Amazon’s security experts say they disrupted a new “watering hole” campaign conducted by the Russian state-sponsored threat actor group known as APT29.In this case, APT29 managed to compromise multiple websites, and used them to redirect the victims to other, attacker-controlled domains.A watering hole attack is when cybercriminals inject malware into a website usually visited by a specific group of people, hoping to compromise their devices when they access it.APT29 used the sites to redirect victims to two malicious domains: findcloudflare[.]com, and cloudflare[.]redirectpartners[.]com. There, they would mimic Microsoft’s usual device code authentication flow, in an effort to log into their victims’ Microsoft accounts. Is Russian hackers the greatest threat to global cyberspace ?

