logo

Russian hackers shift to cloud attacks, US and allies warn

ID: b7b2d8c9-8eb5-52b2-8eda-0336b0c452c8

STIX ID: report--b7b2d8c9-8eb5-52b2-8eda-0336b0c452c8

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-02-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

APT29 (SVR) is increasingly targeting cloud services across governments and critical organizations, using credential-based attacks (brute force/password spraying), stolen access tokens, dormant accounts, MFA fatigue, device enrollment abuse, and malware like MagicWeb; a Five Eyes advisory details these cloud-focused TTPs, recent compromises (including Exchange Online), and prescribes mitigations such as enforcing MFA, least privilege, canary accounts, reduced session/token lifetimes, and strict device enrollment controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.