[BREAKING] NSA, Partners Release Cybersecurity Advisory on Brute Force Global Cyber Campaign

Stu Sjouwerman | Jul 1, 2021

nsa3-resized-600NSA and its US and British partners (the UK's NCSC and the US FBI and CISA) late this morning released an advisory detailing a Russian campaign ("almost certainly ongoing") to brute-force access to cloud and enterprise environments. The campaign is global in scope, NSA says, but focused on American and European targets.

Sectors being prospected for collection or disruption amount to a familiar list: "government and military, defense contractors, energy companies, higher education, logistics companies, law firms, media companies, political consultants or political parties, and think tanks."

Attribution is specific: the threat actor is the GRU's 85th Main Special Service Center (GTsSS). While brute-forcing isn't new, the GTsSS's approach is, having "uniquely leveraged software containers to easily scale its brute force attempts."  Here is the link to the NSA press room: https://www.nsa.gov/news-features/press-room/Article/2677750/nsa-partners-release-cybersecurity-advisory-on-brute-force-global-cyber-campaign/

Tip 'o The Hat to The CyberWire.

Identify Your Exposed and Vulnerable Accounts

Stolen or weak passwords account for 81% of hacking-related breaches. Run our Free Password Exposure Test to scan your Active Directory for compromised emails and weak credentials.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.