🔧 AI Nachrichten OpenAI pauses $200 Pro tier as Astra demand strains capacity(11.09.2026 um 11:23 Uhr)
🔧 AI Nachrichten OpenAI seeks tougher AI rules. CIOs may feel the ripple effects(10.09.2026 um 12:11 Uhr)
🔧 AI Nachrichten The quiet reason CIOs are slowing AI down(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten OpenAI pauses $200 Pro tier as Astra demand strains capacity(11.09.2026 um 11:19 Uhr)
🪟 Windows TippsWindows XP's Cursor Indicator Is Getting a Windows 11 Refresh(25.08.2026 um 13:00 Uhr)
🔧 AI Nachrichten OpenAI pauses $200 Pro tier as Astra demand strains capacity(11.09.2026 um 11:23 Uhr)
🔧 AI Nachrichten OpenAI seeks tougher AI rules. CIOs may feel the ripple effects(10.09.2026 um 12:11 Uhr)
🔧 AI Nachrichten The quiet reason CIOs are slowing AI down(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten OpenAI pauses $200 Pro tier as Astra demand strains capacity(11.09.2026 um 11:19 Uhr)
🪟 Windows TippsWindows XP's Cursor Indicator Is Getting a Windows 11 Refresh(25.08.2026 um 13:00 Uhr)

🕵️ Sicherheitslücken 🕛 vor 4 Jahren 36 Min Lesezeit SECURITY-FEED
0

AA22-110A: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure

↗ Quelle (us-cert.cisa.gov)
🗣️ Stimme:
📑 Inhaltsübersicht
Original release date: April 20, 2022 | Last revised: May 9, 2022

Summary

Actions critical infrastructure organizations should implement to immediately protect against Russian state-sponsored and criminal cyber threats:

• Patch all systems. Prioritize patching ][], Australia[], New Zealand[][. This activity may occur as a response to the unprecedented economic costs imposed on Russia as well as materiel support provided by the United States and U.S. allies and partners.



Evolving intelligence indicates that the Russian government is exploring options for potential cyberattacks (see , and older operations have included , which provides an overview of Russian state-sponsored cyber operations and commonly observed tactics, techniques, and procedures (TTPs). This CSA—coauthored by U.S., Australian, Canadian, New Zealand, and UK cyber authorities with contributions from industry members of the webpage. For more information on the heightened cyber threat to critical infrastructure organizations, see the following resources:



  • Cybersecurity and Infrastructure Security Agency (CISA) webpages 

  • Australian Cyber Security Centre’s (ACSC) Advisory

  • National Cyber Security Centre New Zealand (NZ NCSC) General Security Advisory on how to


    Technical Details

    Russian State-Sponsored Cyber Operations



    Russian state-sponsored cyber actors have demonstrated capabilities to compromise IT networks; develop mechanisms to maintain long-term, persistent access to IT networks; exfiltrate sensitive data from IT and operational technology (OT) networks; and disrupt critical industrial control systems (ICS)/OT functions by deploying destructive malware. 

    Historical operations have included deployment of destructive malware—including —against Ukrainian government and critical infrastructure organizations. Recent Russian state-sponsored cyber operations have included DDoS attacks against Ukrainian organizations. Note: for more information on Russian state-sponsored cyber activity, including known TTPs, see joint CSA .



    High-Profile Activity: in 2017, FSB employees, including one employee in the FSB Center for Information Security (also known as Unit 64829 and Center 18), were indicted by the U.S. Department of Justice (DOJ) for accessing email accounts of U.S. government and military personnel, private organizations, and cybersecurity companies, as well as email accounts of journalists critical of the Russian government.[] 



    Resources: for more information on FSB, see: 



    • U.S. DOJ Press Release  

    • UK Press Release ]

    High-Profile Activity: the U.S. Government, the Government of Canada, and the UK Government assess that SVR cyber threat actors were responsible for the SolarWinds Orion supply chain compromise and the associated campaign that affected U.S. government agencies, critical infrastructure entities, and private sector organizations.[][]



    Resources: for more information on SVR, see:



    • Joint CSA

    • The MITRE ATT&CK webpage on webpage

    • CISA’s webpage on

    GRU, 85th Main Special Service Center



    Overview: GTsSS, or Unit 26165, is an APT group that has operated since at least 2004 and primarily targets government organizations, travel and hospitality entities, research institutions, and non-governmental organizations, in addition to other critical infrastructure organizations. 



