CyberzSOC

Publication detail
← Back to advisories & guidance

Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure ↗ source

September 5, 2024 NSA Alert
Co-sealed by: ASD/ACSC, CCCS, CISA, CNMF, FBI, MIVD, NCSC-UK, NSA, Treasury, USCC

Summary

GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and especially for webmail, virtual private networks (VPNs), and accounts that access critical systems. This Cybersecurity Advisory provides tactics, techniques, and procedures (TTPs) associated with Unit 29155 cyber actors—both during and succeeding their deployment of WhisperGate against Ukraine—as well as further analysis (see Appendix A) of the WhisperGate malware initially published in the joint advisory, Destructive Malware Targeting Organizations in Ukraine, published February 26, 2022. FBI, CISA, NSA and the following partners are releasing this joint advisory as a collective assessment of Unit 29155 cyber operations since 2020: Justice)  Computer Emergency Response Team of Mission Force (CNMF)  Canadian Security Intelligence Service Security Service (MIVD)  Communications Security Establishment Service (BIS) Australian Cyber Security Centre (ASD’s of the Constitution (BfV)  United Kingdom National Cyber Security For additional information on Russian state-sponsored malicious cyber activity and related indictments, see the recent U.S.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-26084 9.8 Critical Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthentica…
CVE-2021-33044 9.8 Critical Dahua IP Camera Firmware Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client du…
CVE-2021-33045 9.8 Critical Dahua IP Camera Firmware Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authe…
CVE-2022-26134 9.8 Critical Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remo…
CVE-2022-26138 9.8 Critical Atlassian Confluence Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker…
CVE-2022-3236 9.8 Critical Sophos Firewall A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
CVE-2021-3156 7.8 High Sudo Sudo Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.
CVE-2021-4034 7.8 High Red Hat Polkit The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rig…
CVE-2020-1472 5.5 Medium Microsoft Netlogon Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secur…
CVE-2022-27666 — n/a n/a A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.