Red Russians: How Russian APT groups follow offensive security research

Will Thomas (Senior Threat Intelligence Adviser · Team Camry)

DEF CON 33 · Day 1 · Main Stage

Overview

In this compelling DEF CON talk, Will Thomas, a Senior Threat Intelligence Adviser at Team Camry, unveils a critical trend observed over years of tracking sophisticated adversaries: Russian advanced persistent threat (APT) groups are increasingly leveraging publicly available offensive security research and tools. Thomas argues that these state-sponsored entities, rather than consistently developing novel zero-day exploits, are exhibiting a form of "laziness" by rapidly adopting and weaponizing techniques and proof-of-concept (PoC) exploits released by red teamers and security researchers. This phenomenon presents both a significant challenge and a unique opportunity for defenders.

Watch on YouTube

Visual summary for Red Russians: How Russian APT groups follow offensive security research by Will Thomas
Visual summary for Red Russians: How Russian APT groups follow offensive security research by Will Thomas

Key moments

  1. 2:00 Russian APTs copying red team research for espionage
  2. 2:50 Red teamers: consider impact of releasing tools
  3. 3:30 Blue teamers: follow red team research
  4. 4:00 Overview of relevant Russian intelligence services (APTs)
  5. 4:50 Example 1: SVR's M365 device code fishing
  6. 6:00 Detection opportunities for M365 device code fishing
  7. 6:50 Example 2: RDP config fishing by APTs

Red Russians: How Russian APT groups follow offensive security research

Speakers: Will Thomas, Senior Threat Intelligence Adviser, Team Camry

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=bpUxuOdfGHM

Overview

In this compelling DEF CON talk, Will Thomas, a Senior Threat Intelligence Adviser at Team Camry, unveils a critical trend observed over years of tracking sophisticated adversaries: Russian advanced persistent threat (APT) groups are increasingly leveraging publicly available offensive security research and tools. Thomas argues that these state-sponsored entities, rather than consistently developing novel zero-day exploits, are exhibiting a form of "laziness" by rapidly adopting and weaponizing techniques and proof-of-concept (PoC) exploits released by red teamers and security researchers. This phenomenon presents both a significant challenge and a unique opportunity for defenders.

The core message of the talk resonates deeply within the cybersecurity community: the gap between offensive disclosure and defensive implementation is being exploited by nation-state actors. Thomas emphasizes that offensive security researchers bear a responsibility to consider the downstream implications of their public releases, perhaps by aiding defenders with detection guidance. Crucially, for blue teams and threat hunters, this trend means a paradigm shift is necessary – instead of waiting for APT reports to emerge, security teams should proactively monitor offensive security blogs, GitHub repositories, and conference talks to pre-emptively build detections for techniques that are likely to be weaponized by adversaries.

Background

▶ Watch: Russian APTs copying red team research for espionage (2:00)

Will Thomas's research stems from over three to four years of dedicated threat intelligence work, particularly during his tenure as the Head of Threat Hunting at Equinix, the world's largest data center company. In this role, his focus was heavily on Russian APT groups, given the global presence and critical assets of his former organization. He observed a consistent pattern: these sophisticated adversaries were actively monitoring the offensive security landscape and swiftly integrating newly disclosed techniques and tools into their espionage campaigns.

The talk specifically identifies three prominent Russian intelligence services involved in this practice:

  • The GRU (Military Intelligence Service): Known by various monikers such as APT28, Fancy Bear, and Forest Blizzard, this group is frequently cited in threat intelligence reports for its aggressive and opportunistic cyber operations.
  • The SVR (Foreign Intelligence Service): Also tracked as APT29, Cozy Bear, and Midnight Blizzard, this group is notorious for high-profile operations, including the SolarWinds supply chain attack, targeting numerous US and UK government organizations, and NATO entities.
  • The FSB (Federal Security Service): Often referred to as TAR, Venus Bear, and Secret Blizzard, this group is recognized as one of the longest-running and most technically proficient APTs.

Thomas highlights that the proactive monitoring of red team research offers a strategic advantage for defenders. By staying abreast of offensive disclosures, security teams can develop and deploy detections for new techniques before they are weaponized in the wild, thus turning an adversary's "laziness" into a defensive strength. This approach challenges the traditional reactive security posture, advocating for a more anticipatory and intelligence-driven defense.

Key Findings

▶ Watch: Blue teamers: follow red team research (3:30)

The central finding of Will Thomas's presentation is the consistent and rapid adoption of publicly available offensive security research by Russian APT groups. This isn't an isolated incident but a pervasive trend observed across multiple campaigns and threat actors over several years. Instead of investing heavily in discovering and developing zero-day exploits for every campaign, these well-resourced nation-state groups demonstrate a preference for leveraging readily available, well-documented techniques and tools, often within days or weeks of their public disclosure.

