From 4d71f3c5a7dd854ce5ab5391393c8c2d31d92fc1 Mon Sep 17 00:00:00 2001 From: DarkSun Date: Thu, 8 Aug 2019 02:10:30 +0800 Subject: [PATCH 1/2] =?UTF-8?q?=E9=80=89=E9=A2=98:=2020190806=20Microsoft?= =?UTF-8?q?=20finds=20Russia-backed=20attacks=20that=20exploit=20IoT=20dev?= =?UTF-8?q?ices?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md --- ...backed attacks that exploit IoT devices.md | 73 +++++++++++++++++++ 1 file changed, 73 insertions(+) create mode 100644 sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md diff --git a/sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md b/sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md new file mode 100644 index 0000000000..b8009d3923 --- /dev/null +++ b/sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md @@ -0,0 +1,73 @@ +[#]: collector: (lujun9972) +[#]: translator: ( ) +[#]: reviewer: ( ) +[#]: publisher: ( ) +[#]: url: ( ) +[#]: subject: (Microsoft finds Russia-backed attacks that exploit IoT devices) +[#]: via: (https://www.networkworld.com/article/3430356/microsoft-finds-russia-backed-attacks-that-exploit-iot-devices.html) +[#]: author: (Jon Gold https://www.networkworld.com/author/Jon-Gold/) + +Microsoft finds Russia-backed attacks that exploit IoT devices +====== +Microsoft says default passwords, unpatched devices, poor inventory of IoT gear led to exploits against companies by Russia's STRONTIUM hacking group. +![Zmeel / Getty Images][1] + +The STRONTIUM hacking group, which has been strongly linked by security researchers to Russia’s GRU military intelligence agency, was responsible for an [IoT][2]-based attack on unnamed Microsoft customers, according to the company. a blog post from the company’s security response center issued Monday. + +Microsoft [said in a blog][3] that the attack, which it discovered in April, targeted three specific IoT devices – a VoIP phone, a video decoder and a printer (the company declined to specify the brands) – and used them to gain access to unspecified corporate networks. Two of the devices were compromised because nobody had changed the manufacturer’s default password, and the other one hadn’t had the latest security patch applied. + +**More on IoT:** + + * [][4] [Most powerful Internet of Things companies][5] + * [10 Hot IoT startups to watch][6] + * [The 6 ways to make money in IoT][7] + * [What is digital twin technology? [and why it matters]][8] + * [Blockchain, service-centric networking key to IoT success][9] + * [Getting grounded in IoT networking and security][10] + * [Building IoT-ready networks must become a priority][11] + * [What is the Industrial IoT? [And why the stakes are so high]][12] + + + +Devices compromised in this way acted as back doors to secured networks, allowing the attackers to freely scan those networks for further vulnerabilities, access additional systems, and gain more and more information. The attackers were also seen investigating administrative groups on compromised networks, in an attempt to gain still more access, as well as analyzing local subnet traffic for additional data. + +STRONTIUM, which has also been referred to as Fancy Bear, Pawn Storm, Sofacy and APT28, is thought to be behind a host of malicious cyber-activity undertaken on behalf of the Russian government, including the 2016 hack of the Democratic National Committee, attacks on the World Anti-Doping Agency, the targeting of journalists investigating the shoot-down of Malaysia Airlines Flight 17 over Ukraine, sending death threats to the wives of U.S. military personnel under a false flag and much more. + +According to an indictment released in July 2018 by the office of Special Counsel Robert Mueller, the architects of the STRONTIUM attacks are a group of Russian military officers, all of whom are wanted by the FBI in connection with those crimes. + +Microsoft notifies customers that it discovers are attacked by nation-states and has delivered about 1,400 such notifications related to STRONTIUM over the past 12 months. Most of those – four in five – went to organizations in the government, military, defense, IT, medicine, education and engineering sectors, and the remainder were for NGOs, think-tanks and other “politically affiliated organizations,” Microsoft said. + +The heart of the vulnerability, according to the Microsoft team, was a lack of full awareness by institutions of all the devices running on their networks. They recommended, among other things, cataloguing all IoT devices running in a corporate environment, implementing custom security policies for each device, walling off IoT devices on their own separate networks wherever practical, and performing regular patch and configuration audits on IoT gadgets. + +**[ [Prepare to become a Certified Information Security Systems Professional with this comprehensive online course from PluralSight. Now offering a 10-day free trial!][13] ]** + +Join the Network World communities on [Facebook][14] and [LinkedIn][15] to comment on topics that are top of mind. + +-------------------------------------------------------------------------------- + +via: https://www.networkworld.com/article/3430356/microsoft-finds-russia-backed-attacks-that-exploit-iot-devices.html + +作者:[Jon Gold][a] +选题:[lujun9972][b] +译者:[译者ID](https://github.com/译者ID) +校对:[校对者ID](https://github.com/校对者ID) + +本文由 [LCTT](https://github.com/LCTT/TranslateProject) 原创编译,[Linux中国](https://linux.cn/) 荣誉推出 + +[a]: https://www.networkworld.com/author/Jon-Gold/ +[b]: https://github.com/lujun9972 +[1]: https://images.idgesg.net/images/article/2019/07/cso_russian_hammer_and_sickle_binary_code_by_zmeel_gettyimages-927363118_2400x1600-100801412-large.jpg +[2]: https://www.networkworld.com/article/3207535/what-is-iot-how-the-internet-of-things-works.html +[3]: https://msrc-blog.microsoft.com/2019/08/05/corporate-iot-a-path-to-intrusion/ +[4]: https://www.networkworld.com/article/3207535/internet-of-things/what-is-the-iot-how-the-internet-of-things-works.html +[5]: https://www.networkworld.com/article/2287045/internet-of-things/wireless-153629-10-most-powerful-internet-of-things-companies.html +[6]: https://www.networkworld.com/article/3270961/internet-of-things/10-hot-iot-startups-to-watch.html +[7]: https://www.networkworld.com/article/3279346/internet-of-things/the-6-ways-to-make-money-in-iot.html +[8]: https://www.networkworld.com/article/3280225/internet-of-things/what-is-digital-twin-technology-and-why-it-matters.html +[9]: https://www.networkworld.com/article/3276313/internet-of-things/blockchain-service-centric-networking-key-to-iot-success.html +[10]: https://www.networkworld.com/article/3269736/internet-of-things/getting-grounded-in-iot-networking-and-security.html +[11]: https://www.networkworld.com/article/3276304/internet-of-things/building-iot-ready-networks-must-become-a-priority.html +[12]: https://www.networkworld.com/article/3243928/internet-of-things/what-is-the-industrial-iot-and-why-the-stakes-are-so-high.html +[13]: https://pluralsight.pxf.io/c/321564/424552/7490?u=https%3A%2F%2Fwww.pluralsight.com%2Fpaths%2Fcertified-information-systems-security-professional-cisspr +[14]: https://www.facebook.com/NetworkWorld/ +[15]: https://www.linkedin.com/company/network-world From b0c3da036d813d2100f584ff3cf2d913694fd822 Mon Sep 17 00:00:00 2001 From: "Xingyu.Wang" Date: Thu, 8 Aug 2019 11:47:59 +0800 Subject: [PATCH 2/2] Rename sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md to sources/news/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md --- ...rosoft finds Russia-backed attacks that exploit IoT devices.md | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename sources/{talk => news}/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md (100%) diff --git a/sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md b/sources/news/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md similarity index 100% rename from sources/talk/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md rename to sources/news/20190806 Microsoft finds Russia-backed attacks that exploit IoT devices.md