Russian Attack Group Uses Phones & Printers to Breach Corporate Networks

  /     /     /  
Publicated : 23/11/2024   Category : security


Russian Attack Group Uses Phones & Printers to Breach Corporate Networks


Microsoft spotted Strontium, also known as APT28 or Fancy Bear, using IoT devices to breach businesses and seek high-value data.



Microsoft reports Russian state-sponsored attack group Strontium, also known as APT28 and Fancy Bear, is using popular Internet of Things devices to breach enterprise networks and elevate privileges.
Back in April, researchers with the Microsoft Threat Intelligence Center noticed infrastructure belonging to Strontium communicating with, and attempting to compromise, external devices including a voice-over-IP phone, office printer, and video decoder across multiple customer locations. These devices became points of ingress from which the actor established a presence on the network and continued looking for further access, the Microsoft Security Response Center team writes in a blog post.
Once on the network, the actor could do a network scan to seek other insecure devices that let them move across the environment in search of more privileged accounts and higher-value data. With access to each of these devices, they ran tcpdumpto sniff network traffic on local subnets. Microsoft also saw them noting administrative groups to further broaden their access.
As they moved throughout target networks, actors would drop a shell script to establish persistence so they could continue their exploration. The devices they compromised were seen communicating with an external command-and-control server, researchers report. However, because the attacks were identified early, they have not determined Strontiums motivation for this activity.
In the last 12 months, Microsoft has issued nearly 1,400 nation-state alerts to victims of Strontium activity. While 20% of these notifications related to attacks on non-governmental institutions, 80% of Strontiums attacks are focused on the government, IT, military, defense, medicine, education, and engineering sectors.
Read more details
here
.
 
Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the 
conference
 and 
to register.


Last News

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Russian Attack Group Uses Phones & Printers to Breach Corporate Networks