Amazon flagged and disrupted the campaign, but the group quickly spun up new domains. #CyberSecurity thehackernews.com/2025/08/amaz...
Amazon flagged and disrupted the campaign, but the group quickly spun up new domains. #CyberSecurity thehackernews.com/2025/08/amaz...
research.checkpoint.com/2025/apt29-p...
research.checkpoint.com/2025/apt29-p...
They posed as the U.S. State Dept to steal access from academics and critics. #APT29 #CyberAlerts thehackernews.com/2025/06/russ...
They posed as the U.S. State Dept to steal access from academics and critics. #APT29 #CyberAlerts thehackernews.com/2025/06/russ...
Germany caught it:
🟥 Doppelgänger – fake news clones
🟥 Storm-1516 – deepfake factories
🟥 Matryoshka – bot-driven manipulation
🟥 APT29 – malware hacks like WINELOADER
These tools weren’t one-offs. They were templates. And we’re next.
Germany caught it:
🟥 Doppelgänger – fake news clones
🟥 Storm-1516 – deepfake factories
🟥 Matryoshka – bot-driven manipulation
🟥 APT29 – malware hacks like WINELOADER
These tools weren’t one-offs. They were templates. And we’re next.
Ivan Kwiatkowski is a security researcher and a malware analyst working on account investigations.
His talk, "When State Actors Go Mobile: APT29’s Use of Commodity Malware" details APT29.
cyberwarcon.com
Ivan Kwiatkowski is a security researcher and a malware analyst working on account investigations.
His talk, "When State Actors Go Mobile: APT29’s Use of Commodity Malware" details APT29.
cyberwarcon.com
Threat Intelligence Group w/analysis & attribution!
Great!
Our bad actors are: 🇷🇺 #UNC6293, a #Russian state-sponsored threat actor.
Google adds bonus additional low confidence association to #APT29 (that would be the #SVR).
Nice people.
Threat Intelligence Group w/analysis & attribution!
Great!
Our bad actors are: 🇷🇺 #UNC6293, a #Russian state-sponsored threat actor.
Google adds bonus additional low confidence association to #APT29 (that would be the #SVR).
Nice people.
Like how exploits first used by #NSOGroup's Pegasus & #Intellexa's Predator mysteriously found their way to Russian gov hackers...
blog.google/threat-analy...
Like how exploits first used by #NSOGroup's Pegasus & #Intellexa's Predator mysteriously found their way to Russian gov hackers...
blog.google/threat-analy...
/s
/s
www.mandiant.com/resources/bl...
www.mandiant.com/resources/bl...
Face à cette tentative d’humiliation, Moscou a alors riposté en réalisant, selon Bakou, des attaques informatiques via le groupe APT29 – lié au FSB – contre des médias Azerbaïdjanais. Pour le Kremlin, c’est une manière de riposter et de menacer l’Azerbaïdjan.
10/22
Face à cette tentative d’humiliation, Moscou a alors riposté en réalisant, selon Bakou, des attaques informatiques via le groupe APT29 – lié au FSB – contre des médias Azerbaïdjanais. Pour le Kremlin, c’est une manière de riposter et de menacer l’Azerbaïdjan.
10/22
russia continues its hybrid attacks against European states. In particular, Check Point, a cybersecurity company, has reported in its recent research on an operation by the hacker group APT29, targeting European diplomats
👇
russia continues its hybrid attacks against European states. In particular, Check Point, a cybersecurity company, has reported in its recent research on an operation by the hacker group APT29, targeting European diplomats
👇
united24media.com/latest-news/...
united24media.com/latest-news/...
#Amazon disrupted a watering‑hole campaign by Russia’s #APT29, who hijacked legitimate websites to redirect 10% of visitors into a malicious #Microsoft device‑code auth flow, tricking them into granting unauthorized access.
#ransomNews #APT29 #AuthPhishing
#Amazon disrupted a watering‑hole campaign by Russia’s #APT29, who hijacked legitimate websites to redirect 10% of visitors into a malicious #Microsoft device‑code auth flow, tricking them into granting unauthorized access.
#ransomNews #APT29 #AuthPhishing
Read: hackread.com/amazon-disru...
#CyberSecurity #CyberAttack #Russia #Amazon #Microsoft
Read: hackread.com/amazon-disru...
#CyberSecurity #CyberAttack #Russia #Amazon #Microsoft