Russia's APT29 Mimics AWS Domains to Steal Windows Credentials
ID: 02320dad-38cb-5f62-b23f-b0a1a7534184
STIX ID: report--02320dad-38cb-5f62-b23f-b0a1a7534184
Feed Name: Dark Reading
Threat Score
APT29 (aka Midnight Blizzard/Nobelium/Cozy Bear) ran a wide-reaching phishing campaign since August using malicious domains masquerading as AWS to deliver RDP configuration file attachments to government, military, and private-sector targets; those RDP files initiated outbound connections to attacker servers and granted broad remote access and script execution capabilities, enabling credential theft and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
