Technology

Secret Blizzard upgrades Kazuar into modular P2P botnet

Kazuar modular – Researchers say Secret Blizzard has turned its Kazuar backdoor into a modular peer-to-peer botnet with a coordinator/leader model, “silent” non-leader systems, and a worker module that performs keylogging, screenshotting, reconnaissance, and encrypted data the

A long-running backdoor used for intelligence collection has been reworked to linger longer. hide better. and steal data with fewer visible traces.. Microsoft researchers say Secret Blizzard has developed Kazuar into a modular peer-to-peer (P2P) botnet designed for long-term persistence. stealth. and data collection.

Secret Blizzard’s broader activity overlaps with groups including Turla, Uroburos, and Venomous Bear.. The actor has been associated with the Russian intelligence service (FSB) and is known for targeting government and diplomatic organizations. defense-related entities. and critical systems across Europe. Asia. and Ukraine.

Kazuar has been documented since 2017, and its code lineage is traced back as far as 2005.. Researchers have also linked Kazuar’s activity to the Turla espionage group working for the FSB.. In 2020. Kazuar was exposed in attacks targeting European government organizations. and three years later it was seen deployed in attacks against Ukraine.

image

Microsoft’s analysis of a recent variant describes Kazuar running through three distinct modules: kernel, bridge, and worker.. The kernel module is the central coordinator. managing tasks. controlling other modules. electing a leader. and orchestrating communications and data flow across the botnet.. In that design, the leader is essentially one infected system inside a compromised environment or network segment.. It communicates with the command-and-control (C2) server, receives tasks, and forwards them internally to other infected systems.

Non-leader systems are kept in “silent” mode and don’t communicate directly with the C2.. Microsoft says this approach improves stealth and reduces the detection surface.. “The Kernel leader is the one elected Kernel module that communicates with the Bridge module on behalf of the other Kernel modules. reducing visibility by avoiding large volumes of external traffic from multiple infected hosts. ” the researchers write.

image

The election process happens internally and autonomously, using uptime, reboot, and interruption counts.. Once a leader is selected. the bridge module becomes an external communications proxy that relays traffic between the elected kernel leader and the remote C2 infrastructure.. Microsoft lists protocols such as HTTP, WebSockets, or Exchange Web Services (EWS) for those relayed communications.

Internal communications rely on IPC (inter-process communication), including Windows Messaging, Mailslots, and named pipes, blending with normal operational noise. Microsoft says the messages are AES-encrypted and serialized with Google Protocol Buffers (Protobuf).

image

The worker module is where Kazuar carries out the espionage functions.. Microsoft lists keylogging; capturing screenshots; harvesting data from the filesystem; performing system and network reconnaissance; collecting email/MAPI data (including Outlook downloads); monitoring windows; stealing recent files.. The collected information is encrypted, staged locally, and later exfiltrated through the bridge module.

Microsoft also points to Kazuar’s versatility, saying it now supports 150 configuration options.. Those options let operators enable or disable specific security bypasses. perform task scheduling. time data theft and the size of exfiltration chunks. perform process injection. manage tasks and command execution. and more.

On the security bypass side, Kazuar is described as offering AMSI bypass, ETW bypass, and Windows Lockdown Policy (WLDP) bypass.. Microsoft says Secret Blizzard typically seeks long-term persistence on target systems for intelligence collections. including exfiltrating documents and email content that has political importance.

Between the “silent” non-leader systems. the kernel leader’s single communication path to the bridge module. and the bridge’s use of protocols like HTTP. WebSockets. or Exchange Web Services (EWS). the described architecture keeps most infected hosts from generating direct external traffic to the command-and-control infrastructure while still funneling tasks and data flow through a reduced set of contacts.

For defenders, Microsoft’s recommendation is to focus on behavioral detection rather than static signatures, arguing that Kazuar’s modular and highly configurable design makes the threat especially evasive.

Secret Blizzard Kazuar modular P2P botnet Microsoft analysis FSB-linked hacking keylogging screenshots data exfiltration AMSI bypass ETW bypass WLDP bypass Protobuf IPC command-and-control

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Secret Link