Fancy Bear Malware Attacks Exposed by NCSC
Russian Cyber Espionage Group Fancy Bear Linked to Elegant “Authentic Antics” Malware
London, UK – A sophisticated new malware strain, dubbed ”Authentic Antics,” has been attributed to the Russian military intelligence-linked cyber-espionage group Fancy Bear. The malware is designed to stealthily gain persistent access to victim email accounts,exfiltrate data,and evade detection by blending seamlessly wiht legitimate user activity. The national Cyber Security Center (NCSC) has issued a warning, urging organizations to bolster their defenses against this advanced threat.
“Authentic Antics”: A Masterclass in Stealth and Deception
The NCSC’s analysis reveals that ”Authentic Antics” is engineered with a high degree of technical sophistication, specifically to exploit users’ growing familiarity with genuine Microsoft authentication prompts. This includes the ability to generate these prompts from within legitimate Outlook processes, ensuring they appear infrequently and thus avoid raising suspicion.
A key characteristic of “authentic Antics” is its complete lack of communication with any command and control (C2) infrastructure. This means it cannot receive external instructions or updates, making it significantly harder to detect and attribute during active operations. Instead, the malware interacts solely with legitimate services.
data exfiltration is achieved by sending emails from the compromised account to an email address controlled by Fancy Bear. Crucially, these sent emails are hidden from the victim’s sent items folder, further obscuring the malicious activity.
Design Principles: Blending In with Normal Activity
“Critically important thought” has been invested in the design of “Authentic Antics” to ensure it remains undetected.Its presence on disk is minimized,and it stores sensitive data in registry locations specific to Outlook. Moreover, its codebase incorporates genuine microsoft authentication library code as an obfuscation technique, making it appear as a legitimate component.
“It is clear the intention of the malware is to gain persistent access to victim email accounts,” stated NCSC analysts. ”This highlights the benefit of monitoring your tenant for suspicious logins.”
Sanctions and Broader Implications
The attribution of “Authentic Antics” to Fancy bear coincides with the proclamation of wider sanctions against three GRU Units, including Unit 26165, and 18 officers and agents. These individuals are accused of conducting cyber and data interference operations in support of Russia’s geopolitical and military objectives.
Among those sanctioned are GRU military intelligence officers implicated in the targeting and surveillance of Yulia Skripal, daughter of former Russian military intelligence officer Sergei Skripal, prior to the 2018 Novichok poisoning attempt in Salisbury.
“GRU spies are running a campaign to destabilise Europe, undermine ukraine’s sovereignty and threaten the safety of British citizens,” said Foreign Secretary David Lammy. “The Kremlin should be in no doubt: we see what they are trying to do in the shadows and we won’t tolerate it. That’s why we’re taking decisive action with sanctions against Russian spies.”
A NATO spokesperson echoed the UK’s stance, condemning Russia’s ongoing malicious cyber activities. The spokesperson noted previous attributions made to Fancy Bear for targeting Western logistics and technology organizations involved in supporting Ukraine’s defense.
“We call on Russia to stop its destabilising cyber and hybrid activities,” the spokesperson stated. “These activities demonstrate Russia’s disregard for the United Nations framework for responsible state behavior in cyberspace, which Russia claims to uphold.”
The spokesperson concluded, “Russia’s actions will not deter Allies’ support to Ukraine, including cyber assistance through the Tallinn Mechanism and IT capability coalition. We will continue to use the lessons learned from the war against Ukraine in countering Russian malicious cyber activity.”
