Skip to main content
  1. Home
  2. Computing
  3. News

Fancy Bear is back to its old tricks of exploiting IoT and doing network recon

Add as a preferred source on Google

In a new intelligence report on threats was released this week by Microsoft, which claims to have detected resumed activity, in the form of Internet of Things (IoT) device compromise, from Russian hacking group Fancy Bear.

The group, alternatively known by its STRONTIU or APT28 designations and thought to be an arm of Russian state intelligence, was found to have taken control of networked appliances such as printers as a way of pivoting deeper into the network. Once inside, the attackers would then find vulnerable, secluded portions of it to establish persistence and, finally, phone home to command and control servers. According to Microsoft’s findings, the attackers primarily targeted critical government or civic infrastructure including political, defense, medical, and engineering networks. 

Recommended Videos

It is not clear whether the organizations whose networks were breached were the ultimate intended targets, or simply cover for hiding resources for later use. If the attribution to Fancy Bear is accurate, these reported intrusions would constitute the latest in a long string of attack from the group that depends heavily on IoT compromise. 

Fancy Bear is most famous for infiltrating the network of the Democratic National Committee in 2016, but their oeuvre is otherwise largely based on breaking into routers and other small network appliances. In 2017, the group turned its attention to hotel networks, which they seized control of by exploiting network equipment. The group followed that up with the VPNFilter attack last year, which also took over routers.

This recent pattern from Fancy Bear brings an evolving picture of the Russian state-sponsored hackers into sharper resolution. Whereas the group formerly appeared content to break into specific kinds of networks simply to monitor them, Fancy Bear’s attack on hotel Wi-Fi positioned them to spy on guests of those hotels. The IoT compromise that Microsoft detailed fits a new pattern of conducting reconnaissance on networks they breach and following up with corresponding next steps.

The fact that Fancy Bear’s predisposition toward IoT has not changed should come as no surprise, as the perennially weak security of this class of devices provides ample attack surface. It is for this reason that some of the biggest DDoS attacks to date have been executed by enormous global botnets of IoT devices, such as the Mirai botnet.

Jonathan Terrasi
Former Digital Trends Contributor
Jonathan has studiously followed trends in technology, particularly in information security and digital privacy, since 2014…
Gemini Notebook’s new Collections arrive just as Google turns it into a bigger workspace
Google is cleaning up notebook organization as the former NotebookLM expands across Gemini and Search
Gemini Notebook branding on a MacBook

Google has barely finished renaming NotebookLM, and it’s already addressing one of the headaches that comes with building a large research library.

Collections are rolling out to all Gemini Notebook users, giving them a way to group related notebooks while keeping everything visible under My Notebooks. The dashboard gets some structure without asking users to rearrange the library they’ve already built.

Read more
Samsung’s humanoid robot ambitions are real, but factories come first
Samsung’s new robotics division has humanoids in its sights, although its immediate business is far more practical factory automation
Robot Touch Human Finger

Samsung wants a place in the humanoid race, but its new robotics push begins with machines built for factories rather than homes.

The CEO-led RX robotics division will initially focus on manufacturing robots. Samsung has separately identified humanoids as a priority, although it hasn’t announced a commercial model or explained where one fits into the division’s immediate plans.

Read more
WhatsApp’s Liquid Glass redesign is finally coming to Mac after months of waiting
WhatsApp's Mac app is getting Apple's Liquid Glass-inspired makeover
WhatsApp

WhatsApp has been steadily adopting Apple's new design language across its apps, but Mac users have largely been left watching from the sidelines. That is finally beginning to change.

The messaging platform has started rolling out its Liquid Glass redesign for the WhatsApp Mac app, bringing the desktop experience much closer to what iPhone and iPad users have been seeing over the past few months. The update introduces a refreshed interface with redesigned navigation elements, updated menus, and a cleaner layout that aligns with Apple's latest software aesthetic. According to WABetaInfo, the rollout has begun through the latest Mac App Store update and is currently reaching a limited number of users.

Read more