RUSSIAN STATE-SPONSORED ADVANCED PERSISTENT THREAT ACTORCOMPROMISESU.S.GOVERNMENT TARGETS

Callout Box: This joint cybersecurity advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterpriseframework for all referenced threat actor tactics and techniques.



This joint cybersecurity advisory—written by the Federal Bureau of Investigation (FBI) andthe Cybersecurity and Infrastructure Security Agency (CISA)—providesinformation on Russian state-sponsored advanced persistent threat (APT) actoractivitytargeting various U.S.state, local, territorial, and tribal (SLTT)government networks,as well as aviation networks.This advisory updatesjoint CISA-FBI cybersecurity advisoryAA20-283A: APT Actors Chaining Vulnerabilities Against SLTT, Critical Infrastructure, and Elections Organizations.

Since at leastSeptember2020, a Russian state-sponsored APTactor—known variously as Berserk Bear, Energetic Bear,TeamSpy, Dragonfly, Havex, Crouching Yeti, and Koalain open-source reporting—hasconducteda campaignagainst awide variety of U.S.targets. The Russianstate-sponsored APT actor has targeteddozens of SLTT government and aviation networks, attempted intrusions at several SLTTorganizations, successfullycompromised network infrastructure, and as of October 1, 2020,exfiltrated data from at least two victim servers.

The Russian-sponsored APT actor is obtaininguser andadministrator credentials toestablish initial access,enable lateral movementonce insidethe network, and locate high value assetsin order to exfiltratedata. In at least one compromise, theAPT actor laterally traversed anSLTTvictim network and accessed documents related to:

Sensitive network configurations and passwords.

Standard operating procedures (SOP),such as enrolling in multi-factor authentication (MFA).

IT instructions, such as requesting password resets.

Vendors and purchasing information.

Printing access badges.

To date, the FBI and CISA haveno information to indicate thisAPT actor hasintentionally disrupted any aviation, education,elections,or government operations. However, the actormay be seeking.

Para el ver artículo original: https://www.ic3.gov/Media/News/2020/201022-1.pdf