Malware Technical Insight _Turla “Penquin_x64”.pdf
ID: 5f742864-696f-4ce3-b199-fe8fe522624e
STIX ID: report--5f742864-696f-4ce3-b199-fe8fe522624e
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2020-05-13
Last Modified Date: 2020-05-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical report analyses new 64-bit samples of the Turla Linux backdoor family (Penquin_x64), describing how the malware mimics cron, uses libpcap filters (a port‑knock–like activation) to remain stealthy, and derives a callback IP from crafted packets. It documents cryptography (Blowfish with Diffie‑Hellman key exchange), built‑in commands for remote file operations and execution (including peer-to-peer file operations), embedded legitimate cron binaries used for build‑date estimation (placing the latest builds after April 2016), MITRE ATT&CK mappings, extensive IOCs (SHA256 hashes) and YARA rules, and provides a Python proof‑of‑concept to activate the backdoor for defensive detection.
