Turla__2020__Tracking_Turla_New_backdoor_delivered_via_Armenian_watering_holes_WeLiveSecurity.pdf
ID: 03273118-5913-4379-9b8a-9bb417a48772
STIX ID: report--03273118-5913-4379-9b8a-9bb417a48772
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2020-03-13
Last Modified Date: 2020-03-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers report a Turla watering hole campaign targeting Armenian government and related sites, injecting obfuscated JavaScript to load fingerprinting data and delivering two new backdoors, NetFlash and PyFlash, through a fake Adobe Flash update; NetFlash uses a .NET downloader with scheduled tasks and PyFlash is a Python-based backdoor that communicates over HTTP, accompanied by IoCs and MITRE techniques.
