Turla PNG Dropper is back
ID: 8417d278-a54b-54c8-a628-7324fe7bbf67
STIX ID: report--8417d278-a54b-54c8-a628-7324fe7bbf67
Feed Name: NCC Research
## Executive summary This blog post analyzes a Turla Group toolchain: a PNG Dropper that encodes PE files into PNG resources and an associated service component, RegRunnerSvc, which enumerates the registry to locate a 0x200-byte blob, uses CNG/BCrypt to derive an AES key from a system KSP key, decrypts an AES-encrypted PE and manually maps and executes it; the report includes Yara rules, two sample SHA256 hashes, the fake service name WerFaultSvc, and a link to a payload-extraction tool.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
