Turla__2018__Turla_APT.pdf
ID: 8951ab0d-de7f-4a5a-9617-a390e60ddb6b
STIX ID: report--8951ab0d-de7f-4a5a-9617-a390e60ddb6b
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2018-02-21
Last Modified Date: 2018-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint analyzes Turla APT activity using KopiLuwak, a new .NET/MSIL and JavaScript-based backdoor delivered with a G20-related decoy document; the dropper writes stage components, installs a JS decryptor, and loads the KopiLuwak backdoor in memory, with persistence, system fingerprinting, and RC4-encrypted C2 communications, suggesting a sophisticated, reconnaissance-focused campaign that remains unobserved in the wild so far.
