Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

COVID-19 Vaccine Attacks Teach an Important Cybersecurity Lesson

COVID-19 Vaccine Attacks Teach an Important Cybersecurity Lesson

Since the outbreak of the COVID-19 coronavirus has wreaked havoc across the globe, there has been a lot of hope and effort put towards developing a vaccine against it. Unfortunately, just as some experiments have produced promising results, hackers have begun targeting the research centers responsible. Let’s look at this situation to see what it can teach us.

The Cozy Bear Threat

According to the National Cyber Security Centre, a government security organization based in the United Kingdom, a hacking group known as “APT29” (also referred to as “the Dukes” or “Cozy Bear”) has actively targeted the research centers conducting research into developing a COVID-19 vaccine. These claims have been supported by both the United States’ National Security Agency and Canada’s Communications Security Establishment.

In fact, the National Cyber Security Center released a report that outlined the attack that the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency also endorses.

This report describes the use of various exploits in conjunction with spear phishing attacks by APT29. Both tactics give APT29 access to carry out the rest of their attacks, which often involves deploying malware known as WellMess or WellMail.

On a side note, some of these exploits have been patched, so make sure you’re also up to date on your patches as well.

Many experts also share the opinion that Cozy Bear has struck before, and that the current threat needs to be taken very seriously as a result. It is believed that APT29 was responsible for the 2016 intrusion into the Democratic National Committee’s systems, as reported by CNN. The group has also been linked to assorted attacks on healthcare, energy, governmental and diplomatic organizations, and think tanks in the past.

What is Spear Phishing?

Phishing is a form of hacking that targets the end user, rather than using software vulnerabilities, to gain access to a system. Spear phishing is a more direct form of phishing. Instead of sending a generic message to massive groups of potential targets to see who takes the bait, spear phishing is specifically directed to an individual with access to key data and resources.

While APT29 may not target your organization as a part of these efforts to steal research, it is nevertheless critical that you and your team can recognize a potential phishing attack and mitigate it before it causes significant problems. While the following is by no means a comprehensive list of warning signs, it is a good place to start educating your team:

  • Always check the details. Many phishing attacks can be identified by close-but-no-cigar “From” addresses. When in doubt, try looking up the email address that sent an email.
  • Proofread the message. While legitimate messages can contain terrible spelling and grammar mistakes, and attackers can more and more effectively mimic professional communications, many phishing messages can be rife with errors.
  • Double-check. If possible, don’t be afraid to confirm that the email is legitimate by reaching out to the supposed sender (through some non-email form of communication) to confirm that they sent the message.

