EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard

Fonte aperta verificata
Intelligence con provenienza tracciabile. EudorIA conserva gli indicatori tecnici acquisiti dai feed supportati, con fonte, data e contesto. Gli IOC condivisibili sono disponibili nei feed STIX; le azioni di rilevamento e blocco richiedono la valutazione di validita, confidenza e applicabilita al perimetro del cliente. Consulta i feed STIX
Sintesi operativa EudorIA

Cosa significa

Priorità 70/100

MISP EudorIA ha pubblicato l'advisory "Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Perché conta

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

DestinatariITSOCCISO

Testo acquisito dalla fonte

Evento MISP pubblicato con TLP:CLEAR: Secret Blizzard compromising Storm-0156 infrastructure for espionage / Snowblind: The Invisible Hand of Secret Blizzard. Summary Based on both Microsoft Threat Intelligence’s findings and those reported by governments and other security vendors, we assess that the Russian nation-state actor tracked as Secret Blizzard has used the tools and infrastructure of at least six other threat actors during the past seven years. They also have actively targeted infrastructure where other threat actors have staged exfiltrated data from victims with the intention of collecting this data for their own espionage program. We assess that Secret Blizzard’s use of other actors’ infrastructure and tools, both state-sponsored and cybercriminal, is exclusively for facilitating espionage operations. In this first of a two-part blog series, we discuss how Secret Blizzard has used the infrastructure of the Pakistan-based threat activity cluster we call Storm-0156 — which overlaps with the threat actor known as [SideCopy]([URL rimossa]), [Transparent Tribe]([URL rimossa]), and APT36 — to install backdoors and collect intelligence on targets of interest in South Asia. Microsoft Threat Intelligence partnered with [Black Lotus Labs]([URL rimossa]), the threat intelligence arm of Lumen Technologies, to confirm that Secret Blizzard command-and-control (C2) traffic emanated from Storm-0156 infrastructure, including infrastructure used by Storm-0156 to collate exfiltrated data from campaigns in Afghanistan and India. We thank th

Fonte
MISP EudorIA
Entità pubblicatrice
MISP EudorIA
Tipo entità
Comunità di intelligence
Area
Global
Lingua originale
it · traduzione non necessaria
Pubblicazione
30/07/2026 02:52
Condivisione
TLP:CLEAR
Indicatori dichiarati dalla fonte
55
IOC indicizzati per la ricerca
0 valori nel periodo di conservazione
IOC disponibili nel feed STIX
55Ultima verifica di condivisione: 2026-09-26T04:30:43.374472+00:00
Evento MISP
f1d310ba-7e51-41d8-97a8-d9a7c1f973ab
Classificazione
Alta
Gruppo attribuito dalla fonte
Turla
Apri la fonte originale