logo

Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure

ID: f781d37e-cb44-5be6-8d1e-2085eb831516

STIX ID: report--f781d37e-cb44-5be6-8d1e-2085eb831516

Feed Name: ASD's ACSC - Advisories RSS

Threat Score
90/100

Date Published: 2024-09-06

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

This advisory details the GRU Unit 29155 cyber component’s operations since at least 2020, describing their use of publicly available scanning/exploitation tools, exploitation of CVEs, deployment of destructive malware (e.g., WhisperGate), lateral movement techniques (Impacket, psexec, secretsdump), anonymization/tunneling (VPNs, ProxyChains, GOST, DNS tunneling), and data exfiltration (Rclone, mega.nz), with observed impacts against NATO members, EU countries, and critical infrastructure sectors and appended IOCs and mitigation notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.