Amazon seizes domains used in rogue Remote Desktop campaign to steal data
ID: fa15b2c8-7bf3-59af-a9bf-94b248bb5156
STIX ID: report--fa15b2c8-7bf3-59af-a9bf-94b248bb5156
Feed Name: Bleeping Computer
Amazon and CERT-UA reported that Russian state-linked APT29 conducted a broad phishing campaign delivering malicious .rdp connection files (e.g., "Zero Trust Security Environment Compliance Check.rdp") that, when opened, redirected local disks, network shares, printers, clipboard and other resources to attacker-controlled RDP servers to steal Windows credentials and data; Amazon seized domains impersonating AWS to disrupt the operation and CERT‑UA issued IoC-based detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
