logo

Russian APT Turla Wields Novel Backdoor Malware Against Polish NGOs

ID: b4cac446-1faf-598f-96e9-a84d6d79d4b1

STIX ID: report--b4cac446-1faf-598f-96e9-a84d6d79d4b1

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-02-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Russia-linked APT group Turla is conducting a targeted cyberespionage campaign against Polish NGOs supporting Ukraine, deploying a new modular service-DLL backdoor called TinyTurla-NG and a PowerShell exfiltration implant (TurlaPower-NG) to harvest credential databases and exfiltrate files; compromised WordPress sites are used as C2 infrastructure and Cisco Talos published IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.