Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0215

Also known as: APT29, CozyBear, the SVR, Point of Sale, POS

Description

UAC-0215 is a sophisticated adversary believed to be state‑backed with primary motivation of intelligence gathering. Over the past year, it has deployed widespread spearphishing emails that impersonate Microsoft staff and embed signed .rdp configuration files. These fake RDP files trick recipients into connecting to attacker‑controlled servers via Remote Desktop, granting attackers a foothold without needing elevated privileges or exploiting client vulnerabilities. After initial compromise, UAC-0215 escalates its privileges through various methods, including abusing User Account Control (UAC) bypasses and process injection. It also deploys remote access trojans such as FOGGYWEB, MAGICWEB, and several RAT families to establish persistence, map local device resources, and exfiltrate data. The adversary routinely expands reach by pivoting into cloud accounts via compromised on‑premises credentials, exploiting Active Directory Federation Services (AD FS) for lateral movement. The group’s toolset is diverse: it uses open source utilities like Mimikatz for credential dumping and commercial malware such as Avaddon and RoKRAT for additional RDP access. It also employs obfuscation, scheduled tasks, and boot‑autostart mechanisms to maintain control across disparate environments. UAC-0215’s operations indicate integration with a broader supply‑chain attack framework; the mention of Sunburst suggests possible coordination or shared infrastructure with other APT29 campaigns. The attacker remains active across multiple regions, targeting both Eastern European and global entities.

Goals & Targeting

Targeted Sectors

Government
Defense
Non profit
Manufacturing
Healthcare
Education

Targeted Countries / Regions

UA
GB
KR
JP
US
RU
CN
IN
VN
RO
KP
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 14 hours ago

Executive Summary

UAC-0215, also known as APT29 or Midnight Blizzard, has conducted a large‑scale spearphishing campaign using signed Remote Desktop Protocol (RDP) files to gain illicit access to government, defense, and commercial organizations worldwide. The group leverages user credentials obtained via legitimate RDP sessions to move laterally into corporate networks and cloud environments for espionage objectives.

Goals & Targeting

The primary goal of UAC-0215 is espionage of sensitive governmental, defense‑related, and industrial information. By compromising high‑value accounts through spearphishing and legitimate RDP sessions, it seeks to harvest strategic data, infiltrate cloud infrastructures, and maintain long‑term undetected presence within targeted organizations.

Enhanced Description

Key Capabilities

  • Spearphishing via email attachments
  • Use of signed RDP configuration files as a novel initial access vector
  • Impersonation of Microsoft employees in phishing messages
  • Reference to cloud providers within lures
  • Compromise of valid accounts and authentication mechanisms
  • Lateral movement from on‑premises environments into cloud deployments
  • Deployment of Active Directory Federation Service (AD FS) malware FOGGYWEB and MAGICWEB
  • Bidirectional mapping of local device resources including hard disks, clipboard, printers, peripherals, audio, and authentication data
  • Installation of malware via AutoStart folders or boot‑autostart mechanisms
  • Use of remote access trojans to establish persistence and maintain control
  • Privilege escalation through UAC bypasses and process injection
  • Credential dumping with tools like Mimikatz
  • Obfuscated delivery and payloads
  • Scheduled job creation for persistence

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Acquisition
Discovery
Lateral Movement
Collection

ATT&CK Techniques

T0030
T1071
T1123
T1548.002
T1547
T1059
T1555
T1005
T1566
T1105
T1559
T1036
T1106
T1027
T1120
T1082
T1033
T1529
T1204
T1102
T1055
T1057
T1534
T1218

Software / Tooling

FOGGYWEB
MAGICWEB
Mimikatz
Avaddon
RoKRAT
Ghost RAT
GIFTEDCROOK stealer
Dogcall
Karae
NavRAT
BLUELIGHT
CALENDAR
Matrix
Spear‑phishing utilities
Sunburst
Winnti
Cobalt Strike
PittyTiger
Explorer
Rogue
Rootkit
Microsoft Defender XDR

Campaigns & Victims

UAC-0215 employed a high‑volume campaign against more than 100 organizations, primarily in Ukraine but also across the UK, South Korea, Japan, the US, Russia, China, India, Vietnam, Romania, North Korea, and Australia. The operational tempo was rapid—thousands of spearphishing emails were sent within weeks—indicating a prepared and well‑resourced threat actor. Victim profiles included government agencies, defense contractors, non‑profit organizations, manufacturing firms, healthcare providers, and educational institutions. Notable operations involved the deployment of signed RDP files to bypass standard authentication controls, followed by lateral movement into cloud accounts via compromised on‑premises credentials. The tactics suggest an emphasis on stealth, persistence, and collection of strategic data over destructive sabotage.

IOC Patterns

  • domain
  • file
  • ip-v4

Recommended Actions

  • Block RDP configuration files (.rdp) at mail gateways and enforce attachment whitelisting.
  • Restrict outbound RDP connections from internal networks; limit to designated servers only.
  • Implement MFA for all Remote Desktop access, particularly for privileged accounts.
  • Monitor authentication logs for anomalous RDP logins originating from unapproved IPs or unusual patterns.
  • Maintain strict least‑privilege principles in AD FS and revoke unused credentials promptly.
  • Deploy Endpoint Detection and Response (EDR) solutions that detect malware such as FOGGYWEB, MAGICWEB, and RAT installations.
  • Disable auto‑run and AutoStart folders on endpoint operating systems where possible.
  • Regularly patch Windows update-related vulnerabilities that could be exploited via RDP.
  • Use secure gateway or proxy for RDP sessions to inspect traffic for malicious payloads.
  • Conduct user awareness training focused on spearphishing with attachments, especially those mimicking Microsoft communications.

Suggested Tags

APT29
CozyBear
UAC-0215
Midnight Blizzard
spearphishing
RDP file
Microsoft impersonation
credential theft
lateral movement
cloud compromise
AD FS malware
ransomware
rootkit
state‑backed
espionage
supply chain attack

Confidence Assessment

The core elements—phishing emails with signed RDP attachments and subsequent Remote Desktop exploitation—are corroborated across multiple reputable sources, giving high confidence to these findings. Tool attribution outside of the well‑known RAT families (e.g., FOGGYWEB, MAGICWEB) relies on references rather than hard evidence; thus medium confidence is appropriate for those claims. The lack of precise dates for first and last activity, as well as incomplete data on internal supply‑chain mechanisms, introduces information gaps that limit overall situational awareness.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.microsoft.com — Cited by web research for: the SVR
  2. attack.mitre.org — Cited by web research for: T1071
  3. learn.microsoft.com — Cited by web research for: Guard
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: Matrix
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  6. https://www.infosecurity-magazine.com/news/apt29-spearphishing-thousands-rdp/ — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.

Intel Summary

29

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
Phishing
Government Targeting
Email Compromise
RDP Abuse
Geopolitical Espionage
APT29
CozyBear
UAC-0215
Midnight Blizzard
spearphishing
RDP file
Microsoft impersonation
credential theft
lateral movement
cloud compromise
AD FS malware
ransomware
rootkit
state‑backed
espionage
supply chain attack

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.