Amazon security boss blames Russia's GRU for years-long energy-sector hacks
ID: 8e4df2a2-bdf4-567c-8ac5-60c72c2fec9c
STIX ID: report--8e4df2a2-bdf4-567c-8ac5-60c72c2fec9c
Feed Name: The Register (Security)
Amazon Threat Intelligence attributes a multi-year GRU campaign (2021–present) targeting Western energy, telecommunications, and technology providers. Attackers prioritized misconfigured AWS-hosted network edge virtual appliances and exploited known CVEs (including WatchGuard CVE-2022-26318 and Confluence CVEs) to gain persistence on EC2 instances, conducted credential-replay likely via packet capture, and attempted access to collaboration and cloud project-management platforms; Amazon reports continual disruption of operations, customer remediation, and guidance to perform edge audits, authentication-log reviews, and monitoring for anomalous appliance admin access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
