In a recent joint report by Microsoft Threat Intelligence and Black Lotus Labs, new insights have emerged about “Secret Blizzard,” a sophisticated Russian nation-state cyber actor attacking windows infrastructure using a variety of hacking tools.
Known for its stealthy espionage operations, Secret Blizzard has been using the infrastructure and tools of at least six other threat actors over the past seven years to enhance its intelligence-gathering capabilities.
The U.S. Cybersecurity and Infrastructure Security Agency attributes Russia’s Federal Security Service (FSB) to Secret Blizzard, a unique method that leverages the tools and infrastructure of other state-sponsored and cybercriminal actors.
The primary target of this approach is state-level espionage, which includes ministries of foreign affairs, embassies, defense departments, and related organizations worldwide.
They not only conduct a wide range of operations but also aim to establish long-term access to valuable systems for gathering politically significant intelligence.
A significant revelation in the report is Secret Blizzard’s use of the infrastructure of a Pakistan-based espionage group known as Storm-0156, also known as SideCopy, Transparent Tribe, and APT36.
Targeted to facilitate operations in South Asia, this group primarily installs backdoors and collects intelligence.
Microsoft Threat Intelligence and Black Lotus Labs’ collaboration has confirmed that Storm-0156 infrastructure, which has staged data exfiltrated from campaigns in Afghanistan and India, originated the command-and-control traffic of Secret Blizzard.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
Since November 2022, Microsoft Threat Intelligence has observed Secret Blizzard compromising the infrastructure of Storm-0156, a Pakistan-based espionage group.
Secret Blizzard hijacked Storm-0156’s tools, such as CrimsonRAT and Arsenal, to deploy their own malware, including TwoDash, MiniPocket, and Statuezy, while mimicking Storm-0156’s operations through DLL-sideloading and similar filenames.
This access allowed Secret Blizzard to redirect C2 traffic to their own infrastructure and take over Storm-0156 backdoors like CrimsonRAT and Wainscot for further attacks.
Secret Blizzard’s methodology involves deploying multiple backdoors, including the TinyTurla variant and a custom downloader known as TwoDash, to enhance their infiltration capabilities.
In addition, they employ a clipboard monitoring tool referred to as Statuezy, and other malware to bolster their espionage efforts.
The report highlights Secret Blizzard’s significant impact on global cybersecurity. Through strategic positioning and backdoor deployment, this group has effectively broken into infrastructure in Afghanistan’s government, including the Ministry of Foreign Affairs and the General Directorate of Intelligence.
Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…