Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Recent Russian Cyberattacks Against Coronavirus Researchers and Other Industries Provides a Lesson on Cyber Preparedness

By Sean C. Griffin on July 17, 2020
Email this postTweet this postLike this postShare this post on LinkedIn
shutterstock_1083511010

Recently, this blog warned about Advanced Persistent Threats (APTs)—state-sponsored hackers that attack U.S. companies in the hopes of sowing political, technological, or financial disruption. In particular, we warned that healthcare companies were a favorite APT target, as foreign governments sought to extract data relating to healthcare research.

Security officials in the United States, the United Kingdom, and Canada recently announced that a Russian APT called APT29 is targeting organizations involved in national and international COVID-19 responses. According to U.S. intelligence services, APT29 is part of the SVR, Russia’s CIA equivalent, and UK officials also blame it for attacks against the 2016 presidential election.

APT29’s targets include vaccine research and development organizations. Officials believe that it is “highly likely” that APT29 is trying to steal information and intellectual property relating to the development and testing of COVID-19 vaccines through the typical APT tactics of spear-phishing and custom malware, according to the UK statement. The malware programs, known as “WellMess” and “WellMail,” use publicly available exploits to conduct widespread scanning and exploitation against vulnerable systems.

APT29 has apparently selected a broad array of targets for its COVID-19 attacks, some of which are only tangentially related to the COVID-19 research they currently seek. According to the UK, APT29 targeted government, diplomatic, think-tank, healthcare and energy groups to obtain the COVID-19 data it seeks. The Department of Defense notes that, by choosing its targets broadly, APT29 could potentially gain access to a large number of systems globally, and it may maintain a store of stolen credentials to access these systems if they become more useful in the future. APTs will typically cast a wide net of cyberattacks, both to ensnare the information it wants in the near term and to gather information that may become useful in the long term.

The lesson remains clear. APTs’ attacks on an array of organizations make any U.S. organization a potential APT target—regardless of whether or not the organization is “political” or involved in high-profile industries. Organizations must learn about APTs and their tactics, and they must prepare themselves to detect and repel sophisticated APT cyberattacks.

For more information regarding this article, please contact Sean Griffin.

For information regarding Dykema’s Privacy and Data Security Team, please contact Cindy Motley.

To sign up for Dykema’s Privacy and Data Security Blog e-mail updates, please click here.


As part of our service to you, we regularly compile short reports on new and interesting developments and the issues the developments raise. Please recognize that these reports do not constitute legal advice and that we do not attempt to cover all such developments. Rules of certain state supreme courts may consider this advertising and require us to advise you of such designation. Your comments are always welcome. ©2020 Dykema Gossett PLLC.

Photo of Sean C. Griffin Sean C. Griffin

Sean C. Griffin is a Member in the Washington, D.C. office of Dykema. Sean focuses his practice on commercial litigation, with a specialty in cases involving allegations of breach of contract or fraud. His experience includes litigating cases in federal and state courts…

Sean C. Griffin is a Member in the Washington, D.C. office of Dykema. Sean focuses his practice on commercial litigation, with a specialty in cases involving allegations of breach of contract or fraud. His experience includes litigating cases in federal and state courts and arbitration panels around the country. He also responds to subpoenas investigating violations of federal or state laws, including the False Claims Act, the U.S. Foreign Corrupt Practices Act (FCPA), and securities laws. Additionally, he assists clients with data security and responding to data breaches and is an IAPP Certified Information Privacy Professional (CIPP/US).

After graduating from Columbia University School of Law, Sean clerked for the U.S. District Court for the District of Maryland. After his clerkship, he worked as a trial attorney at the U.S. Department of Justice, Civil Division, where he handled commercial litigation trials and appeals as well as government contract and construction litigation.

Read more about Sean C. GriffinEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    The Firewall
  • Organization:
    Dykema
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo