Turla hackers backdoor NGOs with new TinyTurla-NG malware
ID: dba469b4-1525-536a-a054-3d3a6d7ac4b4
STIX ID: report--dba469b4-1525-536a-a054-3d3a6d7ac4b4
Feed Name: Bleeping Computer
Threat Score
Cisco Talos researchers discovered and analyzed TinyTurla-NG, a service DLL backdoor, and TurlaPower-NG PowerShell scripts used by the Russia-linked Turla APT to maintain persistence and exfiltrate sensitive data (notably password-manager master passwords) from NGOs; the campaign used compromised, vulnerable WordPress sites as C2/hosting and Talos published IOCs and a technical report detailing commands, functionality, and timeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
