Adversary Intelligence — 2026-05-15

Microsoft Exposes FSB Center 16 Kazuar Botnet Targeting Foreign Ministries and Defense Departments Worldwide

BLUFKazuar's leader-election redesign and EWS-based C2 mark a deliberate FSB pivot toward survivable, low-signature collection inside hardened diplomatic and defense networks, eroding the network-detection assumptions defenders currently rely on.

On May 14, Microsoft Threat Intelligence published a technical analysis attributing Kazuar malware to Secret Blizzard, which CISA has publicly linked to Center 16 of Russia's FSB. Microsoft documents the malware's restructuring into a three-module peer-to-peer botnet in which a single elected Kernel leader handles all external C2 traffic while remaining nodes operate silently to limit network visibility. Worker modules execute keylogging, screenshot capture, file harvesting, and email enumeration via MAPI, staging collected data locally before periodic exfiltration over HTTP, WebSockets, or Exchange Web Services. The report identifies government, diplomatic, and defense organizations across Europe and Central Asia as the primary target set, including Ukrainian systems previously compromised by Aqua Blizzard.

Analysis
Kazuar's restructuring around a leader-election architecture signals that FSB Center 16 is engineering survivability directly into tooling for environments where defenders actively hunt for C2 traffic. Restricting all external communications to a single elected node while forcing every other infected host into silent mode eliminates the network-level signatures that conventional detection relies on. The host-bound payload encryption, which ties decryption to the target hostname, and the 150-variable configuration space point to precision targeting of specific environments rather than opportunistic mass infection. Targeting Aqua Blizzard-compromised Ukrainian systems suggests FSB is piggybacking on established access chains, consistent with interagency collection coordination under wartime intelligence requirements. Exchange Web Services as a C2 transport blends espionage traffic into routine enterprise email infrastructure, a deliberate design choice that challenges detection at diplomatic and defense organizations where EWS traffic is normal. The configuration's built-in blackout periods, which synchronize exfiltration to target-environment activity rhythms, reflect a long-duration collection mandate oriented toward sustained intelligence production rather than one-time exploitation.
4 sources
  1. Kazuar: Anatomy of a nation-state botnet - Microsoft Security Blog
  2. Microsoft: Russian hackers evolved Kazuar malware into stealthy P2P botnet - CyberInsider
  3. Kazuar: Anatomy of a nation-state botnet - TheWindowsUpdate
  4. Kazuar: Anatomy of a nation-state botnet - Malware News

View in full brief →

UNCLASSIFIED // OPEN SOURCE