Russia Hits Critical Orgs Via Misconfigured Edge Devices
ID: 09bef80d-19dc-509c-b185-e9778873ed91
STIX ID: report--09bef80d-19dc-509c-b185-e9778873ed91
Feed Name: Dark Reading
**Executive Summary:** Amazon Threat Intelligence details a 2021–2025 Russian GRU-linked campaign targeting misconfigured network edge devices and cloud-hosted infrastructure (notably in energy and other critical sectors), highlighting a tactical shift away from CVE exploitation toward harvesting credentials via packet capture and credential replay; AWS detected compromises of customer appliances, notified affected parties, and recommended auditing edge devices, monitoring for credential replay, and applying the provided IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
