The intelligence alliance of the so-called Five Eyes, comprising agencies from the Anglophone world – the UK, the US, Australia, Canada and New Zealand – have issued a stark warning about a tactical shift by Russian hacker groups towards cloud services.
New battleground
This shift is a departure from traditional on-premises infrastructure attacks and signals a new battleground in the realm of cyber threats.
The advisory notes that, mirroring the business sector's migration to cloud-based operations, threat actors are adapting their strategies to infiltrate cloud environments and services.
Traditional access methodologies, such as password spraying and brute force attacks, continue to be the tools of choice for these hackers, underscoring the persistent vulnerability of cloud breaches in recent years.
A memorable instance of such cyber aggression was the SolarWinds attack, perpetrated by the Russian hacker group APT29, also known as CozyBear, MidnightBlizzard or TheDukes.
The sophisticated operation compromised the software of SolarWinds, leading to breaches in several federal agencies, including the US Department of State, affecting some 18,000 customers.
Dormant accounts and other weak points
The advisory also sheds light on lucrative cloud access points for these hackers, such as dormant organisational accounts with unrevoked access privileges and the exploitation of stolen access tokens to circumvent credential and multi-factor authentication (MFA) safeguards.
One of the calling cards of Russian-backed cyber operations identified by the advisory is the use of MagicWeb malware, enabling attackers to masquerade as legitimate users within an organisation's infrastructure.
To counteract these evolving threats, the advisory recommends several mitigation and detection strategies, including the adoption of two-factor or multi-factor authentication, the use of strong, unique passwords, the deactivation of inactive accounts and the restriction of user access to essential applications and files.
It promotes the creation of 'canary accounts' as a deception technique, the establishment of minimal session lifetimes, device enrolment authentication, frequent sanitisation of outdated devices and the use of diverse information sources for intrusion detection.
This shift to cloud-based targets underscores the necessity for heightened vigilance and robust security measures to safeguard against the sophisticated tactics of Russian-backed cyber threats.