Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-14 and was added to the RWP archive on 2026-09-07.
Kazuar stopped being a backdoor and became an FSB P2P botnet with a local leader
Microsoft's May 2026 anatomy of Kazuar shows Secret Blizzard (Turla / FSB Center 16) electing one infected host as the only egress, then talking Kernel-Bridge-Worker over IPC.
Bottom line up front
CONFIRMED On 14 May 2026 Microsoft published the architecture of Kazuar as used by Secret Blizzard (Turla, VENOMOUS BEAR, Snake lineage; CISA: FSB Center 16). It is no longer a single C2 backdoor. Microsoft describes a modular Kernel / Plugin / Bridge design, 150-plus config parameters, patchless AMSI/ETW bypasses, and leader election so only one host in the victim network talks out — over HTTPS, DNS, named pipes, SMB, TCP, UDP, or WebSockets. Targets: government and diplomatic orgs in Europe and Central Asia, plus reuse of Aqua Blizzard-compromised Ukrainian systems. Publishing this level of detail is itself a disruption play.
Historical backfill of 14 May 2026 reporting; added 7 September 2026.
What happened
Symantec/Broadcom's same-week bulletin treats Waterbug as the overlap name and points detections at the family, not one hash. CISA's older Snake advisory is the lineage, not this build.
Why it mattered
Netflow to "the C2" will miss a botnet that relays internally. IR that images one noisy host may miss the elected Bridge.
OT: UNKNOWN. Diplomatic/government targeting is IT espionage unless a specific ICS victim is named.
Who / what was affected
Microsoft-named sectors/regions. Counts UNKNOWN.
Technical context
Hunt IPC, unexpected named pipes/SMB between workstations, staging directories, and a single host with weird egress while siblings are quiet. Do not wait for a domain IOC.
Exploitation / threat status at the time
CONFIRMED Microsoft architecture and attribution.
ASSESSED (high): public teardown forces rotation, not retirement.
What defenders should have done
- East-west detections for workstation-to-workstation C2-like traffic.
- Memory hunting for AMSI/ETW patchless bypasses.
- Assume Snake-class persistence if Secret Blizzard is in the threat model.
RWP assessment
Confidence: High. This is how you stay in a ministry for years without a loud beacon.
Defensive actions
- Segment workstations; workstations should not peer-admin each other.
- EDR that sees named pipes and SMB between endpoints.
- Diplomatic/defense orgs: treat this as current, not historical Turla lore.
Sources
- Microsoft Threat Intelligence — Kazuar: anatomy of a nation-state botnet
- Broadcom Symantec — Kazuar Botnet protection bulletin
- CISA — Hunting Russian Intelligence Snake malware (AA23-129A)