Intelligence

Top German official said Germany blocked Russian APT28 cyber attacks in 2016

According to a German top official, Germany warded off two cyber attacks launched by the Russian state actor APT28 group in 2016.

On Friday, a top German official told Reuters that last year Germany warded off two cyber attacks launched by the Russian APT28 group (aka Fancy BearPawn StormSednit, Sofacy, and Strontium)

According to Arne Schoenbohm, president of the Federal Office for Information Security (BSI), the first attack occurred in May 2016, the hackers attempted to create an Internet domain for Chancellor Angela Merkel’s Christian Democratic Union (CDU) party in the Baltic region

The second attack was observed months later, the hackers launched a spear-phishing campaign against German parties in the lower house of parliament, the Bundestag. Experts said that attack used a NATO domain name to try to inject malicious software into the networks of politicians.

“Experts said that attack used a NATO domain name to try to inject malicious software into the networks of politicians.” reported the Reuters agency.

The U.S. intelligence agencies warned in early this year that Russia was likely to target other European states in the next months, especially France and Germany that are holding major elections.

“Germany remains in danger in the cyber arena since we are highly digitized,” Schoenbohm told Reuters in an interview. “The more we digitize, the more dependent we become on networks, the greater the risk of attack.”

Schoenbohm explained that the German Government has largely invested to improve the security of its networks against cyber attacks. It is conducting an awareness campaign to educate politicians and parties about how to protect their networks.

“We give them advice and help them with certain measures. But in the end, what each party does is its own responsibility,” Schoenbohm said.

The official also added that Germany is sharing information on cyber attacks with other governments targeted by the APT28 group, including United States and France.

In 2015, the APT28 group stole 16 gigabytes of data from the German parliament. In December the APT28 group also targeted the Organization for Security and Cooperation in Europe (OSCE) in December, the organization is a security and human rights watchdog, the attack is part of a cyber espionage operation.

“Schoenbohm said neither of the 2016 attacks targeting Germany – or a string of others he did not detail – was successful, but it was unclear to what extent political parties might have experienced security breaches.” continues the Reuters.

Schoenbohm welcomed work by Merkel’s coalition on a law that would bolster the security posture of the Government. The law will enforce security for a growing number of household Internet-connected appliances that are exposed to cyber attacks.

The diffusion of IoT devices must be accomplished by a significant improvement of their security to keep the owner safe.

“The worst thing that could happen” would be that consumers withdrew from the so-called ‘Internet of Things’ for fear of being hacked, he said. “We want to have a successful digitization.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – cyber espionage, APT28)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

18 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

20 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.