Fancy Bear 'Nearest Neighbor' Attack Uses Nearby Wi-Fi Network
ID: 118dc300-a36f-5c24-a847-f5d4042ab559
STIX ID: report--118dc300-a36f-5c24-a847-f5d4042ab559
Feed Name: Dark Reading
Date Published: 2024-11-25
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Fancy Bear (APT28) executed a sophisticated "Nearest Neighbor" espionage campaign by compromising nearby organizations' Wi‑Fi networks via credential-stuffing and chaining access through Organizations B and C to reach a US target; the actor used RDP, living‑off‑the‑land utilities like Cipher.exe and netsh to move laterally and collect data, and researchers recommend Wi‑Fi/Ethernet segmentation, MFA/certificate-based Wi‑Fi authentication, and monitoring for anomalous utility usage to detect similar intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
