Человек в капюшоне

The institution noted that the attacker, operating under the pseudonym "Bytetobreach" and also linked to the June cyber incident and data leak at LVM, publicly announced last week an attack on the National Agency for Cadastre and Land Registration of Romania. To assist their Romanian colleagues in clarifying the situation and reducing potential threats, "Cert.lv" provided the network indicators of the attacker's infrastructure obtained during the analysis of the incident at LVM, as well as other technical information that may aid in the investigation and prevention of further attacks. "Cert.lv" also reported that activity from this attacker continues to be observed in the Latvian cyberspace, with attempts to find new targets for attacks; however, such attempts are being successfully thwarted. To help organizations in Latvia timely identify potential threats, "Cert.lv" published the network indicators of the attacker's infrastructure identified during the investigation of the incident at LVM in early July. The institution urges their use for network monitoring, especially for entities under the National Cybersecurity Law and owners of critical infrastructure who are not yet utilizing the services of "Cert.lv". At the same time, in connection with the cyber incident at LVM, "Cert.lv" also published recommendations for enhancing the resilience of IT infrastructure against cyber threats. Their goal is to assist institutions and organizations in reducing the risks of cyberattacks, improving the ability to timely detect threats, and effectively respond to incidents. As reported, a cyberattack on the IT infrastructure of LVM was recorded on June 22. Following the attack, external information systems supported by LVM - "LVM GEO", a mapping services system, as well as the hunting application "Mednis" - were disabled for security reasons. Additionally, several internal LVM systems that facilitate information exchange between the enterprise and service providers and clients were also disabled. Responsibility for the cyberattack on LVM was claimed by a foreign group using ransomware. In connection with the incident, the State Police initiated a criminal process, and the institution "Cert.lv" became involved in clarifying the circumstances of the cyberattack. According to available information, the attacker gained access to the LVM system on June 11, but only began taking active actions on the night of June 22 to 23.