logo

Russia Hits Critical Orgs Via Misconfigured Edge Devices

ID: 09bef80d-19dc-509c-b185-e9778873ed91

STIX ID: report--09bef80d-19dc-509c-b185-e9778873ed91

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-12-16

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

**Executive Summary:** Amazon Threat Intelligence details a 2021–2025 Russian GRU-linked campaign targeting misconfigured network edge devices and cloud-hosted infrastructure (notably in energy and other critical sectors), highlighting a tactical shift away from CVE exploitation toward harvesting credentials via packet capture and credential replay; AWS detected compromises of customer appliances, notified affected parties, and recommended auditing edge devices, monitoring for credential replay, and applying the provided IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.