Threat reportMalwareTL-2026-0519

Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with Kernel/Bridge/Worker Architecture

highACTIVE

Kazuar P2P Botnet Evolution (TL-2026-0519), also tracked as Kazuar P2P, is a high-severity malware campaign, first published 2026-05-16. It is attributed to Turla (Russia) with high confidence, affects Microsoft Windows, maps to 31 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
1Turla
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-0519

Threat ID
TL-2026-0519
Also known as
Kazuar P2P, Kazuar Botnet, KazuarModule, Turla P2P Implant
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Turla
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, diplomatic, defense, ministries-of-foreign-affairs, embassies, parliament, intelligence-community
Target regions
Europe, Central Asia, Ukraine, Eastern Europe, Balkans
Detection rules
9
Indicators of compromise
23

Malware and tooling in Kazuar P2P Botnet Evolution

Malware and tooling: Kazuar - S0265, Pelmeni, Kazuar P2P Modular Implant, KazuarLoader, ShadowLoader

How Kazuar P2P Botnet Evolution works

Microsoft Threat Intelligence documents Kazuar's evolution from a monolithic .NET backdoor into a modular peer-to-peer botnet operated by Russian state actor Secret Blizzard (Turla / VENOMOUS BEAR / Snake / FSB Center 16). The implant splits responsibilities across three module types — Kernel (coordinator with leader election), Bridge (external C2 proxy), and Worker (collection/tasking) — using IPC over Window Messaging, Mailslots, and Named Pipes, with external command and control over HTTP, WebSockets, and Exchange Web Services. Active campaigns target government, diplomatic, and defense organizations across Europe, Central Asia, and Ukraine.

Secret Blizzard (also tracked as Turla, VENOMOUS BEAR, Uroburos, Snake, Blue Python, WRAITH, ATG26) is one of the longest-running Russian state-sponsored intrusion sets, attributed by CISA, the UK NCSC, and Five Eyes partners to the FSB's Center 16 (military unit 71330). The group has operated since at least the mid-1990s with a near-singular focus on long-term espionage against government, diplomatic, defense, and research targets. Kazuar, a .NET-based modular backdoor first publicly documented by Palo Alto Unit 42 in 2017 and most recently in a satellite DLL-sideloading V3 variant tracked under TL-2026-0084, has now been re-architected by Secret Blizzard into a full peer-to-peer botnet.

The new Kazuar architecture decomposes the implant into three discrete module types. The Kernel module is the in-host coordinator: exactly one Kernel acts as botnet leader per compromised network, while additional Kernels operate in a SILENT mode and participate only in inter-process communication, providing failover redundancy if the leader is killed or the host is rebooted. Leader election uses a deterministic algorithm seeded by per-host attributes (botnet version, install path, install timestamp) so that re-election after Kernel termination is fast and does not produce split-brain conditions. Bridge modules serve as external-facing C2 proxies, terminating outbound transports — default HTTP, with optional WebSockets over TLS (WSS) and Exchange Web Services (EWS) abusing on-premises and cloud Exchange mailboxes for covert tasking and exfiltration via draft messages. Worker modules are tasking executors — credential theft, file collection, screenshot capture, command execution, and lateral movement primitives — that never speak directly to the internet; all of their traffic is relayed via the local Kernel leader and one or more Bridge modules.

Inter-process communication between modules on the same host uses three transports. The default is Window Messaging using a registered window class and WM_COPYDATA structures. Mailslots and Named Pipes are alternatives configurable per-deployment. Pipe and mailslot names are not static — Kazuar derives them as MD5 hashes of fixed strings concatenated with the bot version (for example, the default pipe name resolves to \\.\pipe\82760B84F1D703D596C79B88BA4FAC1E, the MD5 of 'pipename-kernel-<BotVersion>'), making static signatures brittle while leaving structural detection viable. All IPC payloads, as well as external C2 messages, are serialized using Google Protocol Buffers, with up to 150 configuration options across 8 categories controlling beacon timing, transport selection, sleep windows, target Exchange folders, EWS credentials, and module loading.

Initial access in observed intrusions has included spearphishing with malicious documents, exploitation of edge devices including unpatched Exchange and Microsoft IIS instances, abuse of compromised infrastructure of other Russian actors (Microsoft observed Secret Blizzard piggybacking on Aqua Blizzard / Gamaredon footholds in Ukrainian systems), and ISP-level adversary-in-the-middle for diplomatic targets. Deployment uses droppers including the Pelmeni loader and ShadowLoader/KazuarLoader staging components, with the final KazuarModule artifacts loaded reflectively in memory. Persistence is established via scheduled tasks, registry Run keys, WMI event subscriptions, and DLL search-order hijacking against trusted Microsoft binaries. Defense evasion includes anti-analysis checks (debugger and sandbox detection), legitimate code-signing certificate abuse on droppers, IPC over Windows-native primitives that blend into normal process behavior, and use of cloud Exchange tenants as C2 to avoid network-perimeter blocks.

