# Forest Blizzard

> As of 2026-09-19, Forest Blizzard is a threat actor tracked by Threadlinqs Intelligence across 18 threats spanning malware, apt, threat intel. ATT&CK coverage spans 165 techniques across 15 tactics in 18 of 18 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1566 (Phishing), T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 18
- **Categories:** MALWARE, APT, THREAT_INTEL, VULNERABILITY, PHISHING
- **As of:** 2026-09-19

## ATT&CK techniques observed

165 techniques observed across 18 of 18 tracked threats. Tactics: Credential Access (19), Stealth (formerly Defense Evasion) (19), Resource Development (18), Collection (17), Discovery (15), Execution (15).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 13 of 18 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 13 of 18 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 11 of 18 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 11 of 18 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 11 of 18 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 10 of 18 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 10 of 18 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 10 of 18 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 9 of 18 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 9 of 18 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 9 of 18 tracked threats
- [T1114](https://intel.threadlinqs.com/technique/T1114) Email Collection — Collection — observed in 8 of 18 tracked threats
- [T1203](https://intel.threadlinqs.com/technique/T1203) Exploitation for Client Execution — Execution — observed in 8 of 18 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 8 of 18 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 7 of 18 tracked threats

## Tracked threats

- [APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye](https://intel.threadlinqs.com/threat/TL-2026-2213) — HIGH
- [HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2](https://intel.threadlinqs.com/threat/TL-2026-2187) — HIGH
- [BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2173) — HIGH
- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines](https://intel.threadlinqs.com/threat/TL-2026-2058) — HIGH
- [APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)](https://intel.threadlinqs.com/threat/TL-2026-0727) — HIGH
- [Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials via msDS-KeyCredentialLink (CVE-2022-26923, Fog Ransomware, Fighting Ursa)](https://intel.threadlinqs.com/threat/TL-2026-0497) — HIGH
- [APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0330) — HIGH
- [Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain](https://intel.threadlinqs.com/threat/TL-2026-0285) — CRITICAL
- [ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools](https://intel.threadlinqs.com/threat/TL-2026-0282) — HIGH
- [Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail](https://intel.threadlinqs.com/threat/TL-2026-0266) — CRITICAL
- [APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509)](https://intel.threadlinqs.com/threat/TL-2026-0204) — HIGH
- [APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0188) — HIGH
- [APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing](https://intel.threadlinqs.com/threat/TL-2026-0133) — HIGH
- [Operation MacroMaze: APT28 Campaign Targeting Western & Central Europe via Evolving Macro Droppers & Legitimate Infrastructure Abuse](https://intel.threadlinqs.com/threat/TL-2026-0083) — MEDIUM
- [APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs)](https://intel.threadlinqs.com/threat/TL-2026-0066) — HIGH
- [APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-0052) — CRITICAL
- [CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against Ukraine](https://intel.threadlinqs.com/threat/TL-2026-0041) — CRITICAL
- [CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)](https://intel.threadlinqs.com/threat/TL-2026-0021) — HIGH

## Related CVEs

13 CVEs referenced by tracked Forest Blizzard activity.

- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2022-26923](https://intel.threadlinqs.com/cve/CVE-2022-26923)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2017-6742](https://intel.threadlinqs.com/cve/CVE-2017-6742)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Forest%20Blizzard
