Midnight Blizzard hacking group hijacks RDP proxies to launch malware attacks
- Trend Micro spots sophisticated spear-phishing campaign targeting military and government targets
- It uses almost 200 RDP proxies to gain access to endpoints
- The total number of victims is in the hundreds
AN advanced persistent threat, known as Midnight Blizzard, HAS launched a large-scale spear phishing attack that targeted governments, military organizations, and academic researchers in the West.
The group exploited red team methodologies and anonymization tools, as it exfiltrated sensitive data from their target’s IT infrastructure, cybersecurity researchers from Trend Micro has revealed.
In a report, the researchers said the group utilized a rogue Remote Desktop Protocol (RDP) and a Python-based tool called PyRDP. The attack starts with a spear-phishing email carrying a malicious RDP configuration file. If the victim runs it, it connects to an attacker-controlled RDP server.
On Russia’s payroll
The campaign used 34 rogue RDP backend servers in combination with 193 proxy servers to redirect victim connections and mask the attackers’ activities.
Once the victim is connected, the crooks use PyRDP to intercept the connection, acting as a man-in-the-middle (MitM). Then, with access to target endpoints, the attackers could browse files, exfiltrate sensitive data, and more.
While the total number of victims across the entire campaign is unclear, Trend Micro says that approximately 200 high-profile victims were targeted in a single day, when the campaign was at its peak, in late October 2024.
The victims were government and military organizations, think tanks and academic researchers, entities related to the Ukrainian government, a cloud service provider, and entities associated with the Netherlands’ Ministry of Foreign Affairs.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Most of them are located in Europe, the United States, Japan, Ukraine, and Australia.
To put things into more context, it’s worth noting that Midnight Blizzard is also known as APT29, Earth Koschchei, or Cozy Bear. It’s a sophisticated advanced persistent threat group sponsored by the Russian government and under direct control of the Russian Foreign Intelligence Service (SVR). It is known for conducting cyber-espionage campaigns primarily in Western countries.
Via BleepingComputer
You might also like
Trend Micro spots sophisticated spear-phishing campaign targeting military and government targets It uses almost 200 RDP proxies to gain access to endpoints The total number of victims is in the hundreds AN advanced persistent threat, known as Midnight Blizzard, HAS launched a large-scale spear phishing attack that targeted governments, military…
Recent Posts
- How to watch the World Cup Final ‘66 In Colour for *FREE*
- ‘Elon Musk said he thinks humanoid robots will be in many homes in three years, and I agree with him.’ I sat down with Jake Dyson to hear his predictions for AI and robotics in your home — and why you shouldn’t throw out your stick vac just yet
- LaCie 8big Pro5 review: I tested LaCie’s huge 256TB DAS solution, and it’s ideal for 8K video editing but it comes with a price tag that’s just as big
- EA’s Star Wars Zero Company drops August 27
- Amazon Prime members can already get $135 in free perks ahead of Prime Day 2026 — here are 7 freebies to claim right now
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023