Thomas provides compelling evidence of this trend through a timeline of observed incidents, demonstrating that the time lag between offensive research release and APT weaponization can be astonishingly short. For instance, the Team City exploit was adopted by the SVR within a week of its public release by Rapid7. Similarly, a Microsoft Teams fishing tool and the ClickFix technique were utilized by APTs mere days or weeks after their public disclosure. This rapid turnaround underscores the urgent need for defenders to act quickly.

Beyond immediate weaponization, the talk also reveals that APTs are willing to leverage techniques that have been known for several years, capitalizing on the widespread failure of organizations to implement basic detections. Examples include M365 device code phishing, disclosed by Black Hills in 2023 but used by the SVR in February 2024; RDP config phishing, disclosed in February 2022 and observed in SVR campaigns in October 2024; and HTML smuggling, a technique blogged about by red teamers since 2018 but actively used by APT groups in May 2021. This indicates that while some organizations may be well-resourced, many others still lack fundamental controls or the agility to implement detections for "old" but still effective techniques.

This pattern suggests a strategic calculation by Russian APTs: why invest in complex, high-cost zero-day development when a significant portion of their targets remain vulnerable to publicly documented methods? The speaker emphasizes that offensive researchers should be mindful of this reality, potentially incorporating defensive guidance into their disclosures to empower blue teams. For defenders, the implication is clear: proactive monitoring of offensive security research is no longer an optional best practice but a critical component of an effective threat intelligence and hunting program.

Technical Deep Dive

▶ Watch: Overview of relevant Russian intelligence services (APTs) (4:00)

Will Thomas meticulously detailed several specific examples of Russian APT groups leveraging offensive security research, providing insights into the techniques, targeted organizations, and crucial detection opportunities.

M365 Device Code Phishing (SVR, February 2024)

The SVR was observed using M365 device code phishing, a technique initially disclosed by Black Hills in 2023. This method exploits a legitimate Microsoft 365 feature designed for easy login on devices like smart TVs or in corporate settings. Adversaries craft lures disguised as WhatsApp, Signal, Element, or Microsoft Teams messages, prompting users to visit a specific URL (e.g., https://microsoft.com/device login) and enter a code. Upon entering the code, the user inadvertently grants the attacker access to their M365 account. The SVR targeted government and non-government organizations across the US and Europe.

Detection Opportunities: Defenders should monitor web proxy logs (e.g., Zscaler) and email gateway logs for URLs containing /device login. While this is a legitimate Microsoft endpoint, its appearance in unexpected contexts, particularly email attachments or suspicious messages, is a strong indicator of malicious activity.

RDP Config Phishing (SVR, October 2024)

In October 2024, the SVR employed RDP config phishing, a technique also disclosed by Black Hills in February 2022. This straightforward attack involves sending victims a malicious RDP config file via email. When the user executes this file, it establishes a remote connection to an adversary-controlled system, allowing the attacker to capture credentials. Once connected, the APT can run arbitrary commands, steal files, and deploy additional malware. This campaign primarily targeted Ukrainian government organizations, with spillover into UK and US entities.

Detection Opportunities: The presence of RDP files as email attachments should be considered highly suspicious in most corporate environments. Email gateway logs are crucial for identifying such attachments. Additionally, Windows event logs can provide insights into RDP connection attempts and related activities, helping to identify unauthorized remote access.

Azure AD / Entra ID Password Spraying (SVR, ongoing for years)

The SVR has been conducting password spraying attacks against Azure AD (now known as Microsoft Entra ID) login pages for years. A key enabler for this was a bug in Azure AD that allowed infinite password spraying without rate limiting, a vulnerability highlighted by Technica and SecureWorks. The SVR leveraged residential proxies and rotating IP addresses, making attribution challenging and often delayed by years.

Detection Opportunities: While multiple failed login attempts are an obvious indicator, APTs often employ a "low and slow" approach (e.g., one request per hour) to evade basic thresholds. Therefore, comprehensive IP enrichment is vital to correlate login attempts from suspicious sources like VPN exit nodes, residential proxies, or Tor nodes. Microsoft Entra ID Protection logs are the primary source for detecting and analyzing these attacks.

Team City Exploit (SVR, October 2023)

In one of the most rapid weaponization examples, the SVR exploited a vulnerability in Team City in October 2023, mere weeks after Rapid7 publicly released an exploit for it. This demonstrates the APT's swift monitoring and incorporation of public PoCs. The SVR quickly targeted government organizations.

Detection Opportunities: Organizations running Team City applications should monitor for unusual activity on the hosting Windows server. This includes the execution of command-line utilities like wget (used for downloading files) and outbound requests to suspicious domains such as trycloudflare.com. Robust Endpoint Detection and Response (EDR) solutions and Sysmon logging can be instrumental in identifying these anomalies, though Thomas notes that some targeted organizations may lack such advanced controls.

