Russia’s Blizzard Threat Actor Groups Launch Campaigns Against Ukraine and NATO Members for Intelligence Gathering and Espionage

Microsoft Threat Intelligence (Microsoft’s global network of security experts) has analyzed and come to the conclusion that Russian threat actors who have been labelled as ‘Blizzard’ threat actor groups have been launching campaigns primarily targeting Ukraine and NATO members with the aim of intelligence gathering and espionage.
Read more about it below.
Blizzard Threat Actor Groups Strikes Ukraine and NATO Members for Intelligence Gathering and Espionage?
The political turmoil between Russia and Ukraine has been ongoing for several years and the issues are always heating up day by day. Also, Ukraine has shown a strong desire to join NATO and we have also seen NATO providing support for Ukraine during difficulties, however the country is still not a part of NATO yet, and the Russian government has already taken severe measures to counter this alliance, and cyber security threats is one among them.
As mentioned above, as part of state-sponsored campaigns, Blizzard threat actor groups of Russia have been targeting Ukraine and NATO, and this conclusion was reached via the analysis made by Microsoft’s security researchers with the data from previous cyber security threat activities dating from November 2023 to October 2024. Based on this, it was also understood that the main aim of these campaigns was for intelligence gathering and espionage. Microsoft Threat Intelligence reports that these treat groups focus mainly on industries such as IT, education, NGOs as well as other government organizations, and this is to access intelligence that is related with Ukraine support.
Furthermore, it has also been understood and observed that these threat actor groups use state-sponsored and cyber criminal tools and infrastructures to carry out their espionage operations. For example, Secret Blizzard, a Russian threat actor, makes use of tools and infrastructure of at least six other threat actors. While this allowed them to easily gain access to networks of their interests with only a minimal effort, it has also been pointed out that this will lead to the exposure of Secret Blizzard’s or other threat actors activities too.