EXECUTIVE SUMMARY:
Cyber actors affiliated with the Russian GRU's Unit 29155, also known as Cadet Blizzard, have been conducting cyber espionage, sabotage, and influence operations globally, including destructive malware attacks. These operations primarily target critical sectors in Europe, NATO members, and countries providing aid to Ukraine. The threat group is separate from other GRU units but has adopted a range of offensive cyber operations, notably deploying the WhisperGate malware against Ukrainian organizations.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Cyber actors affiliated with the Russian GRU's Unit 29155, also known as Cadet Blizzard, have been conducting cyber espionage, sabotage, and influence operations globally, including destructive malware attacks. These operations primarily target critical sectors in Europe, NATO members, and countries providing aid to Ukraine. The threat group is separate from other GRU units but has adopted a range of offensive cyber operations, notably deploying the WhisperGate malware against Ukrainian organizations.[emaillocker id="1283"]
Unit 29155 cyber actors, also known as Cadet Blizzard, utilize a range of tactics, techniques, and procedures in their operations, notably prioritizing the exploitation of vulnerabilities in internet-facing systems to gain initial access. Cadet Blizzard has been observed using various CVEs, including CVE-2021-33044 and CVE-2021-33045, to bypass authentication on Dahua IP cameras. Furthermore, they conduct extensive reconnaissance using tools like Shodan to scan for vulnerable Internet of Things (IoT) devices and employ publicly available tools for lateral movement within compromised networks. Their operations involve not only the deployment of WhisperGate malware but also the collection of sensitive information through data exfiltration and the public release of stolen data, thereby inflicting reputational harm on their victims.
To combat the threats posed by Unit 29155 and Cadet Blizzard cyber actors, organizations are urged to implement proactive measures. Prioritizing routine system updates and addressing known vulnerabilities is crucial. Additionally, segmenting networks can help contain potential breaches, while enabling phishing-resistant multifactor authentication (MFA) on all external account services is vital for securing critical systems. Given the growing threat of these cyber actors, vigilance and preparedness are essential for organizations to mitigate the risks associated with their malicious activities.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1590 | Gather Victim Network Information |
| T1595 | Active Scanning | |
| Resource Development | T1583 | Acquire Infrastructure |
| T1588 | Obtain Capabilities | |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1505 | Server Software Component |
| Defense Evasion | T1078 | Valid Accounts |
| T1550 | Use Alternate Authentication Material | |
| Credential Access | T1003 | OS Credential Dumping |
| T1110 | Brute Force | |
| T1552 | Unsecured Credentials | |
| Discovery | T1046 | Network Service Discovery |
| T1654 | Log Enumeration | |
| Collection | T1114 | Email Collection |
| T1125 | Video Capture | |
| T1213 | Data from Information Repositories | |
| T1560 | Archive Collected Data | |
| Command and Control | T1090 | Proxy |
| T1071 | Application Layer Protocol | |
| T1095 | Non-Application Layer Protocol | |
| T1105 | Ingress Tool Transfer | |
| T1572 | Protocol Tunneling | |
| Exfiltration | T1567 | Exfiltration Over Web Service |
| Impact | T1485 | Data Destruction |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/09/us-offers-10-million-for-info-on.html