Russian Hackers Used Ukraine as Test Ground Before Targeting US Nuclear Scientists

Russian Hackers Used Ukraine as Test Ground Before Targeting US Nuclear Scientists

Russian state-backed hackers have targeted US nuclear scientists, defense contractors and government employees in a cyber-espionage campaign using techniques first deployed against Ukraine, CNN reported, citing cybersecurity researchers and a new joint warning from Western intelligence agencies. The campaign, attributed to a Russian-linked group tracked as Laundry Bear, Void Blizzard and TA488, has targeted Western government and commercial organizations since at least July 2025, according to a joint cybersecurity advisory released by US and allied agencies.JOIN US ON TELEGRAMFollow our coverage of the war on the @Kyivpost_official. The hackers’ targets suggest Moscow is seeking intelligence on nuclear fusion research as well as information that could support Russia’s war against Ukraine, CNN reported. US cybersecurity firm Proofpoint, which investigated parts of the campaign, found that the group targeted email servers belonging to US “nuclear installations and the defense industrial base.” The hackers were particularly interested in “entities and users with an interest in nuclear fusion,” Proofpoint researcher Greg Lesnewich told CNN, suggesting Moscow may have been seeking insight into advances made by competitors in the field. The campaign also targeted federal and local government agencies, law enforcement, education, energy, media, technology organizations and the defense industry, according to the joint advisory. Other Topics of Interest Kallas Proposes New Sanctions After Russian Strikes Hit Latvian Consulate in Sloviansk EU foreign policy chief demands accountability after Russia's guided bombs damage a Baltic diplomatic outpost. Ukraine used as testing ground The warning was issued by the US National Security Agency, FBI, Cybersecurity and Infrastructure Security Agency and other American bodies together with intelligence and cybersecurity agencies from more than a dozen allied countries, including the UK, France, Italy, Poland, Canada, Australia and several other NATO members. The agencies identified a broader pattern in which Russian cyber groups first deploy techniques against Ukrainian targets before expanding their operations against Western countries. “Extensive Ukrainian targeting, prior to use against US and other NATO allies,” demonstrates an increasing tendency among Russian cyber groups to use Ukrainian users both as priority intelligence targets and as a testbed for new cyber techniques, the advisory said. UK Security Minister Dan Jarvis described that pattern as particularly concerning. “It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO,” Jarvis told CNN. The advisory assessed that the Russian group will very likely continue targeting email systems used by organizations in Western countries. Opening an email was enough The campaign exploited a vulnerability in Zimbra Collaboration Suite, an email platform used by government and commercial organizations. Unlike conventional phishing attacks, victims did not need to click a malicious link or download an attachment. Simply opening or previewing a specially crafted email on a vulnerable Zimbra system could trigger the attack. The vulnerability, identified as CVE-2025-66376, was a previously unknown zero-day when the hackers began exploiting it in July 2025. A patch was released in November. Once activated, the malicious software attempted to steal the victim’s previous 90 days of emails, passwords, two-factor authentication codes and the organization’s entire email directory. It could also create additional credentials allowing the hackers to maintain persistent access to compromised accounts. Proofpoint said the group used the vulnerability for at least five months during 2025 and established persistent access to compromised systems while exfiltrating victims’ emails. Russian intelligence link Proofpoint assesses TA488 as a Russia-aligned group likely directed by Russian intelligence, while the joint Western advisory describes its members as Russian state-supported cyber actors. The campaign was focused on intelligence gathering rather than financial gain, according to the agencies. Cybersecurity researchers believe the targets reveal two overlapping Russian objectives – obtaining advanced scientific and technological information and collecting intelligence relevant to Moscow’s military operations. “The actor likely hoped to gain strategic insight into western military information, logistics, and policy decisions,” Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks’ Unit 42, told CNN. The campaign represents part of a broader resurgence in Russian cyber activity against the US. Western agencies warned that even as organizations patch the particular Zimbra vulnerability, the Russian group is likely to seek new ways of penetrating Western email systems. The joint advisory urged organizations to update vulnerable software and closely monitor email infrastructure for signs of compromise. Kyiv Post is Ukraine’s first and oldest English news organization, reporting since 1995. Its international reach – 97% of readers are outside of Ukraine – make it truly Ukraine’s global voice.

Original Source

Read the full article at Kyivpost →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.