Activity timeline
Forest Blizzard appears in 18 tracked threats between and ; the busiest month was 2026-02 with 6 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 13 of 18 tracked threats
- T1566 Phishing — Initial Accessobserved in 13 of 18 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 11 of 18 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 11 of 18 tracked threats
- T1204 User Execution — Executionobserved in 11 of 18 tracked threats
- T1005 Data from Local System — Collectionobserved in 10 of 18 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 10 of 18 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 10 of 18 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 9 of 18 tracked threats
- T1102 Web Service — Command and Controlobserved in 9 of 18 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 9 of 18 tracked threats
- T1114 Email Collection — Collectionobserved in 8 of 18 tracked threats
- T1203 Exploitation for Client Execution — Executionobserved in 8 of 18 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 8 of 18 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 7 of 18 tracked threats
Tracked threats
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and TürkiyeHIGH
- HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2HIGH
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE BackdoorHIGH
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch TimelinesHIGH
- APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)HIGH
- Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials via msDS-KeyCredentialLink (CVE-2022-26923, Fog Ransomware, Fighting Ursa)HIGH
- APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential TheftHIGH
- Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply ChainCRITICAL
- ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System ToolsHIGH
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMailCRITICAL
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509)HIGH
- APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical InfrastructureHIGH
- APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-PhishingHIGH
- Operation MacroMaze: APT28 Campaign Targeting Western & Central Europe via Evolving Macro Droppers & Legitimate Infrastructure AbuseMEDIUM
- APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs)HIGH
- APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage CampaignCRITICAL
- CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against UkraineCRITICAL
- CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)HIGH