APT

Nobelium SSH

Nobelium SSH

NOBELIUM, also known as APT29, is a Russian state-sponsored threat actor responsible for high-profile cyberattacks, including the SolarWinds supply chain compromise

Known Variants

Known Variants

Part of Nobelium’s broader toolkit, including Sunburst and Teardrop, focused on exploiting SSH vulnerabilities.

Part of Nobelium’s broader toolkit, including Sunburst and Teardrop, focused on exploiting SSH vulnerabilities.

Mitigation Strategies

Mitigation Strategies

Secure SSH configurations by enforcing key-based authentication over password-based methods. Regularly audit SSH key usage and disable unused accounts. Monitor SSH access logs for anomalies, such as login attempts from unfamiliar IP addresses.

Targeted Industries or Sectors

Targeted Industries or Sectors

Focuses on government agencies, think tanks, and NGOs, particularly those in Europe and North America.

Focuses on government agencies, think tanks, and NGOs, particularly those in Europe and North America.

Associated Threat Actors

Associated Threat Actors

Nobelium is attributed to APT29 (Cozy Bear), a Russian state-sponsored threat actor involved in high-profile espionage campaigns.

Nobelium is attributed to APT29 (Cozy Bear), a Russian state-sponsored threat actor involved in high-profile espionage campaigns.

References