Russian cyber-espionage group APT28, also known as Fancy Bear, breached an American company's network using a 'Nearest Neighbor Attack' by exploiting nearby Wi-Fi networks.
The attack targeted a US organization engaged in Ukrainian-related projects, indicating Russia's interest in the firm.
APT28 used password-spraying to gain credentials for the victim's enterprise Wi-Fi network and then turned to a nearby organization to gain entry.
In addition to exploiting a bridge device and using native Windows tools, the attackers also utilized a zero-day vulnerability in the Windows Print Spooler service to escalate privileges.