logo

Russian cyber spies hide behind other hackers to target Ukraine

ID: e6cd9637-477c-5e77-8291-e86063e9ad14

STIX ID: report--e6cd9637-477c-5e77-8291-e86063e9ad14

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-12-11

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Turla (aka Secret Blizzard), a Russian FSB-linked APT, ran a March–April 2024 espionage campaign against Ukrainian military devices using other actors' infrastructure (Amadey botnet and Storm-1837) to deliver PowerShell droppers and deploy modular backdoors Tavdig and KazuarV2; Microsoft observed reconnaissance focused on Starlink-connected devices, use of the Cookbox backdoor and exploitation of CVE‑2023‑38831, and provided mitigations and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.