logo

Russian state threat group shifts focus to US, UK targets

ID: 1a6221fb-8135-5615-b56b-759ecbcd147a

STIX ID: report--1a6221fb-8135-5615-b56b-759ecbcd147a

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-02-12

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Microsoft reports that a Seashell Blizzard subgroup operating the "BadPilot" campaign has, since at least 2021, exploited multiple publicly disclosed vulnerabilities (including CVE-2024-1709 and CVE-2023-48788 among others) to gain long-term access to targets, steal credentials, and move laterally. In 2024 the subgroup expanded from Ukraine-focused operations to broad, opportunistic exploitation across the U.S., U.K., Canada and Australia, affecting critical infrastructure sectors and enabling destructive attacks and wider intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.