TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Case Studies

Russian malicious cyber activities

by Mark Rowe

The authorities in the United States and UK – the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the UKโ€™s National Cyber Security Centre (NCSC) have released a ‘Cybersecurity Advisory‘ on malicious cyber activities by Russia.

โ€œRussian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environmentsโ€ points to the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS).

The document sets out how Russian military intelligence from at least mid-2019 until early 2021 has targeted hundreds of organisations using brute force access to penetrate government and private sector networks. The advisory covers the tactics, techniques, and procedures (TTPs) GTsSS actors used in their campaign to exploit targeted networks, access credentials, move laterally, and collect and exfiltrate data. The Russians’ aim: the actors to evade cyber defences and collect and exfiltrate various information in the networks, including mailboxes.

The NCSC has published advice for defending against such attacks, covering MFA (multi-factor authentication) for online services; and password administration for system owners.

Visit NSA.gov/What-We-Do/Cybersecurity/Advisories-Technical-Guidance/.

Comment

Tom Jermoluk, CEO of Beyond Identity says: โ€œRussian GRU agents and other state actors like those involved in SolarWinds โ€“ and a range of financially motivated attackers (e.g., ransomware) โ€“ all use the same โ€œpassword sprayingโ€ brute force techniques. Why? Because they are so effective. Unfortunately, a misunderstanding of this technique is leading to shockingly flawed advice like the that given in the NSA advisory which, in part, recommends โ€œmandating the use of stronger passwordsโ€. The credential-gathering that preceded the password spraying campaign most certainly collected short and strong passwords. And the Russian Kubernetes cluster used in the attack was capable of spraying โ€œstrong passwords.โ€ The government went on to recommended a โ€œZero Trust security model that uses additional attributes when determining access, and analytics to detect anomalous accessesโ€. This sage advice requires a move to strong, continuous authentication. It also requires organisations to eliminate passwords because they are so completely compromised that you simply cannot achieve Zero Trust with them.โ€

For more on the Solarwinds cyber breach and US President Joe Biden’s work so far on cyber see the July print edition of Professional Security magazine.

Related News

  • Case Studies

    CCTV to combat litter

    by Mark Rowe

    East Riding of Yorkshire Council is trialling video surveillance to combat litter thrown on grass verges in the region. The council is…

  • Case Studies

    Face covering PSPOs

    by Mark Rowe

    Three places are looking to add prohibitions on covering your face as part of a Public Spaces Protection Order (PSPO). Business crime…