Turla__2018__Eset-Turla-Outlook-Backdoor.pdf
ID: 4e908f96-8d0c-4a2a-a2dd-e74f92039494
STIX ID: report--4e908f96-8d0c-4a2a-a2dd-e74f92039494
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2018-08-13
Last Modified Date: 2018-08-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report delivers an in-depth analysis of the Turla Outlook backdoor, detailing how the Turla threat group uses a modular, email-driven malware that forwards outgoing emails, transmits commands and exfiltrated data via specially crafted PDF attachments, and persists through COM object hijacking across Microsoft Outlook and The Bat! clients, including its cryptographic and PDF-based command container architecture, indicators of compromise, and evidence of past and ongoing targeting of European governments and defense contractors.
