CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 2110

As cited

Citation snapshot as of .

threat intel

The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access

In early 2022, Volexity discovered that Russian APT28 (also known as GruesomeLarch) breached an organization by exploiting a novel attack method later dubbed the Nearest Neighbor Attack. The threat actor compromised nearby organizations to locate systems with both wired and wireless network connections, then used those dual-homed systems to authenticate to the target organization's enterprise Wi-Fi network using credentials obtained through password-spray attacks, ultimately gaining network access from thousands of miles away.

Why it matters: Security teams managing enterprise Wi-Fi should review whether their wireless networks enforce the same multi-factor authentication controls as other services, and consider network segmentation to prevent compromised nearby organizations from becoming pivot points into corporate systems.

Source published
First seen by Cybersecurity Tracker

Source attribution