Sign in

Alena Popova

@alenapopova.bsky.social
661 followers 79 following 79 posts

Founder at Cyber Guardians for Democracy | Cyber threats & Geopolitics

PostsRepliesMedia
Alena Popova @alenapopova.bsky.social · 21/02/2025
Germany’s security services warned that fake videos circulating online, which purported to reveal ballot manipulation in the country’s upcoming federal elections, were part of a Russian information operation. therecord.media/german-elect...
therecord.media
German election targeted by Russian disinformation, security services warn
Germany’s security services warned on Friday that fake videos circulating online purporting to reveal ballot manipulation in the country’s upcoming federal elections were part of a Russian information...
001
Alena Popova @alenapopova.bsky.social · 19/02/2025
Employees at major U.S. defense contractors including Lockheed Martin, Boeing, L3Harris, Leidos and Honeywell have been infected with infostealer malware. U.S. military and government agencies were also affected. www.infostealers.com/article/info...
040
Alena Popova @alenapopova.bsky.social · 19/02/2025
Several Russian state-aligned threat actors target Signal Messenger accounts. Their operational interest has likely been sparked by wartime demands to gain access to sensitive government and military communications in the context of Russia's invasion of Ukraine. cloud.google.com/blog/topics/...
cloud.google.com
Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger | Google Cloud Blog
Russia state-aligned threat actors target Signal Messenger accounts used by individuals of interest to Russia's intelligence services.
000
Alena Popova @alenapopova.bsky.social · 03/02/2025
Russia is suspected of compromising the personal email account of British Prime Minister Keir Starmer before he took office. therecord.media/keir-starmer...
therecord.media
Russian hackers suspected of compromising British PM’s personal email account
Russia is suspected of hacking into the personal email account of Keir Starmer before before he became Britain's prime minister, according to a new book.
142
Alena Popova @alenapopova.bsky.social · 31/01/2025
Russian influence operation Doppelganger accounts have become active on Bluesky, focusing on narratives discrediting Ukraine and the German coalition government. The campaign also spreads polarizing narratives and sexualized hate against Ukrainian women. alliance4europe.eu/doppelganger...
alliance4europe.eu
Sky's the Limit - Russian Influence Operation Doppelgänger Expands to Bluesky - Alliance4Europe
This flash report describes the key behaviours of what is likely the Russian influence operation Doppelgänger’s expansion to Bluesky.
053
Alena Popova @alenapopova.bsky.social · 30/01/2025
Russian intelligence agencies, including the GRU and FSB, have reportedly posted job offers with payments between $3,130 and $4,170 to Polish citizens willing to spread disinformation online, according to Poland’s digital affairs minister. therecord.media/poland-accus...
therecord.media
Poland accuses Russia of recruiting Polish citizens online for election meddling
Russia is attempting to recruit Polish citizens via the darknetto conduct influence operations ahead of Poland’s presidential election, a senior Polish official said.
020
Alena Popova @alenapopova.bsky.social · 29/01/2025
Threat actors from China, Russia, Iran, and North Korea are interacting with Google's LLM model, Gemini, to support their cyberattacks and coordinated information operations. cloud.google.com/blog/topics/...
010
Alena Popova @alenapopova.bsky.social · 29/01/2025
Chinese state-linked Spamouflage influence operation has repeatedly targeted the Spain-based non-profit Safeguard Defenders and impersonated the organization to spread calls for the Spanish government to be overthrown following deadly floods in Valencia. graphika.com/reports/chin...
graphika.com
Chinese State Influence
Chinese covert influence operations have impersonated human rights organizations critical of Beijing, almost certainly in an effort to discredit their activities and disrupt domestic political convers...
030
Alena Popova @alenapopova.bsky.social · 28/01/2025
Ukrainian military officials, lawmakers, and experts are discussing the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, according to the General Staff of Ukraine. kyivindependent.com/ukraine-cons...
kyivindependent.com
Ukrainian military considering creation of new cyber army branch
Ukrainian military, lawmakers, and experts discussed the creation of a separate branch of Ukraine's Armed Forces dedicated to cyberspace operations, the General Staff said on Oct. 24.