    According to industry reporting, GTsSS cyber actors frequently collect credentials to gain initial access to target organizations. GTsSS actors have collected victim credentials by sending spearphishing emails that appear to be legitimate security alerts from the victim’s email provider and include hyperlinks leading to spoofed popular webmail services’ logon pages. GTsSS actors have also registered domains to conduct credential harvesting operations. These domains mimic popular international social media platforms and masquerade as tourism- and sports-related entities and music and video streaming services.



    High-Profile Activity: the U.S. Government assesses that GTsSS cyber actors have deployed Drovorub malware against victim devices as part of their cyber espionage operations.[.[]



    Resources: for more information on GTsSS, see the MITRE ATT&CK webpage on ][ in December 2015, leading to disruption of multiple companies’ operations and widespread temporary outages. The actors deployed BlackEnergy malware to steal user credentials and used BlackEnergy’s destructive component, KillDisk, to make infected computers inoperable. 


  • In 2016, GTsST actors conducted a cyber-intrusion campaign against a Ukrainian electrical transmission company and deployed . NotPetya masqueraded as ransomware, had a large collateral impact, and caused damage to millions of devices globally.

  • In 2018, GTsST actors .

The U.S. Government, the Government of Canada, and UK Government have also attributed the October 2019 large-scale, disruptive cyber operations against a range of Georgian web hosting providers to GTsST. This activity resulted in websites—including sites belonging to the Georgian government, courts, non-government organizations (NGOs), media, and businesses—being defaced and interrupted the service of several national broadcasters.[][]



Resources: for more information on GTsST, see the MITRE ATT&CK webpage on ][] Triton is a custom-built malware designed to manipulate safety instrumented systems within ICS controllers, disabling the safety alarms that prevent dangerous conditions. 



Also known as: Temp.Veles, XENOTIME [. For more information on Triton, see:



  • CISA Malware Analysis Report (MAR)

  • Joint CSA

Russian-Aligned Cyber Threat Groups



In addition to the APT groups identified in the Russian State-Sponsored Cyber Operations section, industry reporting identifies two intrusion sets—PRIMITIVE BEAR and VENOMOUS BEAR—as state-sponsored APT groups, but U.S., Australian, Canadian, New Zealand, and UK cyber authorities have not attributed these groups to the Russian government.



  • PRIMITIVE BEAR has, according to industry reporting, targeted Ukrainian organizations since at least 2013. This activity includes targeting Ukrainian government, military, and law enforcement entities using high-volume spearphishing campaigns to deliver its custom malware. According to industry reporting, PRIMITIVE BEAR conducted multiple cyber operations targeting Ukrainian organizations in the lead up to Russia’s invasion.

Resources: for more information on PRIMITIVE BEAR, see the MITRE ATT&CK webpage on the ] VENOMOUS BEAR has also historically leveraged compromised infrastructure and maintained an arsenal of custom-developed sophisticated malware families, which is extremely complex and interoperable with variants developed over time. VENOMOUS BEAR has developed tools for multiple platforms, including Windows, Mac, and Linux.[.



Russian-Aligned Cybercrime Groups



Cybercrime groups are typically financially motivated cyber actors that seek to exploit human or security vulnerabilities to enable direct theft of money (e.g., by obtaining bank login information) or by extorting money from victims. These groups pose consistent threats to critical infrastructure organizations globally. 



Since Russia’s invasion of Ukraine in February 2022, some cybercrime groups have independently publicly pledged support for the Russian government or the Russian people and/or threatened to conduct cyber operations to retaliate against perceived attacks against Russia or materiel support for Ukraine. These Russian-aligned cybercrime groups likely pose a threat to critical infrastructure organizations primarily through:



  • Deploying ransomware through which cyber actors remove victim access to data (usually via encryption), potentially causing significant disruption to operations.

