Get 40% Off
👀 👁 🧿 All eyes on Biogen, up +4,56% after posting earnings. Our AI picked it in March 2024.
Which stocks will surge next?
Unlock AI-picked Stocks

France probes Russian lead in TV5Monde hacking: sources

Published 06/10/2015, 06:08 PM
Updated 06/10/2015, 06:08 PM
© Reuters. A French police officer stands guard in front of the main entrance of French television network TV5Monde headquarters

By Joseph Menn and Leigh Thomas

SAN FRANCISCO/PARIS (Reuters) - Russian hackers linked to the Kremlin could be behind one of the biggest attacks to date on televised communications, which knocked French station TV5Monde off air in April, sources familiar with France's inquiry said.

A French judicial source told Reuters that the investigators are "leaning towards the lead of Russian hackers," confirming a report in French magazine L'Express.

Hackers claiming to be supporters of Islamic State caused the public station's 11 channels to temporarily go off air and posted material on its social media feeds to protest against French military action in Iraq.

But the judicial source said the theory that Islamist militants were behind the cyber attack was no longer the main lead in the investigation.

U.S. cybersecurity company FireEye, which has been assisting French authorities in some cases, said on Wednesday that it believed the attack came from a Russian group it suspects works with the Russian executive branch. Relations between Paris and Moscow have suffered over the crisis in Ukraine, leading France to halt delivery of two helicopter carriers built for Russia.

Information about the TV5 attack was published on a website branded as part of the "Cyber Caliphate," a reference to the Islamic State.

But the site was hosted on the same block of Internet Protocol addresses and used the same domain name server as the group called APT28 by FireEye and Pawn Storm by Trend Micro, another large security company.

"We suspect that this activity aligns with Russia's institutionalized systematic `trolling' -devoting substantive resources to fulltime staff who plant comments and content online that is often disruptive, and always favorable to President Putin" of Russia, FireEye said via email.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

French authorities distributed a sample of malicious software from machines at the TV network that both FireEye and Trend Micro said originated with the Russian hacking group.

Trend Micro Vice President Rik Ferguson said it was possible that both the Russians and true Islamic State sympathizers had hacked the network, but the judicial source and FireEye discounted the possibility, citing other evidence.

Code used in the attack had been typed on a Cyrillic keyboard at times of day corresponding to working hours in St Petersburg or Moscow, FireEye said.

Researchers have tied the Russian group to attacks on NATO countries and on email of the White House and U.S. State Department.

Though paid Russian Internet commenting operations have been described in media reports for months, a story last week by the New York Times associated one of the main operations, in St. Petersburg, with disruptive fake news reports in the United States. The story connected the group with dozens of interconnecting hoax web pages, tweets and other false accounts of a chemical plant explosion in Louisiana, among other misinformation campaigns.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.