Security News > 2024 > December > Russian hackers use RDP proxies to steal data in MiTM attacks

2024-12-18 21:53
The Russian hacking group tracked as APT29 (aka "Midnight Blizzard") is using a network of 193 remote desktop protocol proxy servers to perform man-in-the-middle (MiTM) attacks to steal data and credentials and to install malicious payloads. [...]
News URL
Related news
- Russian hackers attack Western military mission using malicious drive (source)
- Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery (source)
- Chinese hackers target Russian govt with upgraded RAT malware (source)
- Hackers abuse Zoom remote control feature for crypto-theft attacks (source)
- Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp (source)
- DPRK Hackers Steal $137M from TRON Users in Single-Day Phishing Attack (source)
- Lazarus hackers breach six companies in watering hole attacks (source)
- Craft CMS RCE exploit chain used in zero-day attacks to steal data (source)
- France ties Russian APT28 hackers to 12 cyberattacks on French orgs (source)
- Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool (source)