logo

Microsoft Uncovers ‘BadPilot’ Campaign as Seashell Blizzard Targets US and UK

ID: 83ccb9b2-4f36-5bc0-a77a-74c1fcee60b6

STIX ID: report--83ccb9b2-4f36-5bc0-a77a-74c1fcee60b6

Feed Name: HackRead

Threat Score
90/100

Date Published: 2025-02-13

Date Updated: 2026-04-22

Author: Waqas

...
...

Microsoft warns that a GRU-linked Sandworm subgroup (BadPilot) has been exploiting known vulnerabilities in widely used remote-management and security software since at least 2021 to breach and maintain persistent access to critical networks across energy, telecoms, shipping, manufacturing and government sectors globally—expanding operations to the US and UK in 2024—and uses RMM agents, web shells, credential harvesting, DNS manipulation and custom tools like ShadowLink for long-term control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.