Russian Hacking Group is Targeting Corporate IoT Devices, Microsoft Researchers Say

Russian Hacking Group is Targeting Corporate IoT Devices, Microsoft Researchers Say

The state-sponsored hackers, best known as Fancy Bear, attempted to compromise popular IoT devices like office printers and a VOIP phone.

A state-sponsored Russian hacking group is targeting IoT devices as a strategy to breach corporate networks, Microsoft revealed in a Monday blog post.

The security threats were first noted in April by security researchers working for the Microsoft Threat Intelligence Center, a cybersecurity unit of the company. Further research by the group found that the “known adversary” was attempting to compromise popular IoT devices, including a VOIP phone, an office printer and a video decoder, according to the post.

“The investigation uncovered that an actor had used these devices to gain initial access to corporate networks,” the post reads. “These devices became points of ingress from which the actor established a presence on the network and continued looking for further access.”

The hacking group is identified by Microsoft as Strontium, but it is also known by the names APT28 and Fancy Bear. Strontium was previously involved in the hack of the Democratic National Committee during the 2016 election cycle and has been identified by U.S. intelligence officials as a unit of the Russian military intelligence agency GRU, ZDNet reported.

Because the company identified and blocked the attacks so early, the researchers said they were not able to “conclusively determine” what the hackers’ ultimate objectives were in carrying out the breaches.

Read more: IoT Security: Current Threats and How to Overcome Them

In the last 12 months, Microsoft has delivered nearly 1,400 notifications to those who have been targeted or compromised by the hacking group. The researchers also notified the manufacturers of the products that were compromised, prompting the companies to consider additional security measures, according to the blog post.

“One in five notifications of STRONTIUM activity were tied to attacks against non-governmental organizations, think tanks, or politically affiliated organizations around the world,” the researchers wrote, adding that the remaining 80 percent largely targeted organizations in government, military, medicine and education, among others. Olympic organizing committees and anti-doping agencies were also among the victims.

The research team said they were sharing information about the breaches to raise awareness of IoT security risks and issue a call to action regarding the enterprise integration of IoT devices. In their post, the researchers note that the number of deployed IoT devices outnumber the combined total of personal computers and mobile phones.

“With each networked IoT device having its own separate network stack, it’s quite easy to see the need for better enterprise management, especially in today’s ‘bring your own device’ world,” the post reads. “These simple attacks taking advantage of weak device management are likely to expand as more IoT devices are deployed in corporate environments.”

Microsoft’s recommendations for securing enterprise IoT devices include developing custom security policies on each IoT device, using a separate network for those devices if feasible, and monitoring devices for abnormal behavior.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.