As cited
Citation snapshot as of .
threat intel
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early 2022, Volexity discovered that Russian APT28 (also known as GruesomeLarch) breached an organization by exploiting a novel attack method later dubbed the Nearest Neighbor Attack. The threat actor compromised nearby organizations to locate systems with both wired and wireless network connections, then used those dual-homed systems to authenticate to the target organization's enterprise Wi-Fi network using credentials obtained through password-spray attacks, ultimately gaining network access from thousands of miles away.
Why it matters: Security teams managing enterprise Wi-Fi should review whether their wireless networks enforce the same multi-factor authentication controls as other services, and consider network segmentation to prevent compromised nearby organizations from becoming pivot points into corporate systems.
- Source published
- First seen by Cybersecurity Tracker