EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 70/100

MISP EudorIA ha pubblicato l'advisory "Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard. Summary Based on both Microsoft Threat Intelligence’s findings and those reported by governments and other security vendors, we assess that the Russian nation-state actor tracked as Secret Blizzard has used the tools and infrastructure of at least six other threat actors during the past seven years. They also have actively targeted infrastructure where other threat actors have staged exfiltrated data from victims with the intention of collecting this data for their own espionage program. We assess that Secret Blizzard’s use of other actors’ infrastructure and tools, both state-sponsored and cybercriminal, is exclusively for facilitating espionage operations. In this first of a two-part blog series, we discuss how Secret Blizzard has used the infrastructure of the Pakistan-based threat activity cluster we call Storm-0156 — which overlaps with the threat actor known as [SideCopy]([URL rimossa]), [Transparent Tribe]([URL rimossa]), and APT36 — to install backdoors and collect intelligence on targets of interest in South Asia. Microsoft Threat Intelligence partnered with [Black Lotus Labs]([URL rimossa]), the threat intelligence arm of Lumen Technologies, to confirm that Secret Blizzard command-and-control (C2) traffic emanated from Storm-0156 infrastructure, including infrastructure used by Storm-0156 to collate exfiltrated data from campaigns in Afghanistan and India. We thank th

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:52
Sharing
TLP:CLEAR
Indicators reported by the source
55
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
55Last sharing verification: 2026-09-26T04:30:43.374472+00:00
MISP event
f1d310ba-7e51-41d8-97a8-d9a7c1f973ab
Classification
High
Group attributed by the source
Turla
Open the original source