🚨The FBI just published a multi-nation PSA on an active #GRU🇷🇺 cyber operation. If you manage infrastructure or remote workers, read this. ───────────────────────────── 𝗧𝗵𝗿𝗲𝗮𝘁 𝗔𝗰𝘁𝗼𝗿: APT28 / Fancy Bear / Forest Blizzard GRU 85th Main Special Service Center (85th GTsSS) 𝗔𝗰𝘁𝗶𝘃𝗲 𝗦𝗶𝗻𝗰𝗲: At least 2024 ───────────────────────────── 𝗧𝗧𝗣𝘀 — 𝗛𝗼𝘄 𝗧𝗵𝗲𝘆'𝗿𝗲 𝗗𝗼𝗶𝗻𝗴 𝗜𝘁 🔓 𝗜𝗻𝗶𝘁𝗶𝗮𝗹 𝗔𝗰𝗰𝗲𝘀𝘀 — Credential harvesting + exploitation of CVE-2023-50224 on TP-Link SOHO routers. These are unpatched, internet-exposed edge devices sitting in homes and small offices. ↪ 𝗣𝗶𝘃𝗼𝘁 — Actors modify DHCP/DNS settings on compromised routers to point all connected devices to actor-controlled DNS resolvers. No malware on the endpoint required. 🎯 𝗔𝗱𝘃𝗲𝗿𝘀𝗮𝗿𝘆-𝗶𝗻-𝘁𝗵𝗲-𝗠𝗶𝗱𝗱𝗹𝗲 (𝗔𝗶𝘁𝗠) — Fraudulent DNS responses redirect users to actor-controlled infrastructure for targeted services (e.g. Microsoft Outlook Web Access). Traffic is intercepted when users click through TLS certificate warnings. 📦 𝗖𝗼𝗹𝗹𝗲𝗰𝘁𝗶𝗼𝗻 — Passwords, session/auth tokens, emails, and browsing data content normally protected by SSL/TLS is exfiltrated in plaintext. 🎖 𝗧𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴 — Initial compromise is broad and indiscriminate. GRU then filters victims, prioritizing military, government, and critical infrastructure personnel. ───────────────────────────── 𝗧𝗲𝗰𝗵𝗻𝗶𝗰𝗮𝗹 𝗗𝗲𝗳𝗲𝗻𝘀𝗲𝘀 → Patch or replace SOHO routers — CVE-2023-50224 is actively exploited. If the device is end-of-support, replace it. → Disable remote management interfaces exposed to the internet. → Rotate default credentials on all edge devices. Factory defaults are not acceptable. → Enforce strict certificate validation policies. Treat any TLS warning as a hard stop, not a prompt to click through. → Deploy DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) on endpoints so DNS queries are not silently redirectable by a rogue resolver. → Require VPN with MFA for all remote access to sensitive systems. A compromised home router should not be a path into your org. → Monitor for unexpected DHCP/DNS configuration changes on edge devices as an IOC. ───────────────────────────── The DOJ and FBI have already disrupted part of this network. That does not mean it's over. ⚠️ Full PSA: IC3 Alert I-260407-PSA | 07 April 2026 #CyberSecurity #ThreatIntelligence #APT28 #GRU #NetworkSecurity #InfoSec #DNS Cyber Security Forum Initiative #CSFI
Risks to Internet Infrastructure from Russian Cyber Threats
Explore top LinkedIn content from expert professionals.
Summary
Risks to internet infrastructure from russian cyber threats refer to the ongoing and sophisticated cyberattacks by state-sponsored and hacktivist groups in Russia, targeting the devices and systems that keep the internet running. These attacks aim to steal sensitive information, disrupt services, and erode trust in organizations by exploiting vulnerabilities in routers, cloud systems, and critical networks.
- Update and monitor: Regularly check your routers and devices for security updates and review who is responsible for their maintenance, especially in remote work setups.
- Strengthen authentication: Implement multi-factor authentication for all critical accounts and services, which can significantly limit what attackers can do with stolen login details.
- Prepare for disruption: Invest in DDoS defenses and monitor for unusual network activity, as persistent attacks can target public and private organizations to destabilize or signal political intent.
