logo

Turla__2018__Uroburos_EN.pdf

ID: dfa2f2ac-7434-4b7b-bbb3-1b05fa336b5a

STIX ID: report--dfa2f2ac-7434-4b7b-bbb3-1b05fa336b5a

Threat Score

70/100

Uploaded: 2026-08-19

Published Date: 2018-02-09

Last Modified Date: 2018-02-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes the Uroburos (Turla) kernel-mode rootkit, detailing its 64-bit driver, memory hiding techniques, Windows callback abuse, NetIO callouts, encrypted strings, and covert HTTP communications, along with a PoC for remotely detecting a compromised server and a comparison between the 2014 and 2017 variants.