Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Dec 21, 2021 | Updated Aug 07, 2023

Trojan:MSIL/Kazuar.B!sms

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Trojan:MSIL/Kazuar.B!sms is memory-based detection of Kazuar backdoor which has been linked to the threat actor Secret Blizzard.

The threat actors have specifically targeted files containing messages from the Signal Desktop messaging application and documents, images, and archive files on targeted systems.

Guidance for Individual users

  • Keep your operating system and antivirus products up to date. Customers who have turned on automatic updates do not need to take additional action

Take these steps to help prevent malware infection on your computer.

Guidance for enterprise administrators and Microsoft 365 Defender customers

Ransomware more than often attacks enterprises than individuals. Following the below mitigation steps can help prevent ransomware attacks.

Microsoft recommends the following mitigations to reduce the impact of activity associated with Storm-0978’s operations.

Follow us