Site navigation

Five Eyes Expose New Russian Cyber Threat Actor Tactics

Michael Edgar

,

Check Point Software NCSC Cloud security
In an effort to bolster cybersecurity defences, the UK has unveiled evolving tactics employed by Russian-linked cyber actors. 

This warning from the National Cyber Security Centre (NCSC), along with intelligence agencies from the Five Eyes, comes on the backdrop of a significant shift towards cloud-based infrastructure across various sectors. 

The joint advisory from the Five Eyes intelligence agencies, sheds light on the tactics of APT29, a threat group associated with Russia’s Foreign Intelligence Service (SVR).

Also known as Midnight Blizzard, the Dukes, or Cozy Bear, APT29 has been observed adjusting its strategies to target organisations migrating to cloud-hosted environments.

Traditionally, SVR actors exploited software vulnerabilities to gain access to systems. However, with many sectors, including think tanks, healthcare, and education, transitioning to cloud infrastructure, the avenues for such attacks have diminished. 

Instead, the SVR has resorted to stealing system-issued access tokens, enrolling new devices into victim cloud environments via credential reuse, and employing password spraying and brute force techniques, exploiting weak passwords and the absence of 2-step verification.

Once initial access is secured, the SVR can deploy highly sophisticated capabilities, posing a significant threat to organisations’ data security and integrity.


Recommended reading


“We are resolute in our commitment to exposing malicious cyber activity, which includes raising awareness of changes in the behaviour of groups which persistently target the UK,” said Paul Chichester, director of operations at the NCSC.

“The NCSC urges organisations to familiarise themselves with the intelligence and mitigation advice within the advisory to help defend their networks.”

The advisory was jointly published by the NCSC, the US Cyber National Mission Force (CNMF), the US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Australian Signals Directorate (ASD), the Canadian Centre for Cyber Security (CCCS), and the New Zealand National Cyber Security Centre (NCSC)

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data