logo

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

ID: 167cda66-8682-5b4f-97e7-2a475fd30f6f

STIX ID: report--167cda66-8682-5b4f-97e7-2a475fd30f6f

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: [email protected] (The Hacker News)

...
...

Microsoft and industry reporting describe Turla (Secret Blizzard), a Russia-linked APT, transforming the Kazuar .NET backdoor into a modular P2P botnet comprising Kernel, Bridge, and Worker modules to enable stealthy, resilient long-term access to government, diplomatic, and defense targets; the architecture uses multiple inter-module channels and external communication methods, stages data in a dedicated working directory for encrypted exfiltration, and is deployed via droppers such as Pelmeni and ShadowLoader.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.