"Evolution of Russian Cyber Actors' Tactics in Cloud Attacks"

1 min read
Source: CISA
TL;DR Summary

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory detailing the tactics, techniques, and procedures (TTPs) of the SVR-attributed cyber espionage group APT29, also known as Midnight Blizzard, the Dukes, or Cozy Bear. The advisory outlines how these actors have adapted to target cloud-based infrastructure, including accessing cloud environments, using service and dormant accounts, employing cloud-based token authentication, enrolling new devices to the cloud, and utilizing residential proxies to stay covert. The report also provides mitigation and detection strategies to defend against these tactics.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

8 min

vs 9 min read

Condensed

95%

1,65086 words

Want the full story? Read the original article

Read on CISA