Skip naar inhoud

NCSC joins US authorities to expose Russian brute force campaign

Wilt u deze bijdrage aanbevelen? Dat kan via:

A joint attribution by the British and American authorities accuses Russia’s GRU intelligence services of conducting a campaign of brute force attacks on enterprise and cloud environments
The UK’s National Cyber Security Centre (NCSC), alongside US partners including the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI), have today published a joint security advisory exposing a long-running campaign of brute force cyber attacks by Russia’s GRU military intel unit.The campaign supposedly began in mid-2019 and appears to be ongoing. It has seen the 85th Main Special Service Centre (GTsSS) of the Russian General Staff Main Intelligence Directorate (GRU) attempt to compromise the networks of organisations around the world, including government and public sector bodies and enterprises, with brute force attacks – a trial and error method of breaking into a target’s system by running through all possible combinations of credentials until a match is hit.

This technique is not at all new – indeed it resembles to some extent how a bank robber might crack a safe in an old movie, by trying lots of combinations – but in this campaign, the Russian operatives have been using a Kubernetes cluster to scale and automate its credential-busting activities.

A significant number of these attacks are understood to have targeted Microsoft Office 365 cloud services, although the campaign also hit other service providers and even on-premise email servers. The GRU was thus able to access protected data, including emails, and identify valid account credentials to obtain deeper access, establish persistence while evading detection, and escalate privileges. Its spies also exploited publicly known vulnerabilities for remote code execution.

Known targets so far include government and military, defence contractors, energy companies, higher education institutions, logistics companies, law firms, media companies, political consultants and political parties, and think tanks.

Commenting on the latest disclosure, Mandiant Threat Intelligence vice-president John Hultquist said: “APT28 [Mandiant’s designation for GRU ops] conducts intelligence collection against these targets regularly as part of its remit as the cyber arm of a military intelligence agency.

“The bread and butter of this group is routine collection against policy makers, diplomats, the military, and the defence industry and these sorts of incidents don’t necessarily presage operations like hack and leak campaigns. Despite our best efforts we are very unlikely to ever stop Moscow from spying,” he told Computer Weekly in an emailed statement. “This is a good reminder that the GRU remains a looming threat, which is especially important given the upcoming Olympics, an event they may well attempt to disrupt.”

As with any campaign leveraging credential theft techniques, there are several steps organisations can take straight away to avoid becoming compromised. These include:

  • Using of multi-factor authentication (MFA) technology;
  • Enabling time-out and lock-out features whenever password authentication is needed, which can slow brute force attacks;
  • Using services that prevent users from making easily guessed password choices;
  • Using captchas to hinder automated access attempts when protocols support human interaction;
  • Changing all default credentials and disabling protocols that use weak authentication or don’t support MFA;
  • Configuring access controls on cloud resources to ensure only well-maintained and well-protected accounts may access them;
  • Employing network segmentation and restrictions to limit access;
  • And using automated tools to audit access logs for security concerns, and identify dodgy access requests.

The full advisory, including more information on the campaign’s tactics, techniques and procedures, can be found here.

Lees ook:

Wat wil en wenst de ontwikkelaar?

In een krappe ict-arbeidsmarkt is het voor werkgevers interessant te weten wat er onder ontwikkelaars leeft. Bedrijven die de juiste tools bieden, hebben een streepje voor. Een internationaal onderzoek onder ruim zeventigduizend ontwikkelaars uit de Stack Overflow-community geeft inzicht in de trends. Dit rapport is bij recruiters dan ook niet onopgemerkt gebleven. Ze krijgen zo een beeld van hoe developers leren en meer kennis vergaren, welke tools ze gebruiken en waaraan ze behoefte hebben.

TNO: Europa kan tech-overmacht VS en China doorbreken

Zet vol in op de ontwikkeling van 6G, maak Gaia-X volwassen, loop voorop met edge computing en omarm open technologie. Dit zijn enkele aanbevelingen van TNO om in Europa de overheersing van Big Tech en Chinese (5G-)bedrijven te doorbreken.

Subpostmaster campaigning forces government to set up compensation scheme and make interim payments

Subpostmaster campaign group is a step closer to achieving what it was originally set up to do as government launches compensation scheme for its members who did not receive fair payouts

Advies: wacht met 3,5 GHz tot Inmarsat weg is

Het duurt waarschijnlijk tot eind 2023 voordat de 3,5-GHz-frequentieband beschikbaar komt voor openbare mobiele-communicatiediensten. Er is weliswaar veel vraag naar extra frequentieruimte, maar op de daarvoor afgesproken 3,5-GHz-band kan dat storen met noodoproepen van de lucht- en zeevaart. Het ministerie krijgt het advies te wachten totdat satellietbedrijf Inmarsat is verhuisd van het Friese Burum naar Griekenland.

Na sase komt sse (security service edge)

Security service edge (sse) is de evolutie van het sase-framework van Gartner. Door de letter ‘A’ (voor ’access) te verwijderen, wordt duidelijk dat het netwerk niet langer wordt beschouwd als onderdeel van een beveiligingsoplossing. Het is slechts het mechanisme dat de datastromen naar het security- en controleplatform transporteert.

UK tech has 2.8% gender ‘wage gap’, says Hired

The wage offered to women for tech jobs in the UK is 2.8% less than offered to male counterparts – a larger gap than in the US and Canada, says Hired

Wilt u deze bijdrage aanbevelen? Dat kan via:

Klaar voor de beste oplossing voor uw IT & ICT-situatie?

Ik heb mijn wachtwoord gewijzigd in “onjuist.” Dus wanneer ik vergeet wat het is, zal de computer zeggen: “Uw wachtwoord is onjuist.”