ctipilot.ch

Secret Blizzard

actor · actor:secretblizzard single-source

Russian FSB Centre 16 APT (Microsoft: Secret Blizzard; historically Turla); 2026 coverage includes Microsoft Threat Intelligence's Kazuar P2P botnet anatomy (2026-05-14) and the STOCKSTAY diplomatic-espionage backdoor of Kazuar lineage.

Aliases: Turla, FSB Centre 16, TURLA RELIC

Coverage timeline
9
first 2026-05-11 → last 2026-07-19
Peak priority
high
5 high · 4 notable
Sources cited
33
24 hosts
Sections touched
8
active-threats, deep-dive, research
Co-occurring entities
7
see Related entities below
ATT&CK techniques
32
pinned v19.2 · see below
2026-05-119 appearances2026-07-19

ATT&CK techniques

32 techniques observed across 6 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595.001Active Scanning: Scanning IP Blocks×1

Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Resource Development TA0042

T1583.003Acquire Infrastructure: Virtual Private Server×1

Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1584.004Compromise Infrastructure: Server×1

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Evidence: 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1584.008Compromise Infrastructure: Network Devices×1

Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1588.005Obtain Capabilities: Exploits×1

Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1190Exploit Public-Facing Application×5

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-19/weekly-w29-vuln-status-rollup · 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

T1566Phishing×2

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-19/weekly-w29-vuln-status-rollup · ATT&CK page ↗

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×2

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-19/weekly-w29-vuln-status-rollup · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes · ATT&CK page ↗

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×2

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes · ATT&CK page ↗

T1480Execution Guardrails×1

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

Defense Impairment TA0112

T1601.001Modify System Image: Patch System Image×1

Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Credential Access TA0006

T1003OS Credential Dumping×1

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1602.001Data from Configuration Repository: SNMP (MIB Dump)×2

Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).

Evidence: 2026-07-19/weekly-w29-russia-state-nexus-ci-prepositioning-sanctions · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

T1602.002Data from Configuration Repository: Network Device Configuration Dump×1

Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×2

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat · ATT&CK page ↗

T1048Exfiltration Over Alternative Protocol×1

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗

Story timeline

  1. 2026-07-192026-W29 vulnerability status roll-up — nine CVEs crossed into confirmed exploitation/KEV, two more carry public exploit code, and a dense critical-but-unexploited tail hit edge, ERP and OT
    weekly-vuln-rollupW29 CVE trajectory — nine exploited/KEV (SonicWall, ShareFile, Oracle EBS, SharePoint/AD FS, KNX), two public-exploit (WP2Shell, Firefox), a dense critical tail
  2. 2026-07-19Russian state-nexus pre-positioning against European critical infrastructure reached a new attribution-and-consequence threshold this week — router hijacking, the Turla espionage cluster, the Poland grid attack and camera surveillance all named on the same day the EU and UK imposed their first joint cyber-sanctions
    weekly-top-storiesRussian FSB pre-positioning against European CI went public — router hijacking, the Turla and Poland-grid attributions, and the first joint EU/UK sanctions
  3. 2026-07-13AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments
    active-threatsDutch intelligence: Russia hijacked default-credential internet cameras along military-supply routes; four EU states summon Russian ambassadors
  4. 2026-07-13FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
    deep-dive19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland's Dec-2025 grid sabotage
  5. 2026-07-13France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions
    updatesANSSI publishes CERTFR-2026-CTI-005 on FSB Centre 16's Turla cluster as France and the EU formally attribute it and sanction AO AST and NPP Gamma
  6. 2026-06-29Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters
    weekly-research
  7. 2026-06-27Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection
    deep-dive
  8. 2026-06-26ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)
    research
  9. 2026-05-11Public administration and government
    weekly-sector-patterns

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

collaborates with

documented in

related to

attributed activity

Where this entity is cited

  • deep-dive2
  • weekly-sector-patterns1
  • research1
  • weekly-research1
  • updates1
  • active-threats1
  • weekly-top-stories1
  • weekly-vuln-rollup1

Source distribution

  • attack.mitre.org5 (15%)
  • bleepingcomputer.com2 (6%)
  • cisa.gov2 (6%)
  • nltimes.nl2 (6%)
  • thehackernews.com2 (6%)
  • welivesecurity.com2 (6%)
  • blog.talosintelligence.com1 (3%)
  • cert.pl1 (3%)
  • other16 (48%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (33)

Entries about Secret Blizzard (9)

2026-07-19 · view entry permalink →

HIGHexploitedNATOA1

2026-W29 vulnerability status roll-up — nine CVEs crossed into confirmed exploitation/KEV, two more carry public exploit code, and a dense critical-but-unexploited tail hit edge, ERP and OT

This roll-up tracks the week's CVEs by exploitation trajectory, not severity score. Per-CVE mechanics, affected/fixed versions and evidence are in the referenced operational entries.

