ZeroHour
The Recordpublished ()ingested

Russia’s GRU hackers targeting misconfigured network edge devices in attacks on energy sector, Amazon says

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26084
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile).

Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Server and Data Center
CVE-2022-26318
Unauthenticated RCE in WatchGuard Firebox and XTM Fireware OS

CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind.

Do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices.

9.878% KEV
  • WatchGuard Fireware OS (Firebox and XTM appliances) All versions before 12.7.2_U2
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.x before 12.1.3_U8
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.2.x through 12.5.x before 12.5.9_U2
mass~100,000-300,000 internet-exposed Firebox/XTM appliances per public scan counts; vendor-reported install base of 1M+ appliances
CVE-2023-22518
Improper Authorization in Atlassian Confluence Data Center and Server

Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild.

Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Data Center and Server
large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations
CVE-2023-27532
Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials

Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile).

Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials.

7.578% KEV ransomware
  • Veeam Backup & Replication
largetens of thousands of deployments, of which thousands are internet-exposed (estimate)
Full article786 words · extracted from therecord.media · click to collapse

While targeting Western energy companies, prominent Russian government hackers have switched from breaching organizations through novel vulnerabilities to targeting misconfigured network edge devices, according to security researchers from Amazon. 

CJ Moses, CISO of Amazon Integrated Security, told Recorded Future News in an interview that the number of victim organizations is more than 10 and attributed the attacks to a well-known hacking operation known as APT44. Referred to colloquially as Sandworm or Seashell Blizzard, the group has been tied by U.S. officials to Russia’s Main Intelligence Directorate (GRU).

Moses said Amazon began tracking the campaign in 2021 and saw that it focused on Western critical infrastructure, particularly the energy sector. Amazon was able to detect the campaigns through its large network of honeypots that it calls Amazon MadPot. 

Data Amazon obtained showed “coordinated operations against customer network edge devices hosted on AWS.”

“This was not due to a weakness in AWS; these appear to be customer misconfigured devices,” Moses claimed. 

The campaign followed a similar pattern: hackers would compromise a customer network edge device hosted on AWS, steal credentials from intercepted traffic, use the information against victim online services and infrastructure before then establishing persistent access that enabled lateral movement. 

In a press briefing this week, Amazon officials said the years-long campaign “represents a significant evolution in critical infrastructure targeting: a tactical pivot where what appear to be misconfigured customer network edge devices became the primary initial access vector, while vulnerability exploitation activity declined.” 

“This tactical adaptation enables the same operational outcomes, credential harvesting, and lateral movement into victim organizations’ online services and infrastructure, while reducing the actor’s exposure and resource expenditure,” the experts said.

Amazon researchers said the hackers accessed endpoints for multiple sectors in 2025, including electric utility organizations, energy providers and managed security service providers specializing in energy sector clients.

The campaign also involved attacks targeting telecom providers and technology companies. 

Amazon says it notified affected customers if they found compromised network appliances and shared its findings with industry partners as well as affected vendors. 

‘Low hanging fruit’

Amazon researchers found that the same group previously used novel vulnerabilities for years before switching to exploiting misconfigured customer network edge devices in 2025 

From 2021 to 2022, the hackers exploited CVE-2022-26318 — a bug impacting a popular line of firewalls from WatchGuard. The next year, GRU attackers used CVE-2021-26084 and CVE-2023-22518 which affect the Confluence Data Center and Confluence Server products

By 2024, the group shifted to exploiting vulnerabilities from software company Veeam, including CVE-2023-27532, before targeting “misconfigured customer network edge devices” in 2025, according to Amazon.

Both nation-states and cybercriminals have long targeted the “low-hanging fruit” of misconfigured devices with exposed management interfaces — either for persistent access to critical infrastructure networks or for credential harvesting.

The practice, according to Amazon, is in part to reduce the amount of financial investment needed to find and develop zero-day or N-day vulnerabilities. 

Although Amazon did not provide details about the victims, they said the time gap between devices being compromised and attempted intrusions likely indicates the hackers were interested in passive information collection rather than active credential theft. 

The hacking group has previously been accused of targeting critical infrastructure and energy companies globally, particularly in Ukraine. Sandworm, which researchers have tied to Russian Military Intelligence Unit 74455, has been active since at least 2013 and is responsible for some of Russia’s most high-profile destructive attacks, including KillDisk and FoxBlade as well as headline-grabbing incidents like NotPetya and Prestige

Aaron Beardslee, a security expert at Securonix, said Amazon’s findings are representative of a wider cultural shift within the cybersecurity industry. 

Security teams have gotten dramatically better at vulnerability management, patch cycles have compressed from months to weeks, cyber protection platforms now catch exploitation artifacts reliably, he said. 

According to Beardslee, threat intelligence sharing means exploits have shorter useful life spans before defenders adapt. 

“The result is that traditional exploitation now requires more resources, carries higher detection risk and yields diminishing returns. So sophisticated actors did what sophisticated actors do: they pivoted to the path of least resistance,” he said. 

“This shift isn't a failure of security programs; it's evidence they're working. Defenders made the traditional exploitation model too expensive and too risky, so attackers adapted. The problem is that configuration security has been treated as operational housekeeping instead of a critical security control, and that needs to change immediately.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russia-gru-hackers-target-energy-sector-sandworm