Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files
· Published 30/10/2024 22:04 · Modified 30/10/2024 23:08
Essential information
- Published
- 30/10/2024 22:04
- Modified
- 30/10/2024 23:08
- Tags
- 2024-10-30 apt29 backdoor campaign cozy bear hustlecon midnight blizzard phishing rdp remote desktop russia unc2452
- Related entities
- 200 observables, 1 intrusion sets (apt), 5 techniques (mitre), 1 malware
Description
On October 22, 2024, Microsoft identified a spear-phishing campaign in which Midnight Blizzard sent phishing emails to thousands of users in over 100 organizations. The emails were highly targeted, using social engineering lures relating to Microsoft, Amazon Web Services (AWS), and the concept of Zero Trust. The emails contained a Remote Desktop Protocol (RDP) configuration file signed with a LetsEncrypt certificate. RDP configuration (.RDP) files summarize automatic settings and resource mappings that are established when a successful connection to an RDP server occurs.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (200)
us-west-2.ua-sec.cloudus-west-2.ua-energy.cloudus-west-2.gov-ua.cloudus-west-2-aws.ua-energy.cloudus-west-2-aws.s3-ua.cloudus-west-2-aws.mfa-gov.cloudus-west-1.ukrtelecom.cloudus-west-1.ua-gov.cloudus-west-1.ua-energy.cloudus-west-1.aws-ukraine.cloudus-west-1-aws.gov-ua.cloudus-west-1-amazon.ua-sec.cloudus-west-1-amazon.ua-mil.cloudus-west-1-amazon.ua-energy.cloudus-east-console.ua-energy.cloudus-east-2.ukrainesec.cloudus-east-console.aws-ukraine.cloudus-east-2.ua-sec.cloudus-east-2.gov-ua.cloudus-east-2.aws-ukraine.cloudus-east-2-aws.ukrtelecom.cloudus-east-2-aws.ua-gov.cloudus-east-2-aws.gov-ua.cloudus-east-1-aws.ua-sec.cloudus-east-1-aws.ua-gov.cloudus-east-1-aws.mfa-gov.cloudus-east-1-aws.s3-ua.cloudeu-west-3.ukrainesec.cloudeu-west-3.ukrtelecom.cloudeu-west-3.s3-ua.cloudeu-west-3.s3-be.cloudeu-west-3.mzv-sk.cloudeu-west-3.presidencia-pt.cloudeu-west-3.msz-pl.cloudeu-west-3.mindef-nl.cloudeu-west-3.minbuza.cloudeu-west-3.mil-pl.cloudeu-west-3.mil-be.cloudeu-west-3.aws-ukraine.cloudeu-west-3.amazonsolutions.cloudeu-west-3-aws.ua-mil.cloudeu-west-3-aws.s3-ua.cloudeu-west-3-aws.s3-be.cloudeu-west-3-aws.regeringskansliet-se.cloudeu-west-3-aws.quirinale.cloudeu-west-3-aws.mzv-sk.cloudeu-west-3-aws.msz-pl.cloudeu-west-3-aws.mindef-nl.cloudeu-west-3-aws.minbuza.cloudeu-west-3-aws.mil-pt.cloudeu-west-3-aws.mil-pl.cloudeu-west-3-aws.mil-be.cloudeu-west-3-aws.gov-trust.cloudeu-west-3-aws.gov-sk.cloudeu-west-3-aws.gov-pl.cloudeu-west-3-aws.difesa-it.cloudeu-west-3-aws.dep-no.cloudeu-west-2-aws.ua-sec.cloudeu-west-3-aws.aws-ukraine.cloudeu-west-2-aws.s3-ua.cloudeu-west-2-aws.s3-nato.cloudeu-west-2-aws.s3-esa.cloudeu-west-2-aws.s3-de.cloudeu-west-2-aws.s3-be.cloudeu-west-2-aws.quirinale.cloudeu-west-2-aws.mzv-sk.cloudeu-west-2-aws.mindef-nl.cloudeu-west-2-aws.msz-pl.cloudeu-west-2-aws.minbuza.cloudeu-west-2-aws.mil-be.cloudeu-west-2-aws.mil-pl.cloudeu-west-2-aws.gv-at.cloudeu-west-2-aws.gov-sk.cloudeu-west-2-aws.gov-pl.cloudeu-west-2-aws.difesa-it.cloudeu-west-2-aws.dep-no.cloudeu-west-2-aws.amazonsolutions.cloudeu-west-1.ukrtelecom.cloudeu-west-1.s3-ua.cloudeu-west-1.ua-gov.cloudeu-west-1.s3-esa.cloudeu-west-1.s3-de.cloudeu-west-1.mzv-sk.cloudeu-west-1.regeringskansliet-se.cloudeu-west-1.msz-pl.cloudeu-west-1.minbuza.cloudeu-west-1.mil-