Russia's Turla APT Abuses MSBuild to Deliver TinyTurla Backdoor
ID: 55c2bb0d-621e-5564-8289-3edb8be4cf69
STIX ID: report--55c2bb0d-621e-5564-8289-3edb8be4cf69
Feed Name: Dark Reading
Date Published: 2024-05-21
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A Russia-linked APT (Turla) is conducting a targeted campaign against individuals and entities in the Philippines by sending socially engineered emails containing malicious .LNK files that write lure PDFs, encrypted data, and MSBuild project files to %temp%, then use MSBuild and PowerShell to deploy the TinyTurla fileless backdoor; the backdoor supports remote command execution, file upload/download, sleep adjustments, and uses PHP-based C2 infrastructure on compromised servers. Researchers recommend strong email filtering, restricting MSBuild usage, and limiting PowerShell execution to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
