logo

TURLA’s New Phishing Campaign in Eastern Europe

ID: c6f4c33f-6c88-50c0-84e1-3dfde9c8aa29

STIX ID: report--c6f4c33f-6c88-50c0-84e1-3dfde9c8aa29

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2022-05-23

Date Updated: 2026-07-20

...
...

Sekoia TDR expanded on Google's TAG findings and identified a Turla (Russian-linked) reconnaissance and espionage campaign targeting the Baltic Defense College, the Austrian Federal Economic Chamber, and NATO's JDAL via typosquatted domains and weaponized DOCX files that load an external PNG. The remote image request allowed the actor to fingerprint Word versions and capture victim IPs; the report provides infrastructure IoCs (IPs and domains), document hashes, a YARA rule, and ATT&CK technique mappings attributed to TURLA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.