Cyber Security News

Russian Seashell Blizzard Attacking Organizations With Custom-Developed Hacking Tools

A highly sophisticated Russian threat actor known as Seashell Blizzard (also tracked as APT44, Sandworm, and Voodoo Bear) has been conducting extensive cyber operations against organizations worldwide.

Linked to Russian Military Intelligence Unit 74455 (GRU), this adversary has targeted critical sectors across the United States, Canada, Australia, Europe, Central Asia, and the Middle East since at least 2009.

Their operations are characterized by persistent, long-term network access using both publicly available and custom-developed hacking tools.

Seashell Blizzard has demonstrated particular interest in Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems.

Their attacks have resulted in significant disruptions to critical infrastructure, particularly energy distribution systems, with potential for catastrophic consequences.

The group’s strategic focus on sectors including energy, telecommunications, government, military, transportation, manufacturing, and retail indicates a comprehensive approach to cyber espionage and potential sabotage.

Recently, AttackIQ security analysts identified a new campaign dubbed “BadPilot,” which represents a sophisticated, long-running operation primarily focused on gaining initial access to targeted networks.

Vulnerability exploitation & Employing spear-phishing emails

The campaign employs strategic spear-phishing emails and vulnerability exploitation to establish footholds that enable further network penetration.

The group’s persistence mechanisms are particularly concerning. Seashell Blizzard maintains access across system restarts and credential changes by creating or modifying Windows services.

This is accomplished using native Windows tools, as evidenced by the group’s use of the “sc” command line utility to create new services and verify their successful implementation.

sc create BadPilotService binPath= "cmd.exe /c powershell.exe -nop -w hidden -c \"IEX ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String('BASE64_ENCODED_PAYLOAD')))\"" start= auto
sc query BadPilotService

Their evasion tactics include leveraging Windows Background Intelligent Transfer Service (BITS) to quietly download payloads using system idle bandwidth, making malicious activities harder to detect among legitimate network traffic.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago