ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26084
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile).

Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Server and Data Center
CVE-2022-26318
Unauthenticated RCE in WatchGuard Firebox and XTM Fireware OS

CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind.

Do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices.

9.878% KEV
  • WatchGuard Fireware OS (Firebox and XTM appliances) All versions before 12.7.2_U2
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.x before 12.1.3_U8
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.2.x through 12.5.x before 12.5.9_U2
mass~100,000-300,000 internet-exposed Firebox/XTM appliances per public scan counts; vendor-reported install base of 1M+ appliances
CVE-2023-22518
Improper Authorization in Atlassian Confluence Data Center and Server

Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild.

Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Data Center and Server
large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations
CVE-2023-27532
Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials

Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile).

Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials.

7.578% KEV ransomware
  • Veeam Backup & Replication
largetens of thousands of deployments, of which thousands are internet-exposed (estimate)
Full article732 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 16, 2025Cloud Security / Vulnerability

Amazon's threat intelligence team has disclosed details of a "years-long" Russian state-sponsored campaign that targeted Western critical infrastructure between 2021 and 2025.

Targets of the campaign included energy sector organizations across Western nations, critical infrastructure providers in North America and Europe, and entities with cloud-hosted network infrastructure. The activity has been attributed with high confidence to Russia's Main Intelligence Directorate (GRU), citing infrastructure overlaps with APT44, which is also known as FROZENBARENTS, Sandworm, Seashell Blizzard, and Voodoo Bear.

The activity is notable for using as initial access vectors misconfigured customer network edge devices with exposed management interfaces, as N-day and zero-day vulnerability exploitation activity declined over the time period – indicative of a shift in attacks aimed at critical infrastructure, the tech giant said.

"This tactical adaptation enables the same operational outcomes, credential harvesting, and lateral movement into victim organizations' online services and infrastructure, while reducing the actor’s exposure and resource expenditure," CJ Moses, Chief Information Security Officer (CISO) of Amazon Integrated Security, said.

The attacks have been found to leverage the following vulnerabilities and tactics over the course of five years -

  • 2021-2022 - Exploitation of WatchGuard Firebox and XTM flaw (CVE-2022-26318) and targeting of misconfigured edge network devices
  • 2022-2023 - Exploitation of Atlassian Confluence flaws (CVE-2021-26084 and CVE-2023-22518) and continued targeting of misconfigured edge network devices
  • 2024 - Exploitation of Veeam flaw (CVE-2023-27532) and continued targeting of misconfigured edge network devices
  • 2025 - Sustained targeting of misconfigured edge network devices

The intrusion activity, per Amazon, singled out enterprise routers and routing infrastructure, VPN concentrators and remote access gateways, network management appliances, collaboration and wiki platforms, and cloud-based project management systems.

These efforts are likely designed to facilitate credential harvesting at scale, given the threat actor's ability to position themselves strategically on the network edge to intercept sensitive information in transit. Telemetry data has also uncovered what has been described as coordinated attempts aimed at misconfigured customer network edge devices hosted on Amazon Web Services (AWS) infrastructure.

"Network connection analysis shows actor-controlled IP addresses establishing persistent connections to compromised EC2 instances operating customers' network appliance software," Moses said. "Analysis revealed persistent connections consistent with interactive access and data retrieval across multiple affected instances."

In addition, Amazon said it observed credential replay attacks against victim organizations' online services as part of attempts to obtain a deeper foothold into targeted networks. Although these attempts are assessed to be unsuccessful, they lend weight to the aforementioned hypothesis that the adversary is grabbing credentials from compromised customer network infrastructure for follow-on attacks.

The entire attack plays out as follows -

  • Compromise the customer network edge device hosted on AWS
  • Leverage native packet capture capability
  • Gather credentials from intercepted traffic
  • Replay credentials against the victim organizations' online services and infrastructure
  • Establish persistent access for lateral movement

The credential replay operations have targeted energy, technology/cloud services, and telecom service providers across North America, Western and Eastern Europe, and the Middle East.

"The targeting demonstrates sustained focus on the energy sector supply chain, including both direct operators and third-party service providers with access to critical infrastructure networks," Moses noted.

Interestingly, the intrusion set also shares infrastructure overlaps (91.99.25[.]54) with another cluster tracked by Bitdefender under the name Curly COMrades, which is believed to be operating with interests that are aligned with Russia since late 2023. This has raised the possibility that the two clusters may represent complementary operations within a broader campaign undertaken by GRU.

"This potential operational division, where one cluster focuses on network access and initial compromise while another handles host-based persistence and evasion, aligns with GRU operational patterns of specialized subclusters supporting broader campaign objectives," Moses said.

Amazon said it identified and notified affected customers, as well as disrupted active threat actor operations targeting its cloud services. However, the company did not disclose how many attacks it has recorded as part of the campaign, nor share if there has been a change in operational tempo since the first wave of attacks occurred in 2021.

Organizations are recommended to audit all network edge devices for unexpected packet capture utilities, implement strong authentication, monitor for authentication attempts from unexpected geographic locations, and keep tabs on credential replay attacks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/12/amazon-exposes-years-long-gru-cyber.html