We observed a similar pattern of activity stemming from the same cluster to networking equipment that was exposed to the internet, such as enterprise-grade firewalls like Fortinet. Analysis revealed these to be older models and thus we suspect that they were vulnerable to known CVEs. We also observed connections to smaller-brand firewall products such as Nethesis. We suspect that these devices were targeted opportunistically because they are not connected to any of the sectors listed in the
Joint Cybersecurity Advisory on GRU cyber campaigns—including government, defense contractors, IT providers, political organizations, energy and logistics.