Russian cyber actors are targeting organizations involved in coronavirus vaccine development, UK security officials have revealed.

The UK National Cyber Security Centre (NCSC) has published an advisory, detailing activity of the threat group known as APT29, which has exploited organizations globally.

The NCSC assesses that APT29, also named “the Dukes” or “Cozy Bear” almost certainly operate as part of Russian intelligence services. This assessment is also supported by partners at the Canadian Communication Security Establishment (CSE), the US Department for Homeland Security (DHS) Cybersecurity Infrastructure Security Agency (CISA) and the National Security Agency (NSA).

APT29’s campaign of malicious activity is ongoing, predominantly against government, diplomatic, think-tank, healthcare and energy targets to steal valuable intellectual property, says the NCSC. 

According to the advisory, throughout 2020, APT29 has targeted various organizations involved in COVID-19 vaccine development in Canada, the United States and the United Kingdom, highly likely with the intention of stealing information and intellectual property relating to the development and testing of COVID-19 vaccines. APT29, which uses a variety of tools and techniques such as spear-phishing, is using custom malware known as ‘WellMess’ and ‘WellMail’ to target a number of organizations globally, including those organizations involved with COVID-19 vaccine development. WellMess and WellMail have not previously been publicly associated to APT29, says the NCSC. 

NCSC Director of Operations, Paul Chichester, said, “We condemn these despicable attacks against those doing vital work to combat the coronavirus pandemic. Working with our allies, the NCSC is committed to protecting our most critical assets and our top priority at this time is to protect the health sector. We would urge organisations to familiarise themselves with the advice we have published to help defend their networks.”

The NCSC has previously warned that APT groups have been targeting organizations involved in both national and international COVID-19 responses.