Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Nation-State

Microsoft Warns of Russian Spear-Phishing Attacks Targeting Over 100 Organizations

Microsoft says a new spear-phishing campaign by Russia’s Midnight Blizzard uses RDP files, a new vector for this threat group.

Russia APT Secret Blizzard

Microsoft has issued a warning over a recent large-scale spear-phishing campaign that has been attributed to the notorious Russian state-sponsored threat actor tracked by the company as Midnight Blizzard.

According to the tech giant, the campaign has targeted thousands of users at more than 100 organizations in the government, defense, academia, NGO and other sectors, likely with the goal of collecting intelligence.  

Midnight Blizzard is also known as APT29, Cozy Bear, the Dukes, and Yttrium, and it has been known to target these types of organizations, mainly in the United States and Europe. 

The threat actor is also known for recent attacks targeting Microsoft systems, in which the hackers managed to steal source code and spy on executive emails

The latest campaign, which Microsoft has been tracking for the past week, targeted the United Kingdom and other European countries, as well as Australia and Japan. The attacks are ongoing and the company has shared indicators of compromise (IoCs) to help organizations detect potential attacks. 

One new and noteworthy aspect of the campaign is that the spear-phishing emails sent out by the hackers, which sometimes impersonate Microsoft employees, contain a signed RDP configuration file that connects to an attacker-controlled server. 

Advertisement. Scroll to continue reading.

The RDP configuration files contain automatic settings that cause features and resources of the local system to be extended to the attacker’s server, leading to the exposure of sensitive information. 

“Once the target system was compromised, it connected to the actor-controlled server and bidirectionally mapped the targeted user’s local device’s resources to the server,” Microsoft explained. “Resources sent to the server may include, but are not limited to, all logical hard disks, clipboard contents, printers, connected peripheral devices, audio, and authentication features and facilities of the Windows operating system, including smart cards.” 

“This access could enable the threat actor to install malware on the target’s local drive(s) and mapped network share(s), particularly in AutoStart folders, or install additional tools such as remote access trojans (RATs) to maintain access when the RDP session is closed,” the tech giant added.

AWS recently also published a blog post describing this campaign, after the cloud giant seized domains used by the threat actor to conduct attacks. Ukraine’s CERT-UA has also analyzed the campaign.  

Related: Google Catches Russian APT Reusing Exploits From Spyware Merchants NSO Group, Intellexa

Related: Russian Cyberspies Targeting Cloud Infrastructure via Dormant Accounts

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.