Number: AL21-001
Date: 11 January 2021
AUDIENCE
This Alert is intended for IT professionals and managers of notified organizations.
PURPOSE
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
OVERVIEW
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Alert [1] containing additional information about recent APT activity targeting organizations’ cloud environments.
DETAILS
On 8 January 2021 CISA, the United States’ agency responsible for protecting its critical infrastructure from physical and cyber threats, published Alert AA21-008A [1] containing additional information about recent APT activity targeting organizations’ cloud environments. It is a companion product to the previously issued Alert AA20-352A [2], which focused on SolarWinds Orion software as the vector.
AA21-008A describes additional methods of compromise , including techniques for lateral movement, being leveraged by a sophisticated threat actor. It provides tools and guidance on detecting this activity in organizations’ cloud environments and remediation of post-compromise activities.
Should activity matching the content of this Alert be discovered, recipients are encouraged to contact the Cyber Centre by email (contact@cyber.gc.ca) or by telephone (1-833-CYBER-88 or 1-833-292-3788).
REFERENCES
[1] CISA Alert AA21-008A
https://us-cert.cisa.gov/ncas/alerts/aa21-008a
[2] CISA Alert AA20-352A
https://us-cert.cisa.gov/ncas/alerts/aa20-352a
Note to Readers
The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada's national authority on cyber security and we lead the government's response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.