Confirmed exploited / newly KEV-listed this week. Four Microsoft on-prem items moved: AD FS CVE-2026-56155 and SharePoint CVE-2026-56164 shipped 2026-07-14 as exploited zero-days KEV-listed the same day, and CVE-2026-58644 — a July SharePoint RCE first rated only "Exploitation More Likely" — was confirmed exploited and KEV-added on 2026-07-16, with CISA naming it in a cluster it is "aware of active exploitation" of (CISA, 2026-07-16). SonicWall SMA1000 CVE-2026-15409/-15410 (KEV 2026-07-14) and Oracle EBS Payments CVE-2026-46817 (KEV 2026-07-15, CISA) both carried confirmed in-the-wild exploitation, as did ShareFile SZC CVE-2026-2699. Two older CVEs joined KEV as actively exploited: Cisco Smart Install CVE-2018-0171 (the FSB Centre 16 router vector) and — notably for OT — KNX Connection Authorization CVE-2023-4346, a three-year-old account-lockout flaw whose fix is procedural, not a patch.

Public exploit code, no confirmed in-the-wild abuse (short fuse). WordPress core's "WP2Shell" chain (CVE-2026-63030 route-confusion in the unauthenticated REST batch endpoint + CVE-2026-60137 WP_Query SQL injection) reaches pre-auth RCE on a stock install; public PoC is already on GitHub and NCSC-NL assesses short-term exploitation is expected. Firefox 152.0.6 fixed a WebAssembly memory bug (CVE-2026-15718) and a site-isolation bypass (CVE-2026-15719) with public exploit code, though Mozilla states no in-the-wild abuse — contrary to some aggregator "zero-day" framing.

Critical-but-unexploited tail (scheduled, exposure-driven action). No confirmed exploitation yet, but each is a pre-auth or high-impact flaw on exposed or CI-relevant software: SAP's July set (CVE-2026-44747 NetWeaver kernel, CVE-2026-27690 Approuter request-smuggling, CVE-2026-44761 Commerce Cloud hardcoded credential — the last a config exposure a patch alone does not close); VMware Avi Load Balancer control-plane auth bypass CVE-2026-47865 (reported by NATO NCSC, no workaround); Siemens RUGGEDCOM ROX II's three-CVE chain to persistent root (CVE-2025-40947/40948/40949); Rockwell 1715-AENTR CVE-2026-10577 (CVSS 10.0 unauthenticated debug-port takeover) and the ABB T-MAC chain; Abacus ERP's unauthenticated RCE (CVSS 9.8, no CVE, NCSC-CH-flagged, ubiquitous in Switzerland); and Moodle's local_o365 JWT-signature-non-verification takeover CVE-2026-54733 across the European public-sector LMS estate.

Builds on: 2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain · 2026-07-14/progress-sharefile-szc-active-exploitation-confirmed · 2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed · 2026-07-17/cve-2026-58644-sharepoint-confirmed-exploited-kev · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · 2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev · 2026-07-18/wordpress-core-wp2shell-preauth-rce-chain-cve-2026-63030 · 2026-07-17/firefox-152-0-6-wasm-site-isolation-public-exploit · 2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud · 2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass · 2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain · 2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot · 2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch · 2026-07-18/moodle-local-o365-jwt-forgery-admin-takeover-cve-2026-54733

vulnerability19 Jul 23:44Zmulti-sourceOpen finding ↗
Sources: CISA

2026-07-19 · view entry permalink →

HIGHexploitedNATOA1

Russian state-nexus pre-positioning against European critical infrastructure reached a new attribution-and-consequence threshold this week — router hijacking, the Turla espionage cluster, the Poland grid attack and camera surveillance all named on the same day the EU and UK imposed their first joint cyber-sanctions

If you did nothing this week: the internet-facing routers and IP cameras in your estate are exactly the collection surface a 19-agency advisory and Dutch intelligence just documented Russian state actors harvesting at scale — default or weak SNMP community strings, unpatched Cisco Smart Install, and default-credential cameras are being enumerated and read now, not hypothetically.

The week's Russian-state thread was not one disclosure but four landing together, which is itself the signal. The router-hijacking advisory describes FSB Centre 16 (Static Tundra / Berserk Bear) doing something deliberately unglamorous at scale: "The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication" and pair that with the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to pull device configurations out of energy, government, telecom, finance and healthcare networks (joint advisory, 2026-07-13). The consequence side arrived the same day: "The UK together with EU member states has also today formally attributed the December 2025 attack on Poland's energy grid to Russia's FSB Centre 16" (NCSC-UK, 2026-07-13), with the FCDO framing that a "reckless attack ... could have caused 500,000 citizens to lose electricity in the depths of winter" and the EU and UK issuing their first joint cyber-sanctions package (UK Government, 2026-07-13). France's ANSSI simultaneously attributed the Turla espionage set (SecretBlizzard) to the same FSB 16th Centre in CERTFR-2026-CTI-005, with the EU sanctioning 9 individuals and 4 organisations and the UK 24 (CERT-FR, 2026-07-13).

Running underneath all of it, Dutch intelligence disclosed that "Russian actors had compromised 'a small number of cameras' on routes for military shipments to Ukraine" — internet-connected cameras reachable because of default passwords and outdated firmware — a physical-surveillance use of the same exposed-device class the router advisory addresses (NL Times, 2026-07-11).

