logo

SVR cyber actors adapt tactics for initial cloud access

ID: 0ba77700-b426-4a75-8698-80815201252c

STIX ID: report--0ba77700-b426-4a75-8698-80815201252c

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2024-02-23

Last Modified Date: 2024-02-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory from NCSC and international partners attributes ongoing cloud-focused activity to SVR-attributed APT29, describes how the group is evolving its initial-access techniques (password spraying/brute force against service and dormant accounts, stolen access tokens, MFA "bombing", device enrolment, and residential proxies), maps these behaviours to MITRE ATT&CK, and provides detection and mitigation guidance for organisations that have moved to cloud infrastructure.