Amazon and Microsoft disclosed a large spear-phishing campaign by APT29/Midnight Blizzard, the Russian state-linked espionage group tied to the SVR, that used signed malicious .rdp files to trick targets into launching outbound Remote Desktop connections to attacker-controlled servers. The operation, tracked by CERT-UA as UAC-0215, relied on emails sent from previously compromised legitimate accounts and lures themed around Amazon Web Services, Microsoft, and Zero Trust integration issues. Amazon said the attackers used lookalike AWS-related domains, which it moved to seize, but the campaign was aimed at stealing victims' Windows credentials and collecting data rather than compromising Amazon or AWS customer accounts directly.
Microsoft said the campaign targeted thousands of recipients across dozens of countries, including Ukraine, the UK, Europe, Australia, and Japan, with victims spanning government, academia, defense, and NGOs. CERT-UA warned that opening the rogue RDP attachments could expose local disks, network shares, printers, COM ports, audio devices, clipboard contents, and credentials to the attackers, while also enabling unauthorized program or script execution for follow-on activity. Defenders were urged to block .rdp files at email gateways, monitor and restrict outbound RDP connections from mstsc.exe, and apply the indicators and mitigations published by Microsoft and CERT-UA.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly reported the ongoing Midnight Blizzard spear-phishing campaign, describing the use of signed malicious RDP configuration files and assessing the activity as intended for intelligence collection. Microsoft also published indicators and defensive guidance, including blocking RDP files at email gateways and restricting outbound RDP connections via mstsc.exe.
Amazon said it seized domains impersonating AWS-related infrastructure that were used in the campaign's lures themed around Amazon, Microsoft, and Zero Trust Architecture. Amazon stated the attackers were not targeting Amazon or AWS customer credentials directly, but instead sought victims' Windows credentials through Microsoft Remote Desktop.
CERT-UA identified the activity as UAC-0215 and warned that opening the malicious RDP attachments could expose local disks, network shares, clipboard contents, printers, audio devices, COM ports, and Windows credentials to attacker-controlled servers. It also warned the files could enable unauthorized program or script execution and published indicators and mitigations.
APT29/Midnight Blizzard began an espionage-focused spear-phishing campaign using emails from previously compromised legitimate accounts to deliver signed malicious .rdp files. The operation targeted thousands of recipients across dozens of countries, with primary impact reported in Ukraine and additional targeting of government, academia, defense, and NGO personnel in Europe, the UK, Australia, Japan, and other countries viewed as adversaries of Russia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.