# Kazuar P2P Botnet Evolution — Secret Blizzard (Russia FSB Center 16) Modular Espionage Implant with Kernel/Bridge/Worker Architecture

> Microsoft Threat Intelligence documents Kazuar's evolution from a monolithic .NET backdoor into a modular peer-to-peer botnet operated by Russian state actor Secret Blizzard (Turla / VENOMOUS BEAR / Snake / FSB Center 16). The implant splits responsibilities across three module types — Kernel (coordinator with leader election), Bridge (external C2 proxy), and Worker (collection/tasking) — using IPC over Window Messaging, Mailslots, and Named Pipes, with external command and control over HTTP, WebSockets, and Exchange Web Services. Active campaigns target government, diplomatic, and defense organizations across Europe, Central Asia, and Ukraine.

- **Published:** 2026-05-16T12:00:00Z
- **Last reviewed:** 2026-05-16T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0519
- **ID:** TL-2026-0519
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Turla (Russia)
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Secret Blizzard (also tracked as Turla, VENOMOUS BEAR, Uroburos, Snake, Blue Python, WRAITH, ATG26) is one of the longest-running Russian state-sponsored intrusion sets, attributed by CISA, the UK NCSC, and Five Eyes partners to the FSB's Center 16 (military unit 71330). The group has operated since at least the mid-1990s with a near-singular focus on long-term espionage against government, diplomatic, defense, and research targets. Kazuar, a .NET-based modular backdoor first publicly documented by Palo Alto Unit 42 in 2017 and most recently in a satellite DLL-sideloading V3 variant tracked under TL-2026-0084, has now been re-architected by Secret Blizzard into a full peer-to-peer botnet.

The new Kazuar architecture decomposes the implant into three discrete module types. The Kernel module is the in-host coordinator: exactly one Kernel acts as botnet leader per compromised network, while additional Kernels operate in a SILENT mode and participate only in inter-process communication, providing failover redundancy if the leader is killed or the host is rebooted. Leader election uses a deterministic algorithm seeded by per-host attributes (botnet version, install path, install timestamp) so that re-election after Kernel termination is fast and does not produce split-brain conditions. Bridge modules serve as external-facing C2 proxies, terminating outbound transports — default HTTP, with optional WebSockets over TLS (WSS) and Exchange Web Services (EWS) abusing on-premises and cloud Exchange mailboxes for covert tasking and exfiltration via draft messages. Worker modules are tasking executors — credential theft, file collection, screenshot capture, command execution, and lateral movement primitives — that never speak directly to the internet; all of their traffic is relayed via the local Kernel leader and one or more Bridge modules.

Inter-process communication between modules on the same host uses three transports. The default is Window Messaging using a registered window class and WM_COPYDATA structures. Mailslots and Named Pipes are alternatives configurable per-deployment. Pipe and mailslot names are not static — Kazuar derives them as MD5 hashes of fixed strings concatenated with the bot version (for example, the default pipe name resolves to \\.\pipe\82760B84F1D703D596C79B88BA4FAC1E, the MD5 of 'pipename-kernel-<BotVersion>'), making static signatures brittle while leaving structural detection viable. All IPC payloads, as well as external C2 messages, are serialized using Google Protocol Buffers, with up to 150 configuration options across 8 categories controlling beacon timing, transport selection, sleep windows, target Exchange folders, EWS credentials, and module loading.

Initial access in observed intrusions has included spearphishing with malicious documents, exploitation of edge devices including unpatched Exchange and Microsoft IIS instances, abuse of compromised infrastructure of other Russian actors (Microsoft observed Secret Blizzard piggybacking on Aqua Blizzard / Gamaredon footholds in Ukrainian systems), and ISP-level adversary-in-the-middle for diplomatic targets. Deployment uses droppers including the Pelmeni loader and ShadowLoader/KazuarLoader staging components, with the final KazuarModule artifacts loaded reflectively in memory. Persistence is established via scheduled tasks, registry Run keys, WMI event subscriptions, and DLL search-order hijacking against trusted Microsoft binaries. Defense evasion includes anti-analysis checks (debugger and sandbox detection), legitimate code-signing certificate abuse on droppers, IPC over Windows-native primitives that blend into normal process behavior, and use of cloud Exchange tenants as C2 to avoid network-perimeter blocks.

The campaign primarily targets Ministries of Foreign Affairs, embassies, defense ministries, and parliamentary bodies across Europe and Central Asia, plus systems in Ukraine where Secret Blizzard has been documented operating on top of access provided by other FSB and GRU-linked clusters. The operational tempo, modular tradecraft, and infrastructure compartmentalization strongly indicate intelligence collection in support of Russian foreign policy and military objectives rather than financially motivated activity. Defenders should treat any observation of the named-pipe or mailslot derivation patterns, anomalous EWS draft-folder polling, or unsigned/sideloaded .NET assemblies invoking Protobuf serialization in long-lived processes as high-fidelity Kazuar indicators.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1588 Obtain Capabilities
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1546 Event Triggered Execution
- T1574 Hijack Execution Flow
- T1620 Reflective Code Loading
- T1553 Subvert Trust Controls
- T1497 Virtualization/Sandbox Evasion
- T1036 Masquerading
- T1003 OS Credential Dumping
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1057 Process Discovery
- T1087 Account Discovery
- T1021 Remote Services
- T1113 Screen Capture
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1559 Inter-Process Communication
- T1090 Proxy
- T1102 Web Service
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1048 Exfiltration Over Alternative Protocol

## Sources

- [Kazuar: Anatomy of a nation-state botnet](https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/)
- [CISA AA23-129A — Snake Implant: Hunting Russian Intelligence Snake Malware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a)
- [MITRE ATT&CK Group G0010 — Turla](https://attack.mitre.org/groups/G0010/)
- [MITRE ATT&CK Software S0265 — Kazuar](https://attack.mitre.org/software/S0265/)
- [Unit 42: Kazuar — Multiplatform Espionage Backdoor with API Access](https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/)
- [Sekoia.io — Turla Kazuar new variant analysis](https://blog.sekoia.io/turla-a-galaxy-of-opportunities/)
- [Microsoft Threat Intelligence — Secret Blizzard deploys backdoors on Ukrainian targets via Aqua Blizzard access](https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-i-secret-blizzard-compromising-storm-0156-infrastructure-for-espionage/)
- [Kaspersky Securelist — Pelmeni dropper and Kazuar V2](https://securelist.com/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0519
