logo

CISA Alert AA24-249A: Russian GRU Unit 29155 Targeting U.S. and Global Critical Infrastructure

ID: 0eee58bc-06e1-54a3-9469-0490eb3b8762

STIX ID: report--0eee58bc-06e1-54a3-9469-0490eb3b8762

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2024-09-06

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren)

...
...

On 5 September 2024 a joint advisory from FBI/CISA/NSA and subsequent analysis attributed sustained offensive cyber operations to Russian GRU Unit 29155. The report details reconnaissance, initial access (exploited CVEs and default credentials), execution (PowerShell, reverse shells), persistence (web shells), credential theft (LSASS/SAM dumping), lateral movement (pass-the-hash), C2 techniques (multi-hop proxies, DNS tunneling, reverse TCP), and exfiltration (Rclone to cloud). It highlights destructive activity (WhisperGate) against critical infrastructure, provides example commands and IOCs, and maps behaviors to MITRE ATT&CK to inform defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.