  • Conducting DDoS attacks against websites. 
    • In a DDoS attack, the cyber actor generates enough requests to flood and overload the target page and stop it from responding. 

    • DDoS attacks are often accompanied by extortion. 

    • According to industry reporting, some cybercrime groups have recently carried out DDoS attacks against Ukrainian defense organizations, and one group claimed credit for DDoS attack against a U.S. airport the actors perceived as supporting Ukraine (see the Killnet section).


Based on industry and open-source reporting, U.S., Australian, Canadian, New Zealand, and UK cyber authorities assess multiple Russian-aligned cybercrime groups pose a threat to critical infrastructure organizations. These groups include:



  • The CoomingProject

  • Killnet

  • MUMMY SPIDER 

  • SALTY SPIDER

  • SCULLY SPIDER

  • SMOKEY SPIDER

  • WIZARD SPIDER

  • The Xaknet Team

Note: although some cybercrime groups may conduct cyber operations in support of the Russian government, U.S., Australian, Canadian, New Zealand, and UK cyber authorities assess that cyber criminals will most likely continue to operate primarily based on financial motivations, which may include targeting government and critical infrastructure organizations.



The CoomingProject



Overview: the CoomingProject is a criminal group that extorts money from victims by exposing or threatening to expose leaked data. Their data leak site was launched in August 2021.]



Killnet



Overview: according to open-source reporting, Killnet released a video pledging support to Russia.[ in March 2022 in response to U.S. materiel support for Ukraine.[. For more information on TrickBot, see joint CSA ]



Victims: according to industry reporting, in February 2022, SALTY SPIDER conducted DDoS attacks against Ukrainian web forums used to discuss events relating to Russia’s military offensive against the city of Kharkiv.



Also known as: Sality



SCULLY SPIDER



Overview: SCULLY SPIDER is a cybercrime group that operates using a malware-as-a-service model; SCULLY SPIDER maintains command and control infrastructure and sells access to their malware and infrastructure to affiliates, who distribute their own malware.[] SCULLY SPIDER develops and operates the DanaBot botnet, which originated primarily as a banking Trojan but expanded beyond banking in 2021 and has since been used to facilitate access for other types of malware, including TrickBot, DoppelDridex, and Zloader. Like Emotet, Danabot effectively functions as an initial access vector for other malware, which can result in ransomware deployment.



According to industry reporting, recent DDoS activity by the DanaBot botnet suggests SCULLY SPIDER has operated in support of Russia’s military offensive in Ukraine. 



Victims: SCULLY SPIDER affiliates have primarily targeted organizations in the United States, Canada, Germany, United Kingdom, Australia, Italy, Poland, Mexico, and Ukraine.[.



WIZARD SPIDER



Overview: WIZARD SPIDER is a cybercrime group that develops TrickBot malware and Conti ransomware. Historically, the group has paid a wage to the ransomware deployers (referred to as affiliates), some of whom may then receive a share of the proceeds from a successful ransomware attack. In addition to TrickBot, notable initial access and persistence vectors for affiliated actors include Emotet, Cobalt Strike, spearphishing, and stolen or weak Remote Desktop Protocol (RDP) credentials.



After obtaining access, WIZARD SPIDER affiliated actors have relied on various publicly available and otherwise legitimate tools to facilitate earlier stages of the attack lifecycle before deploying Conti ransomware.



WIZARD SPIDER pledged support to the Russian government and threatened critical infrastructure organizations of countries perceived to carry out cyberattacks or war against the Russian government.[]



Victims: Conti victim organizations span across multiple industries, including construction and engineering, legal and professional services, manufacturing, and retail. In addition, WIZARD SPIDER affiliates have deployed Conti ransomware against. For more information on TrickBot, see joint CSA ] According to reporting from industry, on March 31, 2022, XakNet released a statement stating they would work “exclusively for the good of [Russia].” According to industry reporting, the XakNet Team may be working with or associated with Killnet actors, who claimed credit for the DDoS attacks against a U.S. airport (see the Killnet section).



