Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets
Cybersecurity and Infrastructure Security Agency ^ | 10 22 2020 | US CERT CISA GOV

Posted on 10/22/2020 6:05:21 PM PDT by yesthatjallen

Summary

This joint cybersecurity advisory—written by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA)—provides information on Russian state-sponsored advanced persistent threat (APT) actor activity targeting various U.S. state, local, territorial, and tribal (SLTT) government networks, as well as aviation networks. This advisory updates joint CISA-FBI cybersecurity advisory AA20-283A: APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations.

Since at least September 2020, a Russian state-sponsored APT actor—known variously as Berserk Bear, Energetic Bear, TeamSpy, Dragonfly, Havex, Crouching Yeti, and Koala in open-source reporting—has conducted a campaign against a wide variety of U.S. targets. The Russian state-sponsored APT actor has targeted dozens of SLTT government and aviation networks, attempted intrusions at several SLTT organizations, successfully compromised network infrastructure, and as of October 1, 2020, exfiltrated data from at least two victim servers.

The Russian-sponsored APT actor is obtaining user and administrator credentials to establish initial access, enable lateral movement once inside the network, and locate high value assets in order to exfiltrate data. In at least one compromise, the APT actor laterally traversed an SLTT victim network and accessed documents related to:

Sensitive network configurations and passwords.

Standard operating procedures (SOP), such as enrolling in multi-factor authentication (MFA).

IT instructions, such as requesting password resets.

Vendors and purchasing information.

Printing access badges.

To date, the FBI and CISA have no information to indicate this APT actor has intentionally disrupted any aviation, education, elections, or government operations. However, the actor may be seeking access to obtain future disruption options, to influence U.S. policies and actions, or to delegitimize SLTT government entities.

SNIP


TOPICS: News/Current Events
KEYWORDS: russia

1 posted on 10/22/2020 6:05:21 PM PDT by yesthatjallen
[ Post Reply | Private Reply | View Replies]

To: yesthatjallen

When have America’s adversaries NOT been attacking with any and all of their means? This is not news, should have been taught to everyone in history class.


2 posted on 10/22/2020 6:10:55 PM PDT by JungleGoat77 (.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson