logo

Russia's Turla APT Abuses MSBuild to Deliver TinyTurla Backdoor

ID: 55c2bb0d-621e-5564-8289-3edb8be4cf69

STIX ID: report--55c2bb0d-621e-5564-8289-3edb8be4cf69

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-05-21

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

A Russia-linked APT (Turla) is conducting a targeted campaign against individuals and entities in the Philippines by sending socially engineered emails containing malicious .LNK files that write lure PDFs, encrypted data, and MSBuild project files to %temp%, then use MSBuild and PowerShell to deploy the TinyTurla fileless backdoor; the backdoor supports remote command execution, file upload/download, sleep adjustments, and uses PHP-based C2 infrastructure on compromised servers. Researchers recommend strong email filtering, restricting MSBuild usage, and limiting PowerShell execution to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.