Turla__2016__Report_Ruag-Espionage-Case.pdf
ID: e1d3497c-d76a-4dcc-ab34-b40ffec3c646
STIX ID: report--e1d3497c-d76a-4dcc-ab34-b40ffec3c646
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2016-05-19
Last Modified Date: 2016-05-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
GovCERT's RUAG Technical Report analyzes a long-running cyber espionage operation attributed to the Turla/Tavdig actor group, describing recon tools and stage-2 trojans, the use of Carbon-DLL and Tavdig, a hierarchical botnet, communication via named pipes and HTTP-based C2, extensive fingerprinting and information gathering, persistence and lateral movement within Active Directory, data exfiltration of approximately 23 GB, and comprehensive recommendations across system, AD, and network controls to detect and mitigate such attacks.
