logo

TinyTurla Next Generation - Turla APT spies on Polish NGOs

ID: cad2250d-bb4e-5844-94c0-ebade79db648

STIX ID: report--cad2250d-bb4e-5844-94c0-ebade79db648

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2024-02-15

Date Updated: 2026-04-27

Author: Asheer Malhotra

...
...

Cisco Talos discovered and analyzed TinyTurla-NG, a new backdoor attributed to the Russian Turla APT, and associated TurlaPower-NG PowerShell exfiltration scripts used to target Polish NGOs supporting Ukraine; the report details the backdoor's service-DLL architecture, C2 communication via compromised WordPress sites, command capabilities (including file exfiltration and credential-harvesting focus), persistence/cleanup behaviors, and provides hashes, domains and other IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.