Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Microsoft warns that APT29 espionage attacks targeting global organizations are expanding
    Indexed Pages

    Microsoft warns that APT29 espionage attacks targeting global organizations are expanding

    techempireBy techempireUpdated:1 Comment3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 26, 2024Editorial DepartmentThreat Intelligence/Cyber ​​Attacks

    APT29 spy attack

    Microsoft said Thursday that Russian state-sponsored threat actors launched a cyberattack on its systems in late November 2023. They have been targeting other organizations and are now beginning to notify them.

    This development comes just a day after Hewlett Packard Enterprise (HPE) revealed that it had fallen victim to an attack by a hacker group tracked as APT29also known as BlueBravo, Cloaked Ursa, Cozy Bear, Midnight Blizzard (formerly Nobelium), and The Dukes.

    “This threat actor is known to primarily target governments, diplomatic entities, non-governmental organizations (NGOs) and IT service providers in the United States and Europe,” Microsoft’s Threat Intelligence Team said in a new advisory.

    Internet security

    The main goal of these espionage missions is to collect sensitive information of strategic interest to Russia by maintaining a foothold for an extended period of time without attracting any attention.

    The latest revelations suggest the event may be larger than previously thought. However, the tech giant did not reveal which other entities were singled out.

    APT29’s operations involve using legitimate but compromised accounts to gain and expand access within target environments and fly under the radar. It has also been known to identify and abuse OAuth applications for lateral movement between cloud infrastructure and for post-breach activities such as email harvesting.

    “They leverage multiple initial access methods, ranging from credential theft to supply chain attacks, leveraging on-premises environments to move laterally to the cloud, and leveraging the service provider’s chain of trust to gain access to downstream customers,” Microsoft noted.

    Another notable tactic is the use of compromised user accounts to create, modify and grant high privileges to OAuth applications, which they can abuse to hide malicious activity. The company notes that this allows threat actors to maintain access to the application even if they lose access to the initially compromised account.

    These malicious OAuth applications were ultimately used to authenticate to Microsoft Exchange Online and target Microsoft corporate email accounts to steal data of interest.

    Internet security

    In a November 2023 incident against Microsoft, threat actors used a password spray attack to successfully infiltrate legacy non-production test tenant accounts that did not have multi-factor authentication (MFA) enabled.

    Such attacks are launched from a decentralized residential proxy infrastructure to hide their origin, allowing threat actors to interact with compromised tenants and Exchange Online through a vast network of IP addresses that are also used by legitimate users.

    “Due to the high translation rate of IP addresses, Midnight Blizzard uses residential proxies to obfuscate connections, making traditional indicators of compromise (IoC)-based detection unfeasible,” Redmond said. This makes it imperative for organizations to take measures to defend themselves. Malicious OAuth applications and password spraying.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Microsoft warns that APT29 espionage attacks targeting global organizations are expanding
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Top CRM Platforms

    New Recipe Website Allows To Sort By Ingredient

    Nissan reveals ransomware attack exposed Social Security numbers of 53,000 workers

    Using artificial intelligence to revolutionize retail

    The latest version of xAI’s Grok can process images

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.