logo

Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine

ID: 8b13d52c-a5fa-517d-adc7-59121996aef3

STIX ID: report--8b13d52c-a5fa-517d-adc7-59121996aef3

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-12-11

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence documents that Russian nation-state actor Secret Blizzard (attributed to FSB Center 16) commandeered other threat actors' access—specifically Amadey bots (Storm-1919) and a Storm-1837 PowerShell backdoor—to deploy its Tavdig and KazuarV2 backdoors against selected Ukrainian military devices between January and June 2024, providing detailed IOCs, TTPs, detection queries, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.