logo

Turla hackers backdoor NGOs with new TinyTurla-NG malware

ID: dba469b4-1525-536a-a054-3d3a6d7ac4b4

STIX ID: report--dba469b4-1525-536a-a054-3d3a6d7ac4b4

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-15

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Cisco Talos researchers discovered and analyzed TinyTurla-NG, a service DLL backdoor, and TurlaPower-NG PowerShell scripts used by the Russia-linked Turla APT to maintain persistence and exfiltrate sensitive data (notably password-manager master passwords) from NGOs; the campaign used compromised, vulnerable WordPress sites as C2/hosting and Talos published IOCs and a technical report detailing commands, functionality, and timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.