This warning from the National Cyber Security Centre (NCSC), along with intelligence agencies from the Five Eyes, comes on the backdrop of a significant shift towards cloud-based infrastructure across various sectors.
The joint advisory from the Five Eyes intelligence agencies, sheds light on the tactics of APT29, a threat group associated with Russia’s Foreign Intelligence Service (SVR).
Also known as Midnight Blizzard, the Dukes, or Cozy Bear, APT29 has been observed adjusting its strategies to target organisations migrating to cloud-hosted environments.
Traditionally, SVR actors exploited software vulnerabilities to gain access to systems. However, with many sectors, including think tanks, healthcare, and education, transitioning to cloud infrastructure, the avenues for such attacks have diminished.
Instead, the SVR has resorted to stealing system-issued access tokens, enrolling new devices into victim cloud environments via credential reuse, and employing password spraying and brute force techniques, exploiting weak passwords and the absence of 2-step verification.
Once initial access is secured, the SVR can deploy highly sophisticated capabilities, posing a significant threat to organisations’ data security and integrity.
Recommended reading
- Private Branch Exchange Networks at Risk, NCSC Says
- Cyber Threat Actors are ‘Living Off The Land,’ says NCSC
- NCSC Releases New SMB Cybersecurity Guide
“We are resolute in our commitment to exposing malicious cyber activity, which includes raising awareness of changes in the behaviour of groups which persistently target the UK,” said Paul Chichester, director of operations at the NCSC.
“The NCSC urges organisations to familiarise themselves with the intelligence and mitigation advice within the advisory to help defend their networks.”
The advisory was jointly published by the NCSC, the US Cyber National Mission Force (CNMF), the US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Australian Signals Directorate (ASD), the Canadian Centre for Cyber Security (CCCS), and the New Zealand National Cyber Security Centre (NCSC)