Victims: according to industry reporting, in late March 2022, the XakNet Team leaked email contents of a Ukrainian government official. The leak was accompanied by a political statement criticizing the Ukrainian government, suggesting the leak was politically motivated. 


Mitigations

U.S., Australian, Canadian, New Zealand, and UK cyber authorities urge critical infrastructure organizations to prepare for and mitigate potential cyber threats by immediately (1) updating software, (2) enforcing MFA, (3) securing and monitoring RDP and other potentially risky services, and (4) providing end-user awareness and training.



  • Update software, including operating systems, applications, and firmware, on IT network assets. Prioritize patching , including vulnerability scanning, to help reduce exposure to threats. CISA’s vulnerability scanning service evaluates external network presence by executing continuous scans of public, static IP addresses for accessible services and vulnerabilities.


  • Enforce MFA to the greatest extent possible and require accounts with password logins, including service accounts, to have .

  • If you use RDP and/or other potentially risky services, secure and monitor them closely. RDP exploitation is one of the top initial infection vectors for ransomware, and risky services, including RDP, can allow unauthorized access to your session using an on-path attacker.
    • Limit access to resources over internal networks, especially by restricting RDP and using virtual desktop infrastructure. After assessing risks, if RDP is deemed operationally necessary, restrict the originating sources and require MFA to mitigate credential theft and reuse. If RDP must be available externally, use a virtual private network (VPN) or other means to authenticate and secure the connection before allowing RDP to connect to internal devices. Monitor remote access/RDP logs, enforce account lockouts after a specified number of attempts to block brute force attempts, log RDP login attempts, and disable unused remote access/RDP ports.

    • Ensure devices are properly configured and that security features are enabled. Disable ports and protocols that are not being used for a business purpose (e.g., RDP Transmission Control Protocol Port 3389). 


  • Provide end-user awareness and training to help prevent successful targeted social engineering and spearphishing campaigns. Phishing is one of the top infection vectors for ransomware, and Russian state-sponsored APT actors have conducted successful spearphishing campaigns to gain credentials of target networks.
    • Ensure that employees are aware of potential cyber threats and delivery methods. 

    • Ensure that employees are aware of what to do and whom to contact when they receive a suspected phishing email or suspect a cyber incident.


  • As part of a longer-term effort, implement network segmentation to separate network segments based on role and functionality. Network segmentation can help prevent the spread of ransomware and threat actor lateral movement by controlling traffic flows between—and access to—various subnetworks.



    • Ensure OT assets are not externally accessible. Ensure strong identity and access management when OT assets needs to be externally accessible.

    • Appropriately implement network segmentation between IT and OT networks. Network segmentation limits the ability of adversaries to pivot to the OT network even if the IT network is compromised. Define a demilitarized zone that eliminates unregulated communication between the IT and OT networks.

    • Organize OT assets into logical zones by considering criticality, consequence, and operational necessity. Define acceptable communication conduits between the zones and deploy security controls to filter network traffic and monitor communications between zones. Prohibit ICS protocols from traversing the IT network.

    To further prepare for and mitigate cyber threats from Russian state-sponsored or criminal actors, U.S., Australian, Canadian, New Zealand, and UK cyber authorities encourage critical infrastructure organizations to implement the recommendations listed below.



    Preparing for Cyber Incidents



    • Create, maintain, and exercise a cyber incident response and continuity of operations plan. 
      • Ensure the cyber incident response plan contains ransomware- and DDoS-specific annexes. For information on preparing for DDoS attacks, see NCSC-UK guidance on passwords and do not allow passwords to be used across multiple accounts or stored on a system to which an adversary may have access. Consider using a password manager; see NCSC-UK’s .

      • Consider disabling or limiting NTLM and WDigest Authentication.

