Starting October 22, 2024, the APT group Midnight Blizzard (APT29, UNC2452, Cozy Bear), attributed to Russia's Foreign Intelligence Service (SVR), launched a large-scale spear-phishing campaign using malicious RDP configuration files. Emails sent to thousands of users across more than 100 organizations impersonated Microsoft and Amazon Web Services employees with technical themes such as "Zero Trust Architecture" and "AWS IAM Quick Start." Opening the attachment triggered an outbound RDP connection to attacker-controlled servers, exposing local resources bidirectionally.
- The campaign began October 22, 2024, with infrastructure preparation dating back to August 2024, according to CERT-UA
- The .RDP files were signed with a Let's Encrypt certificate and configured full mapping of drives, printers, COM ports, audio, and clipboard to the attacker's server
- Amazon seized abused domains impersonating AWS, confirming the objective: theft of Windows credentials via Microsoft RDP
- Targeted sectors include government, academia, defense, NGOs, and IT in the UK, Europe, Australia, Japan, and Ukraine
How the "Reverse Trust" Engineering Works
The technique stands out for a dangerous inversion of the security paradigm. Let's Encrypt certificates and Zero Trust frameworks are recognized symbols of digital protection. Midnight Blizzard weaponized them: the certificate signed seemingly legitimate RDP files, while the phishing themes exploited administrators' familiarity with these concepts to lower their guard.
The critical technical element lies in the nature of the RDP protocol itself. Unlike macro-enabled Office attachments — now aggressively filtered by email gateways — .RDP files are textual configurations that Windows interprets natively. Opening them requires no exploit; it simply establishes a connection to a remote endpoint, with the decisive complication of "device and resource redirection."
According to CERT-UA and convergent technical reconstructions, the malicious configuration enabled access to local drives, network resources, printers, COM ports, audio devices, and clipboard. The mapping was bidirectional: the attacker could not only view the remote desktop but also directly access data present on the victim machine. Windows credentials — including smart cards, Windows Hello, and security keys — were exposed during the session.
The Timeline and the UAC-0215 Indicator
CERT-UA classified the activity with identifier UAC-0215 and documented a precise timeline. Infrastructure preparation dates back to at least August 2024, with domain and server registration and staging. On October 22, 2024, mass distribution began, detected in near real-time by Microsoft Threat Intelligence and the Ukrainian CERT.
The targeting geography reflects APT29's historical interests: United Kingdom, continental Europe, Australia, Japan, and Ukraine. The sectors — government, higher education, defense, non-governmental organizations, and technology — confirm an intelligence collection pattern rather than immediate monetization. No infrastructure overlaps with historical FOGGYWEB, MAGICWEB, or GraphicalProton campaigns emerge in this specific operation.
"APT29 sought its targets' Windows credentials through Microsoft Remote Desktop" — CJ Moses, CISO Amazon
Amazon's Response and Visibility Limits
On October 24, 2024, CJ Moses published Amazon's response on the official AWS Security blog: "we immediately initiated the process of seizing the domains APT29 was abusing which impersonated AWS in order to interrupt the operation." Amazon explicitly clarified that neither the company nor AWS customer credentials were the end target; the impersonation was instrumental to stealing Windows credentials through the Microsoft protocol.
The dossier does not specify the identity of the seized domains nor the exact number of victims with effectively compromised access. This limit is significant: domain seizure disrupts future operations on that infrastructure, but does not roll back already established sessions nor quantify historical exposure.
Immediate Actions
Primary sources converge on four priority actions:
Block .RDP files at email gateways. CISA explicitly recommends preventing the distribution of Remote Desktop attachments through mail gateway filters, treating them with the same severity reserved for executables.
Restrict outbound RDP connections. Organizations must limit outbound RDP sessions to unauthorized endpoints, with particular attention to configurations that enable redirection of local devices and resources.
Audit RDP connections from the past year. Infrastructure preparation from August 2024 and campaign launch in October mandate an extended lookback window, not limited to recent months.
Inspect RDP configurations received via email. Even seemingly innocuous files must be analyzed for hidden endpoints and active resource redirection flags.
Why This Changes the Defense Perimeter
The Midnight Blizzard campaign signals a relevant tactical shift. For years, defenses have focused on Office attachments, PDFs with JavaScript, and links to phishing pages. The choice of RDP files bypasses this specialization: it uses a protocol native to the operating system, with a chain of trust that starts from the Let's Encrypt certificate and ends in automatic execution by Windows.
The real insight for security teams is the gap between perception and control. Users see a valid certificate and a Zero Trust theme; systems see a legitimate connection. Neither detects the outbound direction toward an attacker server, nor the silent mapping of local resources. The technique does not innovate the protocol, but exposes its implicit assumptions: that whoever configures an RDP connection is part of the trust domain, and that the session direction — traditional inbound or insidious outbound — is irrelevant to risk assessment.
For enterprise organizations, the message is that the perimeter is no longer what filters inbound. It is what authorizes outbound, with which resources, toward whom.
Frequently Asked Questions
Why aren't RDP files blocked by standard antimalware filters?
.RDP files are textual configuration files, not executables: they contain no binary payload or macros, and can be invisible to traditional signatures. The threat resides in the remote endpoint they point to and the redirection options they activate.
Was the Let's Encrypt certificate revoked or compromised?
The dossier does not report compromise of the Let's Encrypt infrastructure. The certificate was issued regularly and served as a visual trust mechanism, not a cryptographic exploit.
Is the campaign still active?
Sources refer to October 2024 activity. Amazon's domain seizure disrupted that specific infrastructure, but the dossier does not document the current status of any parallel operations or reactivation on new endpoints.
Information has been verified against cited sources and updated at time of publication.
Sources
- https://www.picussecurity.com/resource/blog/understanding-and-mitigating-midnight-blizzards-rdp-based-spearphishing-campaign
- https://www.cisa.gov/news-events/alerts/2024/10/31/foreign-threat-actor-conducting-large-scale-spear-phishing-campaign-rdp-attachments
- https://cert.gov.ua/article/6281076
- https://aws.amazon.com/blogs/security/amazon-identified-internet-domains-abused-by-apt29/
- https://discover.picussecurity.com/start-your-free-trial
- https://cert.gov.ua/