Russia Hackers Using TinyTurla-NG to Breach European NGO's Systems
ID: b2df70f6-9c26-5051-bd7d-a2425384a7ec
STIX ID: report--b2df70f6-9c26-5051-bd7d-a2425384a7ec
Feed Name: The Hacker News
Threat Score
**Cisco Talos** attributes a targeted campaign to the Russia-linked APT group Turla that compromised systems at a European NGO and deployed the TinyTurla-NG backdoor; attackers created Microsoft Defender exclusions, established persistence via a masquerading "sdm" service, and used a custom Chisel tunnel for lateral movement and data exfiltration, with activity observed from October 2023 through January 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