031
Alena Popova @alenapopova.bsky.social · 28/01/2025
The EU sanctioned three hackers from Unit 29155 of Russia's military intelligence service (GRU) for their involvement in cyberattacks targeting Estonian government agencies in 2020. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
EU sanctions Russian GRU hackers for cyberattacks against Estonia
The European Union sanctioned three hackers, part of Unit 29155 of Russia's military intelligence service (GRU), for their involvement in cyberattacks targeting Estonia's government agencies in 2020.
010
Alena Popova @alenapopova.bsky.social · 27/01/2025
The Iranian cyber threat actor Handala claimed responsibility for breaching the emergency systems of Maager-Tec at 20 kindergartens across Israel, playing rocket sirens, Arabic messages, and songs that support terror on Sunday morning. www.jpost.com/israel-news/...
jpost.com
Iranian hackers broadcast rocket sirens, pro-terror songs at 20 Israeli kindergartens
The breach reportedly exploited Maager-Tec's interfaces, which are responsible for emergency button systems at various institutions across Israel.
000
Alena Popova @alenapopova.bsky.social · 23/01/2025
A Russian disinformation campaign, Storm-1516, established around 100 fake news sites ahead of Germany's federal election. The traces lead to a former U.S. police officer, the Russian troll factory Internet Research Agency (IRA), and the GRU. correctiv.org/faktencheck/...
correctiv.org
Einflussoperation enttarnt: Russland greift in deutschen Wahlkampf ein
CORRECTIV hat rund 100 Fake-Nachrichtenseiten enttarnt. Ihr Zweck: die Bundestagswahl mit Desinformation beeinflussen.
021
Alena Popova @alenapopova.bsky.social · 23/01/2025
Chinese state-sponsored threat actors, including Mustang Panda and Tonto Team, have been targeting Russian aerospace and defense firms. The attacks aimed to steal sensitive information on Russia's advanced weapons programs, particularly nuclear submarines. www.politico.eu/article/chin...
politico.eu
China’s cyber spies are targeting Russia’s aerospace and defense firms
State-backed hackers seek intel on nuclear weapons and military capabilities, researchers say.
000
Alena Popova @alenapopova.bsky.social · 22/01/2025
A deal signed last week between Iran and Russia outlines commitments to strengthen their military, security, and technological ties. The agreement includes provisions for cooperation in cybersecurity and internet regulation. therecord.media/russia-iran-...
therecord.media
Iran and Russia deepen cyber ties with new agreement
The pact between the world’s two most sanctioned nations aims to elevate relations "to a new level,” the Kremlin said.
010
Alena Popova @alenapopova.bsky.social · 18/01/2025
Social Design Agency (SDA), a Russian organization tied to the Kremlin’s covert influence campaigns, posted over 8,000 political ads on Facebook despite European and American bans on doing business with it. www.nytimes.com/2025/01/17/b...
nytimes.com
Russian Disinformation Campaigns Eluded Meta’s Efforts to Block Them
A new report details how a covert influence operation linked to the Kremlin continued to place ads on Facebook despite U.S. and E.U. prohibitions on doing business with the organization.
010
Alena Popova @alenapopova.bsky.social · 17/01/2025
The Russian state-sponsored threat actor Star Blizzard attempted to compromise WhatsApp accounts of nonprofits supporting Ukraine. It used phishing messages impersonating U.S. government officials, inviting recipients to join a WhatsApp group. therecord.media/russia-star-...
therecord.media
Russian Star Blizzard hackers exploit WhatsApp accounts to spy on nonprofits aiding Ukraine
The Moscow-linked group has been sending phishing messages impersonating U.S. government officials with an invitation to join a fake WhatsApp group for nonprofits supporting Ukraine during the war.
020
Alena Popova @alenapopova.bsky.social · 14/01/2025
Crew of France's atomic-armed submarines publicly share workouts via the Strava app, inadvertently disclosing sensitive patrol schedule information. www.lemonde.fr/en/videos/ar...
lemonde.fr
StravaLeaks: Dates of French nuclear submarine patrols revealed by careless crew members
Crew of France's atomic-armed submarines publicly share workouts via the Strava app, inadvertently disclosing sensitive patrol schedule information.
