'Midnight Blizzard' Targets Networks With Signed RDP Files
ID: 1ff6593f-54c1-5a5f-a00c-0dca375916e3
STIX ID: report--1ff6593f-54c1-5a5f-a00c-0dca375916e3
Feed Name: Dark Reading
Midnight Blizzard (aka APT29) is running a large-scale spear-phishing campaign using digitally signed RDP configuration files to establish bidirectional connections that harvest user credentials, files, smart card data, web authentication credentials, and clipboard contents; the campaign has targeted governmental agencies, higher education, defense, and NGOs across dozens of countries and employs a signed RDP file to evade detection, with Microsoft publishing associated indicators of compromise and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
