BadPilot network hacking campaign fuels Russian SandWorm attacks
ID: 745b578e-a4b4-5ae9-8e66-ef09ad5c64d0
STIX ID: report--745b578e-a4b4-5ae9-8e66-ef09ad5c64d0
Feed Name: Bleeping Computer
- Microsoft intelligence attributes a multi-year campaign named "BadPilot" to an APT44 subgroup (Seashell Blizzard/Sandworm) that has targeted critical infrastructure, governments, and industry since at least 2021 across Ukraine, Europe, Central/South Asia, the Middle East, and more recently the US, UK, Canada, and Australia; the report details exploitation of multiple n-day vulnerabilities, supply-chain intrusions, credential theft, deployment of web shells and backdoors, use of legitimate remote-management tools and Tor for stealth, data exfiltration methods, and linkage to destructive wiper attacks while providing IoCs and detection guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
