back to article Russian spies use remote desktop protocol files in unusual mass phishing drive

Microsoft says a mass phishing campaign by Russia's foreign intelligence services (SVR) is now in its second week, and the spies are using a novel info-gathering technique. First spotted on October 22, Microsoft said in a report published Tuesday that the spearphishing attempts are "ongoing" and targeting governments, NGOs, …

  1. heyrick Silver badge
    Happy

    Let's see, one dollar per byte phished, doubling every kilobyte, before long it'll be the Kremlin owing America obscene amounts of money that don't exist.

  2. x-f

    Midnight Blizzard? Salt Typhoon? Pfft!

    Stop giving those hacker teams glorious names.

    Call them what they are – Cryptic Crapheads, Mystic Morons, Sick Bear.

    1. JWLong Silver badge

      Re: Midnight Blizzard? Salt Typhoon? Pfft!

      I just call them "Shit Heads".

  3. Anonymous Coward
    Anonymous Coward

    I used RDP to get round my late employer's security restrictions in just this way. Their drives mounted on my system, my usb sticks mounted on theirs. Almost too easy.

    1. Hubert Cumberdale Silver badge

      I used to use a reverse SSH tunnel for all that gubbins. It bypassed every restriction they had.

      1. Anonymous Coward
        Anonymous Coward

        That was just one of my countermeasures. Universities exist in a state of constant war between the academics and the IT departments, which we academics always win because (a) we're smarter than they are because (b) the university doesn't pay support staff well enough to get the smart ones.

  4. GoneFission
    Facepalm

    Are we here in 2024 really just letting employees RDP to random-ass addresses on the internet, and without controlling session settings via GPO for anything? Alrighty then

    1. Phones Sheridan

      Would be interested to know how to control the sessions settings of the RDP client. All the settings I've looked at so far have been to restrict access to servers under my control, not access to 3rd party servers.

      The only thing I can think of would be to deny users access to mstsc.exe for members of an AD group.

      User Configuration\Administrative Templates\System

      "dont run specified Windows applications" = enabled

      and add: mstsc.exe

      But that wouldn't stop them running a web based client etc. Port blocking can be trivial to work around if you change the server from 3389 to 443 for example.

    2. Roland6 Silver badge

      Not just random-ass addresses but addresses in Russia etc. that should have been firewall blocked years back.

      But then we are talking about business rather than consumers and ISPs…

  5. PBuon

    Got to love RDP. I still have clients who’s IT teams ignore calls to block it to all inbound traffic (unless going via a VPN or tunnel).

  6. Grunchy Silver badge

    They shut down the Calgary Library

    Well, dunno if “they” did, but some Shit Head did.

    It was a ransomware attack, evidently, which is interesting because it implies that the library had some stockpile of useful information (beyond the books themselves). The S.H. Gang may have been after passwords, or who knows. The library says they never got it.

    What peeves me is they interrupted access to the shared “N.Y. Times” pass, which affects my ability to participate in the Wordle!

    There Are Real World Consequences !!1!1 gosh dang it!

    (Oh well I think I preferred the sudoku puzzles anyway, which are unrestricted.)

  7. X5-332960073452
    WTF?

    M$ Idiots

    Wonder if this has anything to do with Microsoft recently installing the Remote Desktop Connection software on all Win 10 and 11 versions, including Home, without notification, authorisation, etc.

    1. Anonymous Coward
      Anonymous Coward

      Re: M$ Idiots

      Do you think MSTSC being part of windows is a bad thing?

      1. druck Silver badge

        Re: M$ Idiots

        Say after me "increased attack surface".

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like