Microsoft Catches Russian State Hackers Using IoT Devices To Breach Networks

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+igiepjtHz-cnh+PcYxbRHHNqyZ9-NGaESWPdrPxvOKw@mail.gmail.com>
'Hackers working for the Russian government have been using printers,
video decoders, and other so-called Internet-of-things devices as a
beachhead to penetrate targeted computer networks, Microsoft officials
warned on Monday. "These devices became points of ingress from which
the actor established a presence on the network and continued looking
for further access," officials with the Microsoft Threat Intelligence
Center wrote in a post. "Once the actor had successfully established
access to the network, a simple network scan to look for other
insecure devices allowed them to discover and move across the network
in search of higher-privileged accounts that would grant access to
higher-value data."

Microsoft researchers discovered the attacks in April, when a
voice-over-IP phone, an office printer, and a video decoder in
multiple customer locations were communicating with servers belonging
to "Strontium," a Russian government hacking group better known as
Fancy Bear or APT28. In two cases, the passwords for the devices were
the easily guessable default ones they shipped with. In the third
instance, the device was running an old firmware version with a known
vulnerability. While Microsoft officials concluded that Strontium was
behind the attacks, they said they weren't able to determine what the
group's ultimate objectives were.

Microsoft says they have notified the makers of the targeted IoT
devices so they can add new protections. "Monday's report also
provided IP addresses and scripts organizations can use to detect if
they have also been targeted or infected," adds Ars Technica. "Beyond
that, Monday's report reminded people that, despite Strontium's
above-average hacking abilities, an IoT device is often all it needs
to gain access to a targeted network."'

-- source: https://it.slashdot.org/story/19/08/06/0115233

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.