logo

Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure

ID: 7b9fa468-27e8-55a9-bcd4-a718c224af62

STIX ID: report--7b9fa468-27e8-55a9-bcd4-a718c224af62

Feed Name: AWS Security Blog

Threat Score
90/100

Date Published: 2025-12-15

Date Updated: 2026-04-27

Author: CJ Moses

...
...

Amazon Threat Intelligence reports a sustained 2021–2025 GRU-linked campaign (associated with Sandworm/Curly COMrades) that shifted from CVE exploitation to compromising misconfigured customer network edge devices—often hosted on AWS—to perform packet capture, credential harvesting, and credential replay against energy and other critical infrastructure targets; the report includes timelines, exploited CVEs, IOCs, a captured exfiltration payload, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.