CyberzSOC

Publication detail
← Back to advisories & guidance

SVR Cyber Actors Adapt Tactics for Initial Cloud Access ↗ source

February 26, 2024 NSA Alert
Co-sealed by: ASD/ACSC, CCCS, CISA, CNMF, FBI, NCSC-UK, NSA

Summary

The US National Security Agency (NSA), the US Cybersecurity and Infrastructure Security Agency (CISA), the US the Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC) agree with this attribution and the details This advisory provides an overview of TTPs deployed by the actor to gain initial access into the cloud environment and includes advice to detect and mitigate The NCSC has previously detailed how Russian Foreign Intelligence Service (SVR) cyber actors have targeted governmental, think tank, healthcare and energy targets for intelligence gain. It has now observed SVR actors expanding their targeting to include aviation, education, law enforcement, local and state councils, government financial departments and military organisations. SVR actors are also known for: the supply chain compromise of SolarWinds software activity that targeted organisations developing the COVID-19 vaccine As organisations continue to modernise their systems and move to cloud-based infrastructure, the SVR has adapted to these changes in the operating They have to move beyond their traditional means of initial access, such as exploiting software vulnerabilities in an on-premise network, and instead target the cloud services themselves.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.