CRN reports that Amazon has confirmed that Russian state-sponsored hackers, specifically the GRU-linked group Sandworm, conducted a sustained campaign throughout 2025 targeting misconfigured customer network edge devices hosted on AWS infrastructure.According to a security report by Amazon CISO CJ Moses, the attackers shifted their focus from exploiting software vulnerabilities to targeting "low-hanging fruit," such as enterprise routers, VPN concentrators, and remote access gateways with exposed management interfaces, to gain initial access. This tactical adaptation allowed Sandworm to achieve the same strategic goals of credential harvesting and lateral movement into critical infrastructure, particularly in the energy sector, while reducing their own operational exposure and resource expenditure.Moses emphasized that the attacks stem from customer configuration errors, not a weakness in AWS technology, and noted there is no AWS patch required. He urged organizations entering 2026 to prioritize securing network edge devices and monitoring for credential replay attacks to defend against this persistent, years-long threat to critical infrastructure and cloud-hosted network assets.
Threat Intelligence, Cloud Security
Amazon: Russian hackers targeted customer network edge devices in 2025

(Adobe Stock)
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