The campaign primarily targets Ministries of Foreign Affairs, embassies, defense ministries, and parliamentary bodies across Europe and Central Asia, plus systems in Ukraine where Secret Blizzard has been documented operating on top of access provided by other FSB and GRU-linked clusters. The operational tempo, modular tradecraft, and infrastructure compartmentalization strongly indicate intelligence collection in support of Russian foreign policy and military objectives rather than financially motivated activity. Defenders should treat any observation of the named-pipe or mailslot derivation patterns, anomalous EWS draft-folder polling, or unsigned/sideloaded .NET assemblies invoking Protobuf serialization in long-lived processes as high-fidelity Kazuar indicators.

MITRE ATT&CK techniques used in TL-2026-0519

Credential Access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

Collection

T1005 Data from Local System; T1113 Screen Capture

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Persistence

T1053 Scheduled Task/Job; T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1087 Account Discovery

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1573 Encrypted Channel

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing

defense-impairment

T1553 Subvert Trust Controls

execution

T1559 Inter-Process Communication

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities

Affected products and versions in Kazuar P2P Botnet Evolution

  • Microsoft — Windows
    Vulnerable versions: 7; 8.1; 10; 11; Server 2012 R2; Server 2016; Server 2019; Server 2022
  • Microsoft — Exchange Server
    Vulnerable versions: 2016; 2019
  • Microsoft — Exchange Online (EWS)
    Vulnerable versions: All tenants with legacy basic-auth EWS enabled

Remediation for Kazuar P2P Botnet Evolution

Patches

  • Apply latest cumulative Exchange Server security updates to remove SSRF / ProxyShell-class footholds used for initial access
  • Patch internet-facing IIS, edge VPN, and firewall management planes — Secret Blizzard routinely chains edge-device exploitation into Kazuar deployment

Immediate actions

  • Hunt for named pipes and mailslots whose names match an MD5-hex (32-char) pattern in long-lived processes — Kazuar derives IPC channel names as MD5(<role>-<BotVersion>)
  • Audit on-prem and Microsoft 365 Exchange mailboxes for service accounts polling Drafts/Deleted Items folders via EWS from unexpected client IPs or User-Agent strings
  • Block egress to known Secret Blizzard infrastructure ranges and rotate credentials for any Exchange/EWS service accounts exposed to the internet
  • Search EDR telemetry for .NET assemblies in non-standard paths loading Google.Protobuf or System.Net.WebSockets in processes that do not normally use either

Workarounds

  • If full EDR coverage is not available, enable Sysmon with event IDs 1 (process create), 7 (image load), 17/18 (named pipes), and 22 (DNS) and forward to SIEM with Kazuar-aware analytics
  • Restrict outbound WebSocket (WSS) traffic from server and workstation segments to an explicit allow-list

Longer-term hardening

  • Deploy EDR with behavioral coverage for Window Messaging IPC (WM_COPYDATA between unrelated processes), Mailslot use outside of admin tooling, and unsigned .NET assemblies executing reflectively
  • Enforce conditional access and modern auth on all Exchange Online tenants; disable legacy basic-auth EWS where possible
  • Apply application allow-listing (WDAC / AppLocker) to constrain DLL sideloading paths abused by Pelmeni and KazuarLoader
  • Network-segment diplomatic and ministerial workstations from internet-facing relay hosts so Bridge modules cannot be installed transparently

Timeline of Kazuar P2P Botnet Evolution

  • Turla / Snake / Uroburos toolkit lineage first observed; later attributed by Five Eyes and CISA to FSB Center 16 (military unit 71330).
  • Palo Alto Unit 42 publishes first public analysis of Kazuar as a multiplatform .NET espionage backdoor with REST-style C2 API.
  • CISA, FBI, and partners publish AA23-129A and announce Operation MEDUSA disrupting Turla's Snake implant network — Secret Blizzard continues operating with Kazuar lineage.
  • Kaspersky and other vendors document Kazuar V2 with the Pelmeni dropper used against diplomatic targets.
  • Microsoft details Secret Blizzard piggybacking on Aqua Blizzard (Gamaredon) footholds in Ukrainian systems to deploy Kazuar.
  • Initial telemetry hints at multi-module Kazuar variants with internal IPC; isolated samples observed in European diplomatic intrusions.
  • First Bridge module sample fully extracted from a compromised Ministry of Foreign Affairs host in Central Asia, revealing EWS-based external C2.
  • Microsoft researchers reverse-engineer Kernel leader election algorithm and SILENT-mode failover behavior across multiple intrusion sets.
  • Microsoft Threat Intelligence publishes comprehensive Kazuar P2P botnet analysis covering Kernel/Bridge/Worker architecture, IPC mechanisms, and external C2 transports.
  • Threadlinqs Intelligence publishes TL-2026-0519 with detection coverage and adversary simulation for Kazuar P2P botnet tradecraft.
  • As of 2026-05-29, the Kazuar P2P botnet remains an active espionage threat: Microsoft's 2026-05-14 disclosure and broad late-May coverage confirm Secret Blizzard (Turla/FSB Center 16) is still running evolving Kazuar campaigns against European/Central Asian/Ukrainian government targets. No takedown, sinkhole, or arrest has occurred, and the actor and tooling stay fully operational.

Sources cited for Kazuar P2P Botnet Evolution

Detection coverage for TL-2026-0519

As of 2026-05-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0519 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats