ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Amazon Warns Russian GRU Hackers Target Western Firms via Edge Devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26084
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile).

Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Server and Data Center
CVE-2022-26318
Unauthenticated RCE in WatchGuard Firebox and XTM Fireware OS

CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind.

Do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices.

9.878% KEV
  • WatchGuard Fireware OS (Firebox and XTM appliances) All versions before 12.7.2_U2
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.x before 12.1.3_U8
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.2.x through 12.5.x before 12.5.9_U2
mass~100,000-300,000 internet-exposed Firebox/XTM appliances per public scan counts; vendor-reported install base of 1M+ appliances
CVE-2023-22518
Improper Authorization in Atlassian Confluence Data Center and Server

Atlassian Confluence Data Center and Server contain an improper authorization flaw (CWE-863) that can be triggered by an unauthenticated attacker sending crafted requests to a vulnerable instance. Successful exploitation gives the attacker control over the instance and can cause significant data loss, such as wiping or resetting the Confluence site, but there is no confidentiality impact because no data can be exfiltrated. Any organization running a self-managed Confluence Data Center or Server deployment is in scope. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-07 with ransomware use noted, and EPSS assigns it a 100% probability of exploitation within 30 days. No public proof-of-concept is known, but ransomware operators are already using the flaw in the wild.

Do: Upgrade every Confluence Data Center and Server instance to the patched release for your branch listed in Atlassian's advisory, per the CISA KEV required action (apply vendor mitigations or discontinue use). In the interim, restrict internet access to Confluence and check for signs of compromise such as unexpected instance resets, missing data, or ransom notes; restore from backups if data loss is detected.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Data Center and Server
large≈70,000+ internet-exposed Confluence instances per public scans, likely 100k+ total self-managed installations
CVE-2023-27532
Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials

Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile).

Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials.

7.578% KEV ransomware
  • Veeam Backup & Replication
largetens of thousands of deployments, of which thousands are internet-exposed (estimate)
Full article465 words · extracted from infosecurity-magazine.com · click to collapse

A Russian state-sponsored malicious campaign that has been targeting critical infrastructure organizations in Western countries for years has shifted its tactics from vulnerability exploitation to compromising misconfigured customer network edge devices.

While the threat actor remains unidentified, Amazon has attributed it “with high confidence” to Russia’s Main Intelligence Directorate (GRU), the country’s military intelligence service which several cyber threat groups are believed to be associated with.

The tech giant documented its latest findings about this threat in a December 15 report.

Shift to Misconfigured Edge Device Targeting

Security researchers at Amazon Threat Intelligence observed this unnamed group targeting global infrastructure between 2021 and 2025.

The group’s typical targets have been energy sector organizations across Western nations, critical infrastructure providers in North America and Europe and organizations with cloud-hosted network infrastructure.

Some of its previous campaigns included the exploitation of vulnerabilities in WatchGuard (e.g. CVE-2022-26318) in 2021 and 2022, in Confluence (e.g. CVE-2021-26084, CVE-2023-22518) in 2022 and 2023 and in Veeam (e.g. CVE-2023-27532) in 2024.

However, Amazon noticed that in 2025, the group shifted it tactics away from vulnerability exploits and now favors the targeting of misconfigured customer network edge device – including some hosted on Amazon Web Services (AWS) – to gain initial access to its victims.

The Amazon report highlighted that the device misconfigurations are on the customer side, not on the AWS cloud infrastructure.

Some of the group’s typical targets include:

  • Enterprise routers and routing infrastructure
  • VPN concentrators and remote access gateways
  • Network management appliances
  • Collaboration and wiki platforms
  • Cloud-based project management systems

“This tactical adaptation enables the same operational outcomes, persistent access to critical infrastructure networks, credential harvesting and lateral movement into victim organizations’ online services and infrastructure, while reducing the actor’s exposure and resource expenditure,” the Amazon researchers noted.

Other tactics observed with this group by the Amazon researchers include harvesting credentials from compromised infrastructure to launch systematic replay attacks against victim organizations’ online services.

Likely Part of a Bigger Russian GRU Campaign

The attribution to the Russian GRU is based on infrastructure overlaps with previous operations linked to another GRU-linked threat group, known as Sandworm, APT44 or Seashell Blizzard.

The latest campaign targeting misconfigured edge devices also contain infrastructure overlaps with a group Bitdefender tracks as ‘Curly COMrades.’

This operation, documented by the cybersecurity firm on November 4, 2025, showed the Curly COMrades group abusing Hyper-V, Microsoft's native hypervisor technology, to evade endpoint detection and response (EDR) solutions and deploying two custom implants CurlyShell and CurlCat.

“We assess these may represent complementary operations within a broader GRU campaign, where one cluster focuses on network access and initial compromise while another handles host-based persistence and evasion,” the Amazone researchers wrote.

This operational division “aligns with GRU operational patterns of specialized subclusters supporting broader campaign objectives,” the Amazon report concluded.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/amazon-russian-gru-hackers-target/