Another quality technical blog from #MIRAGE, this time on Secret Blizzard’s beloved #Kazuar malware. This blog is an in-depth analysis of Kazuar’s progression from a single, monolithic framework into a modular bot ecosystem composed of three distinct module types, each with clearly defined roles. Together, these components distribute functionality across the P2P botnet, enabling flexible configuration, lower observability, and broad tasking while minimizing opportunities for detection.
https://t.co/0VzspKN1Wa
Microsoft identified a campaign by North Korean state actor Sapphire Sleet employing new combinations of macOS execution patterns and techniques, enabling the actor to compromise systems through social engineering rather than software exploitation. https://t.co/7ynhI0V1sW
Microsoft Threat Intelligence uncovered a macOS‑focused cyber campaign by the North Korean threat actor Sapphire Sleet that relies on social engineering rather than software vulnerabilities.
https://t.co/uAPXe5pqIV
🚨 Last chance for BlueHat Redmond
Registration closes March 31 for one of the most unique security research events of the year. Join the security community on May 5-6 for two days of insights, collaboration, and cutting-edge discussions.
Spots are limited. Don’t miss your chance.
👉Register now: https://t.co/7myvMCXegx
The financially motivated threat actor Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics. https://t.co/xH7xqsiaq8
Leveraging cloud-native capabilities, Storm-0501 rapidly exfiltrates large volumes of data, destroys data and backups within the victim environment, and demands ransom—all without relying on traditional malware deployment.
Read our blog to get protection and mitigation recommendations, including strengthening protections for cloud identities and cloud resources, and detection guidance to harden networks against Storm-0501’s cloud-based ransomware attacks.
Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard that has been targeting embassies located in Moscow using an adversary-in-the-middle (AiTM) position to deploy their custom #ApolloShadow malware.
https://t.co/n10NihobGX
#ApolloShadow #MSTIC #MIRAGE
Microsoft Threat Intelligence uncovered a macOS vulnerability, tracked as CVE-2025-31199, that could allow attackers to steal private data of files normally protected by Transparency, Consent, and Control (TCC), such as caches used by Apple Intelligence. https://t.co/RItmoVgnHZ
MSTIC blog on Sharepoint exploitation
At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7:
Linen Typhoon
Violet Typhoon
Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown)
https://t.co/IgEp6yxx3B
Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771.
In collaboration with Microsoft Threat Intelligence (MSTIC), @SonicWall has identified a deceptive campaign to distribute a modified/patched version of SonicWall’s SSL VPN NetExtender application (dubbed #SilentRoute by MSTIC) that closely resembles the official SonicWall NetExtender software.
https://t.co/VeiBXCmuzV
https://t.co/lEzmFqFagu
#SonicWall #NetExtender #MSTIC #SilentRoute
Microsoft has discovered worldwide cloud abuse activity by new Russia-affiliated threat actor Void Blizzard (LAUNDRY BEAR), whose cyberespionage activity targets gov't, defense, transportation, media, NGO, and healthcare in Europe and North America. https://t.co/yVbdaFuqMf
We (me + @2igosha) have discovered a new Google Chrome 0-day that is being used in targeted attacks to deliver sophisticated spyware 🔥🔥🔥. It was just fixed as CVE-2025-2783 and we are revealing the first details about it and “Operation ForumTroll” https://t.co/apx0oXZ6be
Microsoft Threat Intelligence observed a new and notable method used by the threat actor Storm-0249 for distributing the Latrodectus trojan, a malware loader designed to facilitate multi-stage attacks by downloading and installing additional payloads onto compromised devices.
Happy Friday, everyone! With recent changes in #LummaStealer - using ChaCha20 for C2 encryption, here is the new config extractor in C/C++. We will try a different approach this time 🐦
Enjoy!
https://t.co/8hXyToCPGt