Today > 13 Critical | 36 High | 32 Medium vulnerabilities   -   You can now download lists of IOCs here!

Frequent freeloader: Russian actor using tools of other groups to attack Ukraine

Dec. 13, 2024, 7 p.m.

Description

Russian nation-state actor Secret Blizzard has been observed using tools and infrastructure from other threat actors to compromise targets in Ukraine. Between March and April 2024, Secret Blizzard utilized the Amadey bot malware associated with cybercriminal activity to deploy its custom Tavdig and KazuarV2 backdoors on Ukrainian military devices. In January 2024, Secret Blizzard also leveraged a backdoor from Storm-1837, a Russia-based threat actor targeting Ukrainian drone pilots, to install its malware. This approach highlights Secret Blizzard's strategy of diversifying attack vectors and prioritizing access to military targets in Ukraine. The actor employs various techniques including strategic web compromises, adversary-in-the-middle campaigns, and spear-phishing for initial access.

Date

Published: Dec. 13, 2024, 1:28 p.m.

Created: Dec. 13, 2024, 1:28 p.m.

Modified: Dec. 13, 2024, 7 p.m.

Attack Patterns

KazuarV2

Tavdig

Amadey - S1025

Secret Blizzard

T1553.002

T1018

T1059.001

T1012

T1546

T1016

T1082

T1105

T1083

T1047

T1055

T1036

T1204

T1140

T1027

T1566

T1190

T1133

T1078

T1003

Additional Informations

Defense

Government

Ukraine