Russian hackers from the Turla are hacking other hackers, stealing the infrastructure of the Pakistani Storm-0156 to launch their own covert attacks on already compromised networks.
See also: Undercut: Russian Influence Campaign Against Ukraine

Using this tactic, the Turla group (also known as “Secret Blizzard”) gained access to networks previously compromised by Storm-0156, such as government organizations in Afghanistan and India, where they deployed their malware tools.
According to a report from Lumen's Black Lotus Labs, which has been tracking this campaign since January 2023 with the help of Microsoft's Threat Intelligence Team, the Russian hackers from Turla have been active since December 2022.
Turla is a Russian state-run hacking group linked to Center 16 of Russia's Federal Security Service (FSB), the unit responsible for monitoring, decoding, and collecting data from foreign targets.
See also: Russian cyberspies breached their target via Wi-Fi connection
Malicious actors have a long history of covert cyberespionage campaigns targeting governments, organizations, and research facilities worldwide since at least 1996.

They are the suspects behind cyberattacks targeting US Central Command, the Pentagon and NASA, several Eastern European foreign ministries, as well as the Finnish Ministry of Foreign Affairs.
Most recently, Five Eyes disrupted Turla’s “ Snake ” spyware botnet , which is used to compromise devices , steal data, and hide in compromised networks .
See also: Russian hackers exploit NTLM vulnerability to spread RAT Malware via Phishing emails
Russian hackers have gained a reputation for their attacks on a variety of sectors, including government organizations, companies, and private infrastructure. Their cyber activities have raised global concerns as they have discovered new techniques and exploited vulnerabilities in security systems. Countering the threat posed by Russian hackers requires close cooperation between governments, companies, and the public to develop and implement robust protection and deterrence measures.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
