Russian Turla Hackers Target Polish NGOs with New TinyTurla-NG Backdoor
ID: 37761192-119e-5d4a-b51f-1626d4f244da
STIX ID: report--37761192-119e-5d4a-b51f-1626d4f244da
Feed Name: The Hacker News
Threat Score
Cisco Talos and reporting describe a Turla (Russia-linked) targeted campaign using a new "TinyTurla-NG" backdoor against Polish NGOs in late 2023–early 2024; the implant uses compromised WordPress sites as C2, executes commands via PowerShell/cmd, and delivers TurlaPower-NG to harvest and exfiltrate password-manager secrets, with additional tooling (modified Chisel, credential-harvesting scripts) observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
