logo

Turla__2018__Eset-Turla-Outlook-Backdoor.pdf

ID: 4e908f96-8d0c-4a2a-a2dd-e74f92039494

STIX ID: report--4e908f96-8d0c-4a2a-a2dd-e74f92039494

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2018-08-13

Last Modified Date: 2018-08-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report delivers an in-depth analysis of the Turla Outlook backdoor, detailing how the Turla threat group uses a modular, email-driven malware that forwards outgoing emails, transmits commands and exfiltrated data via specially crafted PDF attachments, and persists through COM object hijacking across Microsoft Outlook and The Bat! clients, including its cryptographic and PDF-based command container architecture, indicators of compromise, and evidence of past and ongoing targeting of European governments and defense contractors.