Turla__2019__A_dive_into_Turla_PowerShell_usage.pdf
ID: 8140bee4-3673-4f41-97b4-5af2cb3c5963
STIX ID: report--8140bee4-3673-4f41-97b4-5af2cb3c5963
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2019-05-30
Last Modified Date: 2019-05-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Threat intelligence detailing Turla's multi-component intrusion toolkit, including PowerShell loaders with in-memory execution, WMI persistence, AMSI bypass, RPC backdoors, and PowerStallion using OneDrive for C2, supported by indicators of compromise and MITRE ATT&CK mapping.
