Critical industries targeted by Russian hackers according to Australian Signals Directorate

Australia’s critical industries have been warned they are being targeted by Russian hackers exploiting poorly configured network devices.
The Australian Signals Directorate (ASD) has issued a joint statement with officials from a dozen other countries, warning that hackers at 16 Russian Federal Security Service Centers are continuing to manipulate compromised critical infrastructure networks.
Sectors most at risk include communications, defence, healthcare, finance, energy and government services.
It is stated that the hackers are linked to major cyber threat groups known as Beserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard and Static Tundra.
ASD warned that hackers are scanning the internet for devices that use the Simple Network Management Protocol and weak or default passwords to access information.
“They look for exploited management services, weak security settings, and known vulnerabilities. They use these weaknesses to steal network information and user credentials,” ASD warned.
“Cyber actors can use this information to carry out further malicious activities. The advisory highlights the need to secure network devices and remediate known vulnerabilities.”

ASD also asked organizations to assess whether they are vulnerable to an attack and to secure network devices to reduce the risk of cyberattacks.
“They should implement security updates and strengthen network security controls,” an ASD spokesperson said.
“These recommendations are not limited to Russian state-sponsored activities. They can also help defend against techniques used by other malicious cyber actors.”

