What Happened
On May 14, 2026, Microsoft's Security Blog published a detailed analysis of Kazuar — a backdoor operated by Turla (also known as Secret Blizzard, Venomous Bear, and Waterbug), a Russian state-sponsored APT group linked to the FSB. The report revealed that Turla has transformed Kazuar from a traditional command-and-control (C2) backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistent access to government and diplomatic networks.
BleepingComputer reported that the upgraded Kazuar now uses a decentralized P2P communication architecture, making it significantly harder to disrupt through traditional C2 takedown operations. The campaign has primarily targeted government entities, diplomatic missions, and defense organizations across Europe and Central Asia.
Technical Analysis
Kazuar is not new — Turla has operated variants of this backdoor since at least 2017. What changed in 2026 is the architecture. Palo Alto Networks' Unit 42 tracked the upgraded variant (which they call "Pensive Ursa") and documented the following technical evolution:












