INTEL_REPORT
Microsoft Security Blog · published 5/14/2026, 3:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target environments. The post Kazuar: Anatomy of a nat…
https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet
sha256:c1b7bfacf9a68ea9d16524a6776075921cdaee3cb46eba9f825488b2874d7a66
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| domain | systemevents.sessionended | Open → |
| domain | systemevents.powermodechanged | Open → |
| domain | hpbprndiloc.dll | Open → |
| md5 | 82760b84f1d703d596c79b88ba4fac1e | Open → |
| sha256 | 69908f05b436bd97baae56296bf9b9e734486516f9bb9938c2b8752e152315d4 | Open → |
| sha256 | c1f278f88275e07cc03bd390fe1cbeedd55933110c6fd16de4187f4c4aaf42b9 | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| sha256 | 6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d | Open → |
| sha256 | 436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85 | Open → |