Microsoft detects large-scale phishing attack from Russian hackers Midnight Blizzard

 • 15604 переглядiв

Midnight Blizzard, a hacker group linked to Russian intelligence, has launched a massive phishing campaign. The attacks target government and defense structures in more than 100 organizations using RDP files.

Since October 22, representatives of Microsoft have recorded an increase in the distribution of phishing emails from government and defense agencies, as well as scientific and non-governmental organizations by the Midnight Blizzard hacker group, which is associated with Russia. This was reported by UNN with reference to the blog of the Microsoft Threat Intelligence team .

“Based on our investigation of previous Midnight Blizzard phishing campaigns, we estimate that the purpose of this operation is likely to be to gather intelligence,” the blog post says.

According to Microsoft, the emails were sent to thousands of recipients in more than 100 organizations. In some cases, the attackers impersonated Microsoft employees and referred to other cloud service providers.

While this campaign targets many of Midnight Blizzard's usual targets, the use of a signed RDP configuration file to gain access to target devices represents a new access vector for this agent. The coincidence of activity was also reported by the Ukrainian government's Computer Emergency Response Team (CERT-UA) under the designation UAC-0215, as well as by Amazon.

Midnight Blizzard is a threat source from Russia that the US and UK governments have linked to and the Russian Federation's foreign intelligence service, or SVR. It is known that Midnight Blizzard (NOBELIUM) primarily targets governments, diplomatic missions, NGOs, and IT service providers in the United States and Europe. 

Recall 

On October 25 , the State Service for Special Communications reported that the CERT-UA team had detected a new large-scale cyberattack aimed at local governments in Ukraine. 

Popular
Resident Evil Requiem game sets historic sales record for the series

 • 7576 переглядiв

IMF concerned about Ukraine's financing due to parliamentary delays

 • 14714 переглядiв

Trump asked China to postpone summit with Xi due to war with Iran

 • 11593 переглядiв

Teenagers sue Musk's company over pornographic images created by Grok

 • 14413 переглядiв

Ukrzaliznytsia changes routes and cancels a number of suburban trains

 • 18761 переглядiв

News by theme
Microsoft detects large-scale phishing attack from Russian hackers Midnight Blizzard

 • 15604 переглядiв

South Korea may send a group to Ukraine to monitor DPRK troops

 • 18768 переглядiв

Canada accuses Indian minister of collecting intelligence on Canadian citizens

 • 15403 переглядiв

Second victim of missile attack on Kryvyi Rih: 55-year-old man dies in hospital

 • 16698 переглядiв

A furry cat was rescued from an apartment that burned down after a drone attack in Kyiv

 • 23885 переглядiв

Reddit shares soar 25% as it turns its first profit

 • 16470 переглядiв

175 battles at the front: where the occupiers attacked the most

 • 16406 переглядiв

Currency exchange rate as of October 30: hryvnia depreciates

 • 14988 переглядiв

Third strike in a week: dozens killed in Gaza after Israeli attack

 • 14946 переглядiв