Amazon has issued a warning about a credential theft campaign orchestrated by the advanced persistent threat group APT29, also known as Cozy Bear. This campaign specifically targets cloud users, aiming to steal credentials and gain unauthorized access to cloud environments. APT29 is known for its sophisticated cyber espionage operations, often linked to state-sponsored activities. The campaign involves phishing and other social engineering tactics to compromise user accounts and infiltrate cloud infrastructures. Organizations using cloud services are urged to enhance their security measures, including multi-factor authentication and continuous monitoring, to defend against such threats. This incident highlights the growing risk of targeted attacks on cloud platforms and the importance of proactive cybersecurity strategies to protect sensitive data and maintain operational integrity. Cybersecurity teams should stay vigilant and update their defenses to counteract the evolving tactics employed by threat actors like APT29.
This Cyber News was published on www.darkreading.com. Publication date: Tue, 02 Sep 2025 20:45:06 +0000