APT
Nobelium SSH
Nobelium SSH
NOBELIUM, also known as APT29, is a Russian state-sponsored threat actor responsible for high-profile cyberattacks, including the SolarWinds supply chain compromise
Known Variants
Known Variants
Part of Nobelium’s broader toolkit, including Sunburst and Teardrop, focused on exploiting SSH vulnerabilities.
Part of Nobelium’s broader toolkit, including Sunburst and Teardrop, focused on exploiting SSH vulnerabilities.
Mitigation Strategies
Mitigation Strategies
Secure SSH configurations by enforcing key-based authentication over password-based methods. Regularly audit SSH key usage and disable unused accounts. Monitor SSH access logs for anomalies, such as login attempts from unfamiliar IP addresses.
Targeted Industries or Sectors
Targeted Industries or Sectors
Focuses on government agencies, think tanks, and NGOs, particularly those in Europe and North America.
Focuses on government agencies, think tanks, and NGOs, particularly those in Europe and North America.
Associated Threat Actors
Associated Threat Actors
Nobelium is attributed to APT29 (Cozy Bear), a Russian state-sponsored threat actor involved in high-profile espionage campaigns.
Nobelium is attributed to APT29 (Cozy Bear), a Russian state-sponsored threat actor involved in high-profile espionage campaigns.
References
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.