https://www.wired.com/story/russia-gru-apt28-wifi-daisy-chain-breach/ Skip to main content Open Navigation Menu WIRED Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack * Security * Politics * Gear * The Big Story * Business * Science * Culture * Ideas * Merch More Search * Security * Politics * Gear * The Big Story * Business * Science * Culture * Ideas * Merch * Podcasts * Video * Newsletters * Magazine * Travel * Steven Levy's Plaintext Column * WIRED Classics from the Archive * Events * WIRED Insider * WIRED Consulting * Jobs * Coupons Andy Greenberg Security Nov 22, 2024 8:00 AM Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack In a first, Russia's APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street. City Wifi Logo Russian Flag and Code Photo Illustration: WIRED Staff; Getty Images Save Save For determined hackers, sitting in a car outside a target's building and using radio equipment to breach its Wi-Fi network has long been an effective but risky technique. These risks became all too clear when spies working for Russia's GRU military intelligence agency were caught red-handed on a city street in the Netherlands in 2018 using an antenna hidden in their car's trunk to try to hack into the Wi-Fi of the Organization for the Prohibition of Chemical Weapons. Since that incident, however, that same unit of Russian military hackers appears to have developed a new and far safer Wi-Fi hacking technique: Instead of venturing into radio range of their target, they found another vulnerable network in a building across the street, remotely hacked into a laptop in that neighboring building, and used that computer's antenna to break into the Wi-Fi network of their intended victim--a radio-hacking trick that never even required leaving Russian soil. At the Cyberwarcon security conference in Arlington, Virginia, today, cybersecurity researcher Steven Adair will reveal how his firm, Volexity, discovered that unprecedented Wi-Fi hacking technique--what the firm is calling a "nearest neighbor attack"--while investigating a network breach targeting a customer in Washington, DC, in 2022. Volexity, which declined to name its DC customer, has since tied the breach to the Russian hacker group known as Fancy Bear, APT28, or Unit 26165. Part of Russia's GRU military intelligence agency, the group has been involved in notorious cases ranging from the breach of the Democratic National Committee in 2016 to the botched Wi-Fi hacking operation in which four of its members were arrested in the Netherlands in 2018. In this newly revealed case from early 2022, Volexity ultimately discovered not only that the Russian hackers had jumped to the target network via Wi-Fi from a different compromised network across the street, but also that this prior breach had also potentially been carried out over Wi-Fi from yet another network in the same building--a kind of "daisy-chaining" of network breaches via Wi-Fi, as Adair describes it. "This is the first case we've worked where you have an attacker that's extremely far away and essentially broke into other organizations in the US in physical proximity to the intended target, then pivoted over Wi-Fi to get into the target network across the street," says Adair. "That's a really interesting attack vector that we haven't seen before." Most Popular * The Modular HMD Fusion Is a Sensible (and Boring) $300 Phone Gear The Modular HMD Fusion Is a Sensible (and Boring) $300 Phone By Julian Chokkattu * The Upgrades in Apple's New iMac Are Small but Worthwhile Gear The Upgrades in Apple's New iMac Are Small but Worthwhile By Christopher Null * Our Favorite Smartwatches Do Much More Than Just Tell Time Gear Our Favorite Smartwatches Do Much More Than Just Tell Time By Julian Chokkattu * Your TV Sounds Awful. These Soundbars Can Fix That Gear Your TV Sounds Awful. These Soundbars Can Fix That By Parker Hall * Poster Infographic and Map A slide describing the "nearest neighbor attack" that Russian hackers used to breach a DC network via Wi-Fi, from the Cyberwarcon presentation of Volexity founder Steven Adair. Courtesy of Volexity Based on the hackers' targeting of individuals within their customer's network, Adair says that the GRU hackers appear to have been seeking intelligence about Ukraine. It's no coincidence, he says, that the daisy-chained Wi-Fi-based intrusion was carried out in the months just before and after Russia's initial full-scale invasion of Ukraine in February 2022. Adair argues, though, that the case should serve as a broader warning about cybersecurity threats to Wi-Fi for high-value targets--and not just from the usual suspects loitering in the parking lot or the lobby. "Now we know that a motivated nation-state is doing this and has done it," says Adair, "It puts on the radar that Wi-Fi security has to be ramped up a good bit." He suggests organizations that might be the target of similar remote Wi-Fi attacks consider limiting the range of their Wi-Fi, changing the network's name to make it less obvious to potential intruders, or introducing other authentication security measures to limit access to employees. Adair says that Volexity first began investigating the breach of its DC customer's network in the first months of 2022, when the company saw signs of repeated intrusions into the customer's systems by hackers who had carefully covered their tracks. Volexity's analysts eventually traced the compromise to a hijacked user's account connecting to a Wi-Fi access point in a far end of the building, in a conference room with external-facing windows. Adair says he personally scoured the area looking for the source of that