Critical Infrastructure Security, Threat Intelligence

Cyberattack deluge hits Romanian election infrastructure

Romanian police announced the arrest of members of the REvil ransomware group on Nov. 8. Pictured: The Romanian flag flies Feb. 7, 2017, during an armed forces ceremony at Fort Meyer, Va., Feb. 7, 2017. (Pfc. Gabriel Silva/US Army)

BleepingComputer reports that more than 85,000 cyberattacks from across 33 countries were disclosed by Romania's Intelligence Service to have been launched against the country's election systems last month.

After compromising the Romanian Permanent Electoral Authority's IT infrastructure on Nov. 19, threat actors went on to expose the account credentials for several of the country's election sites while deploying persistent intrusions that sought to infiltrate election infrastructure, prevent systems access, and spread disinformation until Nov. 25, said the SRI in a declassified report. Romania's election infrastructure has also been subjected to intrusions exploiting cross-site scripting and SQL injection vulnerabilities, which could still be leveraged to facilitate lateral movement and network persistence. Another declassified report revealed the Romanian presidential election to have been targeted by a sweeping influence operation via TikTok that promoted presidential candidate Calin Georgescu. Such a campaign was observed by Romania's Ministry of Internal Affairs to be similar with the one used to advance a Moldovan presidential candidate supporting Russia.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds