ADVERTISEMENT

Russian-backed Seashell Blizzard relies on "BadPilot" subgroup for initial exploits, researchers say

Microsoft researchers uncover the “BadPilot campaign,” a threat subgroup working behind the scenes to support the Krelmin-backed hacking cartel Seashell Blizzard, responsible for years of persistent attacks on high-value targets worldwide.

Unknown Russian hacker

Image by Shutterstock

Stefanie Schappert
Stefanie Schappert Senior Journalist
February 13, 2025 Updated: February 13, 2025 3 min read
Seashell Blizzard Microsoft research map
The geographical spread of the initial access of Seashell Blizzard's subgroup targets. Image by Microsoft Threat Intelligence.

Opportunistic and Strategic

ADVERTISEMENT
  • Targeted attacks using scanning and exploitation of specific victim infrastructure, phishing, and modifying existing systems to either expand network access or obtain confidential information.
  • Opportunistic attacks using exploitation of Internet-facing infrastructure, distribution of malware via trojanized software, and conducting significant post-compromise activities.
  • Hybrid attacks (especially focused on organizations within Ukraine) such as limited supply-chain attacks and compromise of regional managed IT service providers.
Ernestas Naprys Gintaras Radauskas Jurgita Lapienyte vilius
Don’t miss our latest stories on Google News
Add us as your Preferred Source on Google.

In support of Seashell Blizzard

  • Deployment of remote management and monitoring (RMM) suites for persistence and command and control (February 24, 2024 – present)
  • Web shell deployment for persistence and C2 (late 2021 – present)
  • Modification of infrastructure to expand network influence through credential collection (late 2021 – 2024)
Seashell Blizzard Microsoft research BadPilot lifecycle
Seashell Blizzard initial access subgroup operational lifecycle. Image by Microsoft Threat Intelligence.
ADVERTISEMENT