logo

Kazuar Backdoor Uses DLL Side-Loading and PowerShell Loaders for Stealthy Execution

ID: c40d171f-5bae-5638-9c00-f5de3fb4fc7d

STIX ID: report--c40d171f-5bae-5638-9c00-f5de3fb4fc7d

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-07-07

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Turla’s Kazuar backdoor has resurfaced as a sophisticated persistence and reconnaissance capability that combines DLL side-loading with obfuscated PowerShell loaders and in-memory payload mapping to evade detection; operators leverage signed or benign host binaries and layered, environment-gated payloads with HTTPS/WebSocket and multi-hop C2 relays to conduct long-term espionage against government and military targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.