Site navigation

Russian Hackers Are Targeting Edge-Devices, Warns Amazon

Tom Quinn

,

AWS network edge
“Going into 2026, organisations must prioritise securing their network edge devices and monitoring for credential replay attacks to defend against this persistent threat,” said Amazon.

A long-running Russian hacking operation targeting Western firms has shifted tactics, according to a new security report from Amazon, and is now targeting misconfigured edge devices.

The threat report, based on Amazon’s tracking of the cyber campaign since 2021, frames the focus on edge devices as a ‘tactical pivot’ to exploit the relatively low-hanging fruit of misconfigured customer systems.

This tactical shift allows hackers to harvest logins and infiltrate online services’ infrastructure with fewer resources, while also lowering their visibility to widely used detection methods. 

Hackers start by compromising misconfigured customer edge devices on AWS, then flip their packet‑capture tools to snatch credentials. Those logins are replayed against victim systems, opening the door to persistent access and lateral movement across infrastructure.  

According to Amazon, the campaign has focused on Western critical infrastructure, particularly within the energy sector, but also across cloud services and telcomms, with the malicious operations continuing through to the present day.

While not explicitly naming the threat group behind the attack, Amazon said that infrastructure overlaps with Sandworm (AKA Seashell Blizzard) and consistent targeting patterns pointed to activity associated with Russia’s Main Intelligence Directorate (GRU).   

Worryingly, Amazon warned that this cyber assault might just be one thread within a broader GRU campaign.

Infrastructure overlaps with a group tracked as “Curly COMrades”, points to the emergence of specialised subclusters where one group focuses on initial access and another on persistence and evasion, a hallmark of GRU’s tactics.


Recommended reading


Among the immediate actions Amazon recommends, organisations should prioritise an audit of all edge devices for unexpected packet capture files or utilities, review configurations for exposed interfaces, implement network segmentation, and strengthen authentication methods.  

“Going into 2026, organisations must prioritise securing their network edge devices and monitoring for credential replay attacks to defend against this persistent threat,” said the AWS report.

“Through coordinated efforts, since our discovery of this activity, we have disrupted active threat actor operations and reduced the attack surface available to this threat activity subcluster. 

“We will continue working with the security community to share intelligence and collectively defend against state-sponsored threats targeting critical infrastructure.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data