Turla Backdoor Evades Detection Via MSBuild Exploit
ID: 2734dc8a-02b2-5e7a-b960-57d2cdeef8bc
STIX ID: report--2734dc8a-02b2-5e7a-b960-57d2cdeef8bc
Feed Name: Cyble Blog
This Cyble report describes a phishing campaign delivering a Tiny Backdoor via malicious .LNK files that extract a lure PDF, encrypted payloads and MSBuild project files; MSBuild.exe is abused to execute inline tasks in-memory resulting in a persistent, remote-control backdoor communicating with a compromised C2 domain (ies.inquirer.com.ph). The report includes step‑by‑step technical analysis, IOCs (hashes and domain), a YARA rule, MITRE ATT&CK mappings, mitigation recommendations, and attributes the activity to the Turla APT with medium confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
