Joint advisory: Further TTPs associated with SVR cyber actors
The NCSC, CISA, FBI and NSA publish advice on detection and mitigation of SVR activity following the attribution of the SolarWinds compromise.
Art Alex via Getty Images
The NCSC, alongside the US Department for Homeland Security’s Cybersecurity Infrastructure Security Agency (CISA), FBI and the National Security Agency (NSA), has today published a report to provide further details of Tactics, Techniques and Procedures (TTPs) associated with SVR cyber actors. SVR cyber actors are known and tracked in open source as APT29, Cozy Bear, and The Dukes.
This advisory follows the public attribution of the SVR to the SolarWinds compromise in 2020.
Organisations are advised to follow the mitigation advice and guidance outlined, as well as the detection rules in the appendix in order to help protect against this activity. A recently published joint NSA, CISA, FBI advisory and joint FBI , DHS, CISA alert, also detail further TTPs linked to SVR cyber actors.
Reporting to the NCSC
UK organisations affected by the activity outlined should report any suspected compromises to the NCSC via the website.