BadPilot Attacking Network Devices to Expand Russian Seashell Blizzard’s Attacks
ID: c502c742-7df2-5ac2-a2a4-7aadc7ce46e9
STIX ID: report--c502c742-7df2-5ac2-a2a4-7aadc7ce46e9
Feed Name: GBHackers
BadPilot, a subgroup of the Russian state-sponsored Seashell Blizzard (Sandworm), has run a global multi-year access campaign since at least 2021 targeting energy, oil and gas, telecommunications, shipping, arms manufacturing and government entities by exploiting known vulnerabilities (e.g., CVE-2021-34473, CVE-2022-41352, CVE-2024-1709, CVE-2023-48788) and employing RMM tool abuse, web shells (LocalOlive), a bespoke ShadowLink Tor-based backdoor, and lateral-movement tooling to maintain persistent covert access; recommended mitigations include patching, MFA, monitoring RMM usage, and deploying EDR and advanced threat detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
