Brief

Summary:

The UK National Cyber Security Centre (NCSC) and international partners have released an advisory on the tactics, techniques, and procedures (TTPs) of APT29, a cyber espionage group attributed to the SVR (Russian intelligence services). The advisory provides an overview of recent TTPs deployed by APT29 to gain initial access into cloud environments and offers advice on detection and mitigation.

Key TTPs include:

1. Access via service and dormant accounts: APT29 uses brute forcing and password spraying to access service accounts, which are often highly privileged and not easily protected with multi-factor authentication (MFA).
2. Cloud-based token authentication: APT29 uses tokens to access accounts without needing a password, often exploiting default token validity times.
3. Enrolling new devices to the cloud: APT29 bypasses password authentication on personal accounts and then registers their own device as a new device on the cloud tenant, often using MFA bombing to get around MFA defenses.
4. Residential proxies: APT29 uses residential proxies to hide the true source of traffic, making it harder to detect malicious connections.

To mitigate these TTPs, organizations should:

1. Use multi-factor authentication
2. Implement strong, unique passwords for all accounts
3. Disable inactive/dormant accounts and manage access with a "joiners

How SVR-Attributed Actors are Adapting to the Move of Government and Corporations to Cloud Infrastructure OVERVIEW This advisory details recent tactics, techniques, and procedures (TTPs) of the group commonly known as APT29, also known as Midnight Blizzard, the Dukes, or Cozy Bear. The UK National Cyber Security Centre (NCSC) and international partners assess that APT29

This content is restricted.

Highlights content goes here...

How SVR-Attributed Actors are Adapting to the Move of Government and Corporations to Cloud Infrastructure OVERVIEW This advisory details recent tactics, techniques, and procedures (TTPs) of the group commonly known as APT29, also known as Midnight Blizzard, the Dukes, or Cozy Bear. The UK National Cyber Security Centre (NCSC) and international partners assess that APT29

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies