Russian APT Turla Wields Novel Backdoor Malware Against Polish NGOs
ID: b4cac446-1faf-598f-96e9-a84d6d79d4b1
STIX ID: report--b4cac446-1faf-598f-96e9-a84d6d79d4b1
Feed Name: Dark Reading
Date Published: 2024-02-15
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Russia-linked APT group Turla is conducting a targeted cyberespionage campaign against Polish NGOs supporting Ukraine, deploying a new modular service-DLL backdoor called TinyTurla-NG and a PowerShell exfiltration implant (TurlaPower-NG) to harvest credential databases and exfiltrate files; compromised WordPress sites are used as C2 infrastructure and Cisco Talos published IoCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
