The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation
ID: ba8edfcb-cae0-5632-bcbe-5474ed4bdb2c
STIX ID: report--ba8edfcb-cae0-5632-bcbe-5474ed4bdb2c
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes a multiyear initial-access subgroup of the Russian-linked Seashell Blizzard actor (the "BadPilot" campaign) that opportunistically exploited public CVEs (notably CVE-2024-1709 and CVE-2023-48788) to compromise Internet-facing infrastructure worldwide. The report catalogs three exploitation patterns — RMM deployment for persistence and C2 (Atera, Splashtop), web shell deployments (including a unique LocalOlive web shell), and infrastructure modification for credential harvesting (OWA/JS and DNS changes) — plus use of tunneling tools and a Tor-based persistence method called ShadowLink, provides sectoral impact, IOCs and hunting queries, and recommends mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
