logo

Turla APT Targets Albania With Backdooor in Ongoing Campaign to Breach European Organizations

ID: 3a28d560-1224-5f96-b989-f4db74b311b2

STIX ID: report--3a28d560-1224-5f96-b989-f4db74b311b2

Feed Name: EclecticIQ

Threat Score
85/100

Date Published: 2024-04-10

Date Updated: 2026-04-27

Author: Aleksander W. Jarosz

...
...

This EclecticIQ research note reports discovery of a plaintext IP list uploaded from Albania that includes a known TinyTurla-NG command-and-control IP (91.193.18.120), linking the Russia-based Turla APT to regional targeting of Albania and other Baltic/Eastern European organizations; the report presents the file as authentic, lists multiple malicious IPs as indicators of compromise, and contextualizes the activity as part of an espionage-focused campaign against government-linked entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.