Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure

A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025.

A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025.

The campaign, linked to Russia's Main Intelligence Directorate (GRU) and the Sandworm group, represents a significant shift in tactics. Instead of focusing on exploiting zero-day vulnerabilities, the hackers now target misconfigured customer network devices with exposed management interfaces.

This approach yields outcomes such as persistent access and credential theft, while making detection much more difficult. The attackers specifically focus on energy sector organizations across North America and Europe, along with other critical infrastructure providers. They compromise enterprise routers, VPN gateways, and network management devices hosted on cloud platforms.

By targeting these devices, hackers position themselves to intercept user credentials transmitted over network traffic, which they subsequently use to access victim organizations' online services and internal systems.

AWS analysts identified this campaign through their threat intelligence telemetry, observing coordinated attacks against customer network edge devices hosted on Amazon Web Services. The compromises occurred due to customer misconfigurations that left management interfaces exposed to the internet.

The campaign, linked to Russia's Main Intelligence Directorate (GRU) and the Sandworm group, represents a significant shift in tactics.
Jason Ford · Thehackingpost

Network analysis revealed persistent connections from attacker-controlled IP addresses to compromised EC2 instances running network appliance software, indicating interactive access and ongoing data collection.

The campaign timeline shows a clear evolution. Between 2021 and 2022, attackers exploited WatchGuard devices using CVE-2022-26318. In 2022-2023, they targeted Confluence platforms through CVE-2021-26084 and CVE-2023-22518. By 2024, Veeam exploitation via CVE-2023-27532 had become prevalent. Throughout 2025, the hackers maintained a sustained focus on misconfigured devices while reducing their investment in vulnerability exploitation, demonstrating a strategic shift toward easier targets.

Credential Harvesting and Replay Operations

The attackers use packet capture capabilities to harvest credentials from compromised network devices. Once they gain access to a network edge device, they intercept authentication traffic passing through it.

The time gap between device compromise and credential replay attempts suggests passive collection rather than active theft. The hackers capture victim organization credentials—not just device passwords—as users authenticate to various services through the compromised infrastructure.

Advertisement

After collecting credentials, the attackers systematically replay them against victim organizations' online services, including collaboration platforms, source code repositories, and cloud management consoles. AWS researchers repeatedly observed this pattern: device compromise, followed by authentication attempts using stolen credentials against the victim's cloud services and enterprise applications.

The attackers established connections to authentication endpoints across multiple sectors, including electric utilities, energy providers, managed security providers, and telecommunications companies spanning North America, Europe, and the Middle East.

The WatchGuard exploitation demonstrated the attackers' technical approach. The captured exploit payload shows how they encrypted stolen configuration files using the Fernet encryption library, exfiltrated them via TFTP to compromised staging servers, and removed evidence by deleting temporary files. This methodology reveals careful attention to operational security and anti-forensics.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories