World News
No Click Needed: How Russian Hackers Stole American Nuclear Data Using A Rare Exploit
A sophisticated Russian cyber espionage campaign has targeted US nuclear scientists, defence contractors and government agencies using a rare “no-click” email exploit.
A Russian cyber espionage group has spent the past year targeting American nuclear scientists, defence contractors and government officials in a sophisticated intelligence-gathering operation that relied on a rare “no-click” email exploit, according to cybersecurity researchers and a joint warning issued by the United States and more than a dozen allied governments.
Investigators believe the campaign was aimed at collecting sensitive information on nuclear fusion research, military technology and strategic policy developments that could support Moscow’s broader war effort in Ukraine. Unlike conventional phishing attacks, the hacking technique required victims only to open an email on a vulnerable server, eliminating the need to click malicious links or download infected attachments.
Cybersecurity company Proofpoint, which investigated part of the operation, said the hackers specifically targeted email servers linked to US nuclear facilities and organisations forming part of the country’s defence industrial base. Greg Lesnewich, a threat researcher at Proofpoint, told CNN that the campaign focused on individuals and institutions involved in nuclear fusion research, suggesting the attackers were attempting to understand technological advances made by Russia’s Western counterparts.
According to the joint advisory, the cyber operation relied on an uncommon software vulnerability that allows attackers to compromise email systems without requiring victims to interact with malicious content beyond opening an email. Once exploited, the vulnerability enables hackers to extract up to three months of email correspondence while also obtaining an organisation’s complete email directory.
Such information can provide valuable intelligence about institutional networks, research collaborations and senior personnel involved in sensitive government and defence programmes.
Officials said the exploit represents a significant evolution in Russian cyber tradecraft because it reduces the opportunities for users to detect suspicious activity. Traditional phishing campaigns often depend on convincing victims to click malicious links or open infected files, whereas this technique operates through vulnerable email infrastructure itself.
Intelligence officials warned that organisations using affected email systems could unknowingly expose extensive communications before identifying any breach.
The multinational advisory also concluded that Russian operators first tested many of these cyber techniques against Ukrainian targets before expanding operations to NATO member states and Western institutions. According to the assessment, Ukraine effectively served as a proving ground where Russian hackers refined their methods before deploying them more broadly against government agencies, defence organisations and critical infrastructure across allied countries.
The agencies described this pattern as an increasingly common feature of Russian cyber operations since the full-scale invasion of Ukraine. Sherrod DeGrippo, Vice President of Threat Intelligence at Palo Alto Networks’ Unit 42, said the attackers were likely seeking strategic insight into Western military planning, logistics and policy decisions.
UK Security Minister Dan Jarvis similarly described it as particularly concerning that the hacking group tested its techniques on Ukrainian victims before targeting NATO members, warning that the campaign demonstrated a deliberate escalation in Russian cyber espionage activity.
Get Latest News Live on Times Now along with Breaking News and Top Headlines from US News and around the World.
-
Finance3 days agoZenith Bank Charts New Path to Scale Nigeria’s $6.1bn Non-Oil Export Market
-
Breaking2 days agoFG targeting 6,500MW of power supply by December, says Tegbe
-
Breaking3 days agoMilitary, police, immigration are unknown gunmen in Nigeria — VeryDarkMan
-
News2 days agoOluwo urges Tinubu to grant Nnamdi Kanu presidential amnesty













