logo

Blitz Brigantine Weaponizes Email Bombing and DNS MX Records to Deploy AOBackdoor

ID: 6aec962c-21bb-54fd-96f0-f637fb85e46a

STIX ID: report--6aec962c-21bb-54fd-96f0-f637fb85e46a

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

BlueVoyant describes a sophisticated Blitz Brigantine (Storm-1811) campaign linked to Black Basta affiliates that uses email-bombing and social-engineering via Microsoft Teams Quick Assist to gain remote access, deploy malicious MSI installers that sideload a DLL, and deliver a final AOBackdoor which uses DNS MX-record tunneling to hide C2 traffic; the malware includes anti-analysis and time-gating protections and has targeted finance and healthcare since at least August 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.