You can’t audit me: Russian hacker group Cozy Bear continues targeting Microsoft 365 accounts
Researchers at the cybersecurity firm Mandiant have warned that the Russian hacking group APT29, also known as Cozy Bear or Nobelium, is actively targeting Microsoft 365 accounts in the US and NATO-affiliated organizations in espionage campaigns to steal sensitive data. For those unaware, APT29 is claimed to be a Russian espionage group that Mandiant says it has been tracking since at least 2014 and is likely sponsored by the Foreign Intelligence Service (SVR). Despite the publicisation of multiple APT29 operations, they continue to be extremely prolific.
Mandiant has observed APT29 continue to demonstrate exceptional operational security and advanced tactics targeting Microsoft 365. The group has highlighted several newer TTPs used by APT29 in recent operations.