Amazon disrupts watering hole campaign by Russia's APT29
Amazon's threat intelligence team has uncovered and disrupted a watering hole campaign conducted by APT29, a Russian threat actor. The campaign involved compromising legitimate websites to redirect visitors to malicious infrastructure, tricking users into authorizing attacker-controlled devices through Microsoft's device code authentication flow. This opportunistic approach demonstrates APT29's evolving tactics in scaling their operations for intelligence collection. The group employed techniques such as injecting obfuscated JavaScript, rapidly adapting infrastructure when faced with disruption, and using server-side redirects. Amazon's response included isolating affected EC2 instances, partnering with providers to disrupt domains, and sharing information with Microsoft. The article provides recommendations for user and organizational protection against such attacks.
Pulse ID: 68b56d5d8b45f7f6c8cb4a3a
Pulse Link: https://otx.alienvault.com/pulse/68b56d5d8b45f7f6c8cb4a3a
Pulse Author: AlienVault
Created: 2025-09-01 09:54:37
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT29 #Amazon #CyberSecurity #EC2 #ICS #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #RAT #Russia #Troll #bot #AlienVault