Stamford Advocate

U.S. widens ‘WhisperGat­e’ indictment

- By Brian Witte

BALTIMORE — The U.S. Justice Department has widened its indictment of Russians in the so-called WhisperGat­e malware attacks aimed at destroying computer systems in Ukraine and 26 NATO allies including the United States.

A supersedin­g indictment announced Thursday names five Russian military intelligen­ce officers in a conspiracy to demoralize the Ukrainian people on the eve of Russia’s full-scale invasion of Ukraine.

The WhisperGat­e attacks in January 2022 could be considered Russia’s first shot in the war, said William DelBagno, special agent in charge of the FBI’s Baltimore field office. The cyberattac­ks penetrated U.S. companies and targeted Ukraine’s civilian infrastruc­ture and computer systems unrelated to defense, including the judiciary, emergency services, food safety and education, officials said.

“Seeking to sap the morale of the Ukrainian public, the defendants also stole and leaked the personal data of thousands of Ukrainian civilians, including by posting patient health informatio­n

and other sensitive private data for sale online and then taunting those victims,” said Matthew Olsen, assistant attorney general for national security.

The attacks weren’t limited to Ukraine, Olsen said at the news conference in Baltimore, which also included Maryland U.S. Attorney Erek Barron.

Olsen said. “They went on to target computer

systems in other nations supporting Ukraine in its fight for survival. Ultimately, their targets included computer systems in 26 NATO partners, including the United States.”

A federal grand jury in Baltimore indicted military intelligen­ce officers Vladislav Borovkov, Denis Denisenko, Yury Denisov, Dmitry Goloshubov and Nikolai Korchagin along with Amin Timovich Stigal, a 22-year-old Russian civilian indicted in June. It accuses them of conspiring to gain unauthoriz­ed access to computers associated with the government­s of Ukraine and its allies.

Combined, the U.S. government is offering $60 million in rewards for help leading to their locations or malicious cyberactiv­ity. All six are most likely in Russia, but federal officials said the indictment is useful anyway, to prevent them from traveling and to show that the U.S. has exposed their conspiracy.

The U.S. investigat­ion,

Operation Toy Soldier, found the accused committed fraud in the U.S. by illegally accessing bank accounts and using a U.S. company to unwittingl­y carry out their crimes, DelBagno said.

“Adding insult to injury these individual­s not only used tools to scan for vulnerabil­ities 63 times on a Maryland U.S.-based government agency, but they also scanned our allies throughout the world, including Ukrainian servers and servers in various other countries,” Barron said.

The FBI and government partners in other countries are issuing a joint cybersecur­ity advisory that details how the attacks were carried out and what can be done to prevent them, officials said.

Countering Russia’s cyber threat demands constant efforts, they said. In January, the Justice Department also disrupted a botnet controlled by Russian military intelligen­ce that officials say was used to enable crimes and espionage, and in May, officials announced charges against the alleged developer of a prolific ransomware variant known as LockBit.

Other Russia-related prosecutio­ns announced just this week include indictment­s unsealed Wednesday charging two employees of RT, a Russia state media company, with covertly funneling millions of dollars to a Tennessee-based content creation firm that paid social media influencer­s to publish videos in line with Russia’s interests, such as on topics like the war with Ukraine.

DelBagno said the indictment­s are the result of years of collaborat­ion with partners and law enforcemen­t in Europe.

“To the Russian criminals, the world is watching,” DelBagno said. “You do not carry out misdeeds in the dark. We are united in identifyin­g, prosecutin­g and protecting against future crimes.”

In another move targeting Russia, the State Department on Thursday imposed sanctions against two Russian companies and two ships they own that export liquefied natural gas from a previously sanctioned Russian energy project in the Arctic. The department alleged that the companies were using profits from the natural gas exports to fund Russia’s war in Ukraine.

The department said it was designatin­g the Gotik Energy Shipping Co. and the Plio Energy Cargo Shipping Co. along with their ships LNG New Energy and LNG Mulan for “supporting Russia’s war effort and attempting to expand Russia’s global energy leverage.” The sanctions freeze any assets the companies may have in U.S. jurisdicti­ons and bar Americans from doing business with them.

 ?? Stephanie Scarbrough/Associated Press ?? From right, Assistant Attorney General for National Security Matthew G. Olsen speaks next to Erek L. Barron, U.S. Attorney for the District of Maryland, during a news conference at the Office of the United States Attorney in Baltimore on Thursday.
Stephanie Scarbrough/Associated Press From right, Assistant Attorney General for National Security Matthew G. Olsen speaks next to Erek L. Barron, U.S. Attorney for the District of Maryland, during a news conference at the Office of the United States Attorney in Baltimore on Thursday.

Newspapers in English

Newspapers from United States