The FBI and CISA have issued a joint warning stating that US think tanks are being targeted by APT hackers. The two agencies advised US think tanks to develop network defense procedures after noticing that APT hackers are carrying out ongoing cyberattacks.
According to the warning, the malicious activity identified by the FBI and CISA targets individuals and organizations active in international affairs or national security policy.

APT hackers use a variety of methods to gain access to their potential victims' systems. These include sending spear-phishing emails and exploiting third-party messaging services targeting both corporate and personal accounts. In addition, hackers often exploit vulnerable web-facing devices and gain remote login capabilities.
Additionally, the FBI and CISA said the COVID -19 has made it easier for APT hackers to target potential victims. Specifically, they noted that teleworking during the global health crisis has increased the workforce’s reliance on remote connectivity, providing more opportunities for malicious actors to exploit these connections to carry out attacks.

The two agencies also added that attackers can leverage VPNs and other remote work tools to gain initial or persistent access to a victim's network. If successful, they can steal sensitive information, obtain credentials , and gain continued access to their victims' networks.
The FBI and CISA recommend that individuals and organizations operating in the fields of international affairs and national security immediately adopt a heightened state of awareness and implement mitigation strategies.

In particular, James McQuiggan, security awareness advocate at KnowBe4, stressed that all organizations, including think tanks, are targets of state hackers, with malicious actors carrying out phishing attacks on individuals as they consider this to be the easiest way to gain access to systems and infrastructure.
Finally, McQuiggan emphasized that organizations should maintain a robust security awareness training program and update it frequently to keep employees informed about the latest attack patterns and phishing emails.
