Cybersecurity and law enforcement groups from the US and the UK have warned of a major ongoing cyberattack from Russian military intelligence service, the GRU.
A joint statement from the US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), along with the UK’s National Cyber Security Centre (NCSC) said that the Russian group has been targeting numerous organisations across the US and Europe, including government institutions.
Other targets include defence contractors, energy companies, higher education, logistics companies, law firms, media companies, political consultants, or political parties, and think tanks.
The cybersecurity groups said that the GRU has been using brute force attacks to access their victims’ networks. This involves repeatedly entering variations of common or easily guessed names and passwords until one eventually proves correct. Once on a network, the hackers aim to access credentials, and collect and exfiltrate data.
While brute force attacks are relatively crude and common, the Russian hack has been using more advanced techniques to easily scale its work. This includes using a Kubernetes cluster, an open-source system for automating application deployment, to hide the attack’s origin and remain anonymous. To compound this, attacks are routed through TOR and commercial VPN services.
The attackers also take steps to hide their footsteps to help stay undetected on a network, though the cybersecurity groups noted that there are many detection opportunities available to stop the malicious actors.
According to the groups, the campaign started in 2019. In addition to being connected to military intelligence, the Russian hack has been linked to established cybercriminal group Fancy Bear.
Recommended
- Leader Insights | TJ Gonen, Head of Cloud Security at Check Point Software
- Comment | Could data become Scotland’s new currency?
- What are the most expensive NFTs ever sold?
Brute force attacks can leverage previously leaked usernames and passwords, or guess common passwords and variations, to access networks. As such, staying aware of potential data leaks and breaches, and ensuring good password security are vital to maintaining cybersecurity.
As part of the attack, the Russian hackers have used previously identified account credentials in conjunction with exploiting publicly known vulnerabilities, such as exploiting compromised Microsoft Exchange servers.
Another example of a potential risk is a recent data scrape that aggregated the details on around 700 million LinkedIn users. The information could provide the basis for hackers, big or small, to execute a brute force attack.
According to an advisory from the cybersecurity groups, the most effective mitigation is the use of multi-factor authentication, which is not guessable during brute force access attempts.
“Additional mitigations to ensure strong access controls include time-out and lock-out features, the mandatory use of strong passwords, implementation of a Zero Trust security model that uses additional attributes when determining access, and analytics to detect anomalous accesses,” the advisory added.





