logo

Amazon security boss blames Russia's GRU for years-long energy-sector hacks

ID: 8e4df2a2-bdf4-567c-8ac5-60c72c2fec9c

STIX ID: report--8e4df2a2-bdf4-567c-8ac5-60c72c2fec9c

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-12-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Amazon Threat Intelligence attributes a multi-year GRU campaign (2021–present) targeting Western energy, telecommunications, and technology providers. Attackers prioritized misconfigured AWS-hosted network edge virtual appliances and exploited known CVEs (including WatchGuard CVE-2022-26318 and Confluence CVEs) to gain persistence on EC2 instances, conducted credential-replay likely via packet capture, and attempted access to collaboration and cloud project-management platforms; Amazon reports continual disruption of operations, customer remediation, and guidance to perform edge audits, authentication-log reviews, and monitoring for anomalous appliance admin access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.