Early this spring, Russian government-linked hackers used three popular internet of things devices with weak security to access several Microsoft customers’ networks, then tried infiltrating more privileged accounts, researchers announced Monday. The company’s Threat Intelligence center said the STRONTIUM group, also known as APT 28 and Fancy Bear, leveraged weak security in an office printer, video decoders and voice over IP, or VOIP, phone to access wider systems. The attacks occurred as recently as April, Microsoft said, adding that hackers used insecure IoT devices as a means to attempt to break into valuable accounts where they would have found more sensitive data. Microsoft disclosed neither the affected devices, nor which of its customers were impacted. “While much of the industry focuses on the threats of hardware implants, we can see in this example that adversaries are happy to exploit simpler configuration and security issues to achieve their objectives,” Microsoft researchers wrote in their […]
The post Russian government hackers used office technology to try to breach privileged accounts appeared first on CyberScoop.
Continue reading Russian government hackers used office technology to try to breach privileged accounts→