logo

Russia’s GRU hackers targeting misconfigured network edge devices in attacks on energy sector, Amazon says

ID: 32cfe3c7-9614-5fb4-917d-087ac947dc65

STIX ID: report--32cfe3c7-9614-5fb4-917d-087ac947dc65

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2025-12-16

Date Updated: 2026-05-01

...
...

Amazon security researchers attribute a 2021–2025 campaign to GRU-linked APT44 (Sandworm) that moved from exploiting software vulnerabilities to targeting misconfigured customer network edge devices hosted on AWS; attackers harvested credentials and established persistent access to hit Western energy, electric utility, MSSP, telecom and technology organizations, with more than ten victims identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.