Russian APT Turla builds long-term access tool with Kazuar Botnet evolution
ID: 48449ecb-ad57-5db7-b6d5-8ae9b3296be6
STIX ID: report--48449ecb-ad57-5db7-b6d5-8ae9b3296be6
Feed Name: Security Affairs
**Executive summary:** Russia-linked APT Turla (aka Secret Blizzard) has upgraded its Kazuar backdoor into a modular peer-to-peer botnet designed for stealthy, resilient, long-term espionage; the report details Kernel/Bridge/Worker components, leader-election P2P communications, multiple C2 fallbacks (HTTP, WebSockets, Exchange Web Services), extensive data-collection capabilities (keylogging, screenshots, file harvesting, Outlook monitoring), and operational artefacts such as a staged working directory and Protobuf-based messaging, with guidance to focus on behaviors rather than individual samples for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
