logo

SVR Cyber Actors Adapt Tactics for Initial Cloud Access

ID: 162eae59-6960-51c6-bff9-be0707c6c6b7

STIX ID: report--162eae59-6960-51c6-bff9-be0707c6c6b7

Feed Name: CISA Cybersecurity Advisories

Threat Score
90/100

Date Published: 2024-02-23

Date Updated: 2026-04-19

Author: CISA

...
...

**Executive summary:** This advisory from the NCSC and international partners describes how SVR‑attributed APT29 (aka Midnight Blizzard/Cozy Bear) has adapted to cloud infrastructures, detailing observed initial access TTPs such as credential brute forcing and password spraying, stealing application access tokens, MFA request flooding, enrolling attacker devices, and using residential proxies, and provides prioritized mitigations (MFA, short session lifetimes, device enrollment policies, account hygiene, and logging) to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.