A long-running Russian hacking operation targeting Western firms has shifted tactics, according to a new security report from Amazon, and is now targeting misconfigured edge devices.
The threat report, based on Amazon’s tracking of the cyber campaign since 2021, frames the focus on edge devices as a ‘tactical pivot’ to exploit the relatively low-hanging fruit of misconfigured customer systems.
This tactical shift allows hackers to harvest logins and infiltrate online services’ infrastructure with fewer resources, while also lowering their visibility to widely used detection methods.
Hackers start by compromising misconfigured customer edge devices on AWS, then flip their packet‑capture tools to snatch credentials. Those logins are replayed against victim systems, opening the door to persistent access and lateral movement across infrastructure.
According to Amazon, the campaign has focused on Western critical infrastructure, particularly within the energy sector, but also across cloud services and telcomms, with the malicious operations continuing through to the present day.
While not explicitly naming the threat group behind the attack, Amazon said that infrastructure overlaps with Sandworm (AKA Seashell Blizzard) and consistent targeting patterns pointed to activity associated with Russia’s Main Intelligence Directorate (GRU).
Worryingly, Amazon warned that this cyber assault might just be one thread within a broader GRU campaign.
Infrastructure overlaps with a group tracked as “Curly COMrades”, points to the emergence of specialised subclusters where one group focuses on initial access and another on persistence and evasion, a hallmark of GRU’s tactics.
Recommended reading
- Millions of Chrome and Edge Users Caught in 7-Year Malware Plot
- Report: Hackers Are Targeting AI Agents and ‘Weaponising’ GenAI
- Hackers Target Devs With 188% Surge in Open Source Attacks
Among the immediate actions Amazon recommends, organisations should prioritise an audit of all edge devices for unexpected packet capture files or utilities, review configurations for exposed interfaces, implement network segmentation, and strengthen authentication methods.
“Going into 2026, organisations must prioritise securing their network edge devices and monitoring for credential replay attacks to defend against this persistent threat,” said the AWS report.
“Through coordinated efforts, since our discovery of this activity, we have disrupted active threat actor operations and reduced the attack surface available to this threat activity subcluster.
“We will continue working with the security community to share intelligence and collectively defend against state-sponsored threats targeting critical infrastructure.”





