Earth Koshchei Hackers Using Red Team Tools To Attack RDP Servers
ID: 95f9895f-da12-5c6f-92ce-67dd9421c7ea
STIX ID: report--95f9895f-da12-5c6f-92ce-67dd9421c7ea
Feed Name: cybersecurityNews.com
Threat Score
**Earth Koshchei RDP Relay Espionage Campaign (Oct 2024)** The report describes a sophisticated APT29 (Earth Koshchei) campaign that used malicious RDP configuration files, an extensive RDP relay and rogue backend infrastructure (193 relay domains, 34 backend servers), and red-team tools like PyRDP to intercept redirected drives and exfiltrate data from government, military, and academic targets, with active operations observed between October 18–22, 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
