The National Cyber Security Centre, in partnership with US agencies such as the FBI and NSA, have issued a fresh advisory about the latest online tactics used by Russia’s Foreign Intelligence Service (SVR).
The advisory details the latest methods used by SVR actors to collect foreign intelligence for future cyber operations, including in support of the Russian invasion of Ukraine.
SVR attackers are exploiting vulnerabilities at a mass scale as part of a continued global campaign and more than 20 publicly disclosed vulnerabilities have been shared which the threat actors are assessed to have the capability and interest to exploit.
These attackers have consistently targeted foreign entities in the defence, technology, and finance sectors, with an emphasis on remaining anonymous and undetected.
According to the advisory, the SVR cyber-actors, also known as APT29, Midnight Blizzard, Cozy Bear, and the Dukes, generally have two types of intended victims: target of intent and targets of opportunity.
Targets of intent include government and diplomatic entities, think tanks, technology companies, and financial institutions across the globe, including in the UK.
On the other hand, targets of opportunity are located by scanning internet-facing systems for unpatched vulnerabilities at scale which are then opportunistically exploited – meaning any organisation with vulnerable systems could be targeted.
For both sets of victims, once initial access has been achieved, the SVR cyber-actors can then conduct follow-on operations from compromised accounts or attempt to pivot to other networks connected to the victim, such as in their supply chain.
“Russian cyber actors are interested in and highly capable of accessing unpatched systems across a range of sectors, and once they are in, they can exploit this access to meet their objectives,” NCSC director of operations Paul Chichester said.
Recommended reading
- Report: IT Leaders Struggling to Keep Up with Cyber-threats
- New Report Highlights Collabs Between Nation-states, Cyber-crime Rings
- NCSC Issues Warning Over Iran Spear-Phishing Attacks
- 67% of Healthcare Organisations Hit by Ransomware In the Past Year
“All organisations are encouraged to bolster their cyber defences: take heed of the advice set out within the advisory and prioritise the deployment of patches and software updates.”
The NCSC, FBI, and NSA have released a list of recommended mitigations to quell the spread and effectiveness of SVR’s attacks.
Rapidly deploying patches, minimising internet-accessible services, and enforcing multi-factor authentication are some of the baseline defence methods recommended.
Limiting token access, regularly auditing cloud-based accounts, and continuing threat hunting activities were also recommended.
Any UK organisation that may have been compromised through the vulnerabilities described in the advisory should report it to the NCSC.





