Saturday, November 16, 2024
HomeCVE/vulnerabilityRussian APT Hackers Attacking Critical Infrastructure

Russian APT Hackers Attacking Critical Infrastructure

Published on

Russia leverages a mix of state-backed Advanced Persistent Threat (APT) groups and financially motivated cybercriminals to achieve its strategic goals, as APT groups conduct espionage to gather valuable political and economic information. 

The Russian government may recruit financially motivated groups, despite their apparent independence, for malicious operations, resulting in a complex threat landscape where the distinctions between criminal and state-sponsored actors are hazy, while intelligence agencies like the SVR and GRU likely orchestrate these cyber activities. 

Hackers believed to be affiliated with Russia’s GRU launched a coordinated cyberattack against Denmark’s energy sector in May 2023 by exploiting a critical vulnerability (CVE-2023-28771) in Zyxel firewalls, compromising eleven organizations and forcing others to isolate their networks.

- Advertisement - SIEM as a Service

ANYRUN malware sandbox’s 8th Birthday Special Offer: Grab 6 Months of Free Service

The unauthenticated remote code execution vulnerability allowed attackers root access to the firewalls, potentially granting them access to critical infrastructure.

While attackers were stopped before gaining deeper access, the pre-selected targets and sophisticated planning suggest significant Russian involvement. 

Hackers believed to be affiliated with Russia infiltrated Kyivstar, Ukraine’s largest telecom provider, in May 2023, as they waited until December to unleash a zero-day malware attack, wiping data and crippling services for days.

The attackers likely exploited a compromised employee account to gain escalated access and target cloud storage and backups. 

While the group, claiming ties to Sandworm, aimed to disrupt Ukrainian military communications, the attack only devastated Kyivstar’s operations, which marks one of at least eleven cyberattacks targeting Ukrainian telecom providers by Sandworm since May 2023. 

APT29, a Russia-linked APT group, exploited a critical authentication bypass vulnerability (CVE-2023-42793) in JetBrains TeamCity servers to gain unauthorized access to victim networks, allowing them to steal sensitive data and potentially manipulate software builds. 

They employed Bring Your Own Vulnerable Driver (BYOVD) to bypass detection, escalate privileges, and laterally move through the network using Windows Management Instrumentation, and deployed additional backdoors to maintain persistence on compromised systems. 

The incident highlights the dangers of supply chain attacks and the evolving tactics of attackers who target traditional IT systems to reach operational technology (OT) networks.  

Researchers at Reliaquest linked the Sandworm Team, a hacking group likely affiliated with Russia, to a 2022 cyberattack on a Ukrainian power grid substation.

Sandworm gained access to the substation’s control system through a compromised virtual machine and exploited legitimate software (LOLBIN) to manipulate the SCADA system. 

It caused a power outage likely timed to coincide with physical attacks, as Sandworm’s extended access suggests a wait for maximum impact and their use of LOLBINs highlights evolving tactics to bypass defenders, which signifies Russia’s growing capabilities in targeting critical operational technology infrastructure. 

Russia has developed multiple OT malware strains, including COSMICENERGY, Industroyer, and Industroyer2, to target ICS and disrupt electrical power. COSMICENERGY exploits IEC 60870-5-104 devices, like RTUs, to manipulate power grids. 

As its variant, Industroyer2, specifically disables circuit-breaker failure protections, which use insecure OT systems and need early detection to prevent network compromises, Industroyer is a modular piece of malware with a backdoor, a launcher, and payloads that can manipulate circuit breakers and wipe data.

Free Webinar on Live API Attack Simulation: Book Your Seat | Start protecting your APIs from hackers

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Critical Laravel Vulnerability CVE-2024-52301 Allows Unauthorized Access

CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for...

4M+ WordPress Websites to Attacks, Following Plugin Vulnerability

A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin,...