strawberry Hill at the last minute. (Photo: Lauren Collins)
Indian farmers rally moves as organizers say Surrey RCMP told them they couldn’t gather

Protest originally planned in Cloverdale, moved to Strawberry Hill

Most Read