Amazon Warns Russian GRU Hackers Target Western Firms via Edge Devices
ID: 58ecf91b-7805-5eb9-af57-3dc471dbe3e8
STIX ID: report--58ecf91b-7805-5eb9-af57-3dc471dbe3e8
Feed Name: Infosecurity Magazine (News)
Amazon Threat Intelligence reports that a Russian state-sponsored group, attributed with high confidence to the GRU, has conducted a long-running campaign (2021–2025) against Western critical infrastructure and in 2025 shifted tactics from exploiting public CVEs (e.g., WatchGuard, Confluence, Veeam) to compromising misconfigured customer network edge devices (routers, VPN concentrators, network management appliances and cloud-hosted devices) to gain persistent access, harvest credentials, and move laterally; the campaign shows infrastructure overlaps with GRU-linked clusters such as Sandworm and Curly COMrades, the latter deploying host-based implants (CurlyShell, CurlCat) for evasion and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
