Russian state hackers hijacked rival servers to spy on targets in India, Afghanistan
ID: a500e229-32e8-5ecd-bd86-775e2f6027d4
STIX ID: report--a500e229-32e8-5ecd-bd86-775e2f6027d4
Feed Name: The Record from Recorded Future News
Russian state-sponsored APT group Secret Blizzard (Turla) compromised infrastructure owned or used by Pakistan-based Storm-0156 beginning in 2022 to conduct long-running espionage across South Asia; the attackers leveraged existing access to deploy or appropriate malware (TwoDash, Statuezy, Waiscot, CrimsonRAT) against Afghan government and Indian military/defense targets and favored operating through another threat actor’s infrastructure to evade attribution and expand access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
