Russian Hacking Group is Targeting Corporate IoT Devices, Microsoft Researchers Say

Russian Hacking Group is Targeting Corporate IoT Devices, Microsoft Researchers Say

The state-sponsored hackers, best known as Fancy Bear, attempted to compromise popular IoT devices like office printers and a VOIP phone.

A state-sponsored Russian hacking group is targeting IoT devices as a strategy to breach corporate networks, Microsoft revealed in a Monday blog post.

The security threats were first noted in April by security researchers working for the Microsoft Threat Intelligence Center, a cybersecurity unit of the company. Further research by the group found that the “known adversary” was attempting to compromise popular IoT devices, including a VOIP phone, an office printer and a video decoder, according to the post.

“The investigation uncovered that an actor had used these devices to gain initial access to corporate networks,” the post reads. “These devices became points of ingress from which the actor established a presence on the network and continued looking for further access.”

The hacking group is identified by Microsoft as Strontium, but it is also known by the names APT28 and Fancy Bear. Strontium was previously involved in the hack of the Democratic National Committee during the 2016 election cycle and has been identified by U.S. intelligence officials as a unit of the Russian military intelligence agency GRU, ZDNet reported.

Because the company identified and blocked the attacks so early, the researchers said they were not able to “conclusively determine” what the hackers’ ultimate objectives were in carrying out the breaches.

Read more: IoT Security: Current Threats and How to Overcome Them

In the last 12 months, Microsoft has delivered nearly 1,400 notifications to those who have been targeted or compromised by the hacking group. The researchers also notified the manufacturers of the products that were compromised, prompting the companies to consider additional security measures, according to the blog post.

“One in five notifications of STRONTIUM activity were tied to attacks against non-governmental organizations, think tanks, or politically affiliated organizations around the world,” the researchers wrote, adding that the remaining 80 percent largely targeted organizations in government, military, medicine and education, among others. Olympic organizing committees and anti-doping agencies were also among the victims.

The research team said they were sharing information about the breaches to raise awareness of IoT security risks and issue a call to action regarding the enterprise integration of IoT devices. In their post, the researchers note that the number of deployed IoT devices outnumber the combined total of personal computers and mobile phones.

“With each networked IoT device having its own separate network stack, it’s quite easy to see the need for better enterprise management, especially in today’s ‘bring your own device’ world,” the post reads. “These simple attacks taking advantage of weak device management are likely to expand as more IoT devices are deployed in corporate environments.”

Microsoft’s recommendations for securing enterprise IoT devices include developing custom security policies on each IoT device, using a separate network for those devices if feasible, and monitoring devices for abnormal behavior.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • 12 Commercial Crime Sites to Do Your Research

    12 Commercial Crime Sites to Do Your Research

    Understanding crime statistics in your industry and area is crucial for making important decisions about your security budget. With so much information out there, how can you know which statistics to trust? Read Now

  • Boosting Safety and Efficiency

    Boosting Safety and Efficiency

    In alignment with the state of Mississippi’s mission of “Empowering Mississippi citizens to stay connected and engaged with their government,” Salient's CompleteView VMS is being installed throughout more than 150 state boards, commissions and agencies in order to ensure safety for thousands of constituents who access state services daily. Read Now

  • Live From GSX: Post-Show Review

    Live From GSX: Post-Show Review

    This year’s Live From GSX program was a rousing success! Again, we’d like to thank our partners, and IPVideo, for working with us and letting us broadcast their solutions to the industry. You can follow our Live From GSX 2023 page to keep up with post-show developments and announcements. And if you’re interested in working with us in 2024, please don’t hesitate to ask about our Live From programs for ISC West in March or next year’s GSX. Read Now

    • Industry Events
    • GSX
  • People Say the Funniest Things

    People Say the Funniest Things

    By all accounts, GSX version 2023 was completely successful. Apparently, there were plenty of mix-ups with the airlines and getting aircraft from the East Coast into Big D. I am all ears when I am in a gathering of people. You never know when a nugget of information might flip out. Read Now

    • Industry Events
    • GSX

Featured Cybersecurity

Webinars

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3