logo

Amazon seizes domains used in rogue Remote Desktop campaign to steal data

ID: fa15b2c8-7bf3-59af-a9bf-94b248bb5156

STIX ID: report--fa15b2c8-7bf3-59af-a9bf-94b248bb5156

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-10-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Amazon and CERT-UA reported that Russian state-linked APT29 conducted a broad phishing campaign delivering malicious .rdp connection files (e.g., "Zero Trust Security Environment Compliance Check.rdp") that, when opened, redirected local disks, network shares, printers, clipboard and other resources to attacker-controlled RDP servers to steal Windows credentials and data; Amazon seized domains impersonating AWS to disrupt the operation and CERT‑UA issued IoC-based detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.