logo

Midnight Blizzard Taps Phishing Emails, Rogue RDP Nets

ID: 1d5834d6-5d67-56db-b121-59ef2280452e

STIX ID: report--1d5834d6-5d67-56db-b121-59ef2280452e

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-12-18

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Trend Micro reports that Russia-linked Midnight Blizzard (Earth Koshchei) ran a large-scale espionage campaign that used spear-phishing with malicious RDP configuration files and PyRDP-based RDP relays to redirect and control victim remote desktop sessions. The campaign deployed over 200 domains and dozens of rogue RDP backend servers, targeted government, military, and academic entities across multiple countries, and relied on living-off-the-land techniques to remain stealthy while enabling data theft and potential malware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.