- Change default passwords, use strong, unique passwords, and enable multi-factor authentication (MFA) where available, choosing authentication apps or hardware tokens over SMS text-based codes.
- Ensure systems are patched and up to date, encrypt sensitive data, and use a virtual private network (VPN).
- Use a firewall, employ DDoS protection solutions, and closely monitor websites and services.
- Identify network edge devices and the organizational assets that should connect to them.
- Baseline normal connections, especially to VPNs or other similar services, and identify anomalous behavior.
- Leverage available dynamic threat feeds that include covert network infrastructure.
- Review the joint advisory for additional recommendations.
- Report malicious cyber activity to the NJCCIC and the FBI's IC3.
