Researchers detail a “nearest neighbor attack” by Russia's APT28, which remotely breached a target's Wi-Fi by hijacking a laptop in a building across the street
The “Nearest Neighbour attack” (very cool name, btw) involves connecting with nearby organizations and using their Wi-Fi networks to reach the main target organization. … @xpnsec.com : This hack is brilliant, APT28 hopping into a target environment over wifi by compromising neighbouring companies and finding a dual-homed host within range. — volexity.com/blog/2024/11... And yet... they got caught doing this! [image] Joseph Menn / @joemenn.bsky.social : This is wild. Time to mandate 2fa for WiFi. www.volexity.com/blog/2024/11... Joshua Wright / @joswr1ght.bsky.social : This Wired article on Russian threat actors exploiting WiFi to gain access to a nearby target is 🧑🍳🤌 💋. www.wired.com/story/russia... Years ago I visited the NSA Cryptological Museum, and the docent told me about an old motel across the street from the base, owned by Russian expats. … @da667cant.hax.lol : Have you ever dual homed, or bridged between a physical network and wi-fi network? guess what? You're an APT now. — www.volexity.com/blog/2024/11... I read it, but I couldn't find actionable network IOCs, but there are some filenames in there for artifacts the bad guy was using at some point. Alena Popova / @alenapopova.bsky.social : Russia's state-sponsored APT28 group compromised an organization in Washington, DC, by breaching its Wi-Fi network through a laptop hijacked from a building across the street. The group appeared to be seeking intelligence on Ukraine. — www.wired.com/story/russia... Ciaran Martin / @ciaranm.bsky.social : Interesting one (as always) from @agreenberg.bsky.social — www.wired.com/story/russia... X: Alena Popova / @alenapopova : Russia's state-sponsored APT28 group compromised an organization in Washington, DC, by breaching its Wi-Fi network through a laptop hijacked from a building across the street. The group appeared to be seeking intelligence on Ukraine. https://www.wired.com/... Frank Groenewegen / @frankgr : Russian hackers' new trick: playing leapfrog with Wi-Fi networks to breach targets across the street — without leaving home. Fancy Bear? More like Fancy Neighbor! Time to lock down and monitor that guest Wi-Fi folks. https://www.wired.com/... Andy Greenberg / @a_greenberg : Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network in a building across the street, hijacked a laptop there, then breached the target organization via its Wifi. https://www.wired.com/... LinkedIn: Augusto Barros : Amazing write-up about a bold attack detected and investigated by Volexity. The “nearest neighbor” threat may not be relevant for organizations … Andy Greenberg : Russian spies—likely Russia's GRU intelligence agency—used a new trick to hack a victim in Washington, DC: They remotely infected another network … Brian Krebs : Your network perimeter probably just got a bit wider. — “The month-and-a-half long investigation revealed that GruesomeLarch was able … Forums: Hacker News : Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack r/cybersecurity : Russian Spies Jumped from One Network to Another via WiFi in an Unprecedented Hack r/technews : Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack BeauHD / Slashdot : Russian Spies Jumped From One Network To Another Via Wi-Fi Ars OpenForum : Spies hack Wi-Fi networks in far-off land to launch attack on target next door
Context & Ripple Effects
This incident extends a documented pattern of Russian GRU-linked operations using wireless access as an entry path: a 2018 account described GRU officers infiltrating Wi-Fi networks at hotels and offices.
The attribution also sits within broader public scrutiny of Russian military intelligence groups, including the identification of Cadet Blizzard as a GRU Unit 29155 operation. Here, Volexity’s investigation ties APT28’s access to a compromised neighboring laptop and a Wi-Fi connection within range of the target.
First-order effects
- The Washington, D.C., target’s network was exposed through a wireless path originating outside its own premises, enabling intelligence collection related to Ukraine.
- The neighboring organization whose laptop was compromised becomes part of the incident’s immediate blast radius, despite not being the apparent intelligence target.
Second-order effects
- Organizations in dense shared-office environments will need to assess whether nearby Wi-Fi networks and dual-homed devices create practical paths around their perimeter controls.
- Incident-response teams may need to extend scoping beyond the victim’s network to adjacent tenants and wireless infrastructure, increasing the coordination burden of a breach.
Third-order effects
- If this technique recurs, network boundaries will be defined less by an organization’s office footprint and more by the radio and device relationships around it.
- The case reinforces a shift in state-backed intrusion tradecraft toward chaining ordinary local access weaknesses rather than relying on a single direct entry point.
The trend: State-linked operators are increasingly treating neighboring organizations and shared connectivity as viable stepping stones into higher-value targets.