CERT-Georgia discovered a cyber attack targeting Georgian governmental resources that was collecting sensitive information and uploading it to command and control servers. The attack used advanced malware and targeted news websites related to NATO, US-Georgian agreements, and Georgian military news. Through analyzing infected servers, files, and scripts, CERT-Georgia linked the attack to Russian security agencies. The sophisticated malware stole documents, took screenshots, recorded audio and video, and more. CERT-Georgia was able to gain access to attacker servers and identify the individuals and groups responsible in Russian security organizations behind the attacks.
Related topics: