Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

COVID-19 Vaccine Attacks Teach an Important Cybersecurity Lesson

COVID-19 Vaccine Attacks Teach an Important Cybersecurity Lesson

Since the outbreak of the COVID-19 coronavirus has wreaked havoc across the globe, there has been a lot of hope and effort put towards developing a vaccine against it. Unfortunately, just as some experiments have produced promising results, hackers have begun targeting the research centers responsible. Let’s look at this situation to see what it can teach us.

The Cozy Bear Threat

According to the National Cyber Security Centre, a government security organization based in the United Kingdom, a hacking group known as “APT29” (also referred to as “the Dukes” or “Cozy Bear”) has actively targeted the research centers conducting research into developing a COVID-19 vaccine. These claims have been supported by both the United States’ National Security Agency and Canada’s Communications Security Establishment.

In fact, the National Cyber Security Center released a report that outlined the attack that the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency also endorses.

This report describes the use of various exploits in conjunction with spear phishing attacks by APT29. Both tactics give APT29 access to carry out the rest of their attacks, which often involves deploying malware known as WellMess or WellMail.

On a side note, some of these exploits have been patched, so make sure you’re also up to date on your patches as well.

Many experts also share the opinion that Cozy Bear has struck before, and that the current threat needs to be taken very seriously as a result. It is believed that APT29 was responsible for the 2016 intrusion into the Democratic National Committee’s systems, as reported by CNN. The group has also been linked to assorted attacks on healthcare, energy, governmental and diplomatic organizations, and think tanks in the past.

What is Spear Phishing?

Phishing is a form of hacking that targets the end user, rather than using software vulnerabilities, to gain access to a system. Spear phishing is a more direct form of phishing. Instead of sending a generic message to massive groups of potential targets to see who takes the bait, spear phishing is specifically directed to an individual with access to key data and resources.

While APT29 may not target your organization as a part of these efforts to steal research, it is nevertheless critical that you and your team can recognize a potential phishing attack and mitigate it before it causes significant problems. While the following is by no means a comprehensive list of warning signs, it is a good place to start educating your team:

  • Always check the details. Many phishing attacks can be identified by close-but-no-cigar “From” addresses. When in doubt, try looking up the email address that sent an email.
  • Proofread the message. While legitimate messages can contain terrible spelling and grammar mistakes, and attackers can more and more effectively mimic professional communications, many phishing messages can be rife with errors.
  • Double-check. If possible, don’t be afraid to confirm that the email is legitimate by reaching out to the supposed sender (through some non-email form of communication) to confirm that they sent the message.

