Amazon says Russian hackers are behind a major cyber campaign to target Western energy sector


  • AWS says Russian GRU-affiliated groups spent years exploiting misconfigured edge devices to persist in Western critical infrastructure
  • Activity overlaps with Curly COMrades, whose tool abuses Hyper-V and Linux VMs for stealth persistence
  • Amazon Urges Edge Auditing, Credential Checking, and Suspicious Admin Portal Access Monitoring

For nearly half a decade, Russian state-sponsored threat actors have exploited misconfigurations in network equipment, as well as various vulnerabilities, to establish persistence in key infrastructure organizations in the West, experts have warned.

In a new threat report (v-one The register), CJ Moses, Chief Information Security Officer (CISO) at Amazon Integrated Security, highlighted the scale of the campaign, which has been ongoing for several years.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top