logo

Kazuar: Anatomy of a nation-state botnet

ID: 5ac5f869-f973-5a4e-8644-71ef6b7e59b1

STIX ID: report--5ac5f869-f973-5a4e-8644-71ef6b7e59b1

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Microsoft Threat Intelligence

...
...

This report provides an in-depth analysis of Kazuar, a sophisticated, modular peer-to-peer botnet attributed to the Russian FSB-affiliated actor known as Secret Blizzard. It documents delivery methods, three-module architecture (Kernel, Bridge, Worker), inter-process and external C2 communication (Windows Messaging, Mailslot, named pipes; HTTP, WSS, EWS), leader-election behavior to minimize visibility, extensive collection/exfiltration features, configuration options and operational tradecraft, mitigation guidance, and several SHA-256 indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.