Russian hackers turn Kazuar backdoor into modular P2P botnet
ID: 01768bda-eda7-56c7-b318-65a4cedc3dbc
STIX ID: report--01768bda-eda7-56c7-b318-65a4cedc3dbc
Feed Name: Bleeping Computer
Microsoft researchers report that the Russian-linked Secret Blizzard has evolved the long-running Kazuar backdoor into a modular peer-to-peer botnet with Kernel, Bridge, and Worker modules for stealthy leader-based communications, long-term persistence, and extensive espionage capabilities (keylogging, screenshots, file and email exfiltration). The malware supports ~150 configuration options and multiple security bypasses (AMSI, ETW, WLDP), and has been observed targeting government, diplomatic, defense, and critical organizations across Europe, Asia, and Ukraine.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
