216.73.216.6

The BadPilot campaign: Multiyear global access operation

· Published 12/02/2025 22:29 · Modified 13/02/2025 10:13

Export JSON

Essential information

Published
12/02/2025 22:29
Modified
13/02/2025 10:13
Tags
2025-02-12 CVE-2021-34473 CVE-2022-41352 CVE-2023-23397 CVE-2023-32315 CVE-2023-42793 CVE-2023-48788 CVE-2024-1709 badpilot credential-theft global operation initial access localolive persistence remote management russian state actor shadowlink vulnerability exploitation
Related entities
1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 11 others

Description

A subgroup within Seashell Blizzard has conducted a global access operation called the campaign since 2021. The group exploits vulnerabilities in Internet-facing infrastructure to gain persistent access to high-value targets across various sectors worldwide. Their tactics include deploying web shells, modifying network resources, and using tools for and command and control. The campaign has expanded Seashell Blizzard's geographical reach beyond Eastern Europe, targeting organizations in the US, UK, Canada, and Australia. The subgroup's activities enable Russia to respond to evolving strategic objectives and provide options for future actions.

External references