US Offers $10M Reward for Russian Hackers Information
Hear’s a breakdown of the information provided in the text:
key individuals & Affiliation:
Hackers: Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov.
Affiliation: Officers in russia’s Federal Security Service (FSB).
Hacking Activities:
Targets: Over 500 foreign energy companies in 135 countries. Timeline: Activities occurred between May and September 2017 (specifically mentioned in relation to a refinery attack).
Impact:
Installed malware in a foreign refinery to disable safety systems, potentially causing damage, injury, and economic harm.
Exploited a critical vulnerability (CVE-2018-0171) in Cisco equipment (specifically the Smart Install feature of Cisco IOS and IOS XE software).
Legal Action & Rewards:
Indictments: The U.S. Department of Justice unsealed indictments against these individuals in 2022.
bounty: The State Department is offering a reward of up to $10 million for information leading to their arrest.
Vulnerability Details:
CVE-2018-0171: A CVSS 9.8 severity vulnerability in Cisco equipment.It’s a remote code execution flaw that is arduous to patch on end-of-life equipment.
* Exploitation: This vulnerability has been used by multiple hacking groups, not just this FSB unit.
Important Note: The text highlights that the vulnerability exploited dates back to 2018, suggesting the attacks are based on an older, but still potent, weakness.
