The UK National Cyber Security Centre, FBI, NSA, and CISA warned that Russia’s Foreign Intelligence Service (SVR), also tracked as APT29 and Nobelium, is running a broad cyber-espionage campaign that combines mass exploitation of known vulnerabilities with targeted intrusions against governments, diplomats, think tanks, technology firms, financial institutions, and cloud environments. Officials said the group scans the internet for unpatched systems and exploits long-known perimeter flaws including CVE-2019-19781, CVE-2019-11510, CVE-2018-13379, and CVE-2020-5902, then uses compromised accounts to move deeper into victim networks and, in some cases, into connected supply chains.
The campaign builds on tradecraft previously tied to the SolarWinds Orion compromise and later phishing and cloud-focused operations attributed to the SVR. U.S. and allied advisories said the service has shifted toward stealthier methods such as password spraying, abuse of mailbox and cloud permissions, temporary email infrastructure, and reduced reliance on custom malware, though earlier operations also used tools such as SUNBURST, TEARDROP, Cobalt Strike Beacon, and WELLMESS. Microsoft separately reported that Nobelium targeted thousands of accounts across hundreds of organizations in a focused espionage effort, while defenders were urged to prioritize patching internet-facing systems, enforce multi-factor authentication, audit identity and mailbox permissions, and investigate signs of lateral movement and account abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
The UK NCSC, together with the FBI and NSA, warned that Russia's SVR was conducting a continued global campaign exploiting established vulnerabilities at scale. The advisory said the actors targeted governments, diplomatic entities, think tanks, technology firms, and financial institutions, while also scanning broadly for opportunistic victims with unpatched internet-facing systems.
CISA, ACSC, NCSC, and the FBI issued a joint advisory identifying the top routinely exploited vulnerabilities in 2020 and widely exploited flaws in 2021. The guidance emphasized that nation-state and criminal actors continued to rely on older, publicly known vulnerabilities in internet-facing systems such as VPNs, Exchange, Citrix, Fortinet, F5, and MobileIron.
Microsoft reported that Nobelium, which it linked to Russia's SVR, targeted thousands of accounts across hundreds of government and human rights organizations in a phishing campaign. Microsoft said it had notified affected customers and had not seen evidence of a significant number of successful compromises at that time.
The UK NCSC, together with CISA, the FBI, and the NSA, published a joint advisory detailing additional tactics, techniques, and procedures associated with SVR cyber actors. The notice followed public attribution of the 2020 SolarWinds compromise to the SVR and included mitigation guidance, detection rules, and reporting instructions for suspected compromises.
The FBI, DHS, and CISA published a joint report on Russian Foreign Intelligence Service cyber operations, describing targets, tactics, and defensive guidance. The report documented SolarWinds-enabled intrusions, password spraying, exploitation of CVE-2019-19781, and the use of false identities, cryptocurrencies, temporary email, and VoIP services.
The White House released a statement attributing the SolarWinds compromise to Russia's Foreign Intelligence Service. U.S. government reporting later cited this attribution as a key reference point in describing SVR tradecraft and ongoing risk.
A state-sponsored actor began a supply-chain campaign in March 2020 by embedding backdoor code into SolarWinds Orion software and distributing it through the product's update mechanism. The operation created remote access opportunities across potentially thousands of public and private organizations.
In 2020, the governments of the United Kingdom, Canada, and the United States attributed WELLMESS malware intrusions to APT29. The activity focused on organizations involved in COVID-19 vaccine development and followed exploitation of unpatched public vulnerabilities.
During the spring and summer of 2020, SVR operators used modified SolarWinds network monitoring software as an initial intrusion vector to expand access to numerous victim networks. After entry, they moved laterally to reach email accounts, including those of IT staff, to support espionage and evade defenders.
The FBI observed that beginning in 2018, SVR actors moved away from malware-heavy intrusions on victim networks and increasingly targeted cloud resources, especially email accounts. This shift included low-and-slow password spraying, abuse of MFA exemptions, and mailbox permission changes.
SolarWinds announced that its Orion Platform had been modified by a state-sponsored threat actor, revealing the supply-chain compromise tied to the broader FireEye breach investigation. Analysis identified the trojanized Orion component as SUNBURST and documented follow-on tooling such as TEARDROP and Cobalt Strike Beacon.
In a separate incident described by U.S. agencies, SVR actors exploited CVE-2019-19781 against a VPN appliance to gain network access, steal credentials, and re-enter the environment until the vulnerable appliance was removed. The case illustrated the group's use of known perimeter-device flaws for persistent access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
ncsc.gov.uk
Open sourceus-cert.cisa.gov
Open sourceblogs.microsoft.com
Open sourcencsc.gov.uk
Open sourcevice.com
Open sourceus-cert.cisa.gov
Open sourcepicussecurity.com
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.