Kazuar Backdoor Uses DLL Side-Loading and PowerShell Loaders for Stealthy Execution
ID: c40d171f-5bae-5638-9c00-f5de3fb4fc7d
STIX ID: report--c40d171f-5bae-5638-9c00-f5de3fb4fc7d
Feed Name: GBHackers
Threat Score
Turla’s Kazuar backdoor has resurfaced as a sophisticated persistence and reconnaissance capability that combines DLL side-loading with obfuscated PowerShell loaders and in-memory payload mapping to evade detection; operators leverage signed or benign host binaries and layered, environment-gated payloads with HTTPS/WebSocket and multi-hop C2 relays to conduct long-term espionage against government and military targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