      • Implement Credential Guard for Windows 10 and Server 2016 (refer to Microsoft: Manage Windows Defender Credential Guard for more information). For Windows Server 2012R2, enable Protected Process Light for Local Security Authority (LSA).

      • Minimize the Active Directory (AD) attack surface to reduce malicious ticket-granting activity. Malicious activity such as “Kerberoasting” takes advantage of Kerberos’ Ticket Granting Service (TGS) and can be used to obtain hashed credentials that malicious cyber actors attempt to crack.


    • Audit domain controllers to log successful Kerberos TGS requests and ensure the events are monitored for anomalous activity.  
      • Secure accounts.

      • Enforce the principle of least privilege. Administrator accounts should have the minimum permission necessary to complete their tasks.

      • Ensure there are unique and distinct administrative accounts for each set of administrative tasks.

      • Create non-privileged accounts for privileged users and ensure they use the non-privileged accounts for all non-privileged access (e.g., web browsing, email access).


    • Disable inactive accounts uniformly across the AD, MFA systems, etc.

    • Implement time-based access for privileged accounts. The FBI and CISA observed cybercriminals conducting increasingly impactful attacks against U.S. entities on or (888) 282-0870 and/or the FBI via your . For ransomware incidents, organizations can also report to the U.S. Secret Service via a .

    • Canadian organizations: report incidents by emailing CCCS at .

    • UK organizations: report a significant cybersecurity incident at .



      See the joint advisory from Australia, Canada, New Zealand, the United Kingdom, and the United States on . Although tailored to federal civilian branch agencies, these playbooks provide operational procedures for planning and conducting cybersecurity incident and vulnerability response activities and detail each step for both incident and vulnerability response.  



      Note: U.S., Australian, Canadian, New Zealand, and UK cyber authorities strongly discourage paying a ransom to criminal actors. Paying a ransom may embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Paying the ransom does not guarantee that a victim’s files will be recovered.



      RESOURCES



      • For more general information on Russian state-sponsored malicious cyber activity, see CISA’s . 

      • For alerts on malicious and criminal cyber activity, see the , a centralized, U.S. government webpage providing ransomware resources and alerts.

      • For more information on mitigating DDoS attacks, see NCSC-UK .

      • For information on destructive malware, see joint CSA

      • CISA factsheet

        [2]

        [4]

        [6]

        [8]

        [10]

        [12]

        [14] 16

        [18]

        [20] 

        [22] 

        [24] 

        [26]

        [28]

        [30]

        [32]

        [34]

        [36]

        [38]

        [40]



        ACKNOWLEDGEMENTS



        The U.S., Australian, Canadian, New Zealand, and UK cyber authorities would like to thank CrowdStrike, Google, LookingGlass Cyber, Mandiant, Microsoft, and Secureworks for their contributions to this CSA.


        Contact Information

        U.S. organizations: to report suspicious or criminal activity related to information found in this Joint Cybersecurity Advisory, contact CISA’s 24/7 Operations Center at , or the FBI’s 24/7 Cyber Watch (CyWatch) at (855) 292-3937 or by email at . Australian organizations: visit . New Zealand organizations: report cyber security incidents to (monitored 24 hours) or, for urgent assistance, call 03000 200 973.


        Revisions


        • April 20, 2022: Initial version
        • May 9, 2022: Added detail on GTsST use of VPNFilter.

        This product is provided subject to this policy.


        Vollständiger Original-Bericht
        Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf us-cert.cisa.gov.
        ↗ Original-Artikel auf us-cert.cisa.gov lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:
    Community Threat-Level Barometer
    Live Votum

    Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

    Noch keine Stimmen — schätze das Risiko als Erster ein.

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    2 Quellen
    OpenAI pauses $200 Pro tier as Astra demand strains capacity
    1 Quelle
    Swiss government explores replacing Microsoft 365 with open-source software
    1 Quelle
    OpenAI seeks tougher AI rules. CIOs may feel the ripple effects
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten AA22-110A: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure

    Thematisch verwandte Begriffe: AA22110A, Russian, StateSponsored, Criminal · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...