TL;DR
- Russian State-Sponsored Attackers Target HP Enterprise and Microsoft in Coordinated Cyber Espionage Campaign
- Emergence of Blackwood APT Using Advanced NSPX30 Backdoor in Cyberespionage
- Jenkins Servers Exposed to Remote Code Execution
- Critical Remote Code Execution Vulnerability in Confluence Under Active Attack
- Google Kubernetes Misconfiguration Lets Any Gmail Account Control Your Clusters
Russian State-Sponsored Attackers Target HP Enterprise and Microsoft in Coordinated Cyber Espionage Campaign
- Widespread Infiltration of HP Enterprise: Hackers with connections to the Kremlin infiltrated Hewlett Packard Enterprise's (HPE) cloud email environment, exfiltrating mailbox data. The incident, first detected in December 2023, persisted undetected for over six months, starting in May 2023. The attack targeted HPE's cybersecurity, go-to-market, business segments, and other functional areas, but the company reported no significant impact on operations.
- APT29's Sophisticated Espionage Tactics: The attacks were orchestrated by APT29, a Russian state-sponsored group, also known as BlueBravo, Cloaked Ursa, Cozy Bear, Midnight Blizzard, and The Dukes. APT29 is renowned for its involvement in high-profile hacks, including the 2016 U.S. Democratic National Committee breach and the 2020 SolarWinds supply chain compromise. Their strategy involves using legitimate yet compromised accounts to maintain extended, undetected presence in target environments.
- Expanding Targets and Advanced Techniques: Microsoft revealed that APT29, responsible for a cyberattack on its systems in late November 2023, is targeting additional organizations globally. The group primarily aims at governmental, diplomatic, NGO, and IT service providers in the U.S. and Europe. Their tactics include diverse initial access methods, exploitation of on-premises environments to cloud migration, and abuse of service providers' trust to access downstream customers.
- Rogue OAuth Applications and Evasion Methods: APT29 utilizes breached accounts to create and manipulate OAuth applications, granting high permissions for clandestine activities. This allows them to maintain access even after losing control over the initial compromised account. They also employed password spray attacks from a distributed residential proxy infrastructure, making traditional IoC-based detection challenging due to the high turnover rate of IP addresses.
