Microsoft and Lumen's Black Lotus Labs find Russia-linked Turla hackers hijacked Pakistan-based hackers' servers to launch their own attacks since December 2022
The notorious Russian cyber-espionage group Turla is hacking other hackers, hijacking the Pakistani threat actor Storm-0156's infrastructure …
Context & Ripple Effects
Turla has repeatedly used others’ infrastructure or tooling to conceal its operations: related coverage documented its reuse of malware from another hacking operation and earlier use of hijacked satellite internet links for anonymity.
The reported takeover of Storm-0156 servers extends that operational pattern from borrowed access and communications channels to another threat actor’s active infrastructure. It matters because infrastructure ownership becomes a weaker signal of who is actually behind an intrusion.
First-order effects
- Storm-0156’s server infrastructure was used by Turla, compromising the Pakistani group’s operational control and obscuring the origin of attacks launched from those systems.
- Microsoft and Lumen’s finding gives defenders a concrete reason to reassess activity associated with the hijacked servers rather than attributing it solely to their apparent operators.
Second-order effects
- Threat-intelligence teams will need to weigh malware, tactics, and command patterns more heavily than server ownership when separating overlapping campaigns.
- Hosting and network defenders may face a more complex cleanup task: removing one actor from compromised servers may not reveal or evict every group using the same infrastructure.
Third-order effects
- If this pattern broadens, criminal and state-linked infrastructure will increasingly function as a contested intermediary layer, making conventional infrastructure-based attribution less reliable.
- The durable shift is toward attribution built from corroborated behavioral evidence rather than single indicators such as an IP address, domain, or server operator.
The trend: This is a data point in the broader trend of advanced threat groups treating other actors’ compromised infrastructure as a reusable anonymity and access layer.