<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Russian-Apt on CuraSec</title><link>https://curasec.metacog.co.kr/tags/russian-apt/</link><description>Recent content in Russian-Apt on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 11:38:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/russian-apt/index.xml" rel="self" type="application/rss+xml"/><item><title>Russian Clusters UNC6293/UNC7005/UNC5976 Abuse OAuth Flows in Espionage Campaigns</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-going-with-the-flow-s-distinct-clusters-target-individuals-o/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-going-with-the-flow-s-distinct-clusters-target-individuals-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> OAuth consent-flow abuse by APT29-linked clusters is a real attack surface for any organization using third-party OAuth integrations; audit configured OAuth app permissions and enforce stricter conditional access policies to reduce the social-engineering foothold these groups exploit.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Three active Russian clusters are running persistent campaigns against high-value sectors using OAuth flow hijacking and captive-portal redirects — pull Google&amp;rsquo;s full IOC list, hunt for anomalous OAuth token grants or device-code auth attempts since mid-2025, and tune detections for captive-portal redirect chains tied to UNC7005 TTPs documented by Reliaquest and Microsoft.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization falls in academia, aerospace/defense, government, or think tanks, queue a targeted user-awareness briefing on OAuth and device-code phishing before next quarter; the APT29 lineage of UNC6293 elevates this beyond routine phishing and warrants a conversation with your security team about protective intelligence coverage.&lt;/li>
&lt;/ul></description></item><item><title>Russian APT Exploited Zimbra Zero-Day to Steal Email and 2FA Codes</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-russian-espionage-group-exploited-zimbra-zero-day-to-steal-m/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-russian-espionage-group-exploited-zimbra-zero-day-to-steal-m/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If you run Zimbra webmail, patch to the latest release immediately — the exploit is zero-click (opening a message triggers it) and a joint NSA/CISA advisory confirms months of active state-actor abuse. Also review Zimbra access logs for bulk email-download activity over the past 90+ days.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Pull the NSA/CISA joint advisory for published IOCs and hunt for bulk email exfiltration patterns and anomalous 2FA-recovery-code access in Zimbra webmail logs; the campaign ran for months, so extend your look-back window accordingly.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If Zimbra is in your webmail stack, confirm patch status with your engineering team this week and assess whether sensitive mailboxes were exposed; a joint NSA/CISA advisory on a months-long Russian espionage campaign stealing credentials and 2FA codes warrants a pre-emptive leadership brief before it surfaces in board news feeds.&lt;/li>
&lt;/ul></description></item><item><title>Russian APT Void Blizzard Exploits Patched Zimbra Flaw for Email Theft</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-russian-hackers-exploit-zimbra-zero-click-flaw-for-email-the/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-russian-hackers-exploit-zimbra-zero-click-flaw-for-email-the/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA warning on active state-sponsored exploitation of a Zimbra zero-click vulnerability means patch status must be confirmed immediately — upgrade Zimbra Collaboration to the patched release and audit server logs for signs of prior compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Void Blizzard (Laundry Bear) is actively combining phishing with this Zimbra exploit in live campaigns — hunt for anomalous Zimbra authentication events and email-sync activity tied to this actor since the campaign began, and request any IOCs from the CISA advisory.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A CISA-attributed Russian espionage campaign targeting enterprise email warrants confirming this week whether Zimbra is in your environment, verifying engineering has applied the patch, and briefing leadership given the data-theft implications.&lt;/li>
&lt;/ul></description></item><item><title>US and allies warn of Russian state hackers targeting routers</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-us-and-allies-warn-of-russian-critical-infrastructure-attack/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-us-and-allies-warn-of-russian-critical-infrastructure-attack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> The advisory targets vulnerable and misconfigured routers — audit your edge router configurations against the joint advisory&amp;rsquo;s hardening guidance and prioritize patching any unmanaged or end-of-life devices on the network perimeter this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A nine-nation joint advisory signals a documented campaign with TTPs worth operationalizing; pull the full advisory for any ATT&amp;amp;CK mappings and IOCs and build or tune detections for lateral movement originating from router-adjacent network segments.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A coordinated advisory from nine countries on Russian state targeting of critical infrastructure raises the threat posture for the quarter — assess whether your sector is named in the advisory and prepare a brief for leadership on edge-device exposure and any vendor dependencies in that space.&lt;/li>
&lt;/ul></description></item></channel></rss>