Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
ID: 1492f18f-c57d-58e7-a427-6b9cd42e6ff0
STIX ID: report--1492f18f-c57d-58e7-a427-6b9cd42e6ff0
Feed Name: Bleeping Computer
Threat Score
Russian state-aligned APT28 (tracked as GruesomeLarch/Fancy Bear) executed a 'nearest neighbor' attack by compromising nearby organizations to pivot into a targeted U.S. company's corporate Wi‑Fi, bypassing MFA protections on public services; they performed lateral movement using RDP from an unprivileged account, dumped Windows registry hives for exfiltration, and likely exploited CVE-2022-38028 in the Print Spooler for privilege escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
