Russian hacker group Secret Blizzard turns Kazuar malware into modular P2P espionage botnet
The Russian cyber‑espionage outfit known as Secret Blizzard, linked to the FSB, has upgraded its long‑standing Kazuar backdoor into a modular, peer‑to‑peer (P2P) botnet. Microsoft researchers say the new architecture consists of three components: a kernel module that selects a leader among infected hosts, a bridge module that proxies traffic to remote command‑and‑control servers, and a worker module that performs espionage functions such as keylogging, screenshot capture, file harvesting and email exfiltration. Communications between modules use Windows IPC mechanisms, are encrypted with AES and serialized with Google Protocol Buffers, making detection harder.
The botnet is designed for long‑term persistence and stealth, targeting government, diplomatic and defence organisations in Europe, Asia and Ukraine. It can be configured with over 150 options, allowing operators to bypass security tools, schedule tasks, control data exfiltration rates and inject processes. The leader election runs autonomously, choosing the most stable infected machine to coordinate the network, while non‑leader nodes remain silent to reduce exposure.
The evolution of Kazuar reflects a broader trend of state‑sponsored groups enhancing malware for sustained intelligence gathering, posing a heightened risk to critical infrastructure and sensitive communications across the affected regions.