The BadPilot campaign: Multiyear global access operation
Essential information
- Published
- 12/02/2025 22:29
- Modified
- 13/02/2025 10:13
- Tags
- 2025-02-12 CVE-2021-34473 CVE-2022-41352 CVE-2023-23397 CVE-2023-32315 CVE-2023-42793 CVE-2023-48788 CVE-2024-1709 badpilot credential-theft global operation initial access localolive persistence remote management russian state actor shadowlink vulnerability exploitation
- Related entities
- 1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 11 others
Description
A Russian state actor subgroup within Seashell Blizzard has conducted a global access operation called the BadPilot campaign since 2021. The group exploits vulnerabilities in Internet-facing infrastructure to gain persistent access to high-value targets across various sectors worldwide. Their tactics include deploying web shells, modifying network resources, and using remote management tools for persistence and command and control. The campaign has expanded Seashell Blizzard's geographical reach beyond Eastern Europe, targeting organizations in the US, UK, Canada, and Australia. The subgroup's activities enable Russia to respond to evolving strategic objectives and provide options for future actions.