CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2110

As cited

Copy frozen at (site build).

threat intel

The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access

In early 2022, Volexity discovered that Russian APT28 (also known as GruesomeLarch) breached an organization by exploiting a novel attack method later dubbed the Nearest Neighbor Attack. The threat actor compromised nearby organizations to locate systems with both wired and wireless network connections, then used those dual-homed systems to authenticate to the target organization's enterprise Wi-Fi network using credentials obtained through password-spray attacks, ultimately gaining network access from thousands of miles away.

Why it matters: Security teams managing enterprise Wi-Fi should review whether their wireless networks enforce the same multi-factor authentication controls as other services, and consider network segmentation to prevent compromised nearby organizations from becoming pivot points into corporate systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access

In early 2022, Volexity discovered that Russian APT28 (also known as GruesomeLarch) breached an organization by exploiting a novel attack method later dubbed the Nearest Neighbor Attack. The threat actor compromised nearby organizations to locate systems with both wired and wireless network connections, then used those dual-homed systems to authenticate to the target organization's enterprise Wi-Fi network using credentials obtained through password-spray attacks, ultimately gaining network access from thousands of miles away.

Why it matters: Security teams managing enterprise Wi-Fi should review whether their wireless networks enforce the same multi-factor authentication controls as other services, and consider network segmentation to prevent compromised nearby organizations from becoming pivot points into corporate systems.

Actorsapt28fancy bearforest blizzard
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary