Microsoft Exposes FSB Center 16 Kazuar Botnet Targeting Foreign Ministries and Defense Departments Worldwide
On May 14, Microsoft Threat Intelligence published a technical analysis attributing Kazuar malware to
Kazuar's restructuring around a leader-election architecture signals that FSB Center 16 is engineering survivability directly into tooling for environments where defenders actively hunt for C2 traffic. Restricting all external communications to a single elected node while forcing every other infected host into silent mode eliminates the network-level signatures that conventional detection relies on. The host-bound payload encryption, which ties decryption to the target hostname, and the 150-variable configuration space point to precision targeting of specific environments rather than opportunistic mass infection. Targeting Aqua Blizzard-compromised Ukrainian systems suggests FSB is piggybacking on established access chains, consistent with interagency collection coordination under wartime intelligence requirements. Exchange Web Services as a C2 transport blends espionage traffic into routine enterprise email infrastructure, a deliberate design choice that challenges detection at diplomatic and defense organizations where EWS traffic is normal. The configuration's built-in blackout periods, which synchronize exfiltration to target-environment activity rhythms, reflect a long-duration collection mandate oriented toward sustained intelligence production rather than one-time exploitation.
4 sources
- Kazuar: Anatomy of a nation-state botnet -
Microsoft Security Blog - Microsoft: Russian hackers evolved Kazuar malware into stealthy P2P botnet -
CyberInsider - Kazuar: Anatomy of a nation-state botnet -
TheWindowsUpdate - Kazuar: Anatomy of a nation-state botnet -
Malware News