pl.cloudeu-west-1.gov-sk.cloudeu-west-1.mil-be.cloudeu-west-1.difesa-it.cloudeu-west-1.aws-ukraine.cloudeu-west-1-aws.ukrainesec.cloudeu-west-1-aws.ua-sec.cloudeu-west-1-aws.s3-nato.cloudeu-west-1-aws.s3-esa.cloudeu-west-1-aws.s3-de.cloudeu-west-1-aws.s3-be.cloudeu-west-1-aws.quirinale.cloudeu-west-1-aws.mil-pl.cloudeu-west-1-aws.minbuza.cloudeu-west-1-aws.mil-be.cloudeu-west-1-aws.gov-ua.cloudeu-west-1-aws.gov-trust.cloudeu-west-1-aws.gov-sk.cloudeu-west-1-aws.gov-pl.cloudeu-west-1-aws.aws-ukraine.cloudeu-west-1-aws.dep-no.cloudeu-west-1-aws.amazonsolutions.cloudeu-southeast-1-aws.ukrainesec.cloudeu-southeast-1-aws.ua-energy.cloudeu-southeast-1-aws.s3-ua.cloudeu-southeast-1-aws.s3-esa.cloudeu-southeast-1-aws.s3-de.cloudeu-southeast-1-aws.s3-be.cloudeu-southeast-1-aws.quirinale.cloudeu-southeast-1-aws.mzv-sk.cloudeu-southeast-1-aws.mzv-cz.cloudeu-southeast-1-aws.msz-pl.cloudeu-southeast-1-aws.mindef-nl.cloudeu-southeast-1-aws.mil-be.cloudeu-southeast-1-aws.mil-pl.cloudeu-southeast-1-aws.gov-trust.cloudeu-southeast-1-aws.gov-sk.cloudeu-southeast-1-aws.difesa-it.cloudeu-southeast-1-aws.amazonsolutions.cloudeu-southeast-1-aws.dep-no.cloudeu-southeast-1-aws.aws-ukraine.cloudeu-south-2.ukrainesec.cloudeu-south-2.ua-sec.cloudeu-south-2.s3-nato.cloudeu-south-2.s3-de.cloudeu-south-2.s3-esa.cloudeu-south-2.s3-be.cloudeu-south-2.mindef-nl.cloudeu-south-2.mil-be.cloudeu-south-2.mil-pl.cloudeu-south-2.gov-pl.cloudeu-south-2.gov-sk.cloudeu-south-2.dep-no.cloudeu-south-2-aws.s3-ua.cloudeu-south-2-aws.ua-gov.cloudeu-south-2-aws.s3-nato.cloudeu-south-2-aws.s3-esa.cloudeu-south-2-aws.s3-de.cloudeu-south-2-aws.s3-be.cloudeu-south-2-aws.quirinale.cloudeu-south-2-aws.regeringskansliet-se.cloudeu-south-2-aws.ncfta.cloudeu-south-2-aws.mzv-sk.cloudeu-south-2-aws.msz-pl.cloudeu-south-2-aws.minbuza.cloudeu-south-2-aws.mil-be.cloudeu-south-2-aws.mil-pt.cloudeu-south-2-aws.mil-pl.cloudeu-south-2-aws.gov-sk.cloudeu-south-2-aws.mfa-gov.cloudeu-south-2-aws.gov-pl.cloudeu-south-2-aws.dep-no.cloudeu-south-2-aws.amazonsolutions.cloudeu-south-1-aws.ua-gov.cloudeu-south-1-aws.s3-de.cloudeu-south-1-aws.s3-be.cloudeu-south-1-aws.quirinale.cloudeu-south-1-aws.mzv-sk.cloudeu-south-1-aws.minbuza.cloudeu-south-1-aws.mil-be.cloudeu-south-1-aws.mfa-gov.cloudeu-south-1-aws.gov-trust.cloudeu-south-1-aws.gov-pl.cloudeu-south-1-aws.difesa-it.cloudeu-south-1-aws.dep-no.cloudeu-south-1-aws.admin-ch.cloudeu-north-1.s3-ua.cloudeu-north-1.s3-de.cloudeu-north-1.s3-be.cloudeu-north-1.regeringskansliet-se.cloudeu-north-1.ncfta.cloudeu-north-1.mil-pl.cloudeu-north-1.mzv-sk.cloudeu-north-1.mil-be.cloudeu-north-1.gv-at.cloudeu-north-1.gov-ua.cloudeu-north-1.gov-trust.cloudeu-north-1.difesa-it.cloudeu-north-1-aws.ua-gov.cloudeu-north-1-aws.ua-energy.cloudeu-north-1-aws.s3-de.cloudeu-north-1-aws.s3-be.cloudeu-north-1-aws.regeringskansliet-se.cloudeu-north-1-aws.quirinale.cloudeu-north-1-aws.presidencia-pt.cloudeu-north-1-aws.minbuza.cloudeu-north-1-aws.ncfta.cloudeu-north-1-aws.mil-pl.cloudeu-north-1-aws.mil-be.cloudeu-north-1-aws.gov-sk.cloudeu-north-1-aws.gov-pl.cloudeu-north-1-aws.dep-no.cloudeu-north-1-aws.difesa-it.cloudeu-east-1-aws.ukrtelecom.cloud
Intrusion sets (APT) (1)
-
Published 30/10/2024 22:04 · Modified 30/10/2024 22:04
Techniques (MITRE) (5)
Malware (1)
-
FamilyPublished 30/10/2024 22:04 · Modified 30/10/2024 22:04