logo

Russia's Midnight Blizzard Seeks to Snow French Diplomats

ID: 59a31dd1-cea6-5ee4-8d52-7e9725e63aff

STIX ID: report--59a31dd1-cea6-5ee4-8d52-7e9725e63aff

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-06-20

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

CERT-FR warns that Midnight Blizzard (Nobelium/APT29) has been actively targeting French diplomatic institutions since at least 2021 in a campaign dubbed "Diplomatic Orbiter," using compromised legitimate email accounts and forged lure documents to phish staff and deliver custom first-stage loaders that enable public offensive tools (Cobalt Strike, Brute Ratel) to establish persistence and exfiltrate strategic diplomatic data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.