logo

Seashell Blizzard Subgroup's Campaign Exploiting Vulnerabilities for Data Exfiltration (Campaign)

ID: cfd35010-4256-5c76-88e1-379ec5cfd15d

STIX ID: report--cfd35010-4256-5c76-88e1-379ec5cfd15d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2025-02-13

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Seashell Blizzard (aka BadPilot) conducts a multiyear, globally distributed access operation that scans and exploits public vulnerabilities in internet-facing software (including Microsoft Exchange, Zimbra, OpenFire, JetBrains TeamCity, and Outlook) to achieve initial access, then deploys web shells (LocalOlive), tunneling tools (Chisel, rsockstun), RMM agents (Atera, Splashtop), and a Tor-based persistence mechanism (ShadowLink) to harvest credentials, expand footholds, and exfiltrate data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.