Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - Russian Actor Midnight Blizzard Conducts Massive Spear-Phishing Campaign Using RDP Files
Phishing Attacks Latest News News & Analysis

Russian Actor Midnight Blizzard Conducts Massive Spear-Phishing Campaign Using RDP Files

Kirsten DoyleBy Kirsten DoyleOctober 31, 2024Updated:November 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Russian Actor Midnight Blizzard Conducts Massive Spear-Phishing Campaign Using RDP Files
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Microsoft Threat Intelligence has issued an alert following the detection of a sophisticated spear-phishing campaign orchestrated by the Russian threat actor known as Midnight Blizzard.

Active since 22 October this year, this operation has distributed spear-phishing emails aimed at government agencies, academia, defense organizations, NGOs, and other critical sectors worldwide.

“Based on our investigation of previous Midnight Blizzard spear-phishing campaigns, we assess that the goal of this operation is likely intelligence collection,” Microsoft said. It added that the blog it released aims to provide context on these external spear-phishing attempts, which are standard attack techniques and do not represent any new compromise of Microsoft.

This latest campaign by Midnight Blizzard features an innovative tactic: the use of signed Remote Desktop Protocol (RDP) configuration files to connect victims’ systems to an attacker-controlled server.

These malicious RDP files are embedded within emails crafted to appear credible by impersonating Microsoft employees and referencing reputable cloud providers. Once opened, the RDP files establish connections that allow attackers to gather sensitive information and potentially install malware on target devices.

According to Microsoft, Midnight Blizzard is consistent and persistent in its operational targeting, and its objectives seldom change. It uses a wide range of initial access methods, including spear phishing, stolen credentials, supply chain attacks, compromise of on-premises environments to move to the cloud laterally, and leveraging service providers’ trust chain to access downstream customers.

“Midnight Blizzard is known to use the Active Directory Federation Service (AD FS) malware known as FOGGYWEB and MAGICWEB. Midnight Blizzard is identified by peer security vendors as APT29, UNC2452, and Cozy Bear,” the company added.

Preventative Measures

Balazs Greksza, Threat Response Lead at Ontinue, commented on the threat’s distinctiveness, noting that:  “The thematic is about Security/Device/AWS/Zero Trust configurations, however, this may change relatively rapidly.” Greksza recommended blocking “.rdp” file extensions in email gateways and limiting the execution of such files to mitigate the risk of attack. He also advised that network firewalls should disable inbound and outbound RDP connections as a preventive measure.

The Midnight Blizzard campaign has primarily targeted organizations in the UK, Europe, Australia, and Japan, mirroring the group’s historical focus on diplomatic and governmental entities in these regions. Microsoft has directly notified affected users and supplied guidance on mitigating further exposure.

Exploiting Public Interest

According to Stephen Kowski, Field CTO at SlashNext, the timing of the attack, just ahead of primary elections, reveals its intent to exploit critical infrastructure vulnerabilities and public interest. “These attacks will likely intensify as we approach Election Day,” Kowski noted. He emphasized that entities need advanced phishing protection to detect and block these spear-phishing messages in real time, highlighting the importance of AI-driven detection to handle sophisticated email threats and prevent unauthorized access.

The Midnight Blizzard campaign’s innovative use of signed RDP files has raised the alarm due to the potential for compromised systems to map a range of local resources—such as files, network drives, and authentication features—to the attacker-controlled server. As Microsoft explains, such access would allow the actor to deploy malware across systems seamlessly, enabling persistent access.

Stringent Controls Needed

Field CTO at ColorTokens, Venky Raju, also pointed to the critical need for stringent controls over Microsoft’s RDP function and said that Microsoft’s advice on using the host firewall to restrict outbound RDP access is spot on and must be urgently heeded. Raju stressed that Group Policy Objects (GPO) policies or micro-segmentation could help limit RDP functionality to essential tasks.

“This attack once again highlights that phishing continues to be the most dangerous threat to your organization,” said Patrick Harr, CEO at SlashNext, reiterating the persistent risks phishing poses. Harr advocates for advanced AI protections and user training and advises organizations to employ “AI detection and phishing sandboxes for malicious links and files directly in their email, collaboration, and messaging apps.”

Microsoft’s recommendations for countering the Midnight Blizzard campaign include strengthening firewalls, using multifactor authentication (MFA), adopting phishing-resistant authentication methods, and ensuring robust email security configurations. By implementing these strategies, organizations can reduce their risk of compromise by Midnight Blizzard’s spear-phishing tactics.

Microsoft will provide updates to inform and assist affected sectors as the situation develops.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}