000
Alena Popova @alenapopova.bsky.social · 14/01/2025
Over the past few years, Barcelona has become a hub for offensive cybersecurity companies, offering attractive tax benefits, fewer restrictions, beautiful beaches, and a vibrant expat community. techcrunch.com/2025/01/13/h...
techcrunch.com
How Barcelona became an unlikely hub for spyware startups | TechCrunch
Barcelona's mix of affordable cost of living and quality of life has helped create a vibrant startup community — and become a hotbed for the creation of surveillance technologies.
111
Alena Popova @alenapopova.bsky.social · 13/01/2025
A Russian state-linked threat actor, sharing overlaps with APT28, conducted a cyber espionage campaign targeting Central Asia, including Kazakhstan and its diplomatic and economic relations with Asian and Western countries. blog.sekoia.io/double-tap-c...
blog.sekoia.io
Double-Tap Campaign: Russia-nexus APT possibly related to APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations
Uncover the details of UAC-0063 cyberespionage campaign in Kazakhstan and its potential connection to APT28
010
Alena Popova @alenapopova.bsky.social · 13/01/2025
Ukraine’s CERT-UA handled 4,315 cyber incidents in 2024, a 69.8% rise from 2023. The most targeted sectors include local governments, federal government agencies, security and defense, energy, business, and telecommunications. euromaidanpress.com/2025/01/12/r...
euromaidanpress.com
Russian cyberattacks on Ukraine surge 70% in 2024 with 4,315 assaults on critical infrastructure
Ukraine's cyber defense teams battle an avalanche of Russian attacks targeting government services and critical infrastructure, with incident rates nearly doubling from previous year.
120
Alena Popova @alenapopova.bsky.social · 09/01/2025
Chinese state-sponsored threat actor breached the Philippine government's executive branch and stole sensitive data, including military documents related to the ongoing China-Philippines territorial dispute in the South China Sea. www.bloomberg.com/news/article...
bloomberg.com
Chinese Hackers Target Philippine President and Steal Military Data
Chinese-state sponsored hackers penetrated the executive branch of the Philippines government and stole sensitive data as part of a yearslong campaign, according to three people familiar with the matt...
011
Alena Popova @alenapopova.bsky.social · 08/01/2025
Russia has a special intelligence unit focused on carrying out cyberattacks against Poland, Deputy Prime Minister Krzysztof Gawkowski said. According to him, Poland is the EU member state most frequently targeted by Russia. tvpworld.com/84412549/mos...
tvpworld.com
Moscow has special cyber-unit targeting Poland, says minister
Poland is the EU country most under attack, the digital affairs minister said.
130
Alena Popova @alenapopova.bsky.social · 08/01/2025
Japan has linked more than 200 cyberattacks over the past five years, targeting national security and advanced technology data, to the Chinese cyber threat actor MirrorFace. The targets included Japan's Foreign and Defense Ministries and its space agency. abcnews.go.com/Internationa...
abcnews.go.com
Japan links hacker MirrorFace to dozens of cyberattacks targeting security, tech data
Japan has linked more than 200 cyberattacks over the past five years targeting the country’s national security and high technology data to a Chinese hacking group, MirrorFace
000
Alena Popova @alenapopova.bsky.social · 07/01/2025
The Lithuanian Ministry of National Defense has officially launched the Lithuanian Cyber Command (LTCYBERCOM), a new unit within the Lithuanian Armed Forces. defence-industry.eu/lithuania-la...
defence-industry.eu
Lithuania launches Cyber Command to bolster national defence and cybersecurity
The Lithuanian Ministry of National Defence has officially launched the Lithuanian Cyber Command (LTCYBERCOM), a new unit within the Lithuanian Armed Forces.
120
Alena Popova @alenapopova.bsky.social · 07/01/2025
Countries in Central Asia and Latin America base their digital surveillance capabilities on Russia’s System for Operative Investigative Activities (SORM). This will not only increase political repression but also likely grant Russia access to information. www.recordedfuture.com/research/tra...
recordedfuture.com
Unveiling Russian Surveillance Tech Expansion in Central Asia and Latin America
A new report by Recorded Future’s Insikt group finds that countries across Central Asia and Latin America are increasingly basing their digital surveillance practices on Russia's System for Operative ...
