EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Report from - [URL rimossa] (1726150964) # Russian Military Cyber Actors Target US and Global Critical Infrastructure Release DateSeptember 05, 2024 Alert CodeAA24-249A Related topics: Incident Detection, Response, and Prevention, Malware, Phishing, and Ransomware, Nation-State Cyber Actors ## **Summary** The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020. GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Unit 74455. To mitigate this malicious cyber activity, organizations should take the following actions today: * Prioritize routine system updates and remediate known exploited vulnerabilities. * Segment networks to prevent the spread of malicious activity. * Enable phishing-resistant multifactor authentication (MFA) for all externally facing account services, especially f

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it ยท translation not needed
Publication
30/07/2026 02:52
Sharing
TLP:CLEAR
Indicators reported by the source
276
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
261Last sharing verification: 2026-09-26T04:09:05.829263+00:00
MISP event
d67bfbe0-e01d-4e2e-8a56-214805d85aee
Classification
undefined
Open the original source