Info

Five Eyes advisory warns of Russia linked cyber attacks

0

Cybersecurity agencies of the Five Eyes intelligence alliance (United States, Australia, Canada, New Zealand, and the United Kingdom) issued a joint advisory warning of cyber attacks on critical infrastructure conducted by Russia-linked threat actors and criminal cyber threats.

The advisory is a joint warning by the eight cybersecurity authorities from the Five Eye nations, which includes US Cybersecurity and Infrastructure Security Agency, the US Federal Bureau of Investigation, US National Security Agency, Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand’s National Cyber Security Centre, UK National Cyber Security Centre, and the UK National Crime Agency.

The agencies stated that evolving intelligence indicates that the Russian government is exploring options for potential cyber attacks. Some cybercrime and cyber threat groups have recently publicly pledged support for the Russian government in light of its invasion into Ukraine. These Russian-aligned cybercrime groups have threatened to conduct cyber operations in retaliation for perceived cyber offensives against the Russian government and the Russian people.

Some groups have also threatened to conduct cyber operations against countries and organizations providing material support to Ukraine, while other groups have conducted disruptive attacks against Ukrainian websites as well.

Some of the cybercrime groups that have aligned with the Russian government are The CoomingProject, Killnet, Mummy Spider, Salty Spider, Scully Spider, Smokey Spider, Wizard Spider, and the Xaknet Team.

Meanwhile, Primitive Bear and Venomous Bear have been flagged as Russian-aligned cyber threat groups that have not been attributed to the Russian government.

Since the Ukraine invasion, the Five Eye cybersecurity authorities have also detected malicious cyber operations against IT networks from various Russian government entities. These include the Russian Federal Security Service (FSB), including FSB’s Center 16 and Center 18, the Russian Foreign Intelligence Service, Russian General Staff Main Intelligence Directorate, GRU’s Main Center of Special Technologies, Russian Ministry of Defense, and the Central Scientific Institute of Chemistry and Mechanics.

In light of this malicious activity, the Five Eyes cybersecurity authorities have urged critical infrastructure network defenders to prepare for potential cyber threats such as destructive malware, ransomware, DDoS attacks, and cyber espionage, by strengthening their cyber defences and performing due diligence in identifying indicators of malicious activity.

In order to protect against this growing cyber threat, the Five Eyes authorities have asked organizations to immediately take the following precautions.

  • To update software, including operating systems, applications, and firmware, on IT network assets. It involves prioritizing patching known exploited vulnerabilities and critical and high vulnerabilities that allow for remote code execution or denial-of-service on internet-facing equipment. They also recommended for IT networks to consider using a centralized patch management system and for OT networks to use a risk-based assessment strategy to determine the OT network assets and zones that should participate in patch management programs.
  • To enforce multi-factor authentication and to use strong passwords for all accounts.
  • Organizations must provide end-user awareness training and the users of remote desktop protocols must secure and monitor these more risky protocols closely.

The advisory states that RDP exploitation is one of the top initial infection vectors for ransomware, and risky services, including RDP, can allow unauthorized access to your session using an on-path attacker.

Image Credits : Global Times

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Lenovo UEFI firmware driver bugs affect over 100 laptop models

Previous article

Docker servers targeted in ongoing cryptomining malware campaign

Next article

You may also like

More in Info

Comments

Leave a reply

Your email address will not be published. Required fields are marked *