Amazon has detected and disrupted a watering hole campaign organized by Russian hackers APT29, as part of their efforts to gather intelligence.

The campaign used compromised websites to redirect visitors to malicious infrastructure designed to trick users into devices attacker-controlledthrough Microsoft's device code authentication flow.
Russian hackers APT29
APT29, also known as BlueBravo, Cloaked Ursa, CozyLarch, Cozy Bear, Earth Koshchei, ICECAP, Midnight Blizzard, and The Dukes, is a state- sponsored hacking group with ties to Russia’s Foreign Intelligence Service (SVR). In recent months, the group has been linked to attacks using malicious Remote Desktop Protocol (RDP) configuration files to target Ukrainian entities and extract sensitive data.
See also: JSCoreRunner: Mac malware distributed via PDF Conversion Site
Since the beginning of the year, hackers have adopted various phishing, including device code phishing and device join phishing, to gain unauthorized access to Microsoft 365 accounts.
In June 2025, Google reported that it had observed a threat cluster with links to APT29, which exploited a Google account feature, called application-specific passwords , to gain access to victims' emails . The targeted campaign was attributed to UNC6293 .
The most recent malicious attacks
The latest activity detected by Amazon's threat intelligence team highlights the threat actor's continued efforts to collect credentials and gather information of interest, while simultaneously refining its techniques.

The attacks included the compromise of various legitimate websites by APT29 and JavaScript injection that redirected approximately 10% of visitors to domains controlled by the hackers (e.g. findcloudflare[.]com), which mimicked Cloudflare verification pages to give the impression of legitimacy.
See also: Hackers exploit Windows and Linux vulnerabilities
In reality, the ultimate goal of the campaign was to trick victims into entering a legitimate device code generated by the threat actor into a login page, essentially giving them access to their Microsoft accounts and data. This technique was described by both Microsoft and Volexity in February 2025.
The activity is also notable for incorporating various evasion techniques, such as Base64 encoding to hide malicious code, setting cookies to avoid repeated redirects of the same visitor, and switching to new infrastructure when blocked.
“Despite the group’s efforts to move to new infrastructure, including moving from AWS to another cloud provider, our team continued to monitor and disrupt their operations,” Amazon said. “Following our intervention, we observed the group registering additional domains such as cloudflare.redirectpartners[.]com, which again attempted to lure victims into Microsoft device code authentication workflows.”
See also: VerifTools: Authorities shut down fake ID marketplace

Russian hackers (APT29 and others) have become a significant force in cyberspace, using their skills for both criminal and political purposes. As technology continues to advance, it is likely that these hackers will continue to adapt and evolve their tactics for more effective attacks. This means that they will continue to pose a significant challenge to governments and organizations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The warnings and efforts to combat Russian hacking highlight the need for international cooperation and innovation in the ever-changing cybersecurity. It is therefore important for both individuals and organizations to remain vigilant and continually update their security measures to protect themselves from potential attacks. With increased awareness and cooperation, we can work to mitigate the impact of Russian hackers on global cybersecurity.
