logo

Turla__2020__Tracking_Turla_New_backdoor_delivered_via_Armenian_watering_holes_WeLiveSecurity.pdf

ID: 03273118-5913-4379-9b8a-9bb417a48772

STIX ID: report--03273118-5913-4379-9b8a-9bb417a48772

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2020-03-13

Last Modified Date: 2020-03-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers report a Turla watering hole campaign targeting Armenian government and related sites, injecting obfuscated JavaScript to load fingerprinting data and delivering two new backdoors, NetFlash and PyFlash, through a fake Adobe Flash update; NetFlash uses a .NET downloader with scheduled tasks and PyFlash is a Python-based backdoor that communicates over HTTP, accompanied by IoCs and MITRE techniques.