The Amazon Threat Intelligence team has disrupted active operations attributed to hackers working for the Russian foreign military intelligence agency, the GRU, who targeted customers' cloud infrastructure. The cloud services provider observed a focus on Western critical infrastructure, especially the energy sector, in activity that started in 2021. Over time, the threat actor pivoted from exploiting vulnerabilities (zero-days and known ones) to leveraging misconfigured edge devices for initial access. CJ Moses, the CISO of Amazon Integrated Security, notes that up to 2024, the "years-long" campaign exploited multiple vulnerabilities in WatchGuard, Confluence, and Veeam as the primary initial access vector and targeted misconfigured devices. This year, though, the threat actor relied less on vulnerabilities and more on targeting misconfigured customer network edge devices, such as enterprise routers, VPN gateways, network management appliances, collaboration platforms, and cloud-based project management solutions. "Targeting the 'low-hanging fruit' of likely misconfigured customer devices with exposed management interfaces achieves the same strategic objectives, which is persistent access to critical infrastructure networks and credential harvesting for accessing victim organizations’ online services," Moses explains. "The threat actor’s shift in operational tempo represents a concerning evolution: while customer misconfiguration targeting has been ongoing since at least 202...
Amazon disrupts Russian GRU hackers attacking edge network devices
BleepingComputer
·Bill Toulas
·Published Dec 16, 2025
·Updated
Affected Software
3 affected components
WatchGuard WatchGuard
Confluence Confluence
VEEAM Veeam
Frequently Asked Questions
1
What is the main topic of this article?
The main topic of the article is Amazon's disruption of operations by the Russian GRU hackers targeting edge network devices.
2
What security implications are discussed in the article?
The article discusses the risks posed to customers' cloud infrastructure by the Russian GRU hackers and their methods of attack.
3
What products or software are affected by the hacker activities mentioned?
The affected products include WatchGuard, Confluence, and Veeam cloud services.
4
How did Amazon respond to the hacking attempts by the GRU?
Amazon's Threat Intelligence team took action to disrupt the active operations of the GRU hackers.
5
Who are the perpetrators identified in the article?
The perpetrators identified in the article are hackers affiliated with the Russian foreign military intelligence agency, the GRU.