For more assistance in dealing with phishing attacks, reach out to us! At Total Tech Care, we’re motivated to help prevent a phishing attack from impacting your operations. Give us a call at 866-348-2602 to learn more.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 30 April 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Software Efficiency Network Security Business Google Microsoft Internet Email Malware Backup Workplace Tips Innovation Data User Tips Computer Mobile Devices Hardware IT Services Disaster Recovery Android VoIP communications Smartphones Business Continuity Communication IT Support Miscellaneous Smartphone Mobile Device Browser Small Business Network Productivity Collaboration Quick Tips Cybersecurity Users Business Management Phishing Upgrade Windows Managed IT Services Data Backup Outsourced IT Ransomware Windows 10 Office Data Recovery Cloud Computing Server Save Money Passwords Windows 10 Virtualization Saving Money Holiday Social Media Gadgets Chrome Tech Term Automation Managed IT Services Managed Service Microsoft Office Computers Facebook Cybercrime Operating System Artificial Intelligence BYOD Mobile Device Management Networking IT Support Internet of Things Health Hacking Wi-Fi Remote Spam Office 365 Telephone Systems Covid-19 Information Technology Information Managed Service Provider Alert Router Bandwidth BDR Recovery Employer-Employee Relationship Social Engineering Mobility Password Data Breach Remote Monitoring Money Mobile Computing Encryption Applications App History Application Law Enforcement Human Resources Big Data Mobile Office Apps Office Tips How To Training Blockchain Government Paperless Office VPN Private Cloud Data Storage Patch Management Remote Computing Managed IT HaaS Work/Life Balance Servers Flexibility Marketing WiFi IT solutions Entertainment Website Data Security Budget Google Drive Wireless Avoiding Downtime Gmail Settings Vulnerability Two-factor Authentication Infrastructure Voice over Internet Protocol Windows 7 Word Bring Your Own Device Data Management Mouse Cleaning User Error Vendor Management Meetings Data Protection End of Support Vendor Education Physical Security Risk Management Managed Services Safety Display Hacker Sports USB HIPAA Redundancy Keyboard The Internet of Things Lithium-ion battery Employee/Employer Relationship Telephone System Staff RMM Software as a Service Machine Learning Remote Work Firewall Connectivity Conferencing Save Time Virtual Reality Apple Scam Social Computing Infrastructure Fraud Botnet Net Neutrality Workplace Strategy Unified Threat Management Going Green IT Plan Help Desk Remote Worker Computer Accessories Printing Cryptocurrency Unsupported Software Wearable Technology Battery Hard Drives Shadow IT Charger Retail Instant Messaging Legal Managed Services Provider Compliance Robot Excel Printer Comparison Internet Exlporer Database OneNote Computer Care Bluetooth Current Events Biometrics CES Telephony Virtual Desktop Remote Workers PDF Samsung Business Technology Content Management Processor DDoS Access Control Proactive IT Value IT Consultant SharePoint Virtual Assistant Hard Drive Best Practice Spam Blocking Electronic Medical Records Authentication Humor YouTube Black Market Computing Hiring/Firing Customer Service Environment Update Fax Server Document Management Solid State Drive Wireless Technology How to Downtime Google Docs Identity Theft Digital Signage SaaS Business Intelligence Data storage Audit Worker Automobile IT Management Network Congestion eWaste Augmented Reality Virus Procurement PowerPoint Social Network Windows Media Player Computer Fan Search Engine Rootkit User Twitter Tablets NIST Entrepreneur Business Mangement Investment Streaming Media Workers Benefits Employees Smart Tech Reputation Employee/Employer Relationships Trending Amazon Tech Support ISP FENG Shortcut Managing Stress Content Windows 365 Addiction IBM Cost Management Techology Video Conferencing Recycling Laptop ROI Flash Shortcuts Wiring Smart Technology Social Networking Sales Practices Cameras Customers Bitcoin Personal Amazon Web Services Cryptomining Audiobook Point of Sale Cache Supercomputer Safe Mode Supply Chain Management Criminal Touchpad Software Tips Sync Emails Running Cable GDPR Monitoring Hosted Computing Batteries Memory Advertising Digitize Online Shopping Politics Windows 8.1 Wireless Internet File Sharing Windows Server 2008 R2 Notifications Netflix Camera Two Factor Authentication Customer relationships Inventory Printer Server Specifications Email Best Practices Wire IT Assessment Evernote Manufacturing Root Cause Analysis Knowledge Music Travel HBO Managed IT Service Millennials Skype Security Cameras Printers Computer Tips Science Relocation Virtual CIO Smart Office OneDrive Wireless Charging Biometric Security Data loss Leadership Troubleshooting Video Games Peripheral Outlook Using Data Workforce Start Menu Distributed Denial of Service Virtual Private Network Customer Relationship Management Worker Commute Digital Security Cameras Experience Analyitcs Copiers Cables 5G Screen Mirroring Loyalty Books Programming Scalability Quick Tip Frequently Asked Questions Telecommuting Mobile Smartwatch Windows 10s Project Management Business Owner Ergonomics Nanotechnology Development Cortana NarrowBand OLED Cast webinar Antivirus Emergency Consultant Search PCI DSS Digital Signature Virtual Machine Tip of the week iPhone Fiber Optics Professional Services Employee Public Cloud Warranty Employer Employee Relationship 2FA Windows 8 Analytics HVAC Messaging Google Apps Cabling Assessment IT service Best Available Policy Analysis Hypervisor Windows Server 2008 Files Trend Micro Tools Administrator WIndows 7 Dark mode Devices Tablet Enterprise Content Management SMS Chromecast Default App Television Domains MSP Procedure Accountants Saving Time Colocation Shopping Credit Cards Uninterrupted Power Supply Google Search IaaS Microchip Maintenance dark theme Thought Leadership Password Management Bloatware AI Password Manager IT Infrastructure Public Computer Bing Transportation FinTech Monitor Multi-Factor Security Regulations

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code