-
-
The Russian foreign intelligence service (SVR, similar to the Soviet KGB) have adapted their tactics for gaining initial access to cloud computing. A recent joint advisory from UKUSA partners outlines how the SVR have adapted. This is relevant if you are in a Government or Defence supply chain, as we have seen with incidents such as the infamous SolarWinds attack. This information is also relevant even if you are not a Government or Defence supplier - you can be sure that cybercriminals will learn from these tactics. For all we know, some of the SVR-backed actors might even be doing crime as a side-hustle! The short version: ⚡ The SVR are also known as APT29, Cozy Bear, and more recently, Midnight Blizzard ⚡ This is the same organization that recently conducted an extensive breach against Microsoft executives, cyber, and legal teams, by moving laterally from a test tenant to the corporate tenant ⚡ Service accounts are the prime target for password spraying attacks, because they usually don't have MFA - also, accounts of departed users ⚡ Cloud-based tokens are also being used for initial access ⚡ Attackers use "MFA-bombing", where the attacker sends many MFA push requests (assumes they have a valid password), in the hope that the victim will accept one of the requests, and allow the attacker to defeat MFA, then set their own device as the second factor ⚡ Use of residential proxies, where the attackers compromise many commodity-grade routers (the Ubiquity EdgeRouter being the most recent target) so that the attacks appear to come from home internet What to do about it: 🔒 Use MFA! Yes, MFA bombing is still as risk, but it adds one more hurdle, and there are also phish-resistant forms of MFA (eg. FIDO2) 🔒 For service accounts that do not have MFA, use a long, complex, unique password - no person will have to type it in on a console, so it does not have to be memorable or convenient! 🔒 Apply the principal of least privilege to service accounts 🔒 Use "canary" service accounts that trigger an alert when authentication attempts are made 🔒 For cloud tokens, keep the validity period short, and (I cannot stress this enough), make sure the validity is checked! 🔒 Ensure that you are logging application and host events, and monitoring for indicators of compromise
-
The National Cyber Security Centre has just published an urgent warning. And if you lead an organisation — or sit on a board — this one is for you. Russian military intelligence has been quietly breaking into routers that connect offices and home workers to the Internet. Not to cause obvious disruption. Not to demand a ransom. To watch. To intercept. And to steal login credentials without anyone noticing. What makes this particularly significant is that it isn't targeted in the way you might expect. They cast a wide net — compromising as many devices as possible — and then quietly sift through to find targets of intelligence value. The question for your organisation isn't whether Russian intelligence was specifically coming for you. It's whether you were swept up in the net, and whether they decided you were worth acting on. The devices being exploited are not obscure. They are common, inexpensive routers. The kind that get set up once and rarely revisited. The kind that many remote workers have at home. This is not a failure of sophisticated technology. It is a failure of maintenance. Devices that haven't been updated. Settings that haven't been reviewed. Infrastructure that fell outside anyone's responsibility. So what does leadership need to do? Ask your IT team or security partner three questions this week. ✅ Do we have any of the router models on the NCSC advisory list — including in our remote workers' homes? ✅ When were those devices last updated, and who is responsible for maintaining them? ✅ Do we have multi-factor authentication — a second verification step beyond a password — on our email and collaboration tools? If the answer to the third question is no, or not fully, that is the most urgent fix. Even if credentials are stolen, multi-factor authentication significantly limits what an attacker can do with them. This is not a theoretical risk. The NCSC does not publish operational advisories like this without evidence of active, ongoing activity. Russian state-sponsored actors are patient, well-resourced, and operating in the grey zone between espionage and disruption. The devices are common. The vulnerability is known. The fix is available. The only question is whether your organisation acts before or after an incident. Link to the NCSC's guidance in the comments. ===== #Cybersecurity #cyberresilience #riskmanagement #cybernews
-
🚨 🐻 🇷🇺 - New Recorded Future Insikt Group report! This was an incredible team effort led by Cal G, with myself, Julian-Ferdinand Vögele, and Lawrence S. Over the past 13 months, the pro-Russian hacktivist group NoName057(16) has carried out an astonishing 3,776 unique DDoS attacks, averaging 50 targets per day, with peaks aligned to major geopolitical events. Their tool of choice? DDoSia, a custom application-layer attack platform run by a volunteer-driven network. These are not random disruptions. They are deliberate, retaliatory strikes designed to punish Ukraine and its allies — particularly NATO-aligned European governments, critical infrastructure providers, and public-sector organizations — for opposing Russian aggression. 🔍 Key Takeaways: ♦️ NoName057(16) operates a multi-tiered C2 infrastructure to obfuscate attribution and evade takedown, rotating Tier 1 servers every 9 days on average. ♦️ Attacks are politically timed and clearly aligned with Russian military interests, including a major spike after Ukraine’s offensive into Kursk. ♦️ Operation Eastwood — a coordinated international law enforcement action — led to arrests and 24 house searches targeting the group’s infrastructure across Europe. But NoName057(16) remains undeterred, publicly dismissing the crackdown and reaffirming its “information war” mission. 🛰️ This is hybrid warfare in action. It’s cyber-enabled influence operations designed to destabilize without crossing the threshold into open war. DDoSia is not about sophistication — it’s about persistence, scale, and political signaling. This is the future of conflict. Public and private entities are no longer just collateral damage, rather they are the primary targets of hostile state-aligned cyber campaigns. The West must treat these attacks as indicators of strategic intent, not noise. 🔑 Organizations must harden DDoS defenses, track volunteer hacktivist networks, monitor geopolitical flashpoints to maintain situational awareness, and recognize that law enforcement disruption alone is not deterrence — but it compounds to support resilience over time. NoName057(16) offers a blueprint for digitally crowdsourced cyber warfare — a model likely to persist and proliferate. Their infrastructure may be tactically fragile, but their political utility ensures their relevance. Please read and share with your networks! PDF: https://lnkd.in/e2tdzgGp