125
Alena Popova @alenapopova.bsky.social · 06/01/2025
Taiwan's National Security Bureau stated that the number of cyberattacks on Taiwan in 2024 has doubled compared to 2023. Most of these attacks are attributed to the PRC cyber force. www.nsb.gov.tw/en/#/%E5%85%...
000
Alena Popova @alenapopova.bsky.social · 04/01/2025
Integrity Tech, a Beijing-based cybersecurity company linked to the Ministry of State Security, was sanctioned by the U.S. Among other things, it aided the Chinese state-sponsored threat actor Flax Typhoon in targeting U.S. critical infrastructure. www.state.gov/sanctioning-...
state.gov
Sanctioning PRC Cyber Company Involved in Malicious Botnet Operations - United States Department of State
The United States is imposing sanctions today on the Beijing-based cybersecurity company Integrity Technology Group, Incorporated (Integrity Tech), which has links to the People’s Republic of China (P...
010
Alena Popova @alenapopova.bsky.social · 03/01/2025
Atos, a French technology company that secures communications for France’s military and intelligence services, dismissed as “unfounded” claims by the Space Bears ransomware group that it had compromised an internal company database. therecord.media/atos-dismiss...
therecord.media
Atos, contractor for French military and intelligence agencies, dismisses ransomware attack claims
Atos, the company that secures communications for France’s military and intelligence services, says a ransomware group’s claims are "unfounded."
010
Alena Popova @alenapopova.bsky.social · 30/12/2024
A Chinese state-sponsored cyber threat actor breached the U.S. Treasury Department's systems this month, stealing documents from its workstations. www.reuters.com/technology/c...
reuters.com
US Treasury's workstations breached in cyberattack by China, AFP reports
A Chinese state-sponsored actor was behind a cyberattack on the U.S. Treasury Department earlier this month, resulting in unauthorized access to some of its workstations, Agence France-Presse reported on Monday, citing a letter to Congress.
000
Alena Popova @alenapopova.bsky.social · 29/12/2024
Movement data from VW, Seat, Audi, and Skoda electric cars, along with owners' contact information, were left unprotected in Amazon cloud storage. The 800,000 affected vehicle owners include politicians, police, and intelligence service employees. www.spiegel.de/netzwelt/web...
010
Alena Popova @alenapopova.bsky.social · 26/12/2024
South Korea has sanctioned 14 North Koreans for their involvement in an overseas IT worker scheme. They are connected to the 313th General Bureau, a subsidiary of the DPRK's Munitions Industry Department (MID). down.mofa.go.kr/www/brd/m_40...
000
Alena Popova @alenapopova.bsky.social · 25/12/2024
AdNow, a Russian advertising firm, was previously involved in a campaign spreading disinformation about Western coronavirus vaccines. After relocating to Bulgaria, the company has been conducting political influence campaigns in Romania and Bulgaria. www.ft.com/content/a0a0...
ft.com
From vaccines to votes: Russian ad agency influences Europeans
AdNow was implicated in misinformation campaigns in France, Germany and Romania
010
Alena Popova @alenapopova.bsky.social · 24/12/2024
The North Korean threat actor UNC4899, associated with the Reconnaissance General Bureau (RGB), stole $308 million in cryptocurrency during an attack on the Japanese crypto exchange DMM Bitcoin. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
FBI links North Korean hackers to $308 million crypto heist
The North Korean hacker group 'TraderTraitor' stole $308 million worth of cryptocurrency in the attack on the Japanese exchange DMM Bitcoin in May.
011
Alena Popova @alenapopova.bsky.social · 23/12/2024
As North Korea became a key perpetrator of cryptocurrency heists, South Korea and the United States will collaborate on research to develop technologies aimed at preventing cryptocurrency-targeted attacks and tracking stolen assets. koreajoongangdaily.joins.com/news/2024-12...
koreajoongangdaily.joins.com
South Korea and U.S. team up to combat crypto heists as North Korean cyber threats rise
South Korea and the United States are conducting joint research to strengthen protection against cryptocurrency heist attempts amid growing concerns of such attacks by North Korea-linked hackers, offi...
