TinyTurla Next Generation - Turla APT spies on Polish NGOs
ID: cad2250d-bb4e-5844-94c0-ebade79db648
STIX ID: report--cad2250d-bb4e-5844-94c0-ebade79db648
Feed Name: Cisco Talos
Threat Score
Cisco Talos discovered and analyzed TinyTurla-NG, a new backdoor attributed to the Russian Turla APT, and associated TurlaPower-NG PowerShell exfiltration scripts used to target Polish NGOs supporting Ukraine; the report details the backdoor's service-DLL architecture, C2 communication via compromised WordPress sites, command capabilities (including file exfiltration and credential-harvesting focus), persistence/cleanup behaviors, and provides hashes, domains and other IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
