Microsoft has warned of an ongoing theft information campaign by Russian hackers Midnight Blizzard (also known as APT29, CozyBear), in which phishing emails are being sent to thousands of targets .

Over 100 organizations related to government, academia, defense, non-governmental organizations (NGOs), and other sectors have already been affected by this information theft campaign.
See also: Transak: Announced that it suffered a phishing attack
The phishing emails themselves impersonate Microsoft employees and other cloud and contain a signed RDP configuration file, which connects to an attacker's server.
“Resources sent to the server may include (but are not limited to) all logical hard disks, clipboard contents, printers, attached peripherals, audio, authentication capabilities , and Windows operating system installations, including smart cards. This access could allow the threat actor to install malware on the target’s local drives and mapped network share(s), particularly AutoStart. Additionally, the attacker may install additional tools such as remote access trojans (RATs) to maintain access,” the company said of the Midnight Blizzard attacks.
See also: Ukraine warns of massive phishing campaign
By establishing an RDP connection to the attackers' server, victims may also expose their own credentials, according to Microsoft.
The company said the targets of the information theft campaign are located in dozens of countries, with those in the UK, Europe, Australia and Japan particularly at risk.
See also: Gophish framework used in phishing attacks

Phishing protection
- User education is crucial. Users need to be informed about phishing techniques and how to recognize suspicious messages or links .
- Use phishing detection technologies. There are tools and services that can detect and block phishing attacks before they reach the end user.
- Implement multi-factor authentication policies. This can include using one-time passwords, SMS , or using authentication apps.
- Keep software and systems up to date. Software updates often include security that can protect against phishing attacks.
- Regularly check your logs and security reports to detect potential phishing attacks. Prevention is important, but knowing how and when a user was attacked can help prevent future attacks.
Source: www.infosecurity-magazine.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
