Press ESC to close

Russian state hackers hijacked rival servers to spy on targets in India, Afghanistan

CategoryDetails
Threat ActorsSecret Blizzard (also known as Turla), Storm-0156
Campaign OverviewRussian state-sponsored hackers (Secret Blizzard) infiltrated Storm-0156 infrastructure to target Afghan and Indian government agencies and institutions.
Target Regions (Victims)Afghanistan (government, intelligence), India (military, defense-related institutions)
MethodologySecret Blizzard used infrastructure of Storm-0156 to deploy its own malware and exploit data exfiltrated by Storm-0156.
Product TargetedAfghan and Indian government, intelligence agencies, military and defense-related institutions.
Malware ReferenceTwoDash, Statuezy, Wainscot, CrimsonRAT
Tools UsedWainscot, CrimsonRAT (appropriated from Storm-0156)
Vulnerabilities ExploitedExploitation of compromised infrastructure from Storm-0156
TTPsInfiltration via third-party infrastructure, malware deployment, and shifting blame to other threat actors.
AttributionSecret Blizzard attributed to Russia’s Federal Security Service (FSB), associated with Turla, Waterbug, and other Russian threat actors.
RecommendationsMonitoring and securing infrastructure, blocking unauthorized use of exfiltrated data, strengthening defenses against third-party infrastructure misuse.
SourceThe Records

Read full article: https://therecord.media/russian-turla-secret-blizzard-hackers-hijack-rival-servers-targeting-south-asia

Disclaimer: The above summary has been generated by an AI language model

Source: The Record

Published on: December 5, 2024

Leave a Reply

Your email address will not be published. Required fields are marked *