Microsoft Uncovers ‘BadPilot’ Campaign as Seashell Blizzard Targets US and UK
ID: 83ccb9b2-4f36-5bc0-a77a-74c1fcee60b6
STIX ID: report--83ccb9b2-4f36-5bc0-a77a-74c1fcee60b6
Feed Name: HackRead
Microsoft warns that a GRU-linked Sandworm subgroup (BadPilot) has been exploiting known vulnerabilities in widely used remote-management and security software since at least 2021 to breach and maintain persistent access to critical networks across energy, telecoms, shipping, manufacturing and government sectors globally—expanding operations to the US and UK in 2024—and uses RMM agents, web shells, credential harvesting, DNS manipulation and custom tools like ShadowLink for long-term control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
