logo

TinyTurla-NG in-depth tooling and command and control analysis

ID: c33db217-187e-51db-9643-c159a4b1c2aa

STIX ID: report--c33db217-187e-51db-9643-c159a4b1c2aa

Feed Name: Cisco Talos

Threat Score
88/100

Date Published: 2024-02-22

Date Updated: 2026-04-27

Author: Asheer Malhotra

...
...

**Executive summary:** Cisco Talos, working with CERT.NGO, analyzes a Turla APT campaign that abused compromised WordPress sites as PHP-based C2/web shells to manage TinyTurla-NG and TurlaPower-NG implants, used PowerShell modules for file enumeration, staging, and exfiltration (including credential harvesting of Edge/Chrome and Firefox profiles), and deployed a modified Chisel tunneling client plus a privilege-impersonation tool; the report includes detailed C2 behavior and IOCs (file hashes, domains, and IP 91.193.18.120).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.