logo

Russian state hackers hijacked rival servers to spy on targets in India, Afghanistan

ID: a500e229-32e8-5ecd-bd86-775e2f6027d4

STIX ID: report--a500e229-32e8-5ecd-bd86-775e2f6027d4

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2024-12-05

Date Updated: 2026-05-01

...
...

Russian state-sponsored APT group Secret Blizzard (Turla) compromised infrastructure owned or used by Pakistan-based Storm-0156 beginning in 2022 to conduct long-running espionage across South Asia; the attackers leveraged existing access to deploy or appropriate malware (TwoDash, Statuezy, Waiscot, CrimsonRAT) against Afghan government and Indian military/defense targets and favored operating through another threat actor’s infrastructure to evade attribution and expand access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.