APT29 abused the Windows Credential Roaming in an attack against a diplomatic entity
Security Affairs
NOVEMBER 10, 2022
Mandiant researchers in early 2022 responded to an incident where the Russia-linked APT29 group (aka SVR group , Cozy Bear , Nobelium , and The Dukes ) successfully phished a European diplomatic entity. Credential Roaming was introduced by Microsoft in Windows Server 2003 SP1 and is still supported on Windows 11 and Windows Server 2022.
Let's personalize your content