{"id":17528,"date":"2023-05-26T17:23:37","date_gmt":"2023-05-27T00:23:37","guid":{"rendered":"https:\/\/essential.construction\/news\/broad-campaign-underway-to-access-us-critical-infrastructure-using-small-home-office-devices\/"},"modified":"2023-05-26T17:23:39","modified_gmt":"2023-05-27T00:23:39","slug":"broad-campaign-underway-to-access-us-critical-infrastructure-using-small-home-office-devices","status":"publish","type":"post","link":"https:\/\/essential.construction\/news\/broad-campaign-underway-to-access-us-critical-infrastructure-using-small-home-office-devices\/","title":{"rendered":"Broad campaign underway to access US critical infrastructure using small, home office devices"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<h3 class=\"standard-heading\">Dive Brief:<\/h3>\n<ul>\n<li>Microsoft researchers and federal authorities are warning about a malicious cyber campaign against U.S. critical infrastructure providers that may be designed to disrupt communications with Asia amid growing hostilities with the People\u2019s Republic of China.\u00a0<\/li>\n<li>A state-sponsored threat actor, which Microsoft <a rel=\"nofollow noopener\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/05\/24\/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques\/\" target=\"_blank\">identified as Volt Typhoon<\/a> under its <a rel=\"nofollow noopener\" href=\"https:\/\/www.cybersecuritydive.com\/news\/microsoft-renames-threat-actors-weather\/648044\/\" target=\"_blank\">new naming taxonomy<\/a>, is operating a stealth campaign that abuses small office, home office routers, firewalls and VPN devices to blend into normal daily activity. The hackers are abusing internet-facing Fortinet FortiGuard devices to gain initial access into companies and leveraging compromised SOHO devices from a range of companies, including ASUS, Cisco, D-Link, Netgear and Zyxel.\u00a0<\/li>\n<li>The Cybersecurity and Infrastructure Security Agency, along with the FBI, the National Security Agency and cyber agencies from the Five Eyes, <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-144a\" target=\"_blank\">issued an advisory about the campaign<\/a> Wednesday. Officials said the hackers are using living-off-the-land techniques to blend in with normal Windows activity and evade discovery by endpoint detection and response software.<\/li>\n<\/ul>\n<h3>Dive Insight:<\/h3>\n<p>Volt Typhoon, active since 2021, has targeted critical infrastructure providers in the U.S. and Guam, according to Microsoft researchers. The major industries targeted by the actor include communications, manufacturing, utilities, transportation, construction, IT, education and government.\u00a0<\/p>\n<p>\u201cAdversaries frequently target critical infrastructure to perform reconnaissance and eventually gain a foothold in the event of an escalation in tension, or in the worst case war, the adversary can disable parts of a country\u2019s infrastructure,\u201d Tom Winston, director of intelligence content at Dragos, said via email.\u00a0<\/p>\n<p>Researchers from Mandiant said they recognize the hackers from prior campaigns involving air, maritime and land transportation targets. The new activity could be in preparation for disruptive or destructive cyberattacks.\u00a0<\/p>\n<p>\u201cPreparation does not mean attacks are inevitable,\u201d said John Hultquist, chief analyst, Mandiant Intelligence, Google Cloud. \u201cStates conduct long-term intrusions into critical infrastructure to prepare for possible conflict, because it simply may be too late to gain access when conflict arises.\u201d<\/p>\n<p>Microsoft said it has directly notified customers who were targeted or compromised.\u00a0<\/p>\n<p>After gaining access through the Fortinet devices, the hackers try to leverage any privilege from those devices and then remove credentials over to an Active Directory account, according to Microsoft. The credentials are then used to authenticate to other devices. Fortinet officials could not be immediately reached for comment.<\/p>\n<p>Microsoft researchers said detecting and mitigating the attacks will be challenging due to the actor\u2019s reliance on active accounts and living-off-the-land binaries. The NSA has published a guide to detect and mitigate <a rel=\"nofollow noopener\" href=\"https:\/\/media.defense.gov\/2023\/May\/24\/2003229517\/-1\/-1\/0\/CSA_Living_off_the_Land.PDF\" target=\"_blank\">living-off-the-land activity<\/a>.<\/p>\n<\/p><\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.constructiondive.com\/news\/campaign-critical-infrastructure-devices\/651285\/\" rel=\"nofollow noopener\" target=\"_blank\">This article was originally posted at Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Dive Brief: Microsoft researchers and federal authorities are warning about a malicious cyber campaign against U.S. critical infrastructure providers &#8230; <a title=\"Broad campaign underway to access US critical infrastructure using small, home office devices\" class=\"read-more\" href=\"https:\/\/essential.construction\/news\/broad-campaign-underway-to-access-us-critical-infrastructure-using-small-home-office-devices\/\" aria-label=\"Read more about Broad campaign underway to access US critical infrastructure using small, home office devices\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[457],"tags":[],"class_list":["post-17528","post","type-post","status-publish","format-standard","hentry","category-construction-dive","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33"],"_links":{"self":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/17528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/comments?post=17528"}],"version-history":[{"count":0,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/17528\/revisions"}],"wp:attachment":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/media?parent=17528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/categories?post=17528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/tags?post=17528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}