Microsoft has issued a warning about ongoing spear-phishing campaign by threat actor called Midnight Blizzard linked to Russia's intelligence agency.
The campaign involves highly targeted spear-phishing emails sent to individuals linked to various sectors, including government, non-government organizations, IT service providers, academia, and defense.
Midnight Blizzard has already sent thousands of spear-phishing emails to over 100 organizations, using stolen email addresses and social engineering techniques.
If recipients open the attachments, the threat actor gains access to their files, network drives, peripherals, and authentication information, potentially installing malware and remaining undetected.