-
#Russia deliberately operates in a legal grey zone where cyberattacks are rarely treated as acts of aggression under international law unless they cause immediate physical destruction or casualties. As long as there are no visible victims, the response remains restrained. #Moscow understands this perfectly. And exploits it. At the Kyiv International Cyber Resilience Forum, Serhii Demediuk, Chairman of the Board at the Institute of Cyber Warfare Research, articulated something that should concern every cybersecurity professional and FIMI expert in the EU and the United States. Instead of a single spectacular strike, Russia applies what can be described as a “thousand cuts” strategy: persistent, accumulative, and often deniable cyber operations that gradually exhaust resilience, erode public trust, and test political red lines. #Europe has already experienced multiple examples of this approach. On the day of the full-scale invasion of Ukraine in February 2022, the KA-SAT/Viasat satellite network was disrupted in an attack publicly attributed to Russia and condemned by the #EU; the incident affected several EU member states and demonstrated how quickly civilian infrastructure can be collateral damage. In 2023, #Denmark’s energy sector reported coordinated intrusions affecting more than twenty energy companies, with investigations pointing to activity associated with the GRU-linked Sandworm group. In 2024, #Germany and #Czech Republic publicly attributed malicious cyber activities to APT28 (also linked to the Russian #GRU), warning that the same actor targeted government entities and critical infrastructure operators across Europe. What makes the current phase even more concerning is the evolution toward a “double strike” tactic. Cyber operations increasingly occur alongside synchronized information attacks. The technical disruption is paired with amplified narratives exaggerating scale and impact. This was designed to intimidate, create panic, and undermine confidence in institutions. Even when the technical damage is limited, the psychological and political effects can be far more significant. This fusion of #cyber operations and #information manipulation is not accidental; it is strategic. A more coordinated and assertive approach to attribution, consequences, and integrated cyber-information response is essential. Russia is not merely probing systems. It is probing resolve.
-
Major Cybersecurity Alert - Russian GRU Unleashes Sophisticated Campaign Against Western Supply Lines A devastating new intelligence report reveals how Russian military hackers have been systematically infiltrating the backbone of Western aid to Ukraine - targeting the very companies moving critical supplies across borders. The Scope is Staggering: • 85th Main Special Service Center (Unit 26165) - Russia's elite cyber warfare unit - has compromised dozens of logistics companies across 13 countries • Victims include major transportation hubs, ports, airports, maritime companies, and IT service providers • The operation spans from Bulgaria to the United States, with over 10,000 IP cameras hijacked to monitor aid shipments in real-time Their Methods: The hackers didn't just break into networks - they studied their targets like predators. They identified key personnel, mapped business relationships, and exploited trust between partner companies. Once inside, they accessed the most sensitive intelligence: train schedules, shipping manifests, container numbers, cargo contents, and exact travel routes of aid shipments to Ukraine. The Most Disturbing Discovery: Russians positioned themselves to watch everything. They compromised traffic cameras and private security cameras near border crossings and military installations. Camera targets were positioned to monitor aid flowing into the country. They could literally watch Western aid arrive and coordinate attacks accordingly. How They Got In: • Exploited Microsoft Outlook vulnerabilities to steal credentials • Used fake login pages impersonating government entities • Weaponized WinRAR file compression software • Conducted massive password-spraying campaigns • Even attempted voice phishing, calling victims while impersonating IT staff The Persistence Factor: Once inside corporate email systems, they manipulated mailbox permissions for sustained access, enrolled compromised accounts in multi-factor authentication to appear legitimate, and used legitimate Microsoft Exchange protocols to blend their data theft with normal business operations. Why This Matters: This isn't just corporate espionage - it's military intelligence gathering that directly threatens Ukrainian defense capabilities. Every compromised shipment manifest potentially enables Russian forces to target aid convoys, anticipate weapon deliveries, or disrupt critical supply chains. The investigation involved 15+ international intelligence agencies, highlighting how seriously Western governments view this threat. Organizations handling sensitive logistics or supporting Ukrainian aid efforts should immediately review their cybersecurity posture and monitor for the specific indicators outlined in this advisory. #CyberSecurity #Ukraine #Russia #NationalSecurity #Logistics
-
On February 24, 2022—one hour before Russian armour crossed into Ukraine—the Viasat KA-SAT satellite network was gutted. The attackers, almost certainly Russia's GRU (Sandworm), did not hack the sky. They hacked the ground. The entry point was a misconfigured Fortinet VPN appliance in Viasat's Turin-based ground station. Once inside, the attackers moved to an FTP server and staged AcidRain, a wiper malware designed to erase flash memory. But the operation's stealth depended entirely on DNS. The malware used DNS over HTTPS (DoH) to mask its command-and-control traffic, blending malicious queries with legitimate web traffic—a technique that made it invisible to traditional security monitoring. DNS was not the target; it was the camouflage as it often is. When the kill command arrived via DNS beaconing, AcidRain destroyed over 27,000 SurfBeam 2 modems. The collateral damage cascaded across Europe: 5,800 German wind turbines lost remote monitoring, and tens of thousands of residential broadband users in France, Italy, and Poland went dark. The lesson is brutal: DNS trust made the attack invisible. PDNS was useless and could not stop it because the domains were new and unknown. Mockapetris warned, 95% of attacks rely on DNS—not because DNS fails, but because it succeeds - unknowingly, uncontrolled, and unsecured.
