Also known as: APT29, CozyBear, the SVR, Point of Sale, POS
UAC-0215 is a sophisticated adversary believed to be state‑backed with primary motivation of intelligence gathering. Over the past year, it has deployed widespread spearphishing emails that impersonate Microsoft staff and embed signed .rdp configuration files. These fake RDP files trick recipients into connecting to attacker‑controlled servers via Remote Desktop, granting attackers a foothold without needing elevated privileges or exploiting client vulnerabilities. After initial compromise, UAC-0215 escalates its privileges through various methods, including abusing User Account Control (UAC) bypasses and process injection. It also deploys remote access trojans such as FOGGYWEB, MAGICWEB, and several RAT families to establish persistence, map local device resources, and exfiltrate data. The adversary routinely expands reach by pivoting into cloud accounts via compromised on‑premises credentials, exploiting Active Directory Federation Services (AD FS) for lateral movement. The group’s toolset is diverse: it uses open source utilities like Mimikatz for credential dumping and commercial malware such as Avaddon and RoKRAT for additional RDP access. It also employs obfuscation, scheduled tasks, and boot‑autostart mechanisms to maintain control across disparate environments. UAC-0215’s operations indicate integration with a broader supply‑chain attack framework; the mention of Sunburst suggests possible coordination or shared infrastructure with other APT29 campaigns. The attacker remains active across multiple regions, targeting both Eastern European and global entities.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC-0215, also known as APT29 or Midnight Blizzard, has conducted a large‑scale spearphishing campaign using signed Remote Desktop Protocol (RDP) files to gain illicit access to government, defense, and commercial organizations worldwide. The group leverages user credentials obtained via legitimate RDP sessions to move laterally into corporate networks and cloud environments for espionage objectives.
Goals & Targeting
The primary goal of UAC-0215 is espionage of sensitive governmental, defense‑related, and industrial information. By compromising high‑value accounts through spearphishing and legitimate RDP sessions, it seeks to harvest strategic data, infiltrate cloud infrastructures, and maintain long‑term undetected presence within targeted organizations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC-0215 employed a high‑volume campaign against more than 100 organizations, primarily in Ukraine but also across the UK, South Korea, Japan, the US, Russia, China, India, Vietnam, Romania, North Korea, and Australia. The operational tempo was rapid—thousands of spearphishing emails were sent within weeks—indicating a prepared and well‑resourced threat actor. Victim profiles included government agencies, defense contractors, non‑profit organizations, manufacturing firms, healthcare providers, and educational institutions. Notable operations involved the deployment of signed RDP files to bypass standard authentication controls, followed by lateral movement into cloud accounts via compromised on‑premises credentials. The tactics suggest an emphasis on stealth, persistence, and collection of strategic data over destructive sabotage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core elements—phishing emails with signed RDP attachments and subsequent Remote Desktop exploitation—are corroborated across multiple reputable sources, giving high confidence to these findings. Tool attribution outside of the well‑known RAT families (e.g., FOGGYWEB, MAGICWEB) relies on references rather than hard evidence; thus medium confidence is appropriate for those claims. The lack of precise dates for first and last activity, as well as incomplete data on internal supply‑chain mechanisms, introduces information gaps that limit overall situational awareness.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics