Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks


Red teaming provides essential tools and testing methodologies for organizations to strengthen their security defenses. Cybercriminals and advanced persistent threat (APT) actors pay close attention to new methods and tools red teams develop, and they may repurpose them with a malicious intent.

In October 2024, an APT group that Trend Micro tracks as Earth Koshchei (also known as APT29 and Midnight Blizzard), likely used a rogue remote desktop protocol (RDP) attack methodology against numerous targets. This methodology was described earlier in 2022 by Black Hills Information Security in detail. The attack technique is called “rogue RDP”, which involves an RDP relay, a rogue RDP server, and a malicious RDP configuration file. A victim of this technique would give partial control of their machine to the attacker, potentially leading to data leakage and malware installation.

Read more…
Source: Trend Micro


Sign up for our Newsletter


Related:

  • Ransomware hackers dump 1.4 million stolen records from German government

    September 7, 2026

    A cybercriminal group known as Rhysida allegedly broke into the network of Berlin’s state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web. According to multiple sources, the group first claimed responsibility for the attack on an ...

  • LG TV flaws could let attackers listen in, even in standby mode

    September 7, 2026

    Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears ...

  • US military disabled ad tracking on troops’ devices following reports of targeted attacks

    September 4, 2026

    The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, ...

  • Angry Birds: Toy Ghouls’ new toys

    September 4, 2026

    Kaspersky continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In ...

  • Free streaming boxes may be routing criminal traffic through your home

    September 4, 2026

    “Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. An earlier report identified CyberFlix ...

  • Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

    September 3, 2026

    We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. Read more… Source:  Palo Alto Unit 42 Sign up for the Cyber Security Review Newsletter The latest cyber security news and insights delivered ...