Back www.techtarget.com Microsoft Warns Of Midnight Blizzard Spear Phishing Campaign
Microsoft warned that a Russian nation-state threat actor known as Midnight Blizzard is conducting an ongoing spear-phishing campaign against a variety of targets including government agencies.
In a blog post published on Tuesday, Microsoft detailed a "large scale spear phishing campaign" it attributed to Midnight Blizzard, the same actor that breached the tech giant earlier this year and was responsible for the notorious supply chain attack against SolarWinds in 2020. Microsoft initially observed the ongoing spear phishing campaign beginning on Oct. 22 and assessed Midnight Blizzard's goal as intelligence gathering.
During the campaign, attackers used legitimate addresses to send emails containing a signed Remote Desktop Protocol (RDP) configuration file to gain initial access to the targets' devices. Microsoft said the campaign represents "a novel access vector" for Midnight Blizzard.
Microsoft warned that targets include government agencies, higher education and defense. While it has affected organizations in dozens of countries, Microsoft observed increased activity in the U.K., Europe, Australia and Japan.
"The spear-phishing emails in this campaign were sent to thousands of targets in over 100 organizations and contained a signed Remote Desktop Protocol (RDP) configuration file that connected to an actor-controlled server," Microsoft wrote in the blog post . "In some of the lures, the actor attempted to add credibility to their malicious messages by impersonating Microsoft employees. The threat actor also referenced other cloud providers in the phishing lures."
The social engineering lures were related to AWS and zero trust . Once opened, the malicious RDP files, which Microsoft said are signed with Let's Encrypt certificates, mapped the target device's resources to the attacker-controlled server.
After gaining initial access with the RDP configuration file, Midnight Blizzard actors could then install malware or additional tools such as remote access Trojans to maintain access when the RDP session expired. Midnight Blizzard also used the RDP connection to view files and directories as well as web authentication processes using Windows Hello, passkeys or security keys on targeted systems.
Microsoft said Amazon and the Government Computer Emergency Response Team of Ukraine also observed similar activity. CERT-UA published a separate advisory last week that said the campaign may have been ongoing since August.
To protect against the campaign, Microsoft recommended that organizations require MFA, leverage phishing resistant authentication methods such as FIDO tokens and bolster Microsoft Office 365 configuration.
"Robust user education can help mitigate the threat of social engineering and phishing emails. Companies should have a user education program that highlights how to identify and report suspicious emails," the blog post read.
Microsoft also said that its Defender Antivirus product "detects at least some of the malicious .RDP files as the following signature: Backdoor:Script/HustleCon.A."
It's unclear how many configuration files have been detected, and why others may have escaped detection. "As outlined in the Detections section of the blog, Microsoft products have both active blocking and alerts for this activity," a Microsoft spokesperson told TechTarget Editorial.
Arielle Waldman is a news writer for TechTarget Editorial covering enterprise security.
Dig Deeper on Threats, Cyberattacks & Vulnerabilities
Russia’s Star Blizzard pivots to WhatsApp in spear-phishing campaign By: Alex Scroxton
Microsoft SFI progress report elicits cautious optimism By: Alexander Culafi
Microsoft files lawsuit to seize domains used by Russian spooks By: Alex Scroxton
Microsoft to roll out mandatory MFA for Azure By: Arielle Waldman
Physical AI security threats and how to mitigate them Malicious prompt injections, sensor manipulation, hardware tampering and vulnerable software take on greater urgency when robotic...
Malicious prompt injections, sensor manipulation, hardware tampering and vulnerable software take on greater urgency when robotic...
While agents cause trouble, calls for AI regulation mount from Anthropic, lawmakers It seems nearly everyone is calling for regulation. Chief among them is Anthropic, whose AI agents are also key troublemakers.
It seems nearly everyone is calling for regulation. Chief among them is Anthropic, whose AI agents are also key troublemakers.
Physical AI in business gets smarter and more autonomous Leaping from the computer screen into dynamic real-world environments, physical AI and embodied robotics take on increasingly ...
Leaping from the computer screen into dynamic real-world environments, physical AI and embodied robotics take on increasingly ...
Evolving MongoDB targets managing agents, performance for AI A memory and governance layer and an updated database engine further the vendor's progress toward becoming a platform provider ...
A memory and governance layer and an updated database engine further the vendor's progress toward becoming a platform provider ...
Microsoft transforming Fabric into AI's foundational layer An integration between Fabric IQ and Copilot helps turn Fabric into a context layer for agents and demonstrates the ...
An integration between Fabric IQ and Copilot helps turn Fabric into a context layer for agents and demonstrates the ...
Databricks buys Row Zero to aid spreadsheet governance for users, AI The acquisition will enable users to run spreadsheets in the Databricks platform, giving data teams greater governance control ...
The acquisition will enable users to run spreadsheets in the Databricks platform, giving data teams greater governance control ...
What CFOs need to know AI agent governance in accounting Accounting AI agent governance begins with the compilation of a complete and accurate inventory of tools that are being used. ...
Accounting AI agent governance begins with the compilation of a complete and accurate inventory of tools that are being used. ...
ERP case study: How business-IT 'dynamic duo' sparked a transformation A midmarket manufacturer's CIO and VP explain how their unusually close working relationship models a culture of trust and ...
A midmarket manufacturer's CIO and VP explain how their unusually close working relationship models a culture of trust and ...
How to gather and evaluate customer sentiment Businesses can glean customer sentiment from sources like surveys, social media, cards, centers and word of mouth...
Businesses can glean customer sentiment from sources like surveys, social media, cards, centers and word of mouth...
Glasswing results put AI 'vulnpocalypse' to the test Noisy AI-generated vulnerability discovery data creates a bottleneck at human triage. A fix? More AI to help. The risk? An ...
Noisy AI-generated vulnerability discovery data creates a bottleneck at human triage. A fix? More AI to help. The risk? An ...
Report: Anthropic locks in $518B AI infrastructure commitments Reports of Anthropic's massive compute commitments give infrastructure providers demand visibility, but contracts alone cannot ...
Reports of Anthropic's massive compute commitments give infrastructure providers demand visibility, but contracts alone cannot ...
Cribl targets SIEM data costs with new Detect tool Cribl touts cost savings as its Detect tool joins a wave of SIEMs that split analytics from data repos, but will it be enough to ...
Cribl touts cost savings as its Detect tool joins a wave of SIEMs that split analytics from data repos, but will it be enough to ...
Oracle Fusion Claw the new grab for fully autonomous agentic AI in ERP Execution runtime software has governance and auditing features that address concerns agentic AI security risks, enabling ...
Execution runtime software has governance and auditing features that address concerns agentic AI security risks, enabling ...
meshIQ's AgentIQ puts AI agent runtime controls to the test Runtime controls can intervene before an AI agent takes action, but their effectiveness depends on where enforcement sits in the ...
Runtime controls can intervene before an AI agent takes action, but their effectiveness depends on where enforcement sits in the ...
Progress-Domo deal is the latest test of CIO software assumptions The Progress-Domo deal offers a fresh look at what happens when a software vendor changes hands, from pricing and product ...
The Progress-Domo deal offers a fresh look at what happens when a software vendor changes hands, from pricing and product ...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
