AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
Cosa significa
MISP EudorIA ha pubblicato l'advisory "AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Report from - [URL rimossa] (1726150964) # Russian Military Cyber Actors Target US and Global Critical Infrastructure Release DateSeptember 05, 2024 Alert CodeAA24-249A Related topics: Incident Detection, Response, and Prevention, Malware, Phishing, and Ransomware, Nation-State Cyber Actors ## **Summary** The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020. GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Unit 74455. To mitigate this malicious cyber activity, organizations should take the following actions today: * Prioritize routine system updates and remediate known exploited vulnerabilities. * Segment networks to prevent the spread of malicious activity. * Enable phishing-resistant multifactor authentication (MFA) for all externally facing account services, especially f
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:52
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 276
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 261Ultima verifica di condivisione: 2026-09-26T04:09:05.829263+00:00
- Evento MISP
- d67bfbe0-e01d-4e2e-8a56-214805d85aee
- Classificazione
- undefined