Secret Blizzard (Turla)
Russian state-sponsored (FSB — Federal Security Service) · Espionage / intelligence collection / counter-intelligence
Tactics, Techniques & Procedures (TTPs)
- Kazuar backdoor rebuilt as a P2P botnet — C2 distributed across victim machines rather than centralised servers, making disruption exceptionally difficult
- ISP-level adversary-in-the-middle (AiTM) against foreign embassies in Moscow — injecting ApolloShadow via legitimate software update channels at the carrier level
- Storm-0156 infrastructure hijacking — piggybacking on Pakistani APT (Storm-0156) infrastructure to reach Afghan government and Indian Army networks while falsely implicating Pakistani attribution
- Snake/Uroburos kernel rootkit for deep, reboot-persistent compromise on high-value targets
- Long-duration stealth: operational continuity since Moonlight Maze (1996-1999) across multiple law enforcement disruptions
- HTTP/HTTPS-based C2 using legitimate web services to blend with normal enterprise traffic
Known Targets
Analyst Notes
Secret Blizzard (Turla) is the FSB's premier espionage capability with an operational record stretching back to Moonlight Maze. Operation MEDUSA (FBI, May 2023) disrupted the Snake rootkit infrastructure, but operations evolved and continued. The Storm-0156 hijacking technique — reaching Afghan and Indian Army networks via Pakistani APT infrastructure — provides both operational access and deliberate attribution confusion. This, combined with ISP-level AiTM against diplomatic missions in Moscow, represents some of the most sophisticated sustained offensive operations documented from any nation-state. Kazuar's P2P architecture means no single C2 server can be seized or blocked.
Also Known As