AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
What it means
MISP EudorIA ha pubblicato l'advisory "AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Report from - [URL rimossa] (1726150964) # Russian Military Cyber Actors Target US and Global Critical Infrastructure Release DateSeptember 05, 2024 Alert CodeAA24-249A Related topics: Incident Detection, Response, and Prevention, Malware, Phishing, and Ransomware, Nation-State Cyber Actors ## **Summary** The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020. GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Unit 74455. To mitigate this malicious cyber activity, organizations should take the following actions today: * Prioritize routine system updates and remediate known exploited vulnerabilities. * Segment networks to prevent the spread of malicious activity. * Enable phishing-resistant multifactor authentication (MFA) for all externally facing account services, especially f
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it ยท translation not needed
- Publication
- 30/07/2026 02:52
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 276
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 261Last sharing verification: 2026-09-26T04:09:05.829263+00:00
- MISP event
- d67bfbe0-e01d-4e2e-8a56-214805d85aee
- Classification
- undefined