Amazon disrupts Russian GRU hackers attacking edge network devices
ID: 13888eae-0109-5ce4-a764-f2098c422dbc
STIX ID: report--13888eae-0109-5ce4-a764-f2098c422dbc
Feed Name: Bleeping Computer
**Executive summary:** Amazon Threat Intelligence disrupted operations attributed to GRU-linked hackers who targeted Western critical infrastructure cloud customers from 2021 onward, pivoting in 2025 from exploiting zero-day and known vulnerabilities to abusing misconfigured edge devices (routers, VPN gateways, management appliances and collaboration platforms) for initial access; the activity enabled credential harvesting, lateral movement, and use of compromised EC2-hosted devices as proxies, and Amazon mitigated affected instances, shared IOAs with partners, and issued hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
