DRC Militia Announces Plans to Disarm

The Cooperative for the Development of the Congo (CODECO) militant group said it would cease fighting in the country’s northeast and called for a dialogue with the government (Reuters).

Targeting of U.S. government employees
Date of report
  • January 2020
Affiliations
The Iranian state-backed hackers sent out sophisticated spear-phishing lures imitating Westat, a research services company, in hopes of compromising U.S. government employees and networks. They could have also intended to compromise actual Westat employees.
Suspected victims
  • U.S. government employees and possibly Westat employees
Suspected state sponsor
  • Iran (Islamic Republic of)
Type of incident
  • Espionage
Target category
  • Government
  • Private sector
Wide-ranging attacks on government organizations and companies across the Middle East and Europe
Date of report
  • January 2020
Affiliations
  • Government of Turkey
The Turkish hackers attacked at least thirty organizations across the Middle East and Europe, including Cypriot and Greek government email services and the Iraqi government’s national security advisor. Their methods include intercepting internet traffic to victim websites.
Suspected victims
  • Government organizations and companies across the Middle East and Europe
Suspected state sponsor
  • Turkey
Type of incident
  • Espionage
Target category
  • Government
  • Private sector
  • Civil society
Spyware sent to Jeff Bezos on WhatsApp
Date of report
  • January 2020
Affiliations
  • Government of Saudi Arabia
An account belonging to Prince Mohammed bin Salman sent Jeff Bezos spyware masquerading as a video over WhatsApp, which allowed Saudi Arabia to surveil Bezos’ phone from May 2018 until February 2019. The attack could have been related to Bezos’ ownership of the Washington Post, whose columnist Jamal Khashoggi was allegedly killed on bin Salman’s orders.
Suspected victims
  • Jeff Bezos
Suspected state sponsor
  • Unknown
Type of incident
  • Espionage
Target category
  • Private sector
  • Civil society
Stolen data on nearly two thousand Mitsubishi employees
Date of report
  • January 2020
Affiliations
The China-linked Bronze Butler threat actor is suspected to have used a zero-day in Trend Micro antivirus to attack Mitsubishi Electric and steal data on thousands of employees. In May 2020, it was disclosed that the breach resulted in the theft of specifications for a hypersonic missile that Japan had been developing to protect disputed territory in the East China Sea.
Suspected victims
  • Mitsubishi Electric employees
Suspected state sponsor
  • China
Type of incident
  • Espionage
Target category
  • Private sector
Compromise of Bapco
Date of report
  • January 2020
Affiliations
The Iranian state-backed hackers installed malware on the network of Bapco, Bahrain’s national oil producer. The malware, called Dustman, used a wiper functionality, but experts suspect this could have been meant to erase itself after being discovered.
Suspected victims
  • Bapco
Suspected state sponsor
  • Iran (Islamic Republic of)
Type of incident
  • Espionage
Target category
  • Private sector
Targeting of Burisma
Date of report
  • January 2020
Affiliations
The alleged Russian actors hacked Burisma, a Ukrainian gas company whose board Joe Biden’s son sat on. President Trump had previously pressed Ukraine to open an investigation into Biden and Burisma, which led to his impeachment.
Suspected victims
  • Burisma
Suspected state sponsor
  • Russian Federation
Type of incident
  • Espionage
Target category
  • Private sector