
image credit: adobe stock
A Russian espionage group attacked multiple organizations to steal credentials using Microsoft Teams chats that appear to originate from technical support.
Microsoft on Wednesday attributed the activity to Midnight Blizzard, previously tracked by the computing giant as Nobelium and also known as Cozy Bear and APT29. The actor used previously compromised Microsoft 365 accounts owned by small businesses to create new domains that appear as technical support entities, Microsoft said. The campaign has affected fewer than 40 organizations since May.