Turla__2014__GData_Uroburos_RedPaper_EN_v1.pdf
ID: a3c363bd-a13d-4dbb-a18b-17e95b860254
STIX ID: report--a3c363bd-a13d-4dbb-a18b-17e95b860254
Threat Score
70/100
Uploaded: 2026-08-19
Published Date: 2014-02-28
Last Modified Date: 2014-02-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
G Data SecurityLabs analyzes Uroburos, a highly sophisticated rootkit designed to steal data and spy on high-profile targets. Composed of a driver and an encrypted virtual file system with persistence, stealth, and network exfiltration capabilities, it appears tailored for intelligence-gathering against governments, research institutions, and large enterprises, with attributed links to the Agent.BTZ operation and a suspected Russian-origin threat actor. The report notes the malware's modular design and its potential to expand further, though concrete infection vectors remain unknown.