Microsoft Teams Fishing (APT Groups, shortly after feature release)

Thomas highlighted that as soon as Microsoft announced the feature allowing users in external tenants to message users in other tenants, he anticipated its abuse. Indeed, APT groups quickly adopted Microsoft Teams fishing. Attackers send messages from external, often compromised or attacker-controlled, tenants. The victim clicks a link, is prompted for a code, and upon entering it, their account is compromised. Targets included foreign ministries, government agencies, and military organizations, particularly those involved in the conflict in Ukraine.

Detection Opportunities: This attack leverages legitimate infrastructure, making detection trickier. Look for suspicious emails involving the onmicrosoft.com domain that originate from external or unfamiliar tenants. The most effective mitigation is to disable external access in Microsoft Teams if it's not strictly necessary for business operations.

HTML Smuggling (APT Groups, May 2021)

Although blogged about by red teamers since 2018, HTML smuggling was observed in APT campaigns in May 2021. This technique involves sending an HTML file that, when opened, decodes into an ISO file (a disk image container). This ISO file, which can contain executables or DLLs, is then mounted on the victim's system. To the user, a seemingly innocuous PDF might appear, while malware is silently executed in the background, often leveraging techniques like DLL sideloading within legitimate applications like Adobe Acrobat (Acro.exe).

Detection Opportunities: Key indicators include DLL sideloading in Acro.exe and, more generally, the mounting of ISO files by explorer.exe. While IT personnel might legitimately mount ISOs, such activity by non-technical users (e.g., "Karen in finance") should raise immediate suspicion. Outbound connections to cloud storage APIs like Dropbox API from unexpected processes or hosts can also be a sign of exfiltration related to this method, especially if Dropbox is an unsanctioned application within the organization.

ClickFix (APT28/GRU, September 2024)

ClickFix, a tool and technique released by John Hammond on GitHub in September 2024, was quickly adopted by APT28 (GRU), as observed by SSU Ukraine. This ingenious social engineering tactic presents a fake CAPTCHA verification. The user is instructed to press Windows+R, which automatically copies a malicious script to the clipboard. The user then presses Windows+V to paste and execute the script, granting the attacker a backdoor, particularly if the user has local administrator privileges.

Detection Opportunities: Detecting ClickFix is challenging due to its reliance on user interaction and legitimate system functions. It necessitates full PowerShell script block logging, a capability not universally present in all EDR solutions. While clipboard monitoring is a theoretical option, Thomas advises caution due to the significant privacy and data collection implications it carries. Focus on the execution context: if a user with high privileges executes an unexpected script via this method, it's a critical alert.

Demo / Proof of Concept

▶ Watch: Detection opportunities for M365 device code fishing (6:00)

While Will Thomas's talk is rich with examples of techniques employed by Russian APTs and provides numerous screenshots of lures and detection artifacts, it does not feature a live demonstration or proof-of-concept by the speaker. Instead, the presentation focuses on dissecting the adversary's methods based on observed campaigns and detailing the corresponding detection opportunities derived from the speaker's extensive threat intelligence and hunting experience. The objective is to inform defenders about the practical application of offensive research by real-world threat actors, rather than to showcase the offensive capabilities themselves.

Defensive Implications

▶ Watch: Example 2: RDP config fishing by APTs (6:50)

The consistent pattern of Russian APTs leveraging publicly disclosed offensive security research carries profound implications for defensive strategies. Will Thomas outlines several key areas where blue teams and security engineers must adapt:

