ZeroHour
CyberScooppublished ()ingested @AJVicens

Five Eyes nations warn of evolving Russian cyberespionage practices targeting cloud environments

criticalThreat actor exploited in the wildimportance 60
Full article732 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The advisory issued by the U.K.'s National Cyber Security Centre breaks down tactics and techniques from SVR hacking ops.

Russian President Vladimir Putin delivers a speech standing in front of the monument "Fatherland, Valor, Honor" outside of the Foreign Intelligence Service of the Russian Federation (SVR) in Moscow on June 30, 2022. (Photo by MIKHAIL METZEL/Sputnik/AFP via Getty Images)

Longstanding cyberespionage and data collection units tied to Russia’s Foreign Intelligence Service (SVR) are evolving their techniques to gain access to cloud environments, the British, U.S. and partner governments said in an advisory Monday.

The advisory — issued by the U.K.’s National Cyber Security Centre and co-signed by a range of counterpart agencies in the U.S., Australia, Canada and New Zealand — details the evolving tactics, techniques and procedures that SVR hacking operations, tracked widely under the “APT29” and “Cozy Bear” monikers, are employing to penetrate the increasing number of cloud environments used by both private and public organizations.

APT29 operations are considered highly sophisticated and have been tracked since at least 2014, targeting a wide range of North American and European industries, including biotechnology, government, nonprofits, telecommunications and think tanks, according to an April 2022 report from Mandiant.

The U.S. government, for instance, attributed to APT29 the 2020 SolarWinds supply chain attack, one of the most consequential cyberespionage operations in recent years.

Even still, the agencies said Monday, basic cloud security measures can go a long way toward stymieing APT29 efforts.

“The SVR is a sophisticated actor capable of carrying out a global supply chain compromise such as the 2020 SolarWinds, however the guidance in this advisory shows that a strong baseline of cyber security fundamentals can help defend from such actors,” the notice read.

Attackers must first successfully authenticate to the cloud provider, the notice read, so basic steps can go a long way. Some of those steps include regularly evaluating and disabling dormant accounts that could be tied to employees who are no longer with organizations, working with cloud providers to limit the validity time of system-issued tokens (which enable logins without passwords), and more stringent device-enrollment policies.

The Cybersecurity and Infrastructure Security Agency has also shared best practices for business-oriented cloud environments through its Secure Cloud Business Applications (SCuBA) project, the advisory said.

More Scoops

US President Donald Trump speaks during a Cabinet meeting at Camp David in Maryland, on July 31, 2026. (Photo by Aaron Schwartz / AFP)

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign.

Miguel Escamilla Jr., mannufacturing manager of ShayoNano, demonstrates the operation of programmable logic controller at the company’s production plant July 25, 2017, in Stafford. The Singapore-based company chose Stafford to be their U.S. headquarters. (Photo by Yi-Chin Lee/Houston Chronicle via Getty Images)

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn

Wind turbines are seen on a wind farm on a field between agricultural produce in a countryside in a village near Radom, Poland on May 19, 2025. (Photo by Dominika Zarzycka/NurPhoto)

After major Poland energy grid cyberattack, CISA issues warning to U.S. audience

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/five-eyes-nations-warn-of-evolving-russian-cyberespionage-practices-targeting-cloud-environments/