Threat Advisory

Russian Cadet Blizzard APT Targeting U.S. and Global Critical Infrastructure

Threat: Malicious Campaign
Threat Actor Name: Cadet Blizzard
Threat Actor Type: State-Sponsored, GRU
Targeted Region: Europe, North America, Latin America, Central Asia, Ukraine
Alias: DEV-0586, Ruinous Ursa
Threat Actor Region: Russia
Targeted Sector: Government & Defense, Finance & Banking, Healthcare, Energy & Utilities, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Cyber actors affiliated with the Russian GRU's Unit 29155, also known as Cadet Blizzard, have been conducting cyber espionage, sabotage, and influence operations globally, including destructive malware attacks. These operations primarily target critical sectors in Europe, NATO members, and countries providing aid to Ukraine. The threat group is separate from other GRU units but has adopted a range of offensive cyber operations, notably deploying the WhisperGate malware against Ukrainian organizations.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Cyber actors affiliated with the Russian GRU's Unit 29155, also known as Cadet Blizzard, have been conducting cyber espionage, sabotage, and influence operations globally, including destructive malware attacks. These operations primarily target critical sectors in Europe, NATO members, and countries providing aid to Ukraine. The threat group is separate from other GRU units but has adopted a range of offensive cyber operations, notably deploying the WhisperGate malware against Ukrainian organizations.[emaillocker id="1283"]

Unit 29155 cyber actors, also known as Cadet Blizzard, utilize a range of tactics, techniques, and procedures in their operations, notably prioritizing the exploitation of vulnerabilities in internet-facing systems to gain initial access. Cadet Blizzard has been observed using various CVEs, including CVE-2021-33044 and CVE-2021-33045, to bypass authentication on Dahua IP cameras. Furthermore, they conduct extensive reconnaissance using tools like Shodan to scan for vulnerable Internet of Things (IoT) devices and employ publicly available tools for lateral movement within compromised networks. Their operations involve not only the deployment of WhisperGate malware but also the collection of sensitive information through data exfiltration and the public release of stolen data, thereby inflicting reputational harm on their victims.

To combat the threats posed by Unit 29155 and Cadet Blizzard cyber actors, organizations are urged to implement proactive measures. Prioritizing routine system updates and addressing known vulnerabilities is crucial. Additionally, segmenting networks can help contain potential breaches, while enabling phishing-resistant multifactor authentication (MFA) on all external account services is vital for securing critical systems. Given the growing threat of these cyber actors, vigilance and preparedness are essential for organizations to mitigate the risks associated with their malicious activities.

THREAT PROFILE:

Tactic Technique Id Technique
Reconnaissance  T1590 Gather Victim Network Information
T1595 Active Scanning
Resource Development T1583 Acquire Infrastructure
T1588 Obtain Capabilities
Initial Access T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
Persistence  T1505 Server Software Component
 Defense Evasion T1078 Valid Accounts
T1550 Use Alternate Authentication Material
Credential Access T1003 OS Credential Dumping
T1110 Brute Force
T1552 Unsecured Credentials
Discovery T1046 Network Service Discovery
T1654 Log Enumeration
 Collection T1114 Email Collection
 T1125 Video Capture
 T1213 Data from Information Repositories
T1560 Archive Collected Data
Command and Control T1090 Proxy
T1071 Application Layer Protocol
T1095 Non-Application Layer Protocol
 T1105 Ingress Tool Transfer
T1572 Protocol Tunneling
Exfiltration T1567 Exfiltration Over Web Service
 Impact  T1485 Data Destruction

 

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/09/us-offers-10-million-for-info-on.html

[/emaillocker]
crossmenu