logo

The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation

ID: ba8edfcb-cae0-5632-bcbe-5474ed4bdb2c

STIX ID: report--ba8edfcb-cae0-5632-bcbe-5474ed4bdb2c

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2025-02-12

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes a multiyear initial-access subgroup of the Russian-linked Seashell Blizzard actor (the "BadPilot" campaign) that opportunistically exploited public CVEs (notably CVE-2024-1709 and CVE-2023-48788) to compromise Internet-facing infrastructure worldwide. The report catalogs three exploitation patterns — RMM deployment for persistence and C2 (Atera, Splashtop), web shell deployments (including a unique LocalOlive web shell), and infrastructure modification for credential harvesting (OWA/JS and DNS changes) — plus use of tunneling tools and a Tor-based persistence method called ShadowLink, provides sectoral impact, IOCs and hunting queries, and recommends mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.