{"id":9270,"date":"2025-12-17T10:04:12","date_gmt":"2025-12-17T10:04:12","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/17\/russian-hackers-attacking-network-edge-devices-in-western-critical-infrastructure\/"},"modified":"2025-12-17T10:04:12","modified_gmt":"2025-12-17T10:04:12","slug":"russian-hackers-attacking-network-edge-devices-in-western-critical-infrastructure","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/17\/russian-hackers-attacking-network-edge-devices-in-western-critical-infrastructure\/","title":{"rendered":"Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure"},"content":{"rendered":"<p>    Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025.<\/p>\n<p>The campaign, linked to Russia\u2019s Main Intelligence Directorate (GRU) and the notorious <a href=\"https:\/\/cybersecuritynews.com\/sandworm-apt-group-adds-new-wiper\/\" target=\"_blank\" rel=\"noreferrer noopener\">Sandworm group<\/a>, represents a major shift in tactics.<\/p>\n<p>Instead of focusing on exploiting zero-day vulnerabilities, the hackers now target misconfigured customer <a href=\"https:\/\/cybersecuritynews.com\/hackers-attacking-network-edge-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">network devices<\/a> with exposed management interfaces.<\/p>\n<p>This approach yields the same outcomes\u2014persistent access and credential theft\u2014while making detection much more difficult.<\/p>\n<p>The attackers specifically focus on energy sector organizations across North America and Europe, along with critical infrastructure providers.<\/p>\n<p>They compromise enterprise routers, VPN gateways, and network management devices hosted on cloud platforms.<\/p>\n<p>By targeting these devices, hackers position themselves to intercept user credentials transmitted over network traffic, which they subsequently use to access victim organizations\u2019 online services and internal systems.<\/p>\n<p>AWS analysts <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/amazon-threat-intelligence-identifies-russian-cyber-threat-group-targeting-western-critical-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign through their threat intelligence telemetry, observing coordinated attacks against customer network edge devices hosted on Amazon Web Services.<\/p>\n<p>The compromises occurred not because of AWS security flaws, but due to customer misconfigurations that left management interfaces exposed to the internet.<\/p>\n<p>Network analysis revealed persistent connections from attacker-controlled IP addresses to compromised EC2 instances running network appliance software, indicating interactive access and ongoing data collection.<\/p>\n<p>The campaign timeline shows a clear evolution. Between 2021 and 2022, attackers exploited WatchGuard devices using CVE-2022-26318. In 2022-2023, they targeted Confluence platforms through CVE-2021-26084 and CVE-2023-22518.<\/p>\n<p>By 2024, Veeam exploitation via CVE-2023-27532 had become prevalent. Throughout 2025, the hackers maintained sustained focus on misconfigured devices while reducing their investment in vulnerability exploitation, demonstrating a strategic shift toward easier targets.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-credential-harvesting-and-replay-operations\"><strong>Credential Harvesting and Replay Operations<\/strong><\/h2>\n<p>The attackers use packet capture capabilities to harvest credentials from compromised network devices.<\/p>\n<p>Once they gain access to a network edge device, they intercept authentication traffic passing through it.<\/p>\n<p>The time gap between device compromise and credential replay attempts suggests passive collection rather than active theft.<\/p>\n<p>The hackers capture victim organization credentials\u2014not just device passwords\u2014as users authenticate to various services through the compromised infrastructure.<\/p>\n<p>After collecting credentials, the attackers systematically replay them against victim organizations\u2019 online services, including collaboration platforms, source code repositories, and <a href=\"https:\/\/cybersecuritynews.com\/cloud-security-posture-management\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud management<\/a> consoles.<\/p>\n<p>AWS researchers repeatedly observed this pattern: device compromise, followed by authentication attempts using stolen credentials against the victim\u2019s cloud services and enterprise applications.<\/p>\n<p>The attackers established connections to <a href=\"https:\/\/cybersecuritynews.com\/esphome-web-server-authentication-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> endpoints across multiple sectors, including electric utilities, energy providers, managed security providers, and telecommunications companies spanning North America, Europe, and the Middle East.<\/p>\n<p>The WatchGuard exploitation demonstrated the attackers\u2019 technical approach. The captured exploit payload shows how they encrypted stolen configuration files using the Fernet encryption library, exfiltrated them via TFTP to compromised staging servers, and removed evidence by deleting temporary files.<\/p>\n<p>This methodology reveals careful attention to operational security and anti-forensics.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/russian-hackers-attacking-network-edge-devices\/\">Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/russian-hackers-attacking-network-edge-devices\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025. The campaign, linked to Russia\u2019s Main Intelligence Directorate (GRU) and the notorious Sandworm group, represents a major shift in tactics. Instead of focusing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9270","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9270"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9270"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9270\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}