Midnight Blizzard Taps Phishing Emails, Rogue RDP Nets
ID: 1d5834d6-5d67-56db-b121-59ef2280452e
STIX ID: report--1d5834d6-5d67-56db-b121-59ef2280452e
Feed Name: Dark Reading
Trend Micro reports that Russia-linked Midnight Blizzard (Earth Koshchei) ran a large-scale espionage campaign that used spear-phishing with malicious RDP configuration files and PyRDP-based RDP relays to redirect and control victim remote desktop sessions. The campaign deployed over 200 domains and dozens of rogue RDP backend servers, targeted government, military, and academic entities across multiple countries, and relied on living-off-the-land techniques to remain stealthy while enabling data theft and potential malware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
