Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse

Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse

•

Episode description

Russian State Exploitation, ShareFile Emergency Shutdown, and DocuSign RMM Abuse

This briefing examines three concurrent threats that share a common vulnerability: neglected infrastructure. The NCSC and eight international partners issued a joint advisory on Russian state actors (FSB-linked Static Tundra and Berserk Bear) exploiting poorly configured network edge devices to establish persistent access in critical infrastructure. The same techniques work on any misconfigured router, including those deployed in UK SMEs. Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details, recalling the MOVEit compromise of 2023. Finally, Stormshield documented a phishing campaign impersonating DocuSign to install legitimate Remote Monitoring and Management tools (specifically Atera) as attacker infrastructure. Across all three incidents, the entry point is not sophisticated exploitation but basic configuration oversights: unchanged default credentials, unpatched firmware, unverified document signing workflows. UK small businesses using managed service providers, file transfer systems, or document signing tools face immediate exposure if they have not recently audited which remote access tools are authorised, verified router configurations, or trained staff to validate DocuSign notifications through the portal rather than email links.

Chapters

  • Introduction Mauven introduces three apparently unrelated threats that share a single operating principle: attackers exploiting unlocked doors rather than breaking through reinforced ones.
  • Russian State Actors Targeting Network Edge Devices A nine-country joint advisory warns of FSB-linked actors exploiting misconfigured routers for persistent access. The technique works on any poorly configured device, not just critical infrastructure. UK SMEs must verify that default credentials are changed, remote management interfaces are disabled, and firmware is current.
  • Call to Action Listeners are encouraged to follow the show and share it with others who need threat intelligence.
  • Progress ShareFile Emergency Shutdown Progress Software ordered an emergency shutdown of ShareFile on-premises storage zone servers without disclosing technical details. Given Progress’s MOVEit breach history, UK SMEs using ShareFile must immediately verify whether they are affected and document what data transits through the platform.
  • DocuSign Impersonation and RMM Tool Abuse Stormshield documented a phishing campaign impersonating DocuSign to install legitimate RMM tools (Atera) as attacker infrastructure. Because the payload is legitimate software, endpoint detection often fails to flag it. UK SMEs must train staff to verify DocuSign notifications through the portal, maintain an authorised RMM tool list, and treat any DocuSign prompt requesting software installation as malicious.
  • Conclusion The three threats share a common vulnerability: organisations have not recently audited their own infrastructure. The action item for UK SMEs is to verify router configurations, file transfer system deployments, and authorised RMM tools this week, not next quarter.

Links

No transcript available for this episode.