Skip to main content

Russian cybercriminal hacked more than 60 government, education agencies

exploit
Image used with permission by copyright holder
Studies have shown that millions of internet-connected machines are vulnerable to cyberattack based on a variety of configuration and other issues. One vulnerability that cybercriminals can use to relatively easily attack systems is called “SQL injection,” meaning that a database server that doesn’t carefully check the data submitted on web forms, for example, can be compromised.

One SQL injection, or SQLi, threat is known as “Rasputin,” referring to a Russian-speaking cybercriminal who has been linked to a number of attacks against various government and private agencies. A recent attack by Rasputin targeted over 60 government and educational institutions, and the solution to such attacks is to change the penalties and incentives related to resolving SQLi issues, according to a recent Recorded Future analysis.

Recorded Future
Recorded Future
Recommended Videos

Recorded Future is a threat intelligence company that uses machine learning to reduce online security risks. The company worked with law enforcement in December 2016 to assess the database attack on the United States Election Assistance Commission (EAC) and the eventual sale of information. It’s Recorded Future who gave the actor the name Rasputin, and according to its analysis, Rasputin used SQLi technology to hack into the EAC’s database.

Please enable Javascript to view this content

SQLi attacks nothing new, having been around for more than 15 years. Malicious agents don’t need special skills or knowledge to conduct SQLi attacks, given that a number of tools are freely available that automate finding and attacking vulnerable database servers. The tools literally make conducting SQLi attacks a “point and click” affair.

Recorded Future
Recorded Future

Rasputin is a bit more sophisticated, as Recorded Future reports, having created his own proprietary SQLi tool. The reason for investing the time in creating such a tool and carrying out such attacks is purely financial — there’s a significant market for information that can generate real money for cybercriminals.

Recorded Future concludes that a number of steps need to be taking to respond to SQLi attacks and reduce their prevalence and impact. First is to raise awareness among developers, but that’s not enough. Rather, penalties and incentives need to be created to make it worthwhile to maintain database and web form security. Until the issues are addressed, however, agents like Rasputin will have their own incentives to hack into our data, often with serious repercussions.

Mark Coppock
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
The 10 announcements that made 2024 a landmark year for AI
ChatGPT and Siri integration on iPhone.

We've officially passed the second anniversary of the start of the AI boom, and things haven't slowed down. Just the opposite. Generative AI is ramping up at a pace that feels nearly overwhelming, expanding into new platforms, mediums, and even devices at a relentless pace.

Here are the 10 announcements that made 2024 a monumental year in the world of AI.
OpenAI releases GPT-4o

Read more
AMD’s next GPU already has two big problems
AMD logo on the RX 7800 XT graphics card.

We're about to enter a new era of GPUs, with Nvidia, AMD, and Intel duking it out for slots among the best graphics cards. But this time around, things are different. Team Red, which has traditionally served as a downward force on prices against much more popular Nvidia GPUs, is caught in the middle of a graphics card market that's headed in two vastly different directions.

Although AMD has yet to formally unveil its RDNA 4 graphics cards, the company has confirmed that it's coming early next year. The details about AMD's next-gen GPUs are still up in the air, but you don't need any official specs or benchmarks to see the precarious position that AMD is in. The company's next-gen graphics cards already have two big problems -- Nvidia, which likely will pursue flagship dominance, and AMD itself.
A picture of what's coming

Read more
Why I traded my MacBook Air for a laptop you’ve never heard of
Honor MagicBook Art 14 Snapdragon with screen on.

I’ve been using the M2 MacBook Air since its launch, and it has been a reliable laptop. It's not perfect though. I wish the display was better and that the laptop was lighter as I’ve had experiences where my carry-on luggage ended up being heavier than expected. And both of these are things even the M3 MacBook Air doesn't address.

What I didn't know, however, was that those wishes could come true in a more feature-packed laptop most people have never heard of. I'm talking about the Honor MagicBook Art 14, powered by the Snapdragon X.

Read more