Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Wie Erpresser A Coinbase Scheterten

    September 2, 2025

    My cat loves this smart air purifier that doubles as a pet bed, and it is $ 100 off for Labor Day

    September 2, 2025

    Amazon interrupted Russian APT29 hackers targeting Microsoft 365

    September 2, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Amazon interrupted Russian APT29 hackers targeting Microsoft 365
    Security

    Amazon interrupted Russian APT29 hackers targeting Microsoft 365

    PineapplesUpdateBy PineapplesUpdateSeptember 2, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Amazon interrupted Russian APT29 hackers targeting Microsoft 365
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Amazon interrupted Russian APT29 hackers targeting Microsoft 365

    Researchers have disrupted an operation responsible for the Russian state-proposed threat group Midnight Blizard, seeking access to Microsoft 365 accounts and data.

    Also known as APT29, the hacker group in a watering hole campaign enrolled the websites to redirect the targets “Microsoft’s device coded in a watering hall campaign compromised for the malicious infrastructure designed to authorize the attacker-controlled equipment through authentication flow.”

    The Midnight Blizzard Threat actor has been linked to Russia’s Foreign Intelligence Service (SVR) and is well known for its clever fishing methods, who have recently influenced European Embassy, ​​Hewlet Packed Enterprises and Teamviewer.

    Random selection

    Amazon’s threats discovered the domain names used in the Watering Hole campaign after creating an analytical for the infrastructure of APT29.

    An investigation revealed that hackers had compromised several legitimate websites and disrupted malicious code using Base 64 encoding.

    Using randomization, APT29 for approximately 10% of the domains of the visitors of the compromised website that mimics cloudflair verification pages Findcloudflare (.) Com Or Cloudflare (.) Redirectpartners (.) Com,

    Malicious JavaScript
    Malicious JavaScript
    Source: Amazon

    Amazon as Tells in a report On recent action, the danger actors used a cookies-based system to prevent the same user from being redirected several times, which reduced doubts.

    The victims who landed on the fake cloudflare pages were directed to a malicious Microsoft device code authentication flow, which attempts to authorize them-invasive devices.

    Fake cloudflare verification page
    Fake cloudflare verification page
    Source: Amazon

    Amazon notes that the campaign was once discovered, its researchers separated the EC2 examples, used to a danger actor, which participates to disrupt the domain identified with cloudflair and Microsoft.

    Researchers noticed that APT29 tried to transfer its infrastructure to another cloud provider and register new domain names (eg) Cloudflare (.) Redirectpartners (.) Com,

    Amazon Chief Information Security Officer CJ Musa says that the researchers continued to track the actor’s movement and disrupted the attempt.

    Amazon underlines that this latest campaign reflects a development for APT29 for the same purpose of collecting credentials and intelligence.

    However, there are “refinery to their technical approach”, which no longer rely on domains that attempts to bypass APS or social engineering multi-factor authentication (MFA), which by tricking the goals in creating an app-specific password.

    Users are recommended to verify the device authority requests, enabling multi-factor authentication (MFA), and avoid executing commands on their system copied from webpages.

    Administrators should consider disabled of unnecessary device authority defects, where possible, apply conditional access policies, and closely monitor for suspected authentication events.

    Amazon stressed that this APT29 campaign did not compromise on its infrastructure or affected its services.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    Amazon APT29 hackers interrupted Microsoft Russian targeting
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSamsung ‘Galaxy Glass’ operated by Android XR is allegedly on track to unveil this month
    Next Article My cat loves this smart air purifier that doubles as a pet bed, and it is $ 100 off for Labor Day
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Wie Erpresser A Coinbase Scheterten

    September 2, 2025
    Security

    My cat loves this smart air purifier that doubles as a pet bed, and it is $ 100 off for Labor Day

    September 2, 2025
    Security

    AI chatbot maker Creesloft’s Fall in Violation – Crebs on Safety

    September 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Wie Erpresser A Coinbase Scheterten

    September 2, 2025

    My cat loves this smart air purifier that doubles as a pet bed, and it is $ 100 off for Labor Day

    September 2, 2025

    Amazon interrupted Russian APT29 hackers targeting Microsoft 365

    September 2, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.