100
Alena Popova @alenapopova.bsky.social · 20/12/2024
North Korea's state-sponsored Lazarus Group has been observed targeting employees of an unnamed nuclear-related organization. thehackernews.com/2024/12/laza...
thehackernews.com
Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware
Lazarus Group's CookiePlus malware targets nuclear engineers, showcasing DPRK's evolving arsenal and $1.34B in 2024 crypto thefts.
000
Alena Popova @alenapopova.bsky.social · 20/12/2024
Russia has carried out a cyberattack on Ukraine's state registries, which contain vital information about Ukrainian citizens, such as births, deaths, marriages, and property ownership. www.reuters.com/technology/c...
reuters.com
Russia conducted mass cyberattack on Ukraine's state registries, deputy PM says
Russia has carried out a mass cyberattack on Ukraine's state registries, Ukrainian Deputy Prime Minister Olha Stefanishyna said late on Thursday, resulting in a temporary suspension of services.
020
Alena Popova @alenapopova.bsky.social · 19/12/2024
Russian state-sponsored threat actor Sandworm, in its latest espionage campaign, has targeted Ukrainian soldiers using the newly developed military app Army+, designed to digitize bureaucratic tasks like submitting reports to commanders. therecord.media/ukraine-mili...
therecord.media
Sandworm-linked hackers target users of Ukraine’s military app in new spying campaign
Russian hackers are creating fraudulent websites that mimic the official page of Army+, a Ukrainian military app, with the goal of spreading malware for espionage.
010
Alena Popova @alenapopova.bsky.social · 19/12/2024
In 2024, crypto funds worth $2.2 billion were stolen worldwide. Of this amount, 61%, or $1.34 billion, was stolen by North Korean hackers—more than ever before. www.chainalysis.com/blog/crypto-...
010
Alena Popova @alenapopova.bsky.social · 19/12/2024
According to French intelligence, over 2,000 European content creators were approached by individuals linked to the Kremlin to spread pro-Russian propaganda. About 20 of them, including nine French nationals, reportedly accepted the offer. www.lemonde.fr/pixels/artic...
lemonde.fr
Des milliers d’influenceurs, dont des Français, approchés par des personnes proches du Kremlin pour diffuser de la propagande prorusse
Selon une source au sein des services de renseignement français, plus de 2 000 producteurs de contenus européens ont été contactés. Une vingtaine d’entre eux, dont neuf Français, auraient accepté le m...
021
Alena Popova @alenapopova.bsky.social · 18/12/2024
During Q4 2024, Google terminated 4,947 YouTube channels associated with Russian coordinated influence operations and 6,318 YouTube channels linked to Chinese ones. blog.google/threat-analy...
blog.google
TAG Bulletin: Q4 2024
This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q4 2024. It was last updated on December 17, 2024.OctoberWe terminated 11…
032
Alena Popova @alenapopova.bsky.social · 18/12/2024
Based in the United Arab Emirates (UAE), Chinese nationals were involved in laundering millions of dollars in illicit funds generated by North Korea's IT worker schemes and cybercrime to support the DPRK government. home.treasury.gov/news/press-r...
home.treasury.gov
Treasury Disrupts North Korean Digital Assets Money Laundering Network
Action taken in partnership with the United Arab Emirates targets a key node in the Kim regime’s illicit revenue generation schemesWASHINGTON — Today, the Department of the Treasury’s Office of Foreig...
001
Alena Popova @alenapopova.bsky.social · 18/12/2024
U.S. authorities are considering a ban on TP-Link, a China-based router manufacturer, whose equipment has been repeatedly targeted in Chinese cyberattacks. TP-Link currently holds approximately 65% of the U.S. market for SOHO routers. www.wsj.com/politics/nat...
wsj.com
Exclusive | U.S. Weighs Ban on Chinese-Made Router in Millions of American Homes
TP-Link is the bestselling router on Amazon—and has been linked to Chinese cyberattacks.
