Friday, December 6, 2024
HomeCVE/vulnerabilityRussian APT Hackers Attacking Critical Infrastructure

Russian APT Hackers Attacking Critical Infrastructure

Published on

SIEM as a Service

Russia leverages a mix of state-backed Advanced Persistent Threat (APT) groups and financially motivated cybercriminals to achieve its strategic goals, as APT groups conduct espionage to gather valuable political and economic information. 

The Russian government may recruit financially motivated groups, despite their apparent independence, for malicious operations, resulting in a complex threat landscape where the distinctions between criminal and state-sponsored actors are hazy, while intelligence agencies like the SVR and GRU likely orchestrate these cyber activities. 

Hackers believed to be affiliated with Russia’s GRU launched a coordinated cyberattack against Denmark’s energy sector in May 2023 by exploiting a critical vulnerability (CVE-2023-28771) in Zyxel firewalls, compromising eleven organizations and forcing others to isolate their networks.

- Advertisement - SIEM as a Service

ANYRUN malware sandbox’s 8th Birthday Special Offer: Grab 6 Months of Free Service

The unauthenticated remote code execution vulnerability allowed attackers root access to the firewalls, potentially granting them access to critical infrastructure.

While attackers were stopped before gaining deeper access, the pre-selected targets and sophisticated planning suggest significant Russian involvement. 

Hackers believed to be affiliated with Russia infiltrated Kyivstar, Ukraine’s largest telecom provider, in May 2023, as they waited until December to unleash a zero-day malware attack, wiping data and crippling services for days.

The attackers likely exploited a compromised employee account to gain escalated access and target cloud storage and backups. 

While the group, claiming ties to Sandworm, aimed to disrupt Ukrainian military communications, the attack only devastated Kyivstar’s operations, which marks one of at least eleven cyberattacks targeting Ukrainian telecom providers by Sandworm since May 2023. 

APT29, a Russia-linked APT group, exploited a critical authentication bypass vulnerability (CVE-2023-42793) in JetBrains TeamCity servers to gain unauthorized access to victim networks, allowing them to steal sensitive data and potentially manipulate software builds. 

They employed Bring Your Own Vulnerable Driver (BYOVD) to bypass detection, escalate privileges, and laterally move through the network using Windows Management Instrumentation, and deployed additional backdoors to maintain persistence on compromised systems. 

The incident highlights the dangers of supply chain attacks and the evolving tactics of attackers who target traditional IT systems to reach operational technology (OT) networks.  

Researchers at Reliaquest linked the Sandworm Team, a hacking group likely affiliated with Russia, to a 2022 cyberattack on a Ukrainian power grid substation.

Sandworm gained access to the substation’s control system through a compromised virtual machine and exploited legitimate software (LOLBIN) to manipulate the SCADA system. 

It caused a power outage likely timed to coincide with physical attacks, as Sandworm’s extended access suggests a wait for maximum impact and their use of LOLBINs highlights evolving tactics to bypass defenders, which signifies Russia’s growing capabilities in targeting critical operational technology infrastructure. 

Russia has developed multiple OT malware strains, including COSMICENERGY, Industroyer, and Industroyer2, to target ICS and disrupt electrical power. COSMICENERGY exploits IEC 60870-5-104 devices, like RTUs, to manipulate power grids. 

As its variant, Industroyer2, specifically disables circuit-breaker failure protections, which use insecure OT systems and need early detection to prevent network compromises, Industroyer is a modular piece of malware with a backdoor, a launcher, and payloads that can manipulate circuit breakers and wipe data.

Free Webinar on Live API Attack Simulation: Book Your Seat | Start protecting your APIs from hackers

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...

Sophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Researchers discovered Celestial Stealer, a JavaScript-based MaaS infostealer targeting Windows systems that, evading detection...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...

Multiple SonicWall Vulnerabilities Let Attackers Execute Remote Code

SonicWall has issued a critical alert regarding multiple vulnerabilities in its Secure Mobile Access...

Django Security Update, Patch for DoS & SQL Injection Vulnerability

 The Django team has issued critical security updates for versions 5.1.4, 5.0.10, and 4.2.17....