Britain summons Russian ambassador over years-long ‘Cold River’ cyberspying campaign against top politicians

The British government has summoned the Russian ambassador and sanctioned two people for what it said was a sustained but failed attempt to interfere in politics by Russian cyber spies.

A hacking group dubbed “Cold River” by cybersecurity researchers, working on behalf of Russia’s Federal Security Service (FSB), targeted British politicians, journalists, and non-profit groups over a period of several years, the foreign office said.

“I can confirm today that the Russian Federal Security Services, the FSB, is behind a sustained effort to interfere in our democratic processes,” junior foreign minister Leo Docherty said in a statement to lawmakers.

Russia’s embassy in London said on Thursday that Moscow has no reason to trust British insinuations about cyberattacks on Britain’s democracy in the absence of concrete evidence, Russian agencies reported.

The British government has summoned the Russian ambassador, Andrei Kelin. Photo: Reuters

Moscow routinely casts cyberespionage accusations as false smears by the West.

The group, which is also known as “Callisto” or “Star Blizzard”, first appeared on the radar of intelligence professionals after it targeted Britain’s foreign office in 2016. It was also behind the leak of private emails belonging to former British spymaster Richard Dearlove in 2022.

In January this year, Reuters exclusively reported that Cold River had targeted three nuclear research laboratories in the United States.

Russia’s foreign ministry dismissed that report as anti-Russian propaganda.

That report, which drew upon internet records and research from five cybersecurity experts, revealed that much of the digital infrastructure used by Cold River was set up by a 36-year-old IT worker named Andrey Korinets, in the northern Russian city of Syktyvkar.

North Korean hackers ‘breach top Russian missile maker’

Reached by phone, Korinets, one of the two individuals to be sanctioned by Britain on Thursday, told Reuters he was unaware of any measures against him, or why such sanctions would have been initiated.

Korinets declined to answer further questions and telephone calls from Reuters.

Cold River sits within the FSB’s “Centre 18”, one of two known cyber espionage units at the intelligence agency.

A Western official, speaking on condition of anonymity, said the group was still very active, and was part of Moscow’s “Active Measures”, intelligence-gathering ecosystem – a Cold War era term used by the Soviet Union to describe covert political disinformation campaigns.

Because of the UK’s support for Ukraine we are in a state of ‘grey warfare’ with Russia; and the Russians will use every means at their disposal to attack British interests short of open conflict

Richard Dearlove, former head of MI6

The group targets the personal email in boxes of high profile victims, Reuters found, including at least three former British intelligence officials.

“Because of the UK’s support for Ukraine we are in a state of ‘grey warfare’ with Russia; and the Russians will use every means at their disposal to attack British interests short of open conflict,” Richard Dearlove, the former head of Britain’s Secret Intelligence Service, or MI6, told Reuters.

Many of Cold River’s targets were vocally critical of Russia and its war in Ukraine.

FBI says it has disabled hacking tool created by Russia’s elite spies

Stewart McDonald, a British lawmaker who has publicly supported Kyiv and for years spoken out against Russian interference, said in February that his private emails were hacked by the group.

“Russia’s military intelligence service, the GRU, has received the lionshare of the attention when it comes to election related activity, which is only natural given their history of serious incidents in the United States and France, but this actor is one to watch closely as elections near,” said John Hultquist, who heads threat analysis at Google’s Mandiant Intelligence.

“The FSB clearly has an interest in political interference, and hacked emails are a powerful tool,” he said.

FOLLOW US ON GOOGLE NEWS

Read original article here

Denial of responsibility! Chronicles Live is an automatic aggregator of the all world’s media. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials, please contact us by email – chronicleslive.com. The content will be deleted within 24 hours.

Leave a Comment