Tag: Amazon Disrupts APT29

Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication
News

Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication

Amazon said Friday that it has detected and stopped what it called an opportunistic watering hole campaign that the Russia-affiliated APT29 actors were using to obtain intelligence. According to Amazon's Chief Information Security Officer CJ Moses, the campaign tricked customers into allowing attacker-controlled devices via Microsoft's device code authentication flow by using hijacked websites to reroute visitors to hostile infrastructure. APT29 is a state-sponsored hacking group associated with Russia's Foreign Intelligence Service (SVR). It is also known by the names BlueBravo, Cloaked Ursa, CozyLarch, Cozy Bear, Earth Koshchei, ICECAP, Midnight Blizzard, and The Dukes. The well-known threat actor has been connected to assaults in recent months that used malicious Remote Deskto...