Seashell Blizzard Subgroup's Campaign Exploiting Vulnerabilities for Data Exfiltration (Campaign)
ID: cfd35010-4256-5c76-88e1-379ec5cfd15d
STIX ID: report--cfd35010-4256-5c76-88e1-379ec5cfd15d
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-13
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Seashell Blizzard (aka BadPilot) conducts a multiyear, globally distributed access operation that scans and exploits public vulnerabilities in internet-facing software (including Microsoft Exchange, Zimbra, OpenFire, JetBrains TeamCity, and Outlook) to achieve initial access, then deploys web shells (LocalOlive), tunneling tools (Chisel, rsockstun), RMM agents (Atera, Splashtop), and a Tor-based persistence mechanism (ShadowLink) to harvest credentials, expand footholds, and exfiltrate data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
