Thursday, March 27, 2025
HomeComputer SecurityRussian Google "Yandex" Hacked with Rare Type of Malware called Regin to...

Russian Google “Yandex” Hacked with Rare Type of Malware called Regin to Spy on Users Accounts

Published on

SIEM as a Service

Follow Us on Google News

Russian Internet Giant Yandex hacked by Western intelligence agencies hackers with a rare type of malware called “Regin” to spy on Yandex users account.

Yandex is a Russian search engine also specializing in Internet-related products and services including Commerce, transportation, navigation, mobile applications, and online advertising. Yandex is widely known as Russian Google.

The attacker was conducted between October and November 2018 by deploying the malware on the Yandex Network.

Regin is one of a sophisticated and rare piece of malware which is used by  “Five Eyes” intelligence-sharing alliance of the United States, Britain, Australia, New Zealand, and Canada, Reuters Reported.

Based on the secret source who has direct knowledge about this attack reported from Russia, “It could not be determined which of the five countries was behind the attack on Yandex”

The attack was targeted the Yandex’s research and development unit, and the purpose of this hack is not to disrupt or steal intellectual property but for espionage purposes.

An interesting fact is that the code deployed on the Yandex’s systems had not been found any cyber attack so far.

In this case, Yandex called the Russian Cybersecurity Firm Kaspersky to perform further investigation and they said that the attack was targeting a group of developers inside Yandex.

Hackers who have involved this attack maintain the covertly maintained the highly persistent access to Yandex for at least several weeks without being detected.

According to the Routers report “The hackers appeared to be searching for technical information that could explain how Yandex authenticates user accounts. Such information could help a spy agency impersonate a Yandex user and access their private messages.”

“This particular attack was detected at a very early stage by the Yandex security team. It was fully neutralized before any damage was done,” he said. “Yandex security team’s response ensured that no user data was compromised by the attack.” Yandex spokesman Ilya Grabovsky said.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Also Read:

Chinese APT 10 Hackers Attack Government and Private Organizations Through Previously Unknown Malware

Chinese Hackers from APT 10 Hacking Group Charged for a Cyber Attack on NASA

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Use “Atlantis AIO” Tool to Automate Credential Stuffing Attacks

In a concerning development for cybersecurity professionals, threat actors are increasingly utilizing a powerful...

Hackers Exploit COM Objects for Fileless Malware and Lateral Movement

Security researchers Dylan Tran and Jimmy Bayne have unveiled a new fileless lateral movement...

B1ack’s Stash Marketplace Actors Set to Release 4 Million Stolen Credit Card Records for Free

In a significant escalation of illicit activities, B1ack’s Stash, a notorious dark web carding...

Pakistan APT Hackers Weaponize malicious IndiaPost Site to Target Windows and Android Users

A Pakistan-based Advanced Persistent Threat (APT) group, likely APT36, has launched a multi-platform cyberattack...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Use “Atlantis AIO” Tool to Automate Credential Stuffing Attacks

In a concerning development for cybersecurity professionals, threat actors are increasingly utilizing a powerful...

Hackers Exploit COM Objects for Fileless Malware and Lateral Movement

Security researchers Dylan Tran and Jimmy Bayne have unveiled a new fileless lateral movement...

B1ack’s Stash Marketplace Actors Set to Release 4 Million Stolen Credit Card Records for Free

In a significant escalation of illicit activities, B1ack’s Stash, a notorious dark web carding...