Russian Hackers Exploit Rival Attackers' Infrastructure for Espionage
ID: c2e7edd1-badf-5b8a-9f3a-2ec48f9e58bc
STIX ID: report--c2e7edd1-badf-5b8a-9f3a-2ec48f9e58bc
Feed Name: Infosecurity Magazine (News)
Microsoft research reveals that the Russian APT known as Secret Blizzard (Turla), attributed to FSB Center 16, has for years been piggybacking on the infrastructure and tools of at least six other threat actors to conduct espionage against foreign ministries, embassies, government and defense organizations. The report details reuse and confiscation of other actors' backdoors, deployment of Secret Blizzard backdoors (e.g., TinyTurla, TwoDash, Statuezy, MiniPocket) onto third‑party C2 servers, and techniques like DLL side‑loading and search order hijacking to execute payloads and stage exfiltrated data — increasing the group's stealth and complicating detection and disruption efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
