SVR cyber actors adapt tactics for initial cloud access
ID: 0ba77700-b426-4a75-8698-80815201252c
STIX ID: report--0ba77700-b426-4a75-8698-80815201252c
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2024-02-23
Last Modified Date: 2024-02-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory from NCSC and international partners attributes ongoing cloud-focused activity to SVR-attributed APT29, describes how the group is evolving its initial-access techniques (password spraying/brute force against service and dormant accounts, stolen access tokens, MFA "bombing", device enrolment, and residential proxies), maps these behaviours to MITRE ATT&CK, and provides detection and mitigation guidance for organisations that have moved to cloud infrastructure.