-
I spent over two decades years chasing threats most people never see coming. Russian state hackers just made your supply chain their playground. Amazon's threat intel team confirmed APT29, Russia's elite cyber unit, and more commonly known as COZY BEAR, has been weaponizing cloud infrastructure to target Western critical infrastructure for years. Not theoretical. Not someday. Right now. Here's what should be keeping Logistics decision makers up at night: They're using AWS, Azure, and Google Cloud as command-and-control hubs. Your logistics systems, vendor portals, and supply chain software all run on these platforms. The lesson? Nation-state actors don't care about your firewall. They're already inside the infrastructure you trust. Three actions for logistics leaders today: 1. Audit your cloud security posture across all providers 2. Implement zero-trust architecture for supply chain access 3. Train your team to recognize sophisticated phishing—APT29 is patient and convincing This isn't an IT problem. It's a business continuity crisis waiting to happen. When your distribution network goes dark because of a nation-state attack, your customers won't care about the technical details. They'll remember you weren't prepared. What's your organization doing to harden supply chain infrastructure against state-sponsored threats? https://lnkd.in/ec65efzP
-
The recent Microsoft Midnight Blizzard breach in January 2024 has raised concerns about targeted social engineering and credential theft. Midnight Blizzard, also known as APT29, is a Russian state-affiliated hacking group that has been identified as the source behind a surge in credential theft attacks. Microsoft has disclosed that the group employs a range of techniques, including password spraying, brute force, token theft, and session replay, to gain unauthorized access to cloud resources. The impact of these attacks is far-reaching, with governments, IT service providers, non-governmental organizations (NGOs), as well as defense and critical manufacturing industries being targeted[3]. In a recent development, Microsoft revealed that executive emails were hacked by this Russian intelligence group, also known as Midnight Blizzard. The group has been using sophisticated, highly targeted social engineering attacks, such as credential theft phishing lures distributed via Microsoft Teams chats. To enhance credibility, the actor employs security-themed or product name-themed keywords in crafting new subdomains. Midnight Blizzard frequently employs token theft techniques as part of their initial access strategy and has been using previously compromised Microsoft 365 tenants owned by small businesses to conduct these attacks[4][5]. The breach highlights the ongoing threat posed by sophisticated state-affiliated hacking groups and the importance of robust cybersecurity measures to protect against such attacks. Organizations and individuals are urged to remain vigilant and implement best practices to safeguard their systems and data. Citations: [1] https://lnkd.in/gmDcGWis [2] https://lnkd.in/g9KhVJ44 [3] https://lnkd.in/gcWbUZYK [4] https://lnkd.in/gGn5xbMS [5] https://lnkd.in/gV6KrMFR
-
Microsoft Threat Intelligence has identified a new Russian-affiliated threat actor known as #VoidBlizzard, who are performing world-wide cloud abuse. Their cyberespionage activity disproportionately targets NATO member states and Ukraine, indicating that the actor is likely collecting intelligence to help support Russian strategic objectives. The threat actor uses stolen credentials—which are likely procured from commodity infostealers—to collect high volumes of email and files from compromised organisations. These include government, defense, transportation, media, NGOs, and healthcare, especially in Europe and North America. In this report, we share our analysis of Void Blizzard’s targeting and TTPs, with detections and mitigations to disrupt and protect against Void Blizzard’s operations. https://lnkd.in/e9vku9wc
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development