News

NSA, FBI issue Russian malware advisory

National Security Agency (NSA) and Federal Bureau of Investigation (FBI) personnel have issued a new Cybersecurity Advisory regarding previously undisclosed Russian malware.

The NSA and FBI said the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165 is deploying malware called Drovorub – designed for Linux systems as part of its cyberespionage operations.

“This Cybersecurity Advisory represents an important dimension of our cybersecurity mission, the release of extensive, technical analysis on specific threats,” NSA Cybersecurity Director Anne Neuberger said. “By deconstructing this capability and providing attribution, analysis, and mitigations, we hope to empower our customers, partners, and allies to take action. Our deep partnership with FBI is reflected in our releasing this comprehensive guidance together.”

Authorities indicated Drovorub consists of an implant coupled with a kernel module rootkit, a file transfer, and port forwarding tool, and a command and control (C2) server, adding when deployed on a victim machine it enables direct communications with actor-controlled C2 infrastructure; file download and upload capabilities; execution of arbitrary commands; port forwarding of network traffic to other hosts on the network; and implements hiding techniques to evade detection.

“For the FBI, one of our priorities in cyberspace is not only to impose risk and consequences on cyber adversaries but also to empower our private sector, governmental, and international partners through the timely, proactive sharing of information,” FBI Assistant Director Matt Gorham said. “This joint advisory with our partners at NSA is an outstanding example of just that type of sharing. We remain committed to sharing information that helps businesses and the public protect themselves from malicious cyber actors.”

Douglas Clark

Recent Posts

Bipartisan effort calls for details on foreign attempts to infiltrate U.S. military bases

A group of seven U.S. representatives recently wrote to Defense Secretary Lloyd Austin in a…

2 days ago

House bill calls for AI task force within Cybersecurity and Infrastructure Security Agency

As more governments and businesses seek what artificial intelligence (AI) can offer, U.S. Reps. Troy…

2 days ago

Senators push to preserve procurement levels for attack submarines

A group of 14 U.S. senators recently called on the U.S. Senate Appropriations Subcommittee on…

3 days ago

House advances appropriations for Coast Guard operations through 2026

In approving the Coast Guard Authorization Act of 2024 (H.R. 7659), the House recently authorized…

3 days ago

Commerce Department blacklists 37 Chinese entities over quantum, spying concerns

The U.S. Commerce Department recently added 37 Chinese entities to the Export Administration Regulations (EAR)…

4 days ago

U.S. Sens. Peters and Britt propose modern, better-suited body armor for DHS personnel

In introducing the DHS Better Ballistic Body Armor Act (S. 4305) this month, U.S. Sens.…

4 days ago

This website uses cookies.