logo

Turla living off other cybercriminals’ tools in order to attack Ukrainian targets

ID: 2d1c7a87-fb7d-5b12-a697-bc7b2544b5e3

STIX ID: report--2d1c7a87-fb7d-5b12-a697-bc7b2544b5e3

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2024-12-11

Date Updated: 2026-04-21

Author: Greg Otto

...
...

Microsoft Threat Intelligence observed Turla (aka Secret Blizzard/Pensive Ursa), a Russian FSB-linked APT, co-opting the Amadey bot (a cybercrime tool) to deploy backdoors (Tavdig and KazuarV2) against Ukrainian military systems during a March–April 2024 campaign; the report highlights Turla's use of third-party infrastructure, strategic web compromises, adversary-in-the-middle techniques, and spear-phishing to achieve persistent espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.