logo

Turla__2014__circl-tr25-analysis-turla-pfinet-snake-uroburos.pdf

ID: adfc70bd-2067-4636-9a8e-cda3e7f77dff

STIX ID: report--adfc70bd-2067-4636-9a8e-cda3e7f77dff

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
TR-25 analyzes the Uroburos (Turla/Snake/Uroburos) rootkit, summarizing static and dynamic analyses of samples A–H. It details a multi‑component infection with a kernel‑mode driver (usbdev.sys) and several userland modules (inetpub.dll, cryptoapi.dll, config.txt), persistence via services, resource‑driven drops, inter‑process communication, mutexes for access control, a virtual file system, and decryption routines; the report also documents IOCs, transport modules (tcp/np/frag/m2b), check‑in messages, and extensive logging, indicating a sophisticated state‑sponsored malware framework attributed to the Turla group.