The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication

NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries) 2026-07-13

The UK together with EU member states has also today formally attributed the December 2025 attack on Poland's energy grid to Russia's FSB Centre 16.

NCSC-UK 2026-07-13

Dutch intelligence services disclosed Friday that Russian actors had compromised “a small number of cameras” on routes for military shipments to Ukraine.

NL Times (ANP) 2026-07-11

Builds on: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology · 2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes

synthesis19 Jul 23:42Zmulti-sourceOpen finding ↗

2026-07-13 · view entry permalink →

NOTABLENATOB2

AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments

Dutch intelligence services AIVD (General Intelligence and Security Service) and MIVD (Military Intelligence and Security Service) disclosed on 2026-07-11 that Russia-linked actors compromised "a small number" of internet-connected cameras positioned along routes used to move military supplies to Ukraine through the Netherlands — including cameras operated by businesses located on those routes — giving the operators remote viewing access to the shipments and equipment being moved (NL Times/ANP, 2026-07-11). The agencies state the cameras were reachable chiefly because they "still us[e] default passwords or outdated firmware" — weak/default-credential abuse and unpatched embedded firmware on internet-exposed devices, not a bespoke exploit chain. On 2026-07-13, after EU ministerial consultations in Brussels, the Netherlands summoned the Russian ambassador; France, Germany and Finland took the same step over related espionage and sabotage concerns, and NATO issued a joint statement condemning "the persistent malicious cyber activities of Russia" (NL Times/ANP, 2026-07-13). AIVD/MIVD separately warned businesses located along military-logistics routes to harden their camera and IoT security. This is a distinct technical story from the same-day FSB Centre 16 router-hijacking advisory and the Turla espionage attribution covered separately today — here the compromised asset class is consumer/commercial IP cameras used for physical-logistics surveillance.

Dutch intelligence services disclosed Friday that Russian actors had compromised “a small number of cameras” on routes for military shipments to Ukraine. The breaches allowed the hackers remote viewing access, according to statements from the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).

We strongly condemn the persistent malicious cyber activities of Russia. The country uses its cyber ecosystem to attack allies and NATO partners.

NL Times (ANP) 2026-07-11
incident13 Jul 20:36Zsingle-sourceOpen finding ↗

Earlier coverage (6)

2026-07-13NOTABLEupdateNATOA2France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctionsOn 2026-07-13 France (ANSSI/C4) and the EU High Representative formally attributed the Turla intrusion set to Russia's FSB 16th Centre, publishing CERT-FR report CERTFR-2026-CTI-005 with French victimology (defence, diplomatic, justice and technology entities since 2017) and its spearphishing/watering-hole TTPs; the EU sanctioned 9 individuals and 4 organisations (incl. AO AST, NPP Gamma) and the UK sanctioned 24. Companion to the morning's Static Tundra router-hijacking advisory — the sibling FSB Centre 16 espionage cluster.2026-07-13HIGHexploitedNATOA1FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctionsA joint Cybersecurity Advisory from 19 agencies across 13 countries (2026-07-13) details how Russian FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically compromises internet-facing routers across energy, government, telecom, finance and healthcare — chiefly by abusing default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations. On the same day the UK and EU formally attributed the destructive 29 Dec 2025 attack on Poland's energy grid to this FSB unit and imposed their first joint cyber-sanctions package. Swiss and European critical-infrastructure operators running Cisco IOS/IOS XE or legacy SNMP on exposed network devices should treat router hygiene as an active-exploitation priority.2026-06-29HIGHThreat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clustersTurla's new STOCKSTAY backdoor (GTIG) broadens Russia-nexus espionage toward Western-European foreign-policy targets — delivered via WinRAR CVE-2025-8088 and malicious RDP files; relevant to Swiss/EU governmental entities with Ukraine-adjacent policy work. (daily 06-26, Google GTIG)2026-06-27NOTABLEexploitedTurla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collectionBackground. Google Threat Intelligence Group (GTIG, formerly Mandiant) published a full technical analysis of STOCKSTAY on 2026-06-25, a modular .NET backdoor it attributes with high confidence to Turla — also tracked as Secret Blizzard, SUMMIT and FSB Center 16 — with activity dating to December 2022 (Google …2026-06-26HIGHESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)ESET's 2025 Gamaredon paper shows the FSB group's exfil and C2 moving entirely onto trusted cloud services — S3-compatible object storage (Wasabi/Tebi/Intercolo) via rclone and Cloudflare-tunnel/Workers/DevTunnel C2 that blends with legitimate egress; targeting stayed exclusively Ukrainian, but the tradecraft is the transferable part (ESET, 2026-06-25).2026-05-11NOTABLEPublic administration and governmentThree operator clusters made the public-administration / government sector pattern this week. Secret Blizzard / Turla (FSB Centre 16) evolved Kazuar into a three-module P2P botnet; Microsoft Threat Intelligence's 2026-05-14 analysis documents historical targeting of government and diplomatic-sector organizations …