[BREAKING] NSA, Partners Release Cybersecurity Advisory on Brute Force Global Cyber Campaign

Stu Sjouwerman | Jul 1, 2021

nsa3-resized-600NSA and its US and British partners (the UK's NCSC and the US FBI and CISA) late this morning released an advisory detailing a Russian campaign ("almost certainly ongoing") to brute-force access to cloud and enterprise environments. The campaign is global in scope, NSA says, but focused on American and European targets.

Sectors being prospected for collection or disruption amount to a familiar list: "government and military, defense contractors, energy companies, higher education, logistics companies, law firms, media companies, political consultants or political parties, and think tanks."

Attribution is specific: the threat actor is the GRU's 85th Main Special Service Center (GTsSS). While brute-forcing isn't new, the GTsSS's approach is, having "uniquely leveraged software containers to easily scale its brute force attempts."  Here is the link to the NSA press room: https://www.nsa.gov/news-features/press-room/Article/2677750/nsa-partners-release-cybersecurity-advisory-on-brute-force-global-cyber-campaign/

Tip 'o The Hat to The CyberWire.

Identify Your Exposed and Vulnerable Accounts

Stolen or weak passwords account for 81% of hacking-related breaches. Run our Free Password Exposure Test to scan your Active Directory for compromised emails and weak credentials.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.