Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard
Cosa significa
MISP EudorIA ha pubblicato l'advisory "Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard. Summary Based on both Microsoft Threat Intelligence’s findings and those reported by governments and other security vendors, we assess that the Russian nation-state actor tracked as Secret Blizzard has used the tools and infrastructure of at least six other threat actors during the past seven years. They also have actively targeted infrastructure where other threat actors have staged exfiltrated data from victims with the intention of collecting this data for their own espionage program. We assess that Secret Blizzard’s use of other actors’ infrastructure and tools, both state-sponsored and cybercriminal, is exclusively for facilitating espionage operations. In this first of a two-part blog series, we discuss how Secret Blizzard has used the infrastructure of the Pakistan-based threat activity cluster we call Storm-0156 — which overlaps with the threat actor known as [SideCopy]([URL rimossa]), [Transparent Tribe]([URL rimossa]), and APT36 — to install backdoors and collect intelligence on targets of interest in South Asia. Microsoft Threat Intelligence partnered with [Black Lotus Labs]([URL rimossa]), the threat intelligence arm of Lumen Technologies, to confirm that Secret Blizzard command-and-control (C2) traffic emanated from Storm-0156 infrastructure, including infrastructure used by Storm-0156 to collate exfiltrated data from campaigns in Afghanistan and India. We thank th
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:52
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 55
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 55Ultima verifica di condivisione: 2026-09-26T04:30:43.374472+00:00
- Evento MISP
- f1d310ba-7e51-41d8-97a8-d9a7c1f973ab
- Classificazione
- Alta
- Gruppo attribuito dalla fonte
- Turla