CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Russian GRU Shifts Tactics to Target Misconfigured Edge Devices in Western Critical Infrastructure

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A Russian state-sponsored threat actor, attributed to the GRU, has shifted its tactics from exploiting vulnerabilities to targeting misconfigured customer network edge devices. The campaign, active since 2021, primarily targets energy sector organizations and critical infrastructure providers in Western nations. The shift in tactics allows the group to maintain persistent access, harvest credentials, and move laterally within victim networks while reducing exposure and resource expenditure.

Timeline

  1. 16.12.2025 14:15 1 articles · 5h ago

    GRU-Linked Threat Actor Shifts to Misconfigured Edge Device Targeting in 2025

    In 2025, a Russian GRU-linked threat actor shifted its tactics from exploiting vulnerabilities to targeting misconfigured customer network edge devices. This shift enables persistent access, credential harvesting, and lateral movement while reducing the actor's exposure and resource expenditure. The campaign is part of a broader GRU operation, with infrastructure overlaps indicating specialized subclusters supporting broader campaign objectives.

    Show sources

Information Snippets