connection. "I went there to physically run down what it could be. We looked at smart TVs, looked for devices in closets. Is someone in the parking lot? Is it a printer?" he says. "We came up dry." Most Popular * The Modular HMD Fusion Is a Sensible (and Boring) $300 Phone Gear The Modular HMD Fusion Is a Sensible (and Boring) $300 Phone By Julian Chokkattu * The Upgrades in Apple's New iMac Are Small but Worthwhile Gear The Upgrades in Apple's New iMac Are Small but Worthwhile By Christopher Null * Our Favorite Smartwatches Do Much More Than Just Tell Time Gear Our Favorite Smartwatches Do Much More Than Just Tell Time By Julian Chokkattu * Your TV Sounds Awful. These Soundbars Can Fix That Gear Your TV Sounds Awful. These Soundbars Can Fix That By Parker Hall * Only after the next intrusion, when Volexity managed to get more complete logs of the hackers' traffic, did its analysts solve the mystery: The company found that the hijacked machine which the hackers were using to dig around in its customer's systems was leaking the name of the domain on which it was hosted--in fact, the name of another organization just across the road. "At that point, it was 100 percent clear where it was coming from," Adair says. "It's not a car in the street. It's the building next door." With the cooperation of that neighbor, Volexity investigated that second organization's network and found that a certain laptop was the source of the street-jumping Wi-Fi intrusion. The hackers had penetrated that device, which was plugged into a dock connected to the local network via Ethernet, and then switched on its Wi-Fi, allowing it to act as a radio-based relay into the target network. Volexity found that, to break into that target's Wi-Fi, the hackers had used credentials they'd somehow obtained online but had apparently been unable to exploit elsewhere, likely due to two-factor authentication. Volexity eventually tracked the hackers on that second network to two possible points of intrusion. The hackers appeared to have compromised a VPN appliance owned by the other organization. But they had also broken into the organization's Wi-Fi from another network's devices in the same building, suggesting that the hackers may have daisy-chained as many as three networks via Wi-Fi to reach their final target. "Who knows how many devices or networks they compromised and were doing this on," says Adair. In fact, even after Volexity evicted the hackers from their customer's network, the hackers tried again that spring to break in via Wi-Fi, this time attempting to access resources that were shared on the guest Wi-Fi network. "These guys were super persistent," says Adair. He says that Volexity was able to detect this next breach attempt, however, and quickly lock out the intruders. Volexity had presumed early on in its investigation that the hackers were Russian in origin due to their targeting of individual staffers at the customer organization focused on Ukraine. Then in April, fully two years after the original intrusion, Microsoft warned of a vulnerability in Windows' print spooler that had been used by Russia's APT28 hacker group--Microsoft refers to the group as Forest Blizzard--to gain administrative privileges on target machines. Remnants left behind on the very first computer Volexity had analyzed in the Wi-Fi-based breach of its customer exactly matched that technique. "It was an exact one-to-one match," Adair says. Most Popular * The Modular HMD Fusion Is a Sensible (and Boring) $300 Phone Gear The Modular HMD Fusion Is a Sensible (and Boring) $300 Phone By Julian Chokkattu * The Upgrades in Apple's New iMac Are Small but Worthwhile Gear The Upgrades in Apple's New iMac Are Small but Worthwhile By Christopher Null * Our Favorite Smartwatches Do Much More Than Just Tell Time Gear Our Favorite Smartwatches Do Much More Than Just Tell Time By Julian Chokkattu * Your TV Sounds Awful. These Soundbars Can Fix That Gear Your TV Sounds Awful. These Soundbars Can Fix That By Parker Hall * The notion that APT28 would be behind the daisy-chained Wi-Fi hacking makes sense, says John Hultquist, the founder of Cyberwarcon who also leads threat intelligence at Google-owned cybersecurity firm Mandiant and has long tracked the GRU hackers. He sees the technique Volexity uncovered as the natural evolution of APT28's "close-access" hacking methods, in which the GRU has sent small traveling teams in person to hack into target networks via Wi-Fi if other methods failed. "This is essentially a close-access op like they've done in the past, but without the close access," Hultquist says. The switch to hacking via Wi-Fi from a remotely compromised device rather than physically placing a spy nearby represents a logical next step following the GRU's operational security disaster in 2018, when its hackers were caught in a car in The Hague attempting to hack the Organization for the Prohibition of Chemical Weapons in response to the OPCW's investigation of the attempted assassination of GRU defector Sergei Skripal. In that incident, the APT28 team was arrested and their devices were seized, revealing their travel around the world from Brazil to Malaysia to carry out similar close-access attacks. "If a target is important enough, they're willing to send people in person. But you don't have to do that if you can come up with an alternative like what we're seeing here," Hultquist says. "This is potentially a major improvement for those operations, and it's something we'll probably see more of--if we haven't already." You Might Also Like ... * In your inbox: Our biggest stories, handpicked for you each day * Election reaction: The