logo

Russian hackers use RDP proxies to steal data in MiTM attacks

ID: 816c9255-434e-5775-ba5f-3bcc66f0db20

STIX ID: report--816c9255-434e-5775-ba5f-3bcc66f0db20

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-12-18

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Trend Micro and other reports describe APT29 (aka Midnight Blizzard/Earth Koshchei) running a large-scale rogue RDP campaign that uses 193 proxy servers and the PyRDP man-in-the-middle tool to intercept RDP sessions, log plaintext credentials and NTLM hashes, steal clipboard and shared-drive data, exfiltrate files in the background, and run remote commands or payloads; targets include government, military, diplomatic, IT/cloud, telecom, and cybersecurity organizations across multiple countries, and the attackers obscure infrastructure using commercial VPNs, TOR exit nodes, and residential proxies while delivering access via phishing attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.