logo

Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure

ID: 7e421554-cd03-583a-832e-75c750e4b467

STIX ID: report--7e421554-cd03-583a-832e-75c750e4b467

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Russian GRU-linked APT (Sandworm) has conducted a multi-year campaign (2021–2025) against Western critical infrastructure by compromising misconfigured cloud-hosted network edge devices (routers, VPN gateways, management appliances) to capture authentication traffic, exfiltrate configuration and credentials (using Fernet encryption and TFTP), and replay stolen credentials against cloud consoles and enterprise services; AWS telemetry observed persistent attacker access and credential-replay activity across energy, utilities, MSSPs, and telecoms in North America, Europe, and the Middle East.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.