A subgroup of the Russian state-sponsored hacking group APT44, also known as 'Seashell Blizzard' and 'Sandworm', has been targeting critical organizations and governments in a multi-year campaign dubbed 'BadPilot.' The threat actor has been active since at least 2021 and is also responsible for breaching networks of organizations in energy, oil and gas, telecommunications, shipping, and arms manufacturing sectors. Microsoft's Threat Intelligence team says that the actor is dedicated to achieving initial access to target systems, establishing persistence, and maintaining presence to allow other APT44 subgroups with post-compromise expertise to take over. "We have also observed the initial access subgroup to pursue access to an organization prior to a Seashell Blizzard-linked destructive attack," reads a Microsoft report shared with BleepingComputer. Microsoft's assessment is "that Seashell Blizzard uses this initial access subgroup to horizontally scale their operations as new exploits are acquired and to sustain persistent access to current and future sectors of interest to Russia." Microsoft's earliest observations of the subgroup's activity show opportunistic operations targeting Ukraine, Europe, Central and South Asia, and the Middle East, focusing on critical sectors. Starting 2022, following Russia's invasion of Ukraine, the subgroup intensified its operations against critical infrastructure supporting Ukraine, including government, military, transportation, and logisti...
BadPilot network hacking campaign fuels Russian SandWorm attacks
BleepingComputer
·Bill Toulas
·Published Feb 12, 2025
·Updated
Affected Software
3 affected components
SimpleHelp Remote Monitoring and Management (RMM) software
Palo Alto Networks PAN-OS
Microsoft Threat Intelligence
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the BadPilot hacking campaign led by a subgroup of the Russian APT44 group, targeting critical organizations and governments.
2
What security implications are discussed?
The article highlights that the BadPilot campaign poses a significant threat to national security and critical infrastructure.
3
What products or software are affected by the BadPilot campaign?
The affected software includes SimpleHelp Remote Monitoring and Management, Palo Alto Networks PAN-OS, and Microsoft Threat Intelligence.
4
Who is behind the BadPilot hacking campaign?
The BadPilot campaign is attributed to a subgroup of the Russian state-sponsored hacking group known as Sandworm.
5
How long has the BadPilot campaign been ongoing?
The BadPilot hacking campaign has been ongoing for multiple years, targeting various organizations.