Hackers Target Russian Spy-Hunting Researchers
The hackers used fake Protonmail web domains to target investigative news outlet Bellingcat.

Kacper Pempel/Reuters
Hackers using fake Protonmail web domains targeted open source investigative news outlet Bellingcat, according to a new report from cybersecurity company ThreatConnect. According to the report, attackers sent spear phishing emails to Bellingcat’s Christo Grosev, who has co-authored a number of investigations for the group identifying alleged Russian intelligence officers involved in the poisoning of a former GRU officer in Salisbury, England, and an attempted coup in Montenegro. The emails claimed that the user’s account had been compromised and directed the recipient to register a new password at a fake Protonmail website controlled by hackers. ThreatConnect researchers said the attempts bore similarities to previous tactics used by hackers from Russian military intelligence but that there was insufficient evidence to link the campaign directly to Russian actors.
Register below to read this article for free or subscribe
to unlock unlimited access to The Daily Beast.
Monthly
$1
First month then $5.99/month
Annual
$35
First year then $59.99/year
Premium
$79
First year then $119.99/year
*Substack access provided by the next business day, using your subscription email. Choosing the Premium plan constitutes your permission to share your subscription email with Substack and your agreement to Substack’s Privacy Policy.
Already have an account? Sign In
Looks like you already have a subscription!
You're all set!
Thanks for subscribing.