Site navigation

UK and US Release Fresh Advisory on Russian Foreign Intelligence

Elizabeth Greenberg

,

russian foreign intelligence
The advisory included recommendations for organisations to minimise their risk of attack. 

The National Cyber Security Centre, in partnership with US agencies such as the FBI and NSA, have issued a fresh advisory about the latest online tactics used by Russia’s Foreign Intelligence Service (SVR).

The advisory details the latest methods used by SVR actors to collect foreign intelligence for future cyber operations, including in support of the Russian invasion of Ukraine.

SVR attackers are exploiting vulnerabilities at a mass scale as part of a continued global campaign and more than 20 publicly disclosed vulnerabilities have been shared which the threat actors are assessed to have the capability and interest to exploit.

These attackers have consistently targeted foreign entities in the defence, technology, and finance sectors, with an emphasis on remaining anonymous and undetected.

According to the advisory, the SVR cyber-actors, also known as APT29, Midnight Blizzard, Cozy Bear, and the Dukes, generally have two types of intended victims: target of intent and targets of opportunity.

Targets of intent include government and diplomatic entities, think tanks, technology companies, and financial institutions across the globe, including in the UK.

On the other hand, targets of opportunity are located by scanning internet-facing systems for unpatched vulnerabilities at scale which are then opportunistically exploited – meaning any organisation with vulnerable systems could be targeted.

For both sets of victims, once initial access has been achieved, the SVR cyber-actors can then conduct follow-on operations from compromised accounts or attempt to pivot to other networks connected to the victim, such as in their supply chain.

“Russian cyber actors are interested in and highly capable of accessing unpatched systems across a range of sectors, and once they are in, they can exploit this access to meet their objectives,” NCSC director of operations Paul Chichester said.


Recommended reading


“All organisations are encouraged to bolster their cyber defences: take heed of the advice set out within the advisory and prioritise the deployment of patches and software updates.”

The NCSC, FBI, and NSA have released a list of recommended mitigations to quell the spread and effectiveness of SVR’s attacks.

Rapidly deploying patches, minimising internet-accessible services, and enforcing multi-factor authentication are some of the baseline defence methods recommended.

Limiting token access, regularly auditing cloud-based accounts, and continuing threat hunting activities were also recommended.

Any UK organisation that may have been compromised through the vulnerabilities described in the advisory should report it to the NCSC.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data