Microsoft reported that Kazuar, a malware family attributed to the Russian state actor Secret Blizzard, has evolved from a conventional backdoor into a modular peer-to-peer botnet built for long-term espionage. The company said the malware now operates through three coordinated components—Kernel, Bridge, and Worker—that divide command-and-control, internal relay, and task execution functions to reduce visible network traffic and improve resilience. According to the report, Kazuar can communicate over HTTP, WebSockets, or Exchange Web Services, uses anti-analysis checks, stores encrypted staging data locally, and employs a leader-election mechanism so only one Kernel node communicates externally for the wider botnet.
Microsoft said Kazuar is delivered through droppers including Pelmeni and is tied to Secret Blizzard, which it links to Russia’s FSB Center 16. The malware has been associated with espionage targeting of government and diplomatic organizations in Europe, Central Asia, and Ukraine, reflecting a focus on stealthy persistence rather than disruptive attacks. Microsoft published mitigations, Microsoft Defender detections, and sample indicators of compromise to help defenders identify and contain infections tied to the botnet.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft published an analysis describing Kazuar as a long-evolving malware family attributed to the Russian state actor Secret Blizzard, now operating as a modular peer-to-peer botnet for stealthy long-term espionage. The report outlined its Kernel, Bridge, and Worker modules, delivery via droppers such as Pelmeni, anti-analysis features, resilient command-and-control methods, and provided detections, mitigations, and indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.polyswarm.io
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcemicrosoft.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcegist.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.