logo

Turla__2018__Turla_APT.pdf

ID: 8951ab0d-de7f-4a5a-9617-a390e60ddb6b

STIX ID: report--8951ab0d-de7f-4a5a-9617-a390e60ddb6b

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2018-02-21

Last Modified Date: 2018-02-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint analyzes Turla APT activity using KopiLuwak, a new .NET/MSIL and JavaScript-based backdoor delivered with a G20-related decoy document; the dropper writes stage components, installs a JS decryptor, and loads the KopiLuwak backdoor in memory, with persistence, system fingerprinting, and RC4-encrypted C2 communications, suggesting a sophisticated, reconnaissance-focused campaign that remains unobserved in the wild so far.