logo

Frequent freeloader part I: Secret Blizzard compromising Storm-0156 infrastructure for espionage

ID: dc3f93bf-d65e-51e0-b772-73b86be930d5

STIX ID: report--dc3f93bf-d65e-51e0-b772-73b86be930d5

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-12-04

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence details how the Russian nation-state actor “Secret Blizzard” (linked to FSB/ Turla) has, since 2022, been compromising and reusing the C2 infrastructure of the Pakistan-aligned cluster Storm-0156 to deploy backdoors (TinyTurla variant, TwoDash, MiniPocket, Statuezy) and exfiltrate intelligence from targets in Afghanistan and India; the report includes technical analysis of malware and persistence (DLL sideloading, credential backup abuse), actionable IOCs (hashes, domains, IPs), observed victimology, and recommended mitigations for Microsoft Defender and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.