manosphere won * The Big Story: California will keep moving the world forward * Trump's failed attempt to overthrow Venezuela's president * Event: Join us for The Big Interview on December 3 in San Francisco [undefined] Andy Greenberg is a senior writer for WIRED covering hacking, cybersecurity, and surveillance. He's the author of the new book Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency. His last book was *Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most... Read more Senior Writer * TopicsRussiahackingcybersecurityhackssecurityespionage Read More Inside a Firewall Vendor's 5-Year War With the Chinese Hackers Hijacking Its Devices Inside a Firewall Vendor's 5-Year War With the Chinese Hackers Hijacking Its Devices Sophos went so far as to plant surveillance "implants" on its own devices to catch the hackers at work--and in doing so, revealed a glimpse into China's R&D pipeline of intrusion techniques. Andy Greenberg Andrew Tate's 'Educational Platform' Was Hacked Andrew Tate's 'Educational Platform' Was Hacked Plus: The worst telecom hack in US history rolls on, iPhones are harder to break into, and more of the week's top security news. Dhruv Mehrotra Auto-Rebooting iPhones Are Causing Chaos for Cops Auto-Rebooting iPhones Are Causing Chaos for Cops Plus: Hot Topic confirms a customer data breach, Germany arrests a US citizen for allegedly passing military secrets to Chinese intelligence, and more. Andrew Couts Man Arrested for Snowflake Hacking Spree Faces US Extradition Man Arrested for Snowflake Hacking Spree Faces US Extradition Alexander "Connor" Moucka was arrested this week by Canadian authorities for allegedly carrying out a series of hacks that targeted Snowflake's cloud customers. His next stop may be a US jail. Matt Burgess Florida Man Accused of Hacking Disney World Menus, Changing Font to Wingdings Florida Man Accused of Hacking Disney World Menus, Changing Font to Wingdings Plus: Cops take down a notorious infostealer, Strava leaks world leaders' locations, and a hacking scandal is causing chaos in Italy. Matt Burgess Zero-Click Flaw Exposes Potentially Millions of Popular Storage Devices to Attack Zero-Click Flaw Exposes Potentially Millions of Popular Storage Devices to Attack A vulnerability categorized as "critical" in a photo app installed by default on Synology network-attached storage devices could give attackers the ability to steal data and worse. Kim Zetter Bitfinex Hacker Gets 5 Years for $10 Billion Bitcoin Heist Bitfinex Hacker Gets 5 Years for $10 Billion Bitcoin Heist Plus: An "AI granny" is wasting scammers' time, a lawsuit goes after spyware-maker NSO Group's executives, and North Korea-linked hackers take a crack at macOS malware. Lily Hay Newman Cybercriminals Pose a Greater Threat of Disruptive US Election Hacks Than Russia or China Cybercriminals Pose a Greater Threat of Disruptive US Election Hacks Than Russia or China A report distributed by the US Department of Homeland Security warned that financially motivated cybercriminals are more likely to attack US election infrastructure than state-backed hackers. Lily Hay Newman Inside the Massive Crime Industry That's Hacking Billion-Dollar Companies Inside the Massive Crime Industry That's Hacking Billion-Dollar Companies When you download a piece of pirated software, you might also be getting a piece of infostealer malware, and entering a highly complex hacking ecosystem that's fueling some of the biggest breaches on the planet. Joseph Cox The WIRED Guide to Protecting Yourself From Government Surveillance The WIRED Guide to Protecting Yourself From Government Surveillance Donald Trump has vowed to deport millions and jail his enemies. To carry out that agenda, his administration will exploit America's digital surveillance machine. Here are some steps you can take to evade it. Andy Greenberg Anyone Can Buy Data Tracking US Soldiers and Spies to Nuclear Vaults and Brothels in Germany Anyone Can Buy Data Tracking US Soldiers and Spies to Nuclear Vaults and Brothels in Germany More than 3 billion phone coordinates collected by a US data broker expose the detailed movements of US military and intelligence workers in Germany--and the Pentagon is powerless to stop it. Dhruv Mehrotra ICE Can Already Sidestep Sanctuary City Laws Through Data-Sharing Fusion Centers ICE Can Already Sidestep Sanctuary City Laws Through Data-Sharing Fusion Centers Built to combat terrorism, fusion centers give US Immigration and Customs Enforcement a way to gain access to data that's meant to be protected under city laws limiting local police cooperation with ICE. Lily Hay Newman WIRED WIRED is where tomorrow is realized. It is the essential source of information and ideas that make sense of a world in constant transformation. The WIRED conversation illuminates how technology is changing every aspect of our lives--from culture to business, science to design. The breakthroughs and innovations that we uncover lead to new ways of thinking, new connections, and new industries. More From WIRED * Subscribe * Newsletters * FAQ * WIRED Staff * Editorial Standards * Archive * RSS * Accessibility Help Reviews and Guides * Reviews * Buying Guides * Mattresses * Electric Bikes * Soundbars * Streaming Guides * Wearables * TVs * Coupons * Code Guarantee * Gift Guides * Advertise * Contact Us * Manage Account * Jobs * Press Center * Conde Nast Store * User Agreement * Privacy Policy * Your California Privacy Rights (c) 2024 Conde Nast. All rights reserved. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices Select international site United States * Italia * Japon * Czech Republic & Slovakia * * * * * *