Skip to main content
  1. Home
  2. Computing
  3. News

Fancy Bear is back to its old tricks of exploiting IoT and doing network recon

Add as a preferred source on Google

In a new intelligence report on threats was released this week by Microsoft, which claims to have detected resumed activity, in the form of Internet of Things (IoT) device compromise, from Russian hacking group Fancy Bear.

The group, alternatively known by its STRONTIU or APT28 designations and thought to be an arm of Russian state intelligence, was found to have taken control of networked appliances such as printers as a way of pivoting deeper into the network. Once inside, the attackers would then find vulnerable, secluded portions of it to establish persistence and, finally, phone home to command and control servers. According to Microsoft’s findings, the attackers primarily targeted critical government or civic infrastructure including political, defense, medical, and engineering networks. 

Recommended Videos

It is not clear whether the organizations whose networks were breached were the ultimate intended targets, or simply cover for hiding resources for later use. If the attribution to Fancy Bear is accurate, these reported intrusions would constitute the latest in a long string of attack from the group that depends heavily on IoT compromise. 

Fancy Bear is most famous for infiltrating the network of the Democratic National Committee in 2016, but their oeuvre is otherwise largely based on breaking into routers and other small network appliances. In 2017, the group turned its attention to hotel networks, which they seized control of by exploiting network equipment. The group followed that up with the VPNFilter attack last year, which also took over routers.

This recent pattern from Fancy Bear brings an evolving picture of the Russian state-sponsored hackers into sharper resolution. Whereas the group formerly appeared content to break into specific kinds of networks simply to monitor them, Fancy Bear’s attack on hotel Wi-Fi positioned them to spy on guests of those hotels. The IoT compromise that Microsoft detailed fits a new pattern of conducting reconnaissance on networks they breach and following up with corresponding next steps.

The fact that Fancy Bear’s predisposition toward IoT has not changed should come as no surprise, as the perennially weak security of this class of devices provides ample attack surface. It is for this reason that some of the biggest DDoS attacks to date have been executed by enormous global botnets of IoT devices, such as the Mirai botnet.

Jonathan Terrasi
Former Digital Trends Contributor
Jonathan has studiously followed trends in technology, particularly in information security and digital privacy, since 2014…
Copilot could soon help diagnose issues with your PC
A new PC Insights feature will help you find what's slowing down your PC, though Copilot itself may be one of the main problems.
Microsoft Copilot Banner Featured

Copilot's next trick is diagnosing your PC's problems, but the catch is that the assistant doing the diagnosing is itself part of the problem. Windows Latest reports that Microsoft is testing a new Copilot feature called PC Insights, which will let you ask the AI assistant natural language questions about your computer's hardware and storage instead of digging through the Task Manager or Settings. The feature will reportedly allow users to ask questions like, "Do I have enough space for a 100GB game?" and Copilot will check the available storage to offer a response. Users will also be able to ask about CPU usage, battery health, etc., to diagnose issues.

What Copilot will be able to see

Read more
OpenAI just took the handcuffs off your ChatGPT Work and Codex usage limits, at least for now
The 5 hour limit is gone for now, your usage counter just reset, and GPT 5.6 Sol is about to get a lot lighter on your allowance.
OpenAI logo on Microsoft surface

It seems that OpenAI has been on a gallop lately, releasing new updates left and right. Just a few days back, the company launched its GPT-5.6 Sol, Terra, and Luna models for the general public, and now it's back with another update that will please its users even more. 

The headline change is that the 5-hour usage limit restriction in ChatGPT Work and Codex is being temporarily removed for all Plus, Business, and Pro plans. If you have ever been in the middle of a long working session and watched the limit message appear at the worst possible moment, this one is for you. 

Read more
This app gives your Mac a music player you’ll actually enjoy using
Apple Music on the Mac is a chore. Liqoria is the fix, and it plays nice with Spotify and YouTube too.
Liqoria music player

The Apple Music app on the Mac is not up to the mark. I don’t like how it looks or behaves, and Apple should take some inspiration from Spotify to make the app more modern and useful. Until that happens, we are stuck with a subpar app experience.

That’s why I never use the Apple Music app on my Mac and rely on third-party apps that let me control music. Today I am featuring one of the latest apps I discovered. It’s called Liqoria, and it’s probably the only music player app you will ever need.

Read more