logo

'Midnight Blizzard' Targets Networks With Signed RDP Files

ID: 1ff6593f-54c1-5a5f-a00c-0dca375916e3

STIX ID: report--1ff6593f-54c1-5a5f-a00c-0dca375916e3

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-10-30

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Midnight Blizzard (aka APT29) is running a large-scale spear-phishing campaign using digitally signed RDP configuration files to establish bidirectional connections that harvest user credentials, files, smart card data, web authentication credentials, and clipboard contents; the campaign has targeted governmental agencies, higher education, defense, and NGOs across dozens of countries and employs a signed RDP file to evade detection, with Microsoft publishing associated indicators of compromise and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.