Russian cyber spies hide behind other hackers to target Ukraine
ID: e6cd9637-477c-5e77-8291-e86063e9ad14
STIX ID: report--e6cd9637-477c-5e77-8291-e86063e9ad14
Feed Name: Bleeping Computer
Threat Score
Turla (aka Secret Blizzard), a Russian FSB-linked APT, ran a March–April 2024 espionage campaign against Ukrainian military devices using other actors' infrastructure (Amadey botnet and Storm-1837) to deliver PowerShell droppers and deploy modular backdoors Tavdig and KazuarV2; Microsoft observed reconnaissance focused on Starlink-connected devices, use of the Cookbox backdoor and exploitation of CVE‑2023‑38831, and provided mitigations and hunting queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
