Microsoft has discovered that cyber threat group Secret Blizzard has been using the Amadey malware to target devices, including Ukrainian military equipment. The malware is used to download a PowerShell dropper on devices, which then installs the Tavdig backdoor to conduct reconnaissance and gather user data. Secret Blizzard is also believed to have used other groups’ tools to install backdoors and collect data across several regions.