000
Alena Popova @alenapopova.bsky.social · 17/12/2024
German security authorities have arrested a 24-year-old on suspicion of aiding DDoS attacks carried out by the Russian threat actor Killnet. The arrest is part of Europol's "Power OFF" operation. www.bild.de/regional/sch...
bild.de
Hacker in Russland: Festnahme – Deutscher soll bei Computer-Sabotage geholfen haben
Behörden nehmen einen Verdächtigen aus Stormarn fest, der der russischen Hacker-Gruppe KillNET angehören und Computersabotage betrieben haben soll.
000
Alena Popova @alenapopova.bsky.social · 16/12/2024
Serbian police and intelligence agencies reportedly used phone spyware and mobile forensic tools developed by the Israeli company Cellebrite to extract data from the mobile devices of journalists and activists. securitylab.amnesty.org/latest/2024/...
securitylab.amnesty.org
Serbia: Authorities using spyware and Cellebrite forensic extraction tools to hack journalists and activists - Amnesty International Security Lab
Serbian police and intelligence authorities are using advanced phone spyware alongside Cellebrite mobile phone forensic products to unlawfully target journalists, environmental activists and other ind...
000
Alena Popova @alenapopova.bsky.social · 13/12/2024
Fourteen North Korean nationals have been indicted for conspiring to secure remote IT work in the U.S. using stolen identities. Operating through front companies in China and Russia, they generated $88 million over six years for the North Korean regime. www.justice.gov/opa/media/13...
000
Alena Popova @alenapopova.bsky.social · 13/12/2024
The Iranian threat group CyberAv3ngers, linked to the Islamic Revolutionary Guard Corps (IRGC), has used custom-built malware to target IoT and operational technology devices in the U.S. and Israel. The group’s primary focus is on civilian critical infrastructure. claroty.com/team82/resea...
claroty.com
Inside a New OT/IoT Cyberweapon: IOCONTROL
Team82 has researched a malware sample called IOCONTROL linked to an Iran-based attack group used to target IoT and OT civilian infrastructure in the U.S. and Israel.
020
Alena Popova @alenapopova.bsky.social · 12/12/2024
Earlier this year, the Russian state-sponsored cyber threat actor Secret Blizzard, linked to Russia’s Federal Security Service (FSB), utilized cybercrime infrastructure to compromise devices associated with the Ukrainian military. www.microsoft.com/en-us/securi...
microsoft.com
Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine | Microsoft Security Blog
Since January 2024, Microsoft has observed Secret Blizzard using the tools or infrastructure of other threat groups to attack targets in Ukraine and download its custom backdoors Tavdig and KazuarV2.
010
Alena Popova @alenapopova.bsky.social · 11/12/2024
The U.S. has sanctioned the Chinese government cybersecurity contractor Sichuan Silence and one of its employees for compromising 81,000 firewalls, including some belonging to U.S. critical infrastructure, and carrying out Ragnarok ransomware attacks. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
US sanctions Chinese firm for hacking firewalls in ransomware attacks
The U.S. Treasury Department has sanctioned Chinese cybersecurity company Sichuan Silence and one of its employees for their involvement in a series of Ragnarok ransomware attacks targeting U.S. criti...
033
Alena Popova @alenapopova.bsky.social · 09/12/2024
A suspected Russian cyber threat actor has been targeting Ukrainian military and defense enterprises by sending phishing emails inviting recipients to a conference in Kyiv on transitioning Ukrainian defense industry products to NATO standards. therecord.media/suspected-ru...
therecord.media
Suspected Russian hackers target Ukrainian defense enterprises in new espionage campaign
Ukraine’s military computer emergency response team said the group sent phishing emails disguised as invitations to a legitimate defense conference that took place in Kyiv last week.
000
Alena Popova @alenapopova.bsky.social · 05/12/2024
A programmer reported that the Russian Federal Security Service (FSB) installed spyware on his Android phone after detaining him in Moscow earlier this year. Security researchers confirmed the presence of spyware on his device. techcrunch.com/2024/12/05/r...
techcrunch.com
Russian programmer says FSB agents planted spyware on his Android phone | TechCrunch
Security researchers confirmed the programmer's phone had spyware, likely during a spell in Russian detention. The programmer told his story to TechCrunch.
000