logo

Malware Technical Insight _Turla “Penquin_x64”.pdf

ID: 5f742864-696f-4ce3-b199-fe8fe522624e

STIX ID: report--5f742864-696f-4ce3-b199-fe8fe522624e

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2020-05-13

Last Modified Date: 2020-05-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical report analyses new 64-bit samples of the Turla Linux backdoor family (Penquin_x64), describing how the malware mimics cron, uses libpcap filters (a port‑knock–like activation) to remain stealthy, and derives a callback IP from crafted packets. It documents cryptography (Blowfish with Diffie‑Hellman key exchange), built‑in commands for remote file operations and execution (including peer-to-peer file operations), embedded legitimate cron binaries used for build‑date estimation (placing the latest builds after April 2016), MITRE ATT&CK mappings, extensive IOCs (SHA256 hashes) and YARA rules, and provides a Python proof‑of‑concept to activate the backdoor for defensive detection.