  1. Proactive Threat Intelligence and Hunting: Defenders must shift from a reactive to a proactive stance. Instead of waiting for official APT reports, security teams should actively monitor the offensive security landscape. This includes subscribing to red team blogs, following prominent security researchers on social media, attending offensive security conferences (or reviewing their content), and tracking new proof-of-concept (PoC) exploits released on platforms like GitHub. Particular attention should be paid to "spicy" research involving Microsoft 365 environments or pre-authentication exploits.
  1. Rapid Detection Engineering: The short window between disclosure and weaponization (sometimes mere days or weeks) necessitates an agile detection engineering process. As soon as a new technique is disclosed, security teams should strive to build, test, and deploy detections within a matter of hours or an afternoon. This requires a dedicated focus on transforming threat intelligence into actionable detection rules for SIEMs, EDRs, and other security tools.
  1. Comprehensive Logging and Telemetry: Effective detection relies on rich telemetry. Organizations must ensure they have robust logging enabled across critical systems and applications. This includes:
  • Email Gateway Logs: For detecting suspicious attachments (e.g., RDP config files) and phishing lures.
  • Web Proxy Logs (e.g., Zscaler): To identify access to suspicious URLs (e.g., /device login).
  • Windows Event Logs: For monitoring RDP connections, process execution, and unusual system activities.
  • PowerShell Script Block Logging: Crucial for detecting script-based attacks like ClickFix, though Thomas acknowledges not all EDRs fully support this.
  • Microsoft Entra ID Protection: Essential for detecting password spraying and other identity-based attacks.
  • EDR/Sysmon: For observing unusual process execution, file modifications, and network connections (e.g., wget, trycloudflare.com on Team City servers, ISO mounting).
  1. IP Enrichment and Correlation: For "low and slow" attacks like password spraying, correlating failed login attempts with IP enrichment data (e.g., identifying VPN exit nodes, residential proxies, Tor nodes) is critical to uncover patterns that might otherwise be missed by simple thresholding.
  1. Configuration Hardening and Feature Management: Proactive configuration management can mitigate entire attack vectors. For instance, disabling external access in Microsoft Teams if not required can prevent specific fishing campaigns. Understanding what's "normal" in an environment is also paramount; if certain SaaS applications (like Dropbox) are unsanctioned, any related outbound connections should be investigated immediately.
  1. Adversary Emulation for Validation: To ensure detections are effective, security engineering teams must perform adversary emulation. This involves running the tools and techniques described by offensive researchers or observed in APT campaigns, extracting artifacts, and validating that the deployed detection rules trigger as expected. This iterative process of "rule vetting, rule deploying, and rule refining" is crucial.
  1. Leveraging Intelligence Resources: Thomas introduced his Russian APT Tool Matrix GitHub project, a valuable resource detailing tools used by various Russian APT groups across different MITRE ATT&CK categories (credential theft, defensive evasion, discovery, exfiltration). By understanding common adversary tools like Mimikatz, Cobalt Strike, InPacket, Sliver, and Brute Retell C4, defenders can build targeted detections. He also highlighted the use of legitimate tools and cloud APIs for exfiltration by groups like Cozy Bear (SVR).

By adopting these defensive strategies, organizations can proactively raise the cost of operations for Russian APTs, making their "lazy" approach far less effective.

Key Takeaways

  • Russian APTs are Agile Adopters: State-sponsored Russian threat groups actively monitor and rapidly weaponize publicly disclosed offensive security research and tools, often within days or weeks of their release.
  • Proactive Defense is Paramount: Defenders must shift from reactive incident response to proactive threat intelligence and hunting, monitoring red team blogs and GitHub repositories to build detections before techniques are exploited in the wild.
  • Offensive Researchers Have a Role: Offensive security tool developers and researchers should consider the defensive implications of their public releases and potentially provide guidance to aid blue teams in detection.
  • Robust Logging and Telemetry are Essential: Comprehensive logging from email gateways, web proxies, Windows event logs, EDRs, and identity protection services (like Microsoft Entra ID Protection) is critical for identifying these sophisticated but often signature-poor attacks.
  • Configuration and Context Matter: Simple mitigations like disabling unnecessary features (e.g., Teams external access) and understanding "normal" activity in an environment can significantly reduce an organization's attack surface.
  • Leverage Public Intelligence: Resources like the speaker's "Russian APT Tool Matrix" can help defenders understand common adversary tools and TTPs, enabling the creation of more targeted and effective detection rules.

About the Speaker(s)

Will Thomas is a Senior Threat Intelligence Adviser with Team Camry, a CTI company and network intelligence organization, where he joined in April. Prior to this role, he served as the Head of Threat Hunting at Equinix, the world's largest data center company, for three and a half years. During his time at Equinix, he built the threat hunting program from scratch, focusing on identifying adversaries, developing detections, and understanding log sources and organizational vulnerabilities. Thomas is also a co-founder of a CTI trust group for intelligence sharing and collaboration, a co-author of SANS4589 (Cyber Crime Investigations), and the co-founder of BSides Bournemouth, as well as an organizer for Bournemouth 2600. His extensive experience in threat intelligence and hunting, particularly concerning Russian APT groups, forms the basis of his insights shared in this talk.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent threat intel talk with a clear, defensible thesis — Russian APTs are lazy, they recycle public offensive research fast, and defenders should get ahead of it by monitoring the same sources. The case studies are concrete and the detection guidance is actionable. But this is practitioner-level synthesis, not original research, and the thesis itself isn't novel to anyone who's been paying attention to APT campaigns for the last few years.

Heather Calloway (CISO) — SOLID

Thomas makes a real, practical observation — Russian APTs are lazily but effectively weaponizing public offensive research — and backs it with credible timelines and detection guidance. The content is operationally useful for threat hunters and detection engineers, but it stays at the practitioner layer and never climbs to the institutional questions that matter most.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33