Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine
ID: 8b13d52c-a5fa-517d-adc7-59121996aef3
STIX ID: report--8b13d52c-a5fa-517d-adc7-59121996aef3
Feed Name: Microsoft Security
Threat Score
Microsoft Threat Intelligence documents that Russian nation-state actor Secret Blizzard (attributed to FSB Center 16) commandeered other threat actors' access—specifically Amadey bots (Storm-1919) and a Storm-1837 PowerShell backdoor—to deploy its Tavdig and KazuarV2 backdoors against selected Ukrainian military devices between January and June 2024, providing detailed IOCs, TTPs, detection queries, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
