In summary:<p>USAID is the United States Agency for International Development -- a U.S. federal international aid agency.<p>The Russian hacking group Nobelium compromised the agency's Constant Contact account -- appears to be a MailChimp/SendGrid type marketing email service.<p>They have proceeded (and continue?) to send out phishing emails to contacts of the agency, including humanitarian organizations, purportedly targeting Kremlin opposition among others. The emails contain a malicious payload with backdoor capabilities.
<a href="https://www.microsoft.com/security/blog/2021/05/27/new-sophisticated-email-based-attack-from-nobelium/" rel="nofollow">https://www.microsoft.com/security/blog/2021/05/27/new-sophi...</a><p>> Microsoft Threat Intelligence Center (MSTIC) has uncovered a wide-scale malicious email campaign operated by NOBELIUM, the threat actor behind the attacks against SolarWinds, the SUNBURST backdoor, TEARDROP malware, GoldMax malware, and other related components. The campaign, initially observed and tracked by Microsoft since January 2021, evolved over a series of waves demonstrating significant experimentation. On May 25, 2021, the campaign escalated as NOBELIUM leveraged the legitimate mass-mailing service, Constant Contact, to masquerade as a US-based development organization to distribute malicious URLs to a wide variety of organizations and industry verticals.
<a href="https://www.volexity.com/blog/2021/05/27/suspected-apt29-operation-launches-election-fraud-themed-phishing-campaigns/" rel="nofollow">https://www.volexity.com/blog/2021/05/27/suspected-apt29-ope...</a><p>Many interesting details in this write-up from Volexity.