For more assistance in dealing with phishing attacks, reach out to us! At Total Tech Care, we’re motivated to help prevent a phishing attack from impacting your operations. Give us a call at 866-348-2602 to learn more.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 21 November 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Network Security Google Business Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices Hardware IT Services Android VoIP Disaster Recovery communications IT Support Smartphones Communication Business Continuity Miscellaneous Smartphone Mobile Device Network Browser Small Business Productivity Collaboration Cybersecurity Quick Tips Users Business Management Phishing Upgrade Windows Managed IT Services Ransomware Data Backup Outsourced IT Windows 10 Office Cloud Computing Server Save Money Data Recovery Windows 10 Passwords Saving Money Holiday Tech Term Gadgets Chrome Virtualization Social Media Managed Service Managed IT Services Microsoft Office Automation Cybercrime Operating System Artificial Intelligence Computers Facebook Mobile Device Management Health Networking IT Support Internet of Things Hacking Wi-Fi BYOD Managed Service Provider Spam Alert Remote Office 365 Telephone Systems Information Technology Covid-19 Information Recovery Employer-Employee Relationship Router Bandwidth BDR Social Engineering Mobility Human Resources Law Enforcement Big Data Remote Monitoring Data Breach Password Money App History Mobile Computing Encryption Applications Application Government Data Storage Remote Computing Patch Management Private Cloud Mobile Office Managed IT Apps Office Tips Blockchain Training Paperless Office How To VPN Infrastructure Two-factor Authentication Avoiding Downtime Voice over Internet Protocol Vulnerability Mouse Windows 7 HaaS Word Bring Your Own Device Servers Data Management Work/Life Balance Flexibility Marketing Wireless Data Security WiFi IT solutions Entertainment Website Gmail Google Drive Budget Settings Firewall Keyboard Employee/Employer Relationship RMM Virtual Reality Apple Conferencing Social Scam User Error Save Time Data Protection Meetings Vendor Management Cleaning Risk Management Hacker End of Support Vendor The Internet of Things Managed Services Education Physical Security Lithium-ion battery Telephone System Staff Software as a Service Display Safety Machine Learning USB HIPAA Sports Remote Work Redundancy Connectivity Hard Drive IT Consultant Fax Server Google Docs Proactive IT Hiring/Firing Identity Theft Best Practice YouTube Humor SaaS Computing Black Market Augmented Reality Network Congestion Fraud Business Intelligence eWaste Document Management Wireless Technology Remote Worker Solid State Drive Digital Signage How to Worker Downtime Audit IT Management Cryptocurrency Data storage Botnet IT Plan Wearable Technology Automobile Procurement Comparison Net Neutrality Hard Drives Workplace Strategy Retail Instant Messaging Virus Unsupported Software CES Robot Computing Infrastructure Help Desk Excel Going Green Unified Threat Management Printing Charger Biometrics Computer Accessories Business Technology Content Management Virtual Desktop Compliance Access Control OneNote Battery Computer Care Managed Services Provider Virtual Assistant DDoS Current Events Shadow IT Database Telephony Authentication Legal SharePoint Samsung Printer Remote Workers Internet Exlporer Bluetooth Value Processor Customer Service PDF Update Electronic Medical Records Environment Spam Blocking Screen Mirroring HVAC Peripheral Antivirus Loyalty Google Apps Relocation Frequently Asked Questions Digital Security Cameras Analysis Using Data Books Windows 8 IT service Video Games 5G Mobile Administrator Windows 10s Devices Copiers Cast Enterprise Content Management Quick Tip Worker Commute Tablet Tip of the week MSP Ergonomics Experience webinar Accountants Emergency Smartwatch Domains Scalability Employer Employee Relationship Credit Cards OLED Professional Services Microchip Public Cloud Thought Leadership Development Password Management PCI DSS Business Owner Assessment Password Manager Virtual Machine NarrowBand Windows Server 2008 2FA IaaS Fiber Optics Maintenance Multi-Factor Security Employee Search Cabling Bloatware Consultant Tools Search Engine Twitter Messaging Analytics NIST Policy Television Business Mangement Hypervisor iPhone Tablets Dark mode Smart Tech Trend Micro Trending Amazon Default App Entrepreneur Best Available Addiction SMS Procedure Public Computer Recycling Saving Time Files WIndows 7 Chromecast Regulations Wiring dark theme Practices Shopping Shortcut Transportation Google Search Computer Fan Cache AI Rootkit Amazon Web Services IT Infrastructure Cost Management Safe Mode FinTech Criminal Social Networking Colocation Bing Uninterrupted Power Supply Benefits GDPR Workers Hosted Computing Social Network FENG Wireless Internet Online Shopping Investment Monitor PowerPoint File Sharing Employees Running Cable Windows Media Player IBM Employee/Employer Relationships User Smart Technology Specifications ISP Memory Flash Camera Windows 365 Inventory Wire Video Conferencing Evernote ROI Reputation Streaming Media Software Tips Sales Content Supercomputer Bitcoin Travel Shortcuts Tech Support Managing Stress Millennials Cryptomining Laptop Sync Printers Point of Sale Emails Personal Techology Smart Office Supply Chain Management Wireless Charging Customers Cameras Monitoring Audiobook Batteries Science Two Factor Authentication Workforce Touchpad Virtual Private Network Windows 8.1 Netflix Digitize Root Cause Analysis Cables Windows Server 2008 R2 HBO Customer relationships Distributed Denial of Service Politics Knowledge Customer Relationship Management Advertising Music Telecommuting Manufacturing Analyitcs Skype Project Management Email Best Practices Nanotechnology IT Assessment Data loss Cortana Programming Notifications Printer Server Outlook Computer Tips Leadership Digital Signature Managed IT Service Troubleshooting Security Cameras Biometric Security Start Menu Warranty Virtual CIO OneDrive

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code