TF-MAL-elf.penquin_turla
📛 Threat Title
Malware family: Penquin Turla
Description
ThreatFox malware family `elf.penquin_turla`. Printable name: Penquin Turla.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014. [1] [2]
-
web:attackevals.github.io
CARBON-DLL downloads the PENQUIN malware to Adalwolfa's workstation, the SSH credentials allows the attackers to copy PENQUIN to the Apache server and execute the malware via plink. PENQUIN is utilized to install a watering hole causing users browsing a legitimate HTML site to be redirected to the malicious, attacker-controlled site.
-
web:github.com
APT_REPORT / Turla / Malware Technical Insight _ Turla "Penquin_x64".pdf Cannot retrieve latest commit at this time.
-
web:lab52.io
During 2020 Leonardo analysts discovered and published a very in depth analysis of a threat known as Penquin , attributed to the APT group Turla . 32-bit samples of this threat had been detected and analyzed by Kaspersky before, but the analysis in this most recent publication was focused on a new 64-bit sample.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Penquin Turla malware family including references, samples and yara signatures.
-
web:medium.com
The first attack flow diagrams the Day 1 scenario — Turla using EPIC, CARBON, and PENQUIN malware to target Windows and Linux systems and establish a watering hole.
-
web:redteam.y-security.de
Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014. 12
-
web:studylib.net
In-depth technical analysis of Turla's Penquin_x64 malware , its capabilities, evolution, and indicators of compromise. Cybersecurity report.
-
web:thrive.trellix.com
How to use this article: If a Threat Hunting table has been created, use the rules contained to search for malware related to this campaign. Review the product detection table and confirm that your environment is at least on the specified content version. To download the latest content versions, go to the Security Updates page.
-
web:www.leonardo.com
In December 2014, Kaspersky reported on a tool attributed to the Turla intrusion set used to target the Linux Operating System: they named it " Penquin " Turla . In 2017, more information about this threat was discovered1. Since then, almost three years have passed with no new information being discovered about this specific threat, until now.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.