logo

Russia’s APT29 Launches Major Spear Phishing Campaign

ID: a748a769-350b-5c10-bd17-e6832bbd71e1

STIX ID: report--a748a769-350b-5c10-bd17-e6832bbd71e1

Feed Name: KnowBe4 Blog

Threat Score
90/100

Date Published: 2024-12-23

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Trend Micro reports that Earth Koshchei (APT29/Cozy Bear) conducted a large-scale spear-phishing campaign, sending emails that delivered rogue RDP configuration files which redirected victims to a network of 193 attacker-controlled RDP relays; the actor registered over 200 phishing domains and used compromised legitimate mail servers to target governments, military, think tanks, researchers, and Ukrainian targets, with the campaign peaking on October 22.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.