Turla living off other cybercriminals’ tools in order to attack Ukrainian targets
ID: 2d1c7a87-fb7d-5b12-a697-bc7b2544b5e3
STIX ID: report--2d1c7a87-fb7d-5b12-a697-bc7b2544b5e3
Feed Name: CyberScoop
Threat Score
Microsoft Threat Intelligence observed Turla (aka Secret Blizzard/Pensive Ursa), a Russian FSB-linked APT, co-opting the Amadey bot (a cybercrime tool) to deploy backdoors (Tavdig and KazuarV2) against Ukrainian military systems during a March–April 2024 campaign; the report highlights Turla's use of third-party infrastructure, strategic web compromises, adversary-in-the-middle techniques, and spear-phishing to achieve persistent espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
