Threats · 122 days ago
Kazuar is no longer just a backdoor you remove from one machine and move on. Microsoft says Secret Blizzard has turned it into a modular P2P botnet, which keeps covert access alive even when individual hosts are taken out.
Microsoft describes Kernel, Bridge, and Worker roles, with restricted external communications through a single elected leader and fallback C2 paths. The targeting remains focused on government and diplomatic networks in Europe and Central Asia, where the goal is long-term intelligence collection.
The shift matters because cleanup on one endpoint may not end the intrusion if peers remain connected. The real risk is a durable espionage foothold that is built to survive partial disruption.
3 sources covering this story
Russian hackers turn Kazuar backdoor into modular P2P botnet
The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection.
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
Turla turns Kazuar into a 3-module P2P botnet, enabling stealthy C2, resilient tasking, and persistent access.
Kazuar: Anatomy of a nation-state botnet | Microsoft Security Blog
Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target environments.
Part of the PlainSec briefing for 2026-05-17