Frequent freeloader: Russian actor using tools of other groups to attack Ukraine
Dec. 13, 2024, 7 p.m.
Tags
External References
Description
Russian nation-state actor Secret Blizzard has been observed using tools and infrastructure from other threat actors to compromise targets in Ukraine. Between March and April 2024, Secret Blizzard utilized the Amadey bot malware associated with cybercriminal activity to deploy its custom Tavdig and KazuarV2 backdoors on Ukrainian military devices. In January 2024, Secret Blizzard also leveraged a backdoor from Storm-1837, a Russia-based threat actor targeting Ukrainian drone pilots, to install its malware. This approach highlights Secret Blizzard's strategy of diversifying attack vectors and prioritizing access to military targets in Ukraine. The actor employs various techniques including strategic web compromises, adversary-in-the-middle campaigns, and spear-phishing for initial access.
Date
Published: Dec. 13, 2024, 1:28 p.m.
Created: Dec. 13, 2024, 1:28 p.m.
Modified: Dec. 13, 2024, 7 p.m.
Attack Patterns
KazuarV2
Tavdig
Amadey - S1025
Secret Blizzard
T1553.002
T1018
T1059.001
T1012
T1546
T1016
T1082
T1105
T1083
T1047
T1055
T1036
T1204
T1140
T1027
T1566
T1190
T1133
T1078
T1003
Additional Informations
Defense
Government
Ukraine