TF-MAL-elf.turla_rat
📛 Threat Title
Malware family: Turla RAT
Description
ThreatFox malware family `elf.turla_rat`. Printable name: Turla RAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Turla Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies.
-
web:blog.netmanageit.com
Description Turla's group names are infamously titled after its top-class rootkits such as Snake, Venomous Bear, WhiteBear, Uroburos, Group 88, and Waterbug, all known for targeting government entities, intelligence agencies, as well as the military, educational, research, and pharmaceutical industries around the world. Like other APT groups, Turla possesses its own specifically-designed ...
-
web:cristianthous.com
The group's previous activities have included the deployment of the *Remote Access Trojan ( RAT )* and other sophisticated malware . The transformation of Kazuar into a P2P botnet reflects a growing trend among advanced persistent threat (APT) groups to leverage modular architectures that complicate detection and mitigation efforts.
-
web:cyble.com
Cyble investigates Turla , a Russian state-linked APT group using advanced malware , stealth tactics, and global espionage campaigns.
-
web:eurepoc.eu
In 2018, in its annual report, the Estonian Foreign Intelligence Service attributed Turla to the Russian domestic intelligence agency FSB. In 2016, the Federal Office for the Protection of the Constitution, Germany's domestic intelligence service, referred to Turla as a state-directed operation. At the time, the Office did not publicly attribute related activities to Russia as a sponsoring ...
-
web:malpedia.caad.fkie.fraunhofer.de
A 2014 Guardian article described Turla as: 'Dubbed the Turla hackers, initial intelligence had indicated western powers were key targets, but it was later determined embassies for Eastern Bloc nations were of more interest. Embassies in Belgium, Ukraine, China, Jordan, Greece, Kazakhstan, Armenia, Poland, and Germany were all attacked, though researchers from Kaspersky Lab and Symantec could ...
-
web:thehackernews.com
The fact that Gamaredon's toolset lacks any .NET malware and Turla's Kazuar is based in .NET suggests this data gathering step is likely meant for Turla , the company assessed with medium confidence.
-
web:unit42.paloaltonetworks.com
A threat assessment of Turla (aka Pensive Ursa) breaks down this Russian-based APT's arsenal and techniques used, covering the top 10 active malware employed.
-
web:www.cisa.gov
This MAR includes suggested response actions and recommended mitigation techniques. FBI has high-confidence that Russian-sponsored APT actor Turla , which is an espionage group active for at least a decade, is using ComRAT malware to exploit victim networks. The group is well known for its custom tools and targeted operations.
-
web:www.hivepro.com
Attack Details #1 In December 2023, the Russian hacker group Turla employed new malware , named TinyTurla-NG and TurlaPower-NG, to gather sensitive data and maintain access to a targeted network. The threat actor utilized malicious PowerShell scripts and took advantage of several websites running vulnerable versions